microsoft / SysmonForLinuxLinks
Sysmon for Linux
☆2,055Updated last week
Alternatives and similar repositories for SysmonForLinux
Users that are interested in SysmonForLinux are comparing it to the libraries listed below
Sorting:
- Open Source EDR for Windows☆1,291Updated 2 years ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,235Updated this week
- Elastic Security detection content for Endpoint☆1,368Updated last week
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,438Updated 3 months ago
- Open EDR public repository☆2,599Updated 2 years ago
- AVML - Acquire Volatile Memory for Linux☆1,049Updated this week
- Digging Deeper....☆3,726Updated last week
- A repository of sysmon configuration modules☆2,963Updated last year
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,330Updated last week
- Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts…☆1,061Updated 2 months ago
- Utilities for Sysmon☆1,568Updated 4 months ago
- APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the …☆1,399Updated last year
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,002Updated this week
- TrustedSec Sysinternals Sysmon Community Guide☆1,359Updated last month
- The multi-platform memory acquisition tool.☆940Updated 3 months ago
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆780Updated 3 years ago
- ReversingLabs YARA Rules☆891Updated 3 months ago
- An Active Defense and EDR software to empower Blue Teams☆1,315Updated 2 years ago
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,921Updated 2 weeks ago
- DRAKVUF Sandbox - automated hypervisor-level malware analysis system☆1,262Updated 3 weeks ago
- YARA signature and IOC database for my scanners and tools☆2,858Updated this week
- Windows Events Attack Samples☆2,499Updated 3 years ago
- Malware Configuration And Payload Extraction☆2,975Updated this week
- Web app that provides basic navigation and annotation of ATT&CK matrices☆2,311Updated this week
- The Linux port of the Sysinternals Sysmon tool.☆281Updated 4 months ago
- Sophos-originated indicators-of-compromise from published reports☆649Updated 3 weeks ago
- Cuckoo3 is a Python 3 open source automated malware analysis system.☆797Updated last month
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆861Updated 4 years ago
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,515Updated 3 weeks ago
- Transform Linux Audit logs for SIEM usage☆811Updated last month