Test Blue Team detections without running any attack.
-
Updated
May 2, 2024 - C#
Test Blue Team detections without running any attack.
Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at https://github.com/ceramicskate0/SWELF/releases/latest.
Bypass windows eventlogs & Sysmon
Converts Sysmon rules to uberAgent ESA Threat Detection rules
Wixsharp based installed MSI for Sysmon and rules from the SwiftOnSecurity project
Add a description, image, and links to the sysmon topic page so that developers can more easily learn about it.
To associate your repository with the sysmon topic, visit your repo's landing page and select "manage topics."