Technical requirements
The following tools and resources are used throughout this chapter:
- Sysmon: https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
sysmonconfig-export.xml
: https://github.com/SwiftOnSecurity/sysmon-config/blob/master/sysmonconfig-export.xml- SilentDefense System Logging Protocol (syslog) configuration: https://github.com/SackOfHacks/Industrial-Cybersecurity-2nd-Edition/blob/main/security-onion-logstash/syslog
- Oinkcode: https://snort.org/