Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
A curated and bespoke list of resources for learning about deploying, managing and hunting with Microsoft Sysmon. Contains presentations, deployment methods, configuration file examples, blogs and additional GitHub repositories.
You can now breeze through most of the content here: https://mhaggis.github.io/sysmon-dfir/
Sysmon-Modular
sysmon-modular | A Sysmon configuration repository for everybody to customize - @olafhartong
@SwiftOnSecurity config
Config will assist with bringing you up to speed in relation to critical process monitoring, network utilization, and so on. Note that the concept is to not log everything, but the most important items.
https://github.com/SwiftOnSecurity/sysmon-config
Hunt Naked
Used for research purposes, this config enables everything with the latest version of Sysmon. This is a full throttle config. Happy Hunting.
Sysmon_config.xml
Solid, detailed config. Probably one of the best ones out there in relation to completeness.
Sysmon-a.cfg
Basic config that will monitor critical Windows process execution. Very basic, but a good config to get used to sysmon and how things operate.
Blog post by blacklanternsecurity
Sysmon-b.cfg
Crypsis Group published config and PDF. Fairly detailed list of excludes that should assist with understanding how they work and get a configuration started.
Sysmon-c.cfg
Great configuration to understand excludes and contains.
Sysmon-d.cfg
Solid blog post related to getting started with Sysmon. Config is nicely laid out and easy to understand.
Sysmon-e.cfg
Config is specific but it provides a good foundation for capturing a lot of specific data.
https://github.com/Prevenity/sysmon
(Translated comments to english)
StartLogging.xml
Provided by https://github.com/Cyb3rWard0g - Roberto Rodriguez
https://gist.github.com/Cyb3rWard0g/6f69475a667ef298d829370bd26ba8c2
Sysmoncfg_v2|31.xml
Related material from Splunking the Endpoint .conf talk by James Brodsky and Dimitri McKay.
Splunking the Endpoint - Files from presentation
Configs are optimized for Splunk.
Additional configs
Configs are updated frequently --
SwiftOnSecurity Fork by Ion-Storm
Server Config: https://gist.github.com/Neo23x0/a4b4af9481e01e749409
Client config: https://gist.github.com/Neo23x0/f56bea38d95040b70cf5