Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TelemetrySource — Reference mapping Windows telemetry events—Sysmon, Security Auditing, and Threat Intelligence ETW—to underlying API functions, helping defenders understand event generation for detection engineering. | Kitploit
Tools/GitHubGitHub/jonny-jhnson/telemetrysource
Defensive ToolsThreat IntelligenceLearning & EducationCurated ResourcesLog Analysis
GitHubjonny-jhnson/telemetrysource

TelemetrySource

Reference mapping Windows telemetry events—Sysmon, Security Auditing, and Threat Intelligence ETW—to underlying API functions, helping defenders understand event generation for detection engineering.

View Repository
2642152 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

TelemetrySource

Project created to map functions repsonsible for triggering events from various telemetry sources.

Main Mapping Sheet: Event Mapping Google Sheet

Currently mapped sources:

Sysmon

Sysmon-Overview

Window Security Events (Microsoft-Windows-Security-Auditing)

WSE-Overview

Threat Intelligence Events (Microsoft-Windows-Threat-Intelligence)

Microsoft-Windows-Threat-Intelligence

  • Each source has it's own README file with the necessary information needed to understand how the mappings work.

Blogs:

I have done a couple of write-ups on my methodology on tracking these events to APIs down, please read them if you are interested:

  • Uncovering Windows Events - Part 1: TelemetrySource
  • Uncovering Windows Events - Part 2: The Methodology
  • Uncovering Windows Events - Part 3: Threat Intelligence ETW

Feedback:

If anyone has suggestions on how this data could be exposed differently to better help defenders or any other feedback, please reach out! The goal with this project is to help defenders understand how data is generated, so that we can be more informed in our decisions when leveraging that data.

To-Dos:

  • Update Sysmon to v14
  • Expand events in Microsoft-Windows-Security-Auditing
  • Add other ETW Providers
Download Tool