ceramicskate0/sysmon-config
CeramicSkate0 Sysmon configuration fork file template with default high-quality event tracing
Issues
- 0
I'd 12-14 include
#97 opened by ceramicskate0 - 0
I'd 11 include
#96 opened by ceramicskate0 - 0
id 13 12 exclude
#95 opened by ceramicskate0 - 0
id 17 18 exclude
#94 opened by ceramicskate0 - 0
id 11 exclude
#93 opened by ceramicskate0 - 0
id 7 add
#92 opened by ceramicskate0 - 3
- 1
CLR Usage log
#87 opened by ceramic-skate0 - 0
lsass dumper
#84 opened by ceramicskate0 - 0
Event ID 7
#85 opened by ceramic-skate0 - 1
DLL Load ID 7 for .net
#86 opened by ceramic-skate0 - 0
id 5 exclude
#89 opened - 0
id 11 exclude
#91 opened - 0
id 12 exclude
#90 opened - 0
- 0
add to wiki or readme
#80 opened by ceramic-skate0 - 0
exclude id 11
#74 opened by ceramic-skate0 - 0
id 3 exempt
#75 opened by ceramic-skate0 - 0
id 11 exempt
#76 opened by ceramic-skate0 - 0
exclude id 22
#77 opened by ceramic-skate0 - 0
id 1 exempt
#78 opened by ceramic-skate0 - 0
id7 add
#79 opened by ceramic-skate0 - 1
- 1
File create event
#83 opened by ceramic-skate0 - 0
CFG disable reg key
#73 opened by ceramic-skate0 - 0
Exclude id1
#60 opened by ceramicskate0 - 0
exclude id 22
#61 opened by ceramicskate0 - 0
exclude id 5
#62 opened by ceramicskate0 - 0
exclude id 5
#63 opened by ceramicskate0 - 0
Exclude id 17 18
#64 opened by ceramicskate0 - 0
Exclude id 1
#65 opened by ceramicskate0 - 0
exclude id 5
#66 opened by ceramicskate0 - 0
excluide id 11 2
#67 opened by ceramicskate0 - 0
refine exclude dllhost id 1
#68 opened by ceramicskate0 - 0
exclude id 22
#69 opened by ceramicskate0 - 0
exclude id 2
#70 opened by ceramicskate0 - 0
exclde id 13
#71 opened by ceramicskate0 - 0
exclude id 11
#72 opened by ceramicskate0 - 1
need to modify dll hijack's/sideloads
#58 opened by ceramic-skate0 - 0
exclude event id 22
#48 opened by ceramic-skate0 - 0
reg include event
#49 opened by ceramicskate0 - 2
any file create evnt with .kirbi
#50 opened by ceramic-skate0 - 0
dll sideload additions
#51 opened by ceramic-skate0 - 0
dll sideload
#52 opened by ceramicskate0 - 0
dll sideload
#53 opened by ceramicskate0 - 1
dll sideload
#54 opened by ceramicskate0 - 0
dll sideload
#55 opened by ceramicskate0 - 1
add to pipes
#56 opened by ceramicskate0 - 0
filecreate (MEM DUMP to disk)
#57 opened by ceramicskate0 - 0
Exclude for id 12 and 13
#59 opened by ceramic-skate0