SysmonForLinux
Aurora-Incident-Response
Our great sponsors
SysmonForLinux | Aurora-Incident-Response | |
---|---|---|
11 | 6 | |
1,608 | 726 | |
2.9% | - | |
6.6 | 0.0 | |
about 1 month ago | 7 months ago | |
C | JavaScript | |
MIT License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
SysmonForLinux
- Sysmon for Linux
- Any useful cybersecurity software under $5k?
-
Security Cadence: Sysmon (Logging Part 2 out of ?????)
Did you know that Sysmon is so fantastic that Microsoft ported it to Linux? They sure did and it is awesome. It can be found here: https://github.com/Sysinternals/SysmonForLinux
-
Install Sysmon for Linux on RHEL 8?
I followed the install instructions for RHEL 8 found here: https://github.com/Sysinternals/SysmonForLinux/blob/main/INSTALL.md and that seemed to work correctly.
- The GoDaddy hack is wider than initially thought. Started on the 6th of September!
- Microsoft releases Linux version of the Windows Sysmon tool
- Sysmon for Linux 1.0.0 Released
- Microsoft releases Symon for Linux
- Sysinternals/SysmonForLinux
- Sysmon For Linux builds
Aurora-Incident-Response
-
Report tips and note taking tips
Aurora - https://github.com/cyb3rfox/Aurora-Incident-Response Good tool for smaller more manageable investigations
- Any useful cybersecurity software under $5k?
- cyb3rfox / Aurora-Incident-Response - Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
- Help! TheHive out, which SIRP shall we choose?
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
-
Are there any free / open source Evidence Management Systems?
Not sure if this is what you'd be looking for but maybe it can do the job good enough: https://github.com/cyb3rfox/Aurora-Incident-Response
What are some alternatives?
sysmon-modular - A repository of sysmon configuration modules
TheHive - TheHive: a Scalable, Open Source and Free Security Incident Response Platform
sysmon-config - Sysmon configuration file template with default high-quality event tracing
response - Monzo's real-time incident response and reporting tool ⚡️
SysmonTools - Utilities for Sysmon
iris-web - Collaborative Incident Response platform
VanillaWindowsReference - A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!
dfirtrack - DFIRTrack - The Incident Response Tracking Application
awesome-pcaptools - A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors.
FIR - Fast Incident Response
threat-tools - Tools for simulating threats
mediator - a medium inspired jekyll theme