All Projects → MHaggis → Sysmon Dfir

MHaggis / Sysmon Dfir

Licence: gpl-3.0
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.

Labels

Projects that are alternatives of or similar to Sysmon Dfir

Windows event logging
Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technical Guidance for Windows Event Logging.
Stars: ✭ 128 (-80.43%)
Mutual labels:  sysmon
TA-Sysmon-deploy
Deploy and maintain Symon through the Splunk Deployment Sever
Stars: ✭ 31 (-95.26%)
Mutual labels:  sysmon
sysmon-splunk-app
Sysmon Splunk App
Stars: ✭ 42 (-93.58%)
Mutual labels:  sysmon
Attack monitor
Endpoint detection & Malware analysis software
Stars: ✭ 186 (-71.56%)
Mutual labels:  sysmon
Threathunter Playbook
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
Stars: ✭ 2,879 (+340.21%)
Mutual labels:  sysmon
SWELF
Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
Stars: ✭ 23 (-96.48%)
Mutual labels:  sysmon
Sysmontools
Utilities for Sysmon
Stars: ✭ 903 (+38.07%)
Mutual labels:  sysmon
Sysmonsearch
Investigate suspicious activity by visualizing Sysmon's event log
Stars: ✭ 302 (-53.82%)
Mutual labels:  sysmon
Detectionlab
Automate the creation of a lab environment complete with security tooling and logging best practices
Stars: ✭ 3,237 (+394.95%)
Mutual labels:  sysmon
system-monitor
Qt based replacement for gnome system monitor
Stars: ✭ 16 (-97.55%)
Mutual labels:  sysmon
Whids
Open Source EDR for Windows
Stars: ✭ 188 (-71.25%)
Mutual labels:  sysmon
Malwless
Test Blue Team detections without running any attack.
Stars: ✭ 215 (-67.13%)
Mutual labels:  sysmon
SysmonResources
Consolidation of various resources related to Microsoft Sysmon & sample data/log
Stars: ✭ 64 (-90.21%)
Mutual labels:  sysmon
Shhmon
Neutering Sysmon via driver unload
Stars: ✭ 166 (-74.62%)
Mutual labels:  sysmon
ir scripts
incident response scripts
Stars: ✭ 17 (-97.4%)
Mutual labels:  sysmon
Sysmon Modular
A repository of sysmon configuration modules
Stars: ✭ 1,229 (+87.92%)
Mutual labels:  sysmon
Zircolite
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
Stars: ✭ 443 (-32.26%)
Mutual labels:  sysmon
Sigma
Generic Signature Format for SIEM Systems
Stars: ✭ 4,418 (+575.54%)
Mutual labels:  sysmon
Sysmon Config
Sysmon configuration file template with default high-quality event tracing
Stars: ✭ 3,287 (+402.6%)
Mutual labels:  sysmon
SysmonConfigPusher
Pushes Sysmon Configs
Stars: ✭ 59 (-90.98%)
Mutual labels:  sysmon

Sysmon - DFIR

A curated list of resources for learning about deploying, managing and hunting with Microsoft Sysmon. Contains presentations, deployment methods, configuration file examples, blogs and additional github repositories.

Sysmon Learning Resources

General

Sysmon Configuration

Sysmon-Modular

sysmon-modular | A Sysmon configuration repository for everybody to customize - @olafhartong

@SwiftOnSecurity config

Config will assist with bringing you up to speed in relation to critical process monitoring, network utilization, and so on. Note that the concept is to not log everything, but the most important items.

https://github.com/SwiftOnSecurity/sysmon-config

Sysmon_config.xml

Solid, detailed config. Probably one of the best ones out there in relation to completeness.

MalwareArchaeology

Sysmon-a.cfg

Basic config that will monitor critical Windows process execution. Very basic, but a good config to get used to sysmon and how things operate.

Blog post by blacklanternsecurity

Sysmon-b.cfg

Crypsis Group published config and PDF. Fairly detailed list of excludes that should assist with understanding how they work and get a configuration started.

Crypsis Group Config

Crypsis Group PDF

Sysmon-c.cfg

Great configuration to understand excludes and contains.

Decent Security Config

Sysmon-d.cfg

Solid blog post related to getting started with Sysmon. Config is nicely laid out and easy to understand.

909Research Blog

Sysmon-e.cfg

Config is specific but it provides a good foundation for capturing a lot of specific data.

https://github.com/Prevenity/sysmon

(Translated comments to english)

StartLogging.xml

Provided by https://github.com/Cyb3rWard0g - Roberto Rodriguez

https://gist.github.com/Cyb3rWard0g/6f69475a667ef298d829370bd26ba8c2

Sysmoncfg_v2|31.xml

Related material from Splunking the Endpoint .conf talk by James Brodsky and Dimitri McKay.

Splunking the Endpoint - Files from presentation

Configs are optimized for Splunk.

Additional configs

Configs are updated frequently --

SwiftOnSecurity Fork by Ion-Storm

Server Config: https://gist.github.com/Neo23x0/a4b4af9481e01e749409

Client config: https://gist.github.com/Neo23x0/f56bea38d95040b70cf5

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].