Stars
SysmonX - An Augmented Drop-In Replacement of Sysmon
Sysmon EDR POC Build within Powershell to prove ability.
Code and yara rules to detect and analyze Cobalt Strike
The FLARE team's open-source tool to identify capabilities in executable files.
TrustedSec Sysinternals Sysmon Community Guide
An Inofficial Sysmon Version History (Change Log)
Logstash - transport and process your logs, events, or other data
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems