{"adoption": {"forks": 1865, "observed_at": "2026-08-28T04:09:26.230564+00:00", "stars": 5630}, "canonical_url": "https://ross.abutalabs.com/products/sysmon-config", "card": {"archived": false, "artifact_type": "infra-config", "description": "Sysmon configuration file template with default high-quality event tracing", "domain": ["security", "windows", "monitoring", "developer-tools"], "enriched": true, "function": ["monitoring", "logging", "security"], "health_score": 20, "homepage": null, "language": null, "license": null, "license_family": "other", "maturity": "maintenance", "member_repos": ["SwiftOnSecurity/sysmon-config"], "name": "SwiftOnSecurity/sysmon-config", "platform": ["windows"], "pushed_at": "2024-07-03T17:26:43+00:00", "repo": "SwiftOnSecurity/sysmon-config", "stars": 5630, "tags": ["sysmon", "sysinternals", "threat-hunting", "threat-intelligence", "endpoint-monitoring", "configuration-template", "incident-response"], "topics": ["sysmon", "threatintel", "threat-hunting", "sysinternals", "windows", "netsec", "monitoring", "logging"], "urls": [], "use_cases": ["set up sysmon event tracing on windows endpoints", "find a starting point sysmon config for threat hunting", "learn how sysmon filtering rules work", "monitor process creation and system changes on windows", "reduce sysmon log noise with tuned exclusions", "deploy endpoint telemetry for incident investigation"], "what_it_is": "A heavily commented Microsoft Sysmon configuration file template providing high-quality default event tracing for Windows systems. It serves as both a deployable monitoring baseline and a tutorial for learning Sysmon's filtering capabilities.", "when_to_avoid": ["you need an exhaustive, modular rule set - use sysmon-modular instead", "you expect it to cover Windows authentication and native event log auditing - Sysmon complements, not replaces, those", "you want a turnkey solution without environment-specific tuning like antivirus exclusions"], "when_to_choose": ["you want a well-commented, community-proven Sysmon baseline to deploy quickly", "you are learning Sysmon and want a self-documenting configuration", "you need a lightweight starting point you can fork and customize"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/sysmon-config", "repo": "SwiftOnSecurity/sysmon-config", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:09:26.230564+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T17:55:20.847513+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c617d709fba382cba4932bd38c307ea19577ed66daaa42ecac8828a4bace5fed", "fetched_at": "2026-08-28T04:09:26.230564+00:00", "kind": "readme", "missing": false, "url": "https://github.com/SwiftOnSecurity/sysmon-config"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3500, "days_push": 791, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}