⤷ Title: SYSMON
════════════════════════
𐀪 Author: rkn
════════════════════════
ⴵ Time: Sun, 15 Jun 2025 12:14:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #sysmon
════════════════════════
𐀪 Author: rkn
════════════════════════
ⴵ Time: Sun, 15 Jun 2025 12:14:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #sysmon
Medium
SYSMON
What is Sysmon??
⤷ Title: Intermediate Lab Environment: Configure Windows VM-1
════════════════════════
𐀪 Author: Allen Ace
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 16:48:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #windows #penetration_testing #technology #sysmon
════════════════════════
𐀪 Author: Allen Ace
════════════════════════
ⴵ Time: Fri, 04 Jul 2025 16:48:25 GMT
════════════════════════
⌗ Tags: #cybersecurity #windows #penetration_testing #technology #sysmon
Medium
Intermediate Lab Environment: Configure Windows VM-1
Part 6a
⤷ Title: TEMPEST TryHackMe Walkthrough
════════════════════════
𐀪 Author: Olodudeibukun
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 18:25:50 GMT
════════════════════════
⌗ Tags: #tryhackme #sysmon #windows_event_logs #tryhackme_walkthrough #tryhackme_writeup
════════════════════════
𐀪 Author: Olodudeibukun
════════════════════════
ⴵ Time: Sat, 05 Jul 2025 18:25:50 GMT
════════════════════════
⌗ Tags: #tryhackme #sysmon #windows_event_logs #tryhackme_walkthrough #tryhackme_writeup
Medium
TEMPEST TryHackMe Walkthrough
TL;DR walkthrough of the TryHackMe Tempest room.
⤷ Title: [CyberDefenders Write-up] MeteorHit (Lab inspired by MeteorExpress incident)
════════════════════════
𐀪 Author: Chicken0248
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 10:14:36 GMT
════════════════════════
⌗ Tags: #digital_forensics #cyberdefender #cybersecurity #blue_team #sysmon
════════════════════════
𐀪 Author: Chicken0248
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 10:14:36 GMT
════════════════════════
⌗ Tags: #digital_forensics #cyberdefender #cybersecurity #blue_team #sysmon
Medium
[CyberDefenders Write-up] MeteorHit (Lab inspired by MeteorExpress incident)
Investigate compromised machine started from GPO immediate task which was inspired by MeteorExpress wiping incident.
⤷ Title: Why Sysmon is a Must-Have in Your Security Toolkit
════════════════════════
𐀪 Author: Prasidh
════════════════════════
ⴵ Time: Sun, 13 Jul 2025 12:06:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #sysmon
════════════════════════
𐀪 Author: Prasidh
════════════════════════
ⴵ Time: Sun, 13 Jul 2025 12:06:42 GMT
════════════════════════
⌗ Tags: #cybersecurity #sysmon
Medium
Why Sysmon is a Must-Have in Your Security Toolkit
When a security incident strikes, the ability to thoroughly investigate and understand “how it happened” is paramount. While Windows’…
⤷ Title: Getting Started with Sysmon — System Monitoring for Windows
════════════════════════
𐀪 Author: Samuel George
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 23:25:43 GMT
════════════════════════
⌗ Tags: #system_monitor #cyber_security_awareness #application_security #information_security #sysmon
════════════════════════
𐀪 Author: Samuel George
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 23:25:43 GMT
════════════════════════
⌗ Tags: #system_monitor #cyber_security_awareness #application_security #information_security #sysmon
Medium
Getting Started with Sysmon — System Monitoring for Windows
Sysmon (System Monitor) is a powerful Windows system service and device driver that logs system activity into the Windows event log…
⤷ Title: Sysmon Config and Sending Logs to Wazuh: Enhancing Endpoint Visibility
════════════════════════
𐀪 Author: Arfan Abid
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 14:36:15 GMT
════════════════════════
⌗ Tags: #siem #wazuh #sysmon #infosec #log_analysis_sysmon
════════════════════════
𐀪 Author: Arfan Abid
════════════════════════
ⴵ Time: Thu, 18 Sep 2025 14:36:15 GMT
════════════════════════
⌗ Tags: #siem #wazuh #sysmon #infosec #log_analysis_sysmon
Medium
Sysmon Config and Sending Logs to Wazuh: Enhancing Endpoint Visibility
By default, the Wazuh Agent collects Windows and system logs. While this provides a basic level of monitoring, it does not deliver enough…
⤷ Title: From The Lab to the SOC: Generating Telemetry and Detecting Malicious Activity in an Isolated…
════════════════════════
𐀪 Author: Humphrey Swanzy Quaicoe
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 07:53:17 GMT
════════════════════════
⌗ Tags: #splunk #virtualbox #sysmon #cybersecurity #dfir
════════════════════════
𐀪 Author: Humphrey Swanzy Quaicoe
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 07:53:17 GMT
════════════════════════
⌗ Tags: #splunk #virtualbox #sysmon #cybersecurity #dfir
Medium
From The Lab to the SOC: Generating Telemetry and Detecting Malicious Activity in an Isolated Virtual Lab
Here’s how I set up an isolated VirtualBox lab (Kali + Windows) to practice threat hunting. With Sysmon for endpoint data and Splunk for…
⤷ Title: Install Sysmon on Windows
════════════════════════
𐀪 Author: James Rawlings
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 15:59:04 GMT
════════════════════════
⌗ Tags: #jamesrawlings #cybersecurity #windows #sysmon #information_technology
════════════════════════
𐀪 Author: James Rawlings
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 15:59:04 GMT
════════════════════════
⌗ Tags: #jamesrawlings #cybersecurity #windows #sysmon #information_technology
Medium
Install Sysmon on Windows
Sysmon, short for System Monitor, is a powerful Windows system service and driver developed by Microsoft that provides detailed monitoring…
⤷ Title: Setup Splunk & Sysmon if you have a Mac Apple Silicon
════════════════════════
𐀪 Author: Mcl0ng0ng
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 21:39:51 GMT
════════════════════════
⌗ Tags: #sysmon #macos #splunk #soc_analyst #cybersecurity
════════════════════════
𐀪 Author: Mcl0ng0ng
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 21:39:51 GMT
════════════════════════
⌗ Tags: #sysmon #macos #splunk #soc_analyst #cybersecurity
Medium
Setup Splunk & Sysmon if you have a Mac Apple Silicon
Hi, today I will try to help you set up your own (mini) home lab, if you want to call it that. If you’re wondering who would be stupid to…
⤷ Title: Windows log file analysis using Sysmon
════════════════════════
𐀪 Author: k1ndlov3r
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 05:41:55 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #windows_logs #sysmon #log_analysis_sysmon #log_analysis
════════════════════════
𐀪 Author: k1ndlov3r
════════════════════════
ⴵ Time: Mon, 20 Oct 2025 05:41:55 GMT
════════════════════════
⌗ Tags: #hackthebox_writeup #windows_logs #sysmon #log_analysis_sysmon #log_analysis
Medium
Windows log file analysis using Sysmon
HackTheBox Sherlock: Unit42 Walkthrough
⤷ Title: Sysmon +Wazuh: The Defense-In-Depth Dynamic Duo
════════════════════════
𐀪 Author: Johnny Meintel
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:19:36 GMT
════════════════════════
⌗ Tags: #wazuh #cybersecurity #sysmon #siem #homelab
════════════════════════
𐀪 Author: Johnny Meintel
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:19:36 GMT
════════════════════════
⌗ Tags: #wazuh #cybersecurity #sysmon #siem #homelab
Medium
Sysmon +Wazuh: The Defense-In-Depth Dynamic Duo
We’ve got Wazuh up and running. Enter Sysmon — a highly granular and metadata-rich Windows system tool that provides the forensic detail…
⤷ Title: How I Set Up Sysmon and Splunk Without Losing My Sanity
════════════════════════
𐀪 Author: Udith Ragav
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:47:32 GMT
════════════════════════
⌗ Tags: #splunk #siem #cybersecurity #sysmon #windows_security
════════════════════════
𐀪 Author: Udith Ragav
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 00:47:32 GMT
════════════════════════
⌗ Tags: #splunk #siem #cybersecurity #sysmon #windows_security
Medium
How I Set Up Sysmon and Splunk Without Losing My Sanity
Let’s be honest — integrating Sysmon with Splunk sounds easy until you try it. Then suddenly you’re knee-deep in XML logs, forwarder…
⤷ Title: Sysmon | Endpoint Security Monitoring — THM [2025]
════════════════════════
𐀪 Author: Rahul
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 10:52:29 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #sysmon #endpoint_security
════════════════════════
𐀪 Author: Rahul
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 10:52:29 GMT
════════════════════════
⌗ Tags: #tryhackme #tryhackme_walkthrough #sysmon #endpoint_security
Medium
Sysmon | Endpoint Security Monitoring — THM [2025]
Learn how to utilize Sysmon to monitor and log your endpoints and environments.
⤷ Title: CyberDefenders — GoldenSpray Lab (Writeup)
════════════════════════
𐀪 Author: Muhammed Alaa
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 18:39:13 GMT
════════════════════════
⌗ Tags: #cyberdefenders_writeup #threat_hunting #sysmon #cybersecurity #elk_stack
════════════════════════
𐀪 Author: Muhammed Alaa
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 18:39:13 GMT
════════════════════════
⌗ Tags: #cyberdefenders_writeup #threat_hunting #sysmon #cybersecurity #elk_stack
Medium
CyberDefenders — GoldenSpray Lab (Writeup)
Lab Link: https://cyberdefenders.org/blueteam-ctf-challenges/goldenspray/
⤷ Title: Microsoft Integrates Sysmon Natively into Windows 11 & Server 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:25:18 +0000
════════════════════════
⌗ Tags: #Windows #Incident Response #Microsoft #Secure Future Initiative #Security Telemetry #security tool #SIEM #Sysmon #Windows 11 #Windows Server 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:25:18 +0000
════════════════════════
⌗ Tags: #Windows #Incident Response #Microsoft #Secure Future Initiative #Security Telemetry #security tool #SIEM #Sysmon #Windows 11 #Windows Server 2025
Penetration Testing Tools
Microsoft Integrates Sysmon Natively into Windows 11 & Server 2025
Sysmon capabilities are now natively integrated into Windows 11 and Server 2025, providing built-in security telemetry for process and network monitoring via Windows Update.
⤷ Title: Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell
════════════════════════
𐀪 Author: Citadel Cybersec
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 17:41:18 GMT
════════════════════════
⌗ Tags: #incident_response #tryhackme #sysmon #cybersecurity #blue_team
════════════════════════
𐀪 Author: Citadel Cybersec
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 17:41:18 GMT
════════════════════════
⌗ Tags: #incident_response #tryhackme #sysmon #cybersecurity #blue_team
Medium
Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell
TryHackMe Sysmon Task 10: Practical Investigations Explained (With PowerShell)
⤷ Title: Native Sysmon Arrives in the Latest Windows 11 Insider Build 26300
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:08:19 +0000
════════════════════════
⌗ Tags: #Windows #Build 26300.7733 #Dev Channel #forensic analysis #KB5074178 #Microsoft Sysinternals #Sysmon #Tech News #Threat Detection #Windows 11 #Windows 26H2 #Windows Insider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 03:08:19 +0000
════════════════════════
⌗ Tags: #Windows #Build 26300.7733 #Dev Channel #forensic analysis #KB5074178 #Microsoft Sysinternals #Sysmon #Tech News #Threat Detection #Windows 11 #Windows 26H2 #Windows Insider
Daily CyberSecurity
Native Sysmon Arrives in the Latest Windows 11 Insider Build 26300
Microsoft integrates native Sysmon into Windows 11 Build 26300.7733 (KB5074178). Track process creation and network links with this built-in forensic "dashcam."
⤷ Title: Deep Diagnostics: Microsoft Supercharges Sysinternals with AI-Era Process Tracking and Linux Support
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 03:21:06 +0000
════════════════════════
⌗ Tags: #Microsoft #Autoruns #Debian 13 #DebugView #IT Administration #Linux Security #Powertoys #ProcDump #Process Explorer #RHEL 10 #Sysinternals #Sysmon #Windows Troubleshooting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 May 2026 03:21:06 +0000
════════════════════════
⌗ Tags: #Microsoft #Autoruns #Debian 13 #DebugView #IT Administration #Linux Security #Powertoys #ProcDump #Process Explorer #RHEL 10 #Sysinternals #Sysmon #Windows Troubleshooting
Penetration Testing Tools
Deep Diagnostics: Microsoft Supercharges Sysinternals with AI-Era Process Tracking and Linux Support
Microsoft has modernized several quintessential utilities within the Sysinternals Suite, a collection frequently utilized by system administrators, support
⤷ Title: Day 8: Sysmon Explained — Why Windows Event Logs Alone Aren’t Enough
════════════════════════
𐀪 Author: SIAM AHMED
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 10:49:37 GMT
════════════════════════
⌗ Tags: #soc_analyst #ethical_hacking #deep_learning #sysmon #cybersecurity
════════════════════════
𐀪 Author: SIAM AHMED
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 10:49:37 GMT
════════════════════════
⌗ Tags: #soc_analyst #ethical_hacking #deep_learning #sysmon #cybersecurity
Medium
Day 8: Sysmon Explained — Why Windows Event Logs Alone Aren’t Enough
In the previous article, we explored how Windows Event Logs provide valuable information for monitoring and investigating security events…