0xrawsec / whids

Open Source EDR for Windows
https://rawsec.lu
GNU Affero General Public License v3.0
1.14k stars 138 forks source link

build a minimal Sysmon agnostic configuration #108

Closed qjerome closed 2 years ago

qjerome commented 2 years ago

The goal is to provide a minimal Sysmon configuration when Sysmon is deployed on endpoints and configuration is not yet available on the manager.