Sysmon for Linux Logo

Sysmon for Linux

0
Free
Updated 11 March 2025
Visit Website

Sysmon for Linux is a tool that monitors and logs system activity including process lifetime, network connections, file system writes, and more. Sysmon works across reboots and uses advanced filtering to help identify malicious activity as well as how intruders and malware operate on your network. Installation: The packages are available in the official Microsoft Linux repositories and instructions on how to install the packages for the different Linux distributions can be found in the Installation instructions. Build: Please see build instructions here. Autodiscovery of Offsets: On systems that are BTF enabled, Sysmon will use BTF for accurate kernel offsets. Sysmon also supports specifying standalone BTF files (using /BTF switch). There are several ways to generate BTF files and BTFHub has a number of standalone BTF files for different distributions/kernels. If BTF isn't available, Sysmon attempts to automatically discover the offsets of some members of some kernel structs. If this fails, please provide details of the kernel version (and config if possible).

FEATURES

SIMILAR TOOLS

Serverless, real-time data analysis framework for incident detection and response.

Free

Graylog offers advanced log management and SIEM capabilities to enhance security and compliance across various industries.

Commercial

ELAT (Event Log Analysis Tool) is a tool that helps in analyzing Windows event logs for malware detection.

Free

A collection of free shareable log samples from various systems with evidence of compromise and malicious activity, maintained by Dr. Anton Chuvakin.

Free

Track user activity and API usage on AWS and in hybrid and multicloud environments.

Free

Logdissect is a CLI utility and Python library for analyzing log files and other data.

Free

Security-Guard helps secure microservices and serverless containers by detecting and blocking exploits.

Free

GrokEVT is a tool for reading Windows event log files and converting them to a human-readable format.

Free

Elasticsearch is a versatile platform for centralized data storage, fast search, and scalable analytics.

Free
CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved