Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
SysmonSimulator — Sysmon 이벤트 시뮬레이션 유틸리티로, 블루팀이 EDR 탐지 및 상관 규칙을 테스트하기 위해 공격을 시뮬레이션하여 Sysmon 이벤트 로그를 생성하는 데 사용할 수 있습니다. | Kitploit
도구/GitHubGitHub/scarredmonk/sysmonsimulator
Defensive ToolsIncident ResponseLog Analysis
GitHubscarredmonk/sysmonsimulator

SysmonSimulator

Sysmon 이벤트 시뮬레이션 유틸리티로, 블루팀이 EDR 탐지 및 상관 규칙을 테스트하기 위해 공격을 시뮬레이션하여 Sysmon 이벤트 로그를 생성하는 데 사용할 수 있습니다.

저장소 보기
8681104년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

SysmonSimulator

SysmonSimulator는 C 언어로 작성된 오픈 소스 Windows 이벤트 시뮬레이션 유틸리티로, WINAPI를 사용하여 대부분의 공격을 시뮬레이션하는 데 사용할 수 있습니다. 블루 팀이 EDR 탐지 및 상관 관계 규칙을 테스트하는 데 사용할 수 있습니다. 관련 Sysmon 이벤트 ID에 대한 공격 데이터를 생성하기 위해 만들었습니다.

블로그 포스트:

이 도구는 블로그 포스트에서 설명되었습니다: https://rootdse.org/posts/understanding-sysmon-events/

중요한 Windows 이벤트에 대한 공격은 다음과 같이 다루어집니다:

  • 프로세스 이벤트: 프로세스 생성, 프로세스 종료, 프로세스 액세스
  • 파일 이벤트: 파일 생성, 파일 생성 시간 변경, 파일 스트림 생성 해시, 파일 삭제, 파일 삭제 감지
  • 명명된 파이프 이벤트: 명명된 파이프 생성, 명명된 파이프 연결 이벤트
  • 레지스트리 작업: 레지스트리 개체 생성 및 삭제, 값 설정, 키 및 값 이름 바꾸기
  • 이미지 로드
  • 네트워크 연결
  • 원격 스레드 생성
  • 원시 액세스 읽기
  • DNS 쿼리
  • WMI 이벤트
  • 클립보드 캡처
  • 프로세스 이미지 변조
root@kitploit:~
 __                        __
(_      _ ._ _   _  ._    (_  o ._ _      |  _. _|_  _  ._
__) \/ _> | | | (_) | |   __) | | | | |_| | (_|  |_ (_) |
    /
                                            by @ScarredMonk

Sysmon Simulator v0.1 - Sysmon event simulation utility
    A Windows utility to simulate Sysmon event logs

Usage:
Run simulation : .\SysmonSimulator.exe -eid <event id>
Show help menu : .\SysmonSimulator.exe -help

Example:
SysmonSimulator.exe -eid 1

Parameters:
-eid 1  : Process creation
-eid 2  : A process changed a file creation time
-eid 3  : Network connection
-eid 5  : Process terminated
-eid 6  : Driver loaded
-eid 7  : Image loaded
-eid 8  : CreateRemoteThread
-eid 9  : RawAccessRead
-eid 10 : ProcessAccess
-eid 11 : FileCreate
-eid 12 : RegistryEvent - Object create and delete
-eid 13 : RegistryEvent - Value Set
-eid 14 : RegistryEvent - Key and Value Rename
-eid 15 : FileCreateStreamHash
-eid 16 : ServiceConfigurationChange
-eid 17 : PipeEvent - Pipe Created
-eid 18 : PipeEvent - Pipe Connected
-eid 19 : WmiEvent - WmiEventFilter activity detected
-eid 20 : WmiEvent - WmiEventConsumer activity detected
-eid 21 : WmiEvent - WmiEventConsumerToFilter activity detected
-eid 22 : DNSEvent - DNS query
-eid 24 : ClipboardChange - New content in the clipboard
-eid 25 : ProcessTampering - Process image change
-eid 26 : FileDeleteDetected - File Delete logged

Description:
Enter an event ID from the above parameters list and the related Windows API function is called
to simulate the attack and Sysmon event log will be generated which can be viewed in the Windows Event Viewer

Prerequisite:
Sysmon must be installed on the system

설명:

위의 매개변수 목록에서 이벤트 ID를 입력하면 관련 Windows API 함수가 호출되어 공격을 시뮬레이션하고 Windows 이벤트 뷰어에서 볼 수 있는 Sysmon 이벤트 로그가 생성됩니다.

사전 요구사항:

시스템에 Sysmon이 설치되어 있어야 합니다.

도구 다운로드