All Categories → Security → sysmon

Top 23 sysmon open source projects

Detectionlab
Automate the creation of a lab environment complete with security tooling and logging best practices
Threathunter Playbook
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
Malwless
Test Blue Team detections without running any attack.
Windowsspyblocker
WindowsSpyBlocker 🛡️ is an application written in Go and delivered as a single executable to block spying and tracking on Windows systems.
Whids
Open Source EDR for Windows
Attack monitor
Endpoint detection & Malware analysis software
Shhmon
Neutering Sysmon via driver unload
Windows event logging
Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technical Guidance for Windows Event Logging.
Sysmon Modular
A repository of sysmon configuration modules
Sentinel Attack
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Sysmon Dfir
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
✭ 654
sysmon
Sysmonsearch
Investigate suspicious activity by visualizing Sysmon's event log
Sysmon Config
Sysmon configuration file template with default high-quality event tracing
sysmon-splunk-app
Sysmon Splunk App
system-monitor
Qt based replacement for gnome system monitor
SysmonResources
Consolidation of various resources related to Microsoft Sysmon & sample data/log
SWELF
Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
Zircolite
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
TA-Sysmon-deploy
Deploy and maintain Symon through the Splunk Deployment Sever
1-23 of 23 sysmon projects