7MS #588: Becoming a Sysmon Sensei with Amanda Berlin

7MS #588: Becoming a Sysmon Sensei with Amanda Berlin

Today Amanda Berlin from Blumira teaches us how to unlock the power of Sysmon so we can gain insight into the good, bad and ugly things happening on our corporate endpoints! Key takeaways:

  • Sysmon turns your windows logging up to 11, and pairs well with a config file like this one or this one.
  • Careful if you are are running sysmon on non-SSD drives - the intense number of writes might bring that disk to its knees.
  • Just getting started logging all the things with sysmon? Why not pump those logs into a free logging/alerting system like Wazuh?
  • I think it was SolarWinds log collector I was trying to think of while recording the show, not CloudTrail.

Populärt inom Politik & nyheter

svenska-fall
motiv
aftonbladet-krim
rss-krimstad
p3-krim
fordomspodden
rss-viva-fotboll
flashback-forever
blenda-2
aftonbladet-daily
rss-sanning-konsekvens
rss-krimreportrarna
rss-vad-fan-hande
dagens-eko
rss-frandfors-horna
grans
olyckan-inifran
rss-flodet
spotlight
krimmagasinet