sysmon-config icon indicating copy to clipboard operation
sysmon-config copied to clipboard

Sysmon configuration file template with default high-quality event tracing

Results 82 sysmon-config issues
Sort by recently updated
recently updated
newest added

Event ID 10 is not been logged and I am unable to get any logs related to event id 10 in windows.

This line inside the sysmon-config peaked my interest but when i open the link i get to a bing homepage. ` NOTE: To collect Sysmon logs centrally for free, see...

The following message is prepended to the top of every Sysmon event for every Event ID: `The description for Event ID # from source Microsoft-Windows-Sysmon cannot be found. Either the...

Hello, I begin use Microsoft Sentinel and I want use your sysmon config. But I missing Microsoft Sentinel Workbook for this sysmon config. Is in plan? Or can you recommend...

Is there any good config out there for sysmon on linux?

I added some file extensions these are used for infection and exploitation.

Hi, On a fresh install following the Sysmon-documentation regarding install, I receive a number of parser errors. These errors also pop up after installation changing the configuration with the -c...

Going over the config, I found a tiny error.. 142

Line 335: 444 **Issue:** I noticed that the line above indicates '444' as the default Metaspolit destination port, but I think the default listener is actually '4444'. Let me know...

hello there, I want to get logs like New-*, Get-*, Invoke-*, ..... etc. i can't find it from sysmon configure and can you please advise?