olafhartong / sysmon-parser

Automatically generated Sysmon parser for Azure Sentinel

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

sysmon-parser

Automatically generated Sysmon parser for Azure Sentinel

Sysmon-AllVersions_Parser.txt can be loaded as a function in Azure Sentinel to parse all your events.

There is an Azure Devops pipeline that triggers daily to install the latest Sysmon version, extracts the schema and populates the parser with all unique fields.

The PowerShell script can also be run locally on a box which has Sysmon installed

About

Automatically generated Sysmon parser for Azure Sentinel


Languages

Language:PowerShell 100.0%