A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data
☆39Mar 23, 2020Updated 6 years ago
Alternatives and similar repositories for sysmon
Users that are interested in sysmon are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Trace ScriptBlock execution for powershell v2☆40Jan 14, 2020Updated 6 years ago
- repo for sharing stuff☆17Jul 1, 2025Updated last year
- A repository that maps API calls to Sysmon Event ID's.☆122Nov 14, 2022Updated 3 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆55Jul 1, 2022Updated 4 years ago
- AppLocker hardening policies☆27Jul 26, 2018Updated 7 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A project that aims to automate Volatility3 at scale with the use of cloud strength and the power of KQL inside ADX.☆16Aug 19, 2025Updated 11 months ago
- Audit Powershell and search from known keywords in history #Blueteam☆25Apr 22, 2020Updated 6 years ago
- incident response scripts☆18Mar 4, 2019Updated 7 years ago
- The Web UI for Antnium☆27Jun 14, 2022Updated 4 years ago
- Modular command-line threat hunting tool & framework.☆17Jul 20, 2020Updated 6 years ago
- ☆18Sep 14, 2023Updated 2 years ago
- A "hooray I am useful" Cobalt Strike Team Server scanner☆20Oct 22, 2021Updated 4 years ago
- RegFineViewer is an utility to visualize and navigate easily the Windows Registry☆18Jan 20, 2021Updated 5 years ago
- Automatic detection engineering technical state compliance☆55Jul 7, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆16Apr 16, 2015Updated 11 years ago
- Invoke-Decoder – A PowerShell script to decode/deobfuscate malware samples☆18Aug 2, 2020Updated 5 years ago
- ☆11Dec 17, 2024Updated last year
- NTLM Hash Generator☆10Apr 2, 2021Updated 5 years ago
- Epimitheus is a tool that uses graphical database Neo4j for Windows Events visualization.☆19Mar 13, 2022Updated 4 years ago
- C# application for creating and comparing registry key snapshots☆17Jul 5, 2022Updated 4 years ago
- Microsoft DNS Documentation Script☆18Apr 10, 2026Updated 3 months ago
- This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆83Mar 20, 2023Updated 3 years ago
- Event metadata collected across all manifest-based ETW providers on Window 10 1903☆32Nov 25, 2019Updated 6 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Radius client for .Net (Net Standard)☆12Nov 29, 2024Updated last year
- Low-level MS Windows registry files analysis tools☆19May 5, 2016Updated 10 years ago
- Walking the PEB in VBA☆24Apr 6, 2020Updated 6 years ago
- A curated list of awesome things related to TheHive & Cortex☆184Oct 9, 2021Updated 4 years ago
- Jupyter notebooks for threat hunting☆62May 16, 2026Updated 2 months ago
- Osquery Packs we use for customer security hardening☆12Jun 30, 2025Updated last year
- A collection of awesome software, libraries, documents, books, resources and cool stuff about cybersecurity packet capture (PCAP) tools.☆29Jun 22, 2022Updated 4 years ago
- Active C&C Detector☆156Oct 5, 2023Updated 2 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆221Sep 17, 2019Updated 6 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Open source endpoint agent providing host information to Zeek. [v2]☆91Apr 30, 2026Updated 2 months ago
- Simple Powershell scripts to collect all Windows Event Logs from a host and parse them into one CSV timeline.☆32Oct 13, 2018Updated 7 years ago
- Helper script for BloodHound to automatically add relationships between multiple accounts owned by the same individual☆15Jul 13, 2022Updated 4 years ago
- A simple and light WMI that do all the hard work for you☆12Oct 2, 2023Updated 2 years ago
- A PowerShell script to prevent Sysmon from writing its events☆17Apr 23, 2020Updated 6 years ago
- A tool to convert Windows evtx files (Windows Event Log Files) into JSON format and log to Splunk (optional) using HTTP Event Collector.☆58Apr 8, 2022Updated 4 years ago
- Hands on lab materials for the PowerShell Security session☆48Aug 29, 2019Updated 6 years ago