Skip to content
#

sysmon

Here are 117 public repositories matching this topic...

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.

  • Updated Nov 5, 2023
  • PowerShell

The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能, 而不用关心底层驱动的开发、维护和兼容性问题,让其可以专注于业务开发

  • Updated Oct 28, 2024
  • Batchfile

Improve this page

Add a description, image, and links to the sysmon topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the sysmon topic, visit your repo's landing page and select "manage topics."

Learn more