Sysmon for Linux Logo

Sysmon for Linux

0
Free
Visit Website

Sysmon for Linux is a tool that monitors and logs system activity including process lifetime, network connections, file system writes, and more. Sysmon works across reboots and uses advanced filtering to help identify malicious activity as well as how intruders and malware operate on your network. Installation: The packages are available in the official Microsoft Linux repositories and instructions on how to install the packages for the different Linux distributions can be found in the Installation instructions. Build: Please see build instructions here. Autodiscovery of Offsets: On systems that are BTF enabled, Sysmon will use BTF for accurate kernel offsets. Sysmon also supports specifying standalone BTF files (using /BTF switch). There are several ways to generate BTF files and BTFHub has a number of standalone BTF files for different distributions/kernels. If BTF isn't available, Sysmon attempts to automatically discover the offsets of some members of some kernel structs. If this fails, please provide details of the kernel version (and config if possible).

FEATURES

ALTERNATIVES

Search AWS CloudWatch logs on the command line with aws-sdk-for-go.

Free

A Security Information and Event Management (SIEM) system with a focus on security and minimalism.

Free

A framework for generating log events without the need for infrastructure, allowing for simple, repeatable, and randomized log event creation.

Free

Browse a library of EQL analytics now natively integrated in Elasticsearch.

Free

A method for log volume reduction without losing analytical capability.

Free

SysmonSearch makes event log analysis more effective by aggregating Microsoft Sysmon logs and providing detailed analysis through Elasticsearch and Kibana.

Free

A log management solution that optimizes SIEM performance, provides rapid search and troubleshooting, and meets compliance requirements.

Commercial

A logging proxy tool created in response to the 'MongoDB Apocalypse', with Docker support.

Free