Sysmon
Microsoft Sysinternals' Sysmon: a Windows service that emits detailed process, network, and file events, vastly richer than default Windows logging. A go-to source for endpoint detection and hunting.
Concept Neighborhood
Start here
Detection engineering
The most substantial related concept here, covered by 16 lessons.
Detection engineeringStart here
16
lessons
Command Line
6
lessons
Endpoint Telemetry
6
lessons
System Calls
6
lessons
Event IDs
2
lessons
Windows Event Log
2
lessons
Show 4 more connections
Related Lessons
8 lessons cover this conceptDesign Security Telemetry
General Beginner
Build Reliable Source Coverage
General Beginner
Protect the Telemetry Pipeline
General Beginner
Store, Query, and Govern Telemetry
General Beginner
Make Telemetry Detection-Ready
General Beginner
Operate and Improve Telemetry
General Beginner
Processes, Users, and the Idea of Security Context
General Beginner
Windows Essentials for Defenders
General Beginner
Sign in to open lesson content directly.
