
Web-based tool for managing and deploying Sysmon configurations across Windows endpoints via agentless (WMI/SMB) or agent-based methods, with remote event log viewing and noise analysis.
A web-based tool for managing Sysmon configurations across Windows endpoints — supports both agentless (WMI/SMB) and agent-based deployments.
| Feature | Description |
|---|---|
| Agentless Deployment | Push Sysmon binaries and configs via WMI and SMB |
| Agent Support | Lightweight agent for cloud VMs and DMZ servers |
| Docker Support | Run on Linux/Docker for agent-only deployments |
| Web Interface | Modern React UI with real-time deployment progress |
| Event Log Viewer | Query Sysmon logs from remote hosts |
| Noise Analysis | Identify high-volume events to tune configurations |
| Scheduled Deployments | Schedule deployments for future execution |
| Flexible Auth | Windows Integrated Auth or API keys |
| Dashboard | Inventory |
|---|---|
![]() | ![]() |
| Config View | Config Editor |
|---|---|
![]() | ![]() |
| Deployment Wizard | Deployment Progress |
|---|---|
![]() | ![]() |
| Schedule Deployments | Noise Analysis |
|---|---|
![]() | ![]() |
appsettings.json)docker run -d --name sysmonpusher \
-p 5001:5001 \
-v sysmonpusher-data:/data \
-e API_KEY_ADMIN="your-admin-key" \
-e AGENT_TOKEN="your-agent-token" \
ghcr.io/antonlovesdnb/sysmonconfigpusher2:latest
Access the UI at https://localhost:5001 (self-signed certificate warning expected).
See Docker Guide for full configuration options.
See the Development Guide for building and running locally.
| Guide | Description |
|---|---|
| Installation Guide | Production deployment on Windows Server |
| Usage Guide | How to use the application, config tagging (SCPTAG) |
| Agent Guide | Deploying and managing the lightweight agent |
| Docker Guide | Container deployment, backup, and recovery |
| Certificate Guide | TLS configuration for server and agents |
| Deployment Modes | Full vs Agent-Only mode comparison |
| Development Guide | Building from source, running locally |
See Deployment Modes for a detailed comparison.