sysmon-modular
sysmon-modular copied to clipboard
ImageLoad detections from hijacklibs.net
Data sourced from https://hijacklibs.net / https://github.com/wietze/HijackLibs/tree/main.
This include file was written mostly programmatically for each DLL in this project and it's known/expected load locations. It is rather long, so any improvement suggestions are welcome.
I included some minor noise excludes when tested in a modestly size production environment.
I'm willing to share the simple PowerShell code used to develop these files if desired.