ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
-
Updated
Mar 20, 2024 - C#
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
BasicEventViewer4 (BEV v4.0), this code will useful for All Blue/Purple Teams , RealTime Monitoring Sysmon Events , Mitre Attack Detections via yaml files
BasicEventViewer (BEV v3.0), this code will useful for All Blue Teamers.
Add a description, image, and links to the threat-hunting-via-sysmon topic page so that developers can more easily learn about it.
To associate your repository with the threat-hunting-via-sysmon topic, visit your repo's landing page and select "manage topics."