Homepage
Open in app
Sign in
Get started
Tagged in
Sysmon
FalconForce
A team of highly specialized security professionals
More information
Followers
689
Elsewhere
More, on Medium
Sysmon
Olaf Hartong
in
FalconForce
Oct 15, 2021
Sysmon vs Microsoft Defender for Endpoint, MDE Internals 0x01
Read more…
278
Gijs Hollestelle
in
FalconForce
Jul 23, 2021
FalconFriday — Direct system calls and Cobalt Strike BOFs — 0xFF14
Read more…
7
Olaf Hartong
in
FalconForce
Apr 21, 2021
Sysmon 13.10 FileDeleteDetected
The Sysinternals team has released Sysmon 13.10 and adds the…
Read more…
41
Olaf Hartong
in
FalconForce
Jan 11, 2021
Sysmon 13 — Process tampering detection
Symon 13 adds a new detective capability to your detection…
Read more…
81
1 response
Olaf Hartong
in
FalconForce
Sep 17, 2020
Sysmon 12.0 — EventID 24
Sysmon 12 is out, with a new event ID: number 24. A very useful new feature,
clipboard monitoring
.
Read more…
45
Henri Hambartsumyan
in
FalconForce
Aug 14, 2020
Introducing Falcon Friday
Every two weeks on “Falcon Friday”, we’ll release hunting queries to detect…
Read more…
5
Olaf Hartong
in
FalconForce
Jul 16, 2020
Using Azure Pipelines to validate my Sysmon configuration
Read more…
62
Olaf Hartong
in
FalconForce
Jun 24, 2020
Sysmon 11.1 Bug fixes, a schema update and a new field
Read more…
14
Olaf Hartong
in
FalconForce
Apr 28, 2020
Sysmon 11 — DNS improvements and FileDelete events
Read more…
131
2 responses