Sysmon
Microsoft Sysinternals' Sysmon: a Windows service that emits detailed process, network, and file events, vastly richer than default Windows logging. A go-to source for endpoint detection and hunting.
Concept Neighborhood
No connected concepts linked yet.
Related Lessons
8 lessons cover this conceptHigh-Quality Security Telemetry
General Beginner
The Major Log Sources Every Defender Should Know
General Beginner
SIEM, Log Management, and the Detection Platform
General Beginner
Detection Rules: Signatures, Behaviors, and Anomalies
General Beginner
Threat Hunting Beyond Alerts
General Beginner
Common Telemetry Pitfalls: Log Gaps, Alert Fatigue, and Low-Quality Data
General Beginner
Processes, Users, and the Idea of Security Context
General Beginner
Windows Essentials for Defenders
General Beginner
Sign in to open lesson content directly.
