olafhartong / sysmon-cheatsheetLinks
All sysmon event types and their fields explained
☆554Updated 3 years ago
Alternatives and similar repositories for sysmon-cheatsheet
Users that are interested in sysmon-cheatsheet are comparing it to the libraries listed below
Sorting:
- TrustedSec Sysinternals Sysmon Community Guide☆1,222Updated last week
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆853Updated 3 years ago
- A collection of red team and adversary emulation resources developed and released by MITRE.☆514Updated 4 years ago
- PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monit…☆813Updated 6 months ago
- Hunting queries and detections☆811Updated 5 months ago
- DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.☆566Updated 3 years ago
- Misc Threat Hunting Resources☆373Updated 2 years ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆526Updated 2 years ago
- Tools for hunting for threats.☆591Updated 2 months ago
- Tool Analysis Result Sheet☆354Updated 7 years ago
- Sysmon configuration file template with default high-quality event tracing