Sysmon Framework is a set of rules and dashboards for the visualization of multiple security checks on Sysmon’s events on Windows hosts. Sysmon is a de-facto standard to extend Microsoft Windows audit which allows detecting anomalies, suspicious events on Windows hosts, gather SHA-256 hashes from every running executable, etc. Further analysis is needed to check if they are caused by malware, user's data leakage intentions, or other reasons. Sysmon Framework contains 26 scenarios that are recommended for monitoring in SOC and early detection of APT activity.
Requirements SIEM: Micro Focus ArcSight ESM 6.9 or higher version.
Log Sources:
Microsoft Sysmon logs.
Sysmon Framework comes with a Sysmon parser for the WINC connector, built for
Sysinternals Sysmon v6.00 downloaded from https://github.com/S3COPS/ArcSight-Sysmon-FlexConnector
Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.
Version 1.1
Version 1.0
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox