SysmonTools
SysmonForLinux
Our great sponsors
SysmonTools | SysmonForLinux | |
---|---|---|
2 | 11 | |
1,445 | 1,605 | |
- | 2.7% | |
3.5 | 6.8 | |
7 months ago | about 1 month ago | |
C | ||
- | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
SysmonTools
SysmonForLinux
- Sysmon for Linux
- Any useful cybersecurity software under $5k?
-
Security Cadence: Sysmon (Logging Part 2 out of ?????)
Did you know that Sysmon is so fantastic that Microsoft ported it to Linux? They sure did and it is awesome. It can be found here: https://github.com/Sysinternals/SysmonForLinux
-
Install Sysmon for Linux on RHEL 8?
I followed the install instructions for RHEL 8 found here: https://github.com/Sysinternals/SysmonForLinux/blob/main/INSTALL.md and that seemed to work correctly.
- The GoDaddy hack is wider than initially thought. Started on the 6th of September!
- Microsoft releases Linux version of the Windows Sysmon tool
- Sysmon for Linux 1.0.0 Released
- Microsoft releases Symon for Linux
- Sysinternals/SysmonForLinux
- Sysmon For Linux builds
What are some alternatives?
sysmon-config - Sysmon configuration file template with default high-quality event tracing
sysmon-modular - A repository of sysmon configuration modules
sysmon-config - Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
Aurora-Incident-Response - Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
SysmonConfigPusher - Pushes Sysmon Configs
VanillaWindowsReference - A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!
SplunkDashboards - Collection of Dashboards for Threat Hunting and more!
awesome-pcaptools - A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors.
MISP - MISP (core software) - Open Source Threat Intelligence and Sharing Platform
threat-tools - Tools for simulating threats