Sysmon
Last updated
Last updated
System Monitor (Sysmon) offers us additional event logging capabilities to detect IOC and other unwanted behavior. It remains active during reboots to monitor and log system activity.
Sysmon for also exists!
Sysmon has it's own event ID's seperate from Windows Event Logs.
Event ID 1: Process Creation Events
Event ID 3: Network Connection Events
Event ID 7: DLL Load Events