SysmonSearch Logo

SysmonSearch

0
Free
Visit Website

SysmonSearch makes event log analysis more effective and less time-consuming by aggregating event logs generated by Microsoft's Sysmon. System Overview: SysmonSearch uses Elasticsearch and Kibana (and Kibana plugin). Elasticsearch collects/stores Sysmon's event log. Kibana provides a user interface for Sysmon's event log analysis. The following functions are implemented as Kibana plugin: Visualizes Function - visualizes Sysmon's event logs to illustrate correlation of processes and networks. Statistical Function - collects the statistics of each device or Sysmon's event ID. Monitor Function - monitors incoming logs based on preconfigured rules and triggers alerts. StixIoC server allows adding search/monitor conditions by uploading STIX/IOC files. From StixIoC server Web UI, you can upload STIXv1, STIXv2, and OpenIOC format files. To try SysmonSearch, you can either install software to your own Linux environment with the provided instructions or use the Docker image. For more details, please refer to the SysmonSearch wiki documentation.

FEATURES

ALTERNATIVES

Graylog offers advanced log management and SIEM capabilities to enhance security and compliance across various industries.

Commercial

A method for log volume reduction without losing analytical capability.

Free

A cloud-native SIEM platform that provides security analytics, intuitive workflow, and simplified incident response to help security teams defend against cyber threats.

Commercial

A Command Line Map-Reduce tool for analyzing cowrie log files over time and creating visualizations and statistics.

Free

Windows Event Log Analyzer with logon timeline generator and noise reduction for fast forensics.

Free

Python library and command line tools for log visualization with interactive plots.

Free

Apache Metron is a centralized tool for security monitoring and analysis that integrates various open-source big data technologies.

Free

A compliant audit log tool that provides a searchable, exportable record of read/write events.

Free

PINNED