Skip to content

Automatically generated Sysmon parser for Azure Sentinel

Notifications You must be signed in to change notification settings

olafhartong/sysmon-parser

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 

Repository files navigation

sysmon-parser

Automatically generated Sysmon parser for Azure Sentinel

Sysmon-AllVersions_Parser.txt can be loaded as a function in Azure Sentinel to parse all your events.

There is an Azure Devops pipeline that triggers daily to install the latest Sysmon version, extracts the schema and populates the parser with all unique fields.

The PowerShell script can also be run locally on a box which has Sysmon installed

About

Automatically generated Sysmon parser for Azure Sentinel

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published