This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.
☆83Mar 20, 2023Updated 3 years ago
Alternatives and similar repositories for Update-Sysmon
Users that are interested in Update-Sysmon are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- TrustedSec Sysinternals Sysmon Community Guide☆1,425Jun 30, 2026Updated 2 weeks ago
- Pushes Sysmon Configs☆91Jun 11, 2021Updated 5 years ago
- incident response scripts☆18Mar 4, 2019Updated 7 years ago
- ☆16Dec 16, 2020Updated 5 years ago
- OSSEM Modular☆27Jun 29, 2020Updated 6 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Jan 30, 2018Updated 8 years ago
- A repository for using windows event forwarding for incident detection and response☆1,336Sep 8, 2025Updated 10 months ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆943Dec 12, 2023Updated 2 years ago
- A repository of sysmon configuration modules☆3,082Jul 13, 2026Updated last week
- A repository that maps API calls to Sysmon Event ID's.☆122Nov 14, 2022Updated 3 years ago
- Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsac…☆890Nov 17, 2020Updated 5 years ago
- Public Repo for Atomic Test Harness☆289Apr 8, 2025Updated last year
- ☆12Mar 24, 2018Updated 8 years ago
- Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into …☆828Nov 5, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK☆1,078Nov 28, 2024Updated last year
- An Inofficial Sysmon Version History (Change Log)☆33Oct 25, 2020Updated 5 years ago
- ☆11Apr 21, 2023Updated 3 years ago
- Utilities for Sysmon☆1,657Apr 4, 2026Updated 3 months ago
- An Active Defense and EDR software to empower Blue Teams☆1,334Mar 31, 2026Updated 3 months ago
- Primary data pipelines for intrusion detection, security analytics and threat hunting☆85Jan 9, 2022Updated 4 years ago
- WEFTools☆14Apr 30, 2020Updated 6 years ago
- Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technic…☆229Feb 5, 2025Updated last year
- ☆49Aug 30, 2020Updated 5 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Documentation and scripts to properly enable Windows event logs.☆709Oct 3, 2025Updated 9 months ago
- Investigate suspicious activity by visualizing Sysmon's event log☆431Dec 22, 2023Updated 2 years ago
- Manticore Adversary Emulation Cli☆47Aug 4, 2020Updated 5 years ago
- Logging Made Easy☆709Nov 1, 2023Updated 2 years ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆96Feb 2, 2022Updated 4 years ago
- Information about most important hunts which can be performed by Threat hunters while searching for any adversary/threats inside the orga…☆15May 18, 2019Updated 7 years ago
- A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆39Mar 23, 2020Updated 6 years ago
- Random hunting ordiented yara rules☆96Mar 27, 2023Updated 3 years ago
- Deploy and maintain Symon through the Splunk Deployment Sever☆32Jul 30, 2020Updated 5 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- THOR Thunderstorm Collectors☆27Jun 19, 2026Updated last month
- Exports MISP events to STIX and ingest into McAfee ESM☆15Feb 12, 2020Updated 6 years ago
- EventList☆380Mar 21, 2021Updated 5 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆161Mar 10, 2025Updated last year
- Bro integration with osquery☆15Mar 24, 2023Updated 3 years ago
- Detecting ATT&CK techniques & tactics for Linux☆258Oct 1, 2020Updated 5 years ago
- Transform Linux Audit logs for SIEM usage☆842Updated this week