sysmon-modular VS Windows-Toolkit

Compare sysmon-modular vs Windows-Toolkit and see what are their differences.

sysmon-modular

A repository of sysmon configuration modules (by olafhartong)

Windows-Toolkit

PS one-liner cmdlets for Windows security (by Samsar4)
Our great sponsors
  • InfluxDB - Build time-series-based applications quickly and at scale.
  • SonarQube - Static code analysis for 29 languages.
  • Zigi - Delete the most useless function ever: context switching.
  • Scout APM - Truly a developer’s best friend
sysmon-modular Windows-Toolkit
11 1
2,034 2
- -
8.9 0.0
9 days ago almost 2 years ago
PowerShell PowerShell
MIT License -
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

sysmon-modular

Posts with mentions or reviews of sysmon-modular. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-11-09.

Windows-Toolkit

Posts with mentions or reviews of Windows-Toolkit. We have used some of these posts to build our list of alternatives and similar projects.

We haven't tracked posts mentioning Windows-Toolkit yet.
Tracking mentions began in Dec 2020.

What are some alternatives?

When comparing sysmon-modular and Windows-Toolkit you can also consider the following projects:

atomic-red-team - Small and highly portable detection tests based on MITRE's ATT&CK.

sysmon-config - Sysmon configuration file template with default high-quality event tracing

DetectionLabELK - DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Power-Response - Powering Up Incident Response with Power-Response

AzureHunter - A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

threathunting - A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

vscode-sysmon - Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.

Fail2Ban - Daemon to ban hosts that cause multiple authentication errors

gitleaks - Protect and discover secrets using Gitleaks 🔑

sysmon-config - Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.

SysmonForLinux

lynis - Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.