


Automate the creation of a lab environment complete with security tooling and logging best practices

A repository of sysmon configuration modules

This project aims to compare and evaluate the telemetry of various EDR products.

TrustedSec Sysinternals Sysmon Community Guide

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Sysmon configuration file template with default high-quality event tracing

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…

Web-based tool for managing and deploying Sysmon configurations across Windows endpoints via agentless (WMI/SMB) or agent-based methods, with remote…

FWT is a security analysis and file monitoring tool that utilizes Sysmon events.

Automatically generated Sysmon parser for Azure Sentinel

Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…