A repository that maps API calls to Sysmon Event ID's.
☆122Nov 14, 2022Updated 3 years ago
Alternatives and similar repositories for Windows-API-To-Sysmon-Events
Users that are interested in Windows-API-To-Sysmon-Events are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆263May 9, 2024Updated 2 years ago
- ☆16Dec 16, 2020Updated 5 years ago
- This is a repository that is meant to hold detections for various process injection techniques.☆34Mar 3, 2020Updated 6 years ago
- Tool that gathers a customizable set of ETW telemetry and generates user-defined detections☆56Jan 28, 2026Updated 6 months ago
- A repo to document API functions mapped to security events across diverse platforms☆74Nov 1, 2019Updated 6 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Silencing Sysmon via driver unload☆237Oct 13, 2022Updated 3 years ago
- ☆267Jun 7, 2025Updated last year
- A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆39Mar 23, 2020Updated 6 years ago
- SysmonX - An Augmented Drop-In Replacement of Sysmon☆222Sep 17, 2019Updated 6 years ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆96Feb 2, 2022Updated 4 years ago
- PowerKrabsEtw is a PowerShell interface for doing real-time ETW tracing.☆102Nov 17, 2020Updated 5 years ago
- TrustedSec Sysinternals Sysmon Community Guide☆1,430Jun 30, 2026Updated last month
- Detect possible sysmon logging bypasses given a specific configuration☆110Dec 26, 2018Updated 7 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆29Aug 6, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- C# Implementation of Jared Atkinson's Get-InjectedThread.ps1☆56Jul 11, 2021Updated 5 years ago
- Investigate suspicious activity by visualizing Sysmon's event log☆432Dec 22, 2023Updated 2 years ago
- Windows Events Attack Samples☆2,605Jan 24, 2023Updated 3 years ago
- Pushes Sysmon Configs☆91Jun 11, 2021Updated 5 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆942Dec 12, 2023Updated 2 years ago
- A simple proof of concept for detecting use of Cobalt Strike's execute-assembly☆59Apr 1, 2022Updated 4 years ago
- Automated, Collection, and Enrichment Platform☆325Nov 14, 2019Updated 6 years ago
- Re-play Security Events☆1,796Mar 20, 2024Updated 2 years ago
- Sysmon EDR POC Build within Powershell to prove ability.☆228May 1, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆868Jan 20, 2022Updated 4 years ago
- C# POC code for the SessionEnv dll hijack by utilizing called functions of TSMSISrv.dll☆63Apr 18, 2019Updated 7 years ago
- This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆83Mar 20, 2023Updated 3 years ago
- Utilities for Sysmon☆1,657Apr 4, 2026Updated 4 months ago
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆51Mar 2, 2022Updated 4 years ago
- Hundred Days of Yara Challenge☆12Jun 21, 2022Updated 4 years ago
- ☆23Jun 1, 2022Updated 4 years ago
- Experimentations with the MSBuild Capabilites in a default environment.☆23Dec 6, 2025Updated 8 months ago
- Documentation and supporting script sample for Windows Exploit Guard☆167Sep 8, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- InvestigationPlaybookSpec☆70Sep 26, 2017Updated 8 years ago
- Nice try reading NTDLL from disk, nerd.☆19Apr 18, 2022Updated 4 years ago
- Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.☆47Jan 5, 2020Updated 6 years ago
- All sysmon event types and their fields explained☆571Nov 13, 2021Updated 4 years ago
- ☆84Oct 18, 2022Updated 3 years ago
- CLI tool to compute the TypeRefHash for .NET binaries.☆19Nov 10, 2021Updated 4 years ago
- ☆852Jun 1, 2023Updated 3 years ago