ION28 / BLUESPAWN

An Active Defense and EDR software to empower Blue Teams
GNU General Public License v3.0
1.23k stars 167 forks source link

Create mitigation to install Sysmon if not installed already #354

Open ION28 opened 4 years ago

ION28 commented 4 years ago

Need to draft a good default config too or decide to rely on another open source project like Olaf's awesome sysmon-modular

Jack-McDowell commented 4 years ago

This may violate sysinternals' licensing. See https://docs.microsoft.com/en-us/sysinternals/license-faq Perhaps if we have BLUESPAWN download it from the official sysinternals site only after user agreeing to it, it will be fine. We also have to require the user to accept the EULA for it.