DCSYNCMonitor
by shellster
Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.
AI summary
DC Synchronization Monitor
Detects unauthorized Domain Controller synchronization attempts and logs alerts to the Windows Event Log.
- stars
- 138
- forks
- 33
- watching
- 7
Similar projects
Found by comparing what the projects do, not just their names.
Interface manager
Automates Suricata monitoring interface configuration and detection thread allocation based on real-time network interface status changes.
Event log analyzer
Analyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations.
Event processor
A fast and extensible system for processing JSON events from security monitoring tools
Logon monitor
A system for detecting and responding to potential insider threats in an Active Directory environment by monitoring for unauthorized logon attempts
droe/xnumon230
Process Monitor
Monitors macOS systems for malicious activity by tracking process activity and system calls
Event log analyzer
A PowerShell module for analyzing Windows event logs to detect and respond to potential security threats.
Systray monitor
A command-line program that monitors and controls the systray on Windows.
DCOM scanner
Automates enumeration of vulnerable DCOM applications to aid in lateral movement and exploitation testing
Monitor
Automated monitoring of application health using Docker containers and scheduled checks
ETW monitor
A tool for monitoring and detecting malicious activity via ETW events
Alarm Monitor
Monitors alarm directory of a SUN Storagetek Common Array Manager and reports alerts to Nagios.
Cluster Monitor
A command-line tool to monitor the status of a MongoDB cluster in real-time.
DNS monitor
A toolkit for monitoring and analyzing DNS traffic to help security teams understand an organization's DNS activity
Command monitor
A plugin for zsh that uses another tool to notify users when long-running commands exceed a threshold.
Log analyzer
Automates analysis of Windows Security Events to identify user logon relations