


Commented Sysmon configuration template for high-quality Windows event tracing, threat hunting, and incident response. Designed as a tutorial for…

Block spying and tracking on Windows

Automate the creation of a lab environment complete with security tooling and logging best practices

A repository of sysmon configuration modules

This project aims to compare and evaluate the telemetry of various EDR products.

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

TrustedSec Sysinternals Sysmon Community Guide

Windows EDR with Gene-based detection engine, real-time artifact collection, Sysmon integration, and REST API for managing endpoints, rules, and…

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Documentation and scripts to properly enable Windows event logs.

Kernel-level tool to disable Sysmon and Windows Event Logging via driver-based hook injection, enabling stealthy post-exploitation operations on…

Sysmon configuration file template with default high-quality event tracing

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

:wrench: Deploy customizable Active Directory labs in Azure - automatically.