JPCERTCC / SysmonSearch

Investigate suspicious activity by visualizing Sysmon's event log
417 stars 58 forks source link
elasticsearch kibana security stix stix2 sysmon


SysmonSearch make event log analysis more effective and less time consuming, by aggregating event logs generated by Microsoft's Sysmon.

SysmonSearch system

System Overview

SysmonSearch uses Elasticserach and Kibana (and Kibana plugin).

Use SysmonSearch

To try SysmonSearch, you can either 1)install softwares to your own linux enviroment with following instractions or 2)use docker image:

  1. Install to your own linux box
  2. Use docker image


For details, please check the SysmonSearch wiki.