oz9un / sysmonforlinux-manual Goto Github PK
View Code? Open in Web Editor NEWThis repo contains specific configuration files for better understanding of sysmon configuration on Linux systems.
This repo contains specific configuration files for better understanding of sysmon configuration on Linux systems.
sysmon -c /opt/sysmon/config.xml
Sysmon v1.0.2 - Monitors system events
Sysinternals - www.sysinternals.com
By Mark Russinovich, Thomas Garnier and Kevin Sheldrake
Copyright (C) 2014-2021 Microsoft Corporation
Using libxml2. libxml2 is Copyright (C) 1998-2012 Daniel Veillard. All Rights Reserved.
Loading configuration file with schema version 4.70
Sysmon schema version: 4.81
Configuration file validated.
Event SYSMONEVENT_PROCESS_TERMINATE
RuleName: -
UtcTime: 2022-09-26 08:05:14.789
ProcessGuid: {00000000-0000-0000-0000-000000000000}
ProcessId: 4285
Image:
User: root
Event SYSMONEVENT_PROCESS_TERMINATE
RuleName: -
UtcTime: 2022-09-26 08:05:14.790
ProcessGuid: {00000000-0000-0000-0000-000000000000}
ProcessId: 4286
Image:
User: root
Event SYSMONEVENT_CREATE_PROCESS
RuleName: -
UtcTime: 2022-09-26 08:05:15.341
ProcessGuid: {20220824-5d3b-6331-31a8-5e90fb550000}
ProcessId: 4287
Image: /usr/bin/sysmon
FileVersion: -
Description: -
Product: -
Company: -
OriginalFileName: -
CommandLine: sysmon -c /opt/sysmon/config.xml
CurrentDirectory: /root
User: root
LogonGuid: {20220824-4111-6331-0000-000004000000}
LogonId: 0
TerminalSessionId: 22
IntegrityLevel: no level
Hashes: -
ParentProcessGuid: {00000000-0000-0000-0000-000000000000}
ParentProcessId: 3184
ParentImage: -
ParentCommandLine: -
ParentUser: -
Event SYSMONEVENT_SERVICE_CONFIGURATION_CHANGE
UtcTime: 2022-09-26 08:05:15.348
Configuration: /opt/sysmon/config.xml
ConfigurationFileHash: -
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.