COLLECTED BY
Organization:
Internet Archive
Focused crawls are collections of frequently-updated webcrawl data from narrow (as opposed to broad or wide) web crawls, often focused on a single domain or subdomain.
The Wayback Machine - https://web.archive.org/web/20221029163211/https://github.com/topics/sysmon
Here are
86 public repositories
matching this topic...
Generic Signature Format for SIEM Systems
Updated
Oct 29, 2022
Python
Automate the creation of a lab environment complete with security tooling and logging best practices
Updated
Oct 22, 2022
HTML
Sysmon configuration file template with default high-quality event tracing
Block spying and tracking on Windows
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
Updated
Sep 14, 2022
Python
A repository of sysmon configuration modules
Updated
Oct 3, 2022
PowerShell
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Open Source EDR for Windows
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
Updated
Oct 21, 2022
Batchfile
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
Updated
Oct 8, 2022
Python
Investigate suspicious activity by visualizing Sysmon's event log
Updated
Jul 6, 2022
JavaScript
Test Blue Team detections without running any attack.
Endpoint detection & Malware analysis software
Updated
Dec 20, 2019
Python
系统监控开发套件(sysmon、promon、edr、终端安全、主机安全、零信任、上网行为管理)
戎码之眼是一个window上的基于att&ck模型的威胁监控工具.有效检测常见的未知威胁与已知威胁.防守方的利剑
Updated
Oct 19, 2022
Python
Neutering Sysmon via driver unload
Sysmon EDR POC Build within Powershell to prove ability.
Updated
May 1, 2021
PowerShell
Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technical Guidance for Windows Event Logging.
Updated
Apr 28, 2022
PowerShell
Improve this page
Add a description, image, and links to the
sysmon
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
sysmon
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.