jsecurity101 / Windows-API-To-Sysmon-Events
A repository that maps API calls to Sysmon Event ID's.
☆117Updated 2 years ago
Alternatives and similar repositories for Windows-API-To-Sysmon-Events:
Users that are interested in Windows-API-To-Sysmon-Events are comparing it to the libraries listed below
- A repo to document API functions mapped to security events across diverse platforms☆75Updated 5 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆107Updated 6 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆148Updated 3 years ago
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity