SwiftOnSecurity/sysmon-config resource
Sysmon configuration file template with default high-quality event tracing observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3500
- days_rel: n/a
- days_push: 791
- n_releases_24m: 0
Adoption not part of the score
5630 stars · 1865 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
A heavily commented Microsoft Sysmon configuration file template providing high-quality default event tracing for Windows systems. It serves as both a deployable monitoring baseline and a tutorial for learning Sysmon's filtering capabilities.
Use cases
- set up sysmon event tracing on windows endpoints
- find a starting point sysmon config for threat hunting
- learn how sysmon filtering rules work
- monitor process creation and system changes on windows
- reduce sysmon log noise with tuned exclusions
- deploy endpoint telemetry for incident investigation
When to choose
- you want a well-commented, community-proven Sysmon baseline to deploy quickly
- you are learning Sysmon and want a self-documenting configuration
- you need a lightweight starting point you can fork and customize
When to avoid
- you need an exhaustive, modular rule set - use sysmon-modular instead
- you expect it to cover Windows authentication and native event log auditing - Sysmon complements, not replaces, those
- you want a turnkey solution without environment-specific tuning like antivirus exclusions
Facets
infra-config · maturity maintenance
monitoring logging security security windows monitoring developer-tools windows sysmon sysinternals threat-hunting threat-intelligence endpoint-monitoring configuration-template incident-response
1 source
- readme: https://github.com/SwiftOnSecurity/sysmon-config · fetched 2026-08-28 · c617d709fba3
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| SwiftOnSecurity/sysmon-config | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="SwiftOnSecurity/sysmon-config")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem