This is a Short video about Sysmon .It is a very good SysInternals tool and has been widely used these days in threat hunting .It Provides very good information about process creation with full command line for both current and parent processes. Installation of tool is simple but without a good configuration ,it will not provide you enough data .
This is First Part of the video . In the next part , we will show you on how to collect logs via Splunk.
Following links are used in making this video .
- Download Sysmon
- Download Sample Configuration from SwiftOnSecurity OR
- Download Sample Configuration from OlafHartong
- Installation of Sysmon with Configuration
- sysmon -accepteula -i sysmonconfig.xml
- sysmon -c sysmonconfig.xml (To Update Configuration)
- Generate Logs via Atomic red team
Name: Shahzad Subhani
Shahzad Subhani is an information security enthusiast with 20 years of experience in different cyber security domains. He is an electrical engineering graduate from UET Lahore. His core expertise includes Malware Protection, Anti phishing, Email Security, Data Loss Protection, Encryption, Incident management, Digital forensics and SIEM Solutions. He is a hands-on guy and is always keen to mentor and share knowledge with his colleagues and juniors. He has a good working experience with industry's Key security Products . Some of these Products include Splunk Enterprise ,Fireeye , Tripwire , Phantom , Websense, Symantec Endpoint Protection , Symantec Data Loss Prevention and Symantec Messaging Gateway. Shahzad also writes Security articles as well as creates and organize video sessions on different information security topics.His articles can be seen at Shahzad Subhani Articles . The Videos can be seen on this Website as well as GISPP Academy YouTube Channel . He believes in spreading cybersecurity awareness among the masses , free knowledge transfer and capacity building of our Youth . LinkedIn Profile : https://www.linkedin.com/in/shahzadsubhani