sysmon
Here are 21 public repositories matching this topic...
PowerShell module for creating and managing Sysinternals Sysmon config files.
-
Updated
Jan 14, 2018 - PowerShell
Analyzing PowerShell execution on Windows systems.
-
Updated
Feb 20, 2024 - PowerShell
A repository of sysmon configuration modules
-
Updated
Jul 2, 2022 - PowerShell
Presentations
-
Updated
Feb 9, 2024 - PowerShell
A Sysmon Install script using the Powershell Application Deployment Toolkit
-
Updated
Jun 23, 2017 - PowerShell
Script is written to fetch LOLBin Details from Security and Sysmon EVTX file.
-
Updated
Nov 11, 2021 - PowerShell
-
Updated
Apr 13, 2021 - PowerShell
Capture all events across all logs produced during the running of a particular exploit/script. Search and filter events
-
Updated
Sep 5, 2021 - PowerShell
A PowerShell client for retrieving and searching Sysmon logs
-
Updated
Jul 6, 2019 - PowerShell
-
Updated
Nov 4, 2018 - PowerShell
A PowerShell script to prevent Sysmon from writing its events
-
Updated
Apr 23, 2020 - PowerShell
This script enhances endpoint logging telemetry for the purpose of advanced malware threat detection or for building detections or malware analysis. This can be used in production, however you might want to tune the GPO edits as needed.
-
Updated
Jul 2, 2024 - PowerShell
incident response scripts
-
Updated
Mar 4, 2019 - PowerShell
Sysmon EDR POC Build within Powershell to prove ability.
-
Updated
May 1, 2021 - PowerShell
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
-
Updated
Nov 5, 2023 - PowerShell
Improve this page
Add a description, image, and links to the sysmon topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the sysmon topic, visit your repo's landing page and select "manage topics."