Sysmon configuration
☆64Jul 12, 2018Updated 7 years ago
Alternatives and similar repositories for Sysmon
Users that are interested in Sysmon are comparing it to the libraries listed below
Sorting:
- Script to parse Process Monitor XML log file, and give you a summary report.☆23May 4, 2016Updated 9 years ago
- Sysmon Tools for PowerShell☆232Aug 17, 2018Updated 7 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆103Nov 17, 2020Updated 5 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆937Dec 12, 2023Updated 2 years ago
- PowerShell module for creating and managing Sysinternals Sysmon config files.☆214Mar 29, 2021Updated 4 years ago
- ☆52Sep 17, 2018Updated 7 years ago
- Scripts to define your azure security governance as code and avoid manual settings of permissions and avoiding configuration drift☆21May 11, 2021Updated 4 years ago
- ☆19Sep 2, 2018Updated 7 years ago
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆69Jun 17, 2018Updated 7 years ago
- Gmail Knocker☆23Jul 24, 2017Updated 8 years ago
- Automated, Collection, and Enrichment Platform☆324Nov 14, 2019Updated 6 years ago
- Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI☆201Dec 11, 2017Updated 8 years ago
- ☆19May 31, 2017Updated 8 years ago
- PowerShell Module to provide Network Block Device like functionality on Windows Hosts☆13Sep 27, 2015Updated 10 years ago
- The opposite of Ruler, provides blue teams with the ability to detect Ruler usage against Exchange.☆96Oct 11, 2017Updated 8 years ago
- Python script to decode common encoded PowerShell scripts☆217Jun 13, 2018Updated 7 years ago
- ☆349Mar 19, 2021Updated 4 years ago
- Plugins for the Serpico Project☆23Dec 4, 2018Updated 7 years ago
- Use CLR to inject all the .NET apps☆184Apr 17, 2021Updated 4 years ago
- Reworked assets for Azure Sentinel using Cisco Umbrella logs as source. Includes logstash config for Cisco Umbrella using Cisco managed A…☆13Apr 14, 2020Updated 5 years ago
- A very fast network scanner of SSL server configurations☆11Mar 28, 2016Updated 9 years ago
- Konrads' Pen-Ultimate (Windows) Log File Parser☆14Dec 27, 2025Updated 2 months ago
- CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across al…☆658Aug 19, 2019Updated 6 years ago
- ☆86Nov 18, 2022Updated 3 years ago
- ☆122Mar 6, 2018Updated 7 years ago
- Generates visualizations from the output of flow tools such as SiLK.☆35Dec 8, 2016Updated 9 years ago
- ☆47Dec 5, 2025Updated 2 months ago
- Async'ly gather unique usernames thru null SMB sessions and bruteforce them with 2 passwords☆51Oct 24, 2017Updated 8 years ago
- ☆265Oct 25, 2025Updated 4 months ago
- A proof of concept for dynamically loading .net assemblies at runtime with only a minimal convention pre-knowledge☆163Jul 25, 2018Updated 7 years ago
- SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in …☆15Nov 1, 2018Updated 7 years ago
- Empire HTTP(S) C2 redirector setup script☆48Jul 10, 2018Updated 7 years ago
- ☆15Oct 24, 2017Updated 8 years ago
- Dumping App Bound Protected Credentials & Cookies Without Privileges.☆59Nov 4, 2025Updated 3 months ago
- Sharing my BITS☆13Feb 23, 2018Updated 8 years ago
- Generates anti-sandbox analysis HTA files without payloads☆120Mar 16, 2017Updated 8 years ago
- ☆229May 10, 2018Updated 7 years ago
- Silencing Sysmon via driver unload☆235Oct 13, 2022Updated 3 years ago
- SharpShareFinder is a minimalistic network share discovery POC designed to enumerate shares in Windows Active Directory networks leveragi…☆36Jul 10, 2024Updated last year