Sysmon

Browse 10 sysmon tools

Kunai is a Linux-based system monitoring tool that provides real-time monitoring and threat hunting capabilities.

Container of 200 Windows EVTX samples for testing detection scripts and training on DFIR.

A Sysmon configuration repository for customizing Microsoft Sysinternals Sysmon configurations with modular setup.

A Splunk app mapped to MITRE ATT&CK to guide threat hunts.

Sysmon for Linux is a tool that monitors and logs system activity with advanced filtering to identify malicious activity.

A Sysmon configuration file template with detailed explanations and tutorial-like features.

Anti-forensics tool for Red Teamers to erase footprints and test incident response capabilities.

SysmonSearch makes event log analysis more effective by aggregating Microsoft Sysmon logs and providing detailed analysis through Elasticsearch and Kibana.

A threat hunting capability that leverages Sysmon and MITRE ATT&CK on Azure Sentinel

A collection of tools and resources for threat hunters.