# olafhartong/sysmon-modular

A repository of sysmon configuration modules

Repository: https://github.com/olafhartong/sysmon-modular
Canonical: https://ross.abutalabs.com/products/sysmon-modular
Language: PowerShell
License: MIT
License Family: permissive
Topics: sysmon, dfir, threat-hunting, mitre-attack, modular, security-tools
Last push: 2026-08-10T00:47:52+00:00

## Health v2 (maintenance only)
Score: 75/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 96, release rhythm 35, longevity 100
- inputs: {"age_days": 3154, "days_push": 24, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3119, forks 657 (observed 2026-08-28T04:07:44.262166+00:00)

## What it is
A modular repository of Microsoft Sysmon configuration modules maintained in PowerShell, with scripts to generate custom sysmonconfig.xml files. It provides pre-generated default, default+, and verbose configurations mapped to MITRE ATT&CK for threat hunting and DFIR.

## Use cases
- generate a custom sysmon configuration for my windows environment
- find a good starting sysmon config for threat hunting
- tune sysmon event logging with modular include/exclude rules
- map sysmon events to MITRE ATT&CK techniques
- build a verbose sysmon config for DFIR investigations

## When to choose
- you run Sysmon on Windows and want a maintained, modular, MITRE-mapped configuration baseline
- you need to generate tailored Sysmon configs by merging your own modules
- you do threat hunting or DFIR and want richer event coverage

## When to avoid
- you need an EDR or detection engine rather than a Sysmon config
- you want a drop-in production config without per-environment tuning
- you are not using Windows or Sysmon

## Facets
- artifact type: dataset
- maturity: active
- function: security, monitoring, configuration-management, developer-tools
- domain: security, windows, developer-tools
- platform: windows
- tags: sysmon, dfir, threat-hunting, mitre-attack, sysmon-config, modular-config, powershell, security-tools, event-logging

## Member repositories
- olafhartong/sysmon-modular (main) score 75

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:44.262166+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:45:58.829326+00:00, confidence not recorded.
  - readme: https://github.com/olafhartong/sysmon-modular (fetched 2026-08-28T04:07:44.262166+00:00, sha 50d76603295a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
