Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
sysmon-modular — A repository of sysmon configuration modules | Kitploit
उपकरण/GitHubGitHub/olafhartong/sysmon-modular
Defensive ToolsDigital ForensicsIntrusion DetectionIncident ResponseLog Analysis
GitHubolafhartong/sysmon-modular

sysmon-modular

A repository of sysmon configuration modules

रिपॉजिटरी देखें
3.1k6532011 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

sysmon-modular | A Sysmon configuration repository for everybody to customise

license Maintenance GitHub last commit Build Sysmon configurations Twitter Discord Shield

Sysmon Modular is a configuration repository for Microsoft Sysinternals Sysmon. Small XML modules make it easier to select, review and maintain the telemetry that is useful to your organisation. The sysmon-modular Go tool builds configurations from those modules and helps validate, analyse and compare them.

Every configuration is a starting point. Review and tune it for your applications, endpoint roles, detection needs and logging budget before deploying it widely. Use a manageable set of profiles for workstations, servers and domain controllers, and measure their behaviour on representative machines.

This project would not have been possible without SwiftOnSecurity's original configuration, which inspired Sysmon Modular and remains part of its foundation.

Contents

  • Pre-generated configurations
  • Get the tooling
  • Generating a config
  • Validate, analyse and compare
  • Generate modules from KQL and MDE
  • Use
  • CI/CD and releases
  • Documentation
  • Contributing
  • Sysmon community
  • More information

Pre-generated configurations

Download the regular starting configurations from the latest GitHub Release. These consolidated XML files are generated from the source modules and distributed as release assets instead of being stored in the repository.

ProfileDownloadCollection goal
Balancedsysmonconfig.xmlThe regular starting configuration, without FileDelete archiving.
Balanced with FileDeletesysmonconfig-with-filedelete.xmlAdds FileDelete collection and file archiving. Account for the archive's disk requirements.
Excludes onlysysmonconfig-excludes-only.xmlA very verbose profile built from exclusion modules. Expect substantial event volume and tune before production use.

All three profiles are generated for Sysmon 15.21, 14.16, 13.34 and 12.03. Versioned filenames include the target, such as sysmonconfig-14.16.xml; the unversioned names above are aliases for 15.21. Select the version installed on your endpoints. For controlled rollouts, pin a specific release rather than automatically deploying latest.

Two profiles remain separate examples in the repository:

  • Research configuration: extremely verbose collection for short, controlled research sessions. It can consume substantial CPU, memory and logging capacity; load a lighter configuration when the investigation is complete.
  • MDE-augment configuration: selected collection intended to complement Microsoft Defender for Endpoint with less overlap. It does not enable every Sysmon event. See the MDE-augment generation guide to rebuild and review its exclusion list.

The release also includes prebuilt tools, an ATT&CK Navigator layer derived from the balanced 15.21 configuration, and a SHA256SUMS manifest.

Get the tooling

The Go CLI is the supported generator. The examples in this README run from the repository root and use a binary saved in tooling. Start with a local checkout if you want to generate configurations from the source modules:

git clone https://github.com/olafhartong/sysmon-modular.git
cd sysmon-modular

Prebuilt binaries

Download the binary for your operating system and architecture from GitHub Releases. Go is not required to use these binaries.

SystemRelease asset
Windows x64sysmon-modular-windows-amd64.exe
Windows ARM64sysmon-modular-windows-arm64.exe
Linux x64sysmon-modular-linux-amd64
Linux ARM64sysmon-modular-linux-arm64
macOS Intelsysmon-modular-darwin-amd64
macOS Apple siliconsysmon-modular-darwin-arm64

Save the download as tooling/sysmon-modular, or tooling/sysmon-modular.exe on Windows. On Linux and macOS, make it executable once:

chmod +x tooling/sysmon-modular

Build

Building from source requires Go 1.22 or newer and uses only the Go standard library.

From the repository root on Linux or macOS:

go -C tooling build -o "$PWD/tooling/sysmon-modular" ./cmd/sysmon-modular

From PowerShell on Windows:

go -C tooling build -o "$PWD\tooling\sysmon-modular.exe" ./cmd/sysmon-modular

You can also run commands directly with Go. For example:

go -C tooling run ./cmd/sysmon-modular --version

go -C tooling run runs the program from the tooling directory. Use absolute paths when adapting repository-root examples to that form, or follow the tooling-relative examples in the command reference.

Version and help

The tooling starts at build version 1.0:

./tooling/sysmon-modular --version
./tooling/sysmon-modular help
./tooling/sysmon-modular merge --help

version and --version print sysmon-modular 1.0. The build version also appears in top-level and command-specific help. It identifies the tooling; --sysmon-version selects the target Sysmon executable instead.

The default is defined in version.go. Local and release builds include it automatically. To override it for a particular build:

go -C tooling build -ldflags="-X main.buildVersion=1.1" \
  -o "$PWD/tooling/sysmon-modular" ./cmd/sysmon-modular

On Windows, use ./tooling/sysmon-modular.exe in the commands below. Multi-line PowerShell examples are available in the custom configuration guide.

Generating a config

टूल डाउनलोड करें