11/12 free views
Tool
Script
Endpoint Security

sysmon-modular

by olafhartong

2.9Kstars
640forks
163watchers
Updated 4 months ago
About

A modular and customizable repository of Sysmon configuration modules designed to simplify the creation and maintenance of Sysmon configs for endpoint security.

A repository of sysmon configuration modules

Primary Use Case

This tool is used by security professionals and system administrators to deploy and manage tailored Sysmon configurations for endpoint protection and intrusion detection. It enables easy customization and generation of Sysmon configs to fit specific environments, improving security monitoring and automation capabilities.

Key Features
  • Modular Sysmon configuration modules for easy customization
  • Pre-generated balanced, verbose, super verbose, and Defender for Endpoint augmentation configs
  • Automated config generation via PowerShell script and Azure Pipeline integration
  • Support for merging external configurations like LOLdrivers for enhanced detection
  • Detailed documentation and wiki for generating custom configurations
  • Configurations designed to optimize performance and event volume based on use case

Installation

  • Download and install Microsoft Sysinternals Sysmon from the official site
  • Clone the sysmon-modular repository from GitHub
  • Use the provided PowerShell script to generate a custom Sysmon configuration by merging desired modules
  • Deploy the generated sysmonconfig.xml to your endpoints with Sysmon installed
  • Tune and customize configurations per environment as strongly recommended

Usage

>_ PowerShell script to generate config

Runs the script to merge selected modules and generate a custom sysmonconfig.xml

>_ sysmon -i sysmonconfig.xml

Installs Sysmon with the generated configuration file

>_ sysmon -c sysmonconfig.xml

Updates Sysmon with a new configuration without reinstalling

>_ Add LOLdrivers config to 29_file_execute_detected folder

Enhances detection capabilities by merging the latest LOLdrivers config into the modular setup

Security Frameworks
Discovery
Collection
Defense Evasion
Credential Access
Execution
Usage Insights
  • Leverage modular config generation to tailor Sysmon logging for specific threat scenarios.
  • Integrate with SIEM and SOAR platforms for automated alerting and response workflows.
  • Use verbose configs in test environments to baseline normal activity and tune detection rules.
  • Combine with external detection rules like LOLdrivers to enhance file execution event visibility.
  • Automate config deployment via Azure Pipelines to ensure consistent endpoint monitoring across environments.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about sysmon-modular. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

3 free chats per tool • Instant responses • No credit card

Security Profile
Red Team30%
Blue Team90%
Purple Team70%
Details
LicenseMIT License
LanguagePowerShell
Open Issues103
Topics
sysmon
dfir
threat-hunting
mitre-attack
modular
security-tools