PowerShell module for creating and managing Sysinternals Sysmon config files.
-
Updated
Jan 14, 2018 - PowerShell
PowerShell module for creating and managing Sysinternals Sysmon config files.
Powershell collection designed to assist in Threat Hunting Windows systems.
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
Add a description, image, and links to the threatintel topic page so that developers can more easily learn about it.
To associate your repository with the threatintel topic, visit your repo's landing page and select "manage topics."