SysmonTools

Event log analyzer

Utilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity.

Utilities for Sysmon

GitHub

1k stars
94 watching
204 forks
last commit: over 2 years ago
Linked from 1 awesome list

loggingmonitoringnetsecsysinternalssysmonthreat-huntingthreat-intelligencethreatintelwindows

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
jpcertcc/sysmonsearchAnalyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations.419
swiftonsecurity/sysmon-configA template configuration file for Microsoft Sysinternals' Sysmon to monitor system changes with high-quality event tracing.4,828
thiber-org/userlineAutomates analysis of Windows Security Events to identify user logon relations241
mhaggis/sysmon-dfirA curated collection of resources and tools for learning and implementing Microsoft Sysmon for incident detection, threat hunting, and endpoint security monitoring.901
yamato-security/welaAnalyzes Windows Event Logs to identify security-related events and provides forensic tools for incident response.769
sans-blue-team/deepbluecliA PowerShell module for analyzing Windows event logs to detect and respond to potential security threats.2,203
ion-storm/sysmon-configA configuration package for advanced system monitoring using Sysmon, designed to detect and alert on various threat activities and provide forensic visibility.780
reed1713/elatA toolset for analyzing Windows event logs to detect and analyze malware29
activecm/beakerAggregates Microsoft Sysmon network events with Elasticsearch and Kibana for threat hunting analysis287
wagga40/zircoliteA standalone tool for analyzing and detecting security-related events in various Linux logs using SIGMA rules684
scarredmonk/sysmonsimulatorA utility to simulate Windows event logs for testing EDR detections and correlation rules836
sivasamyk/logtrailA Kibana plugin to view, analyze, and search log events from multiple hosts in real-time with a centralized interface.1,398
yamato-security/enablewindowslogsettingsEnables Windows event log settings to support a larger percentage of Sigma detection rules and retain logs for longer periods571
zqqf16/symAn app for processing and analyzing crash logs from various frameworks597