trustedsec/SysmonCommunityGuide resource
TrustedSec Sysinternals Sysmon Community Guide observed · 2026-08-28
Health v2 · maintenance only
71/100
- Activity 90
- Release rhythm 29
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2415
- days_rel: 261
- days_push: 64
- n_releases_24m: 1
Adoption not part of the score
1431 stars · 185 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A community-maintained guide by TrustedSec covering Microsoft Sysinternals Sysmon on Windows and Linux, including installation, configuration, event types, and detection engineering fundamentals. It is licensed under Creative Commons BY-SA and serves as reference documentation rather than a software tool.
Use cases
- learn how to install and configure Sysmon on Windows
- understand Sysmon event types like process creation and registry actions
- set up Sysmon on Linux with eBPF
- write better Sysmon configuration files for threat detection
- learn detection engineering fundamentals with Sysmon telemetry
- find documentation on Sysmon network and DNS events
When to choose
- you are a security engineer or threat hunter deploying or tuning Sysmon
- you need a free, community-driven reference for Sysmon event IDs and configuration
- you want to learn detection engineering using endpoint telemetry
When to avoid
- you need a runnable tool or script rather than documentation
- you need vendor-official Microsoft documentation or support
- you need a general-purpose EDR or SIEM product
Facets
learning-resource · maturity active
security monitoring documentation security windows developer-tools windows cross-platform sysmon sysinternals detection-engineering threat-hunting community-guide endpoint-monitoring siem linux
1 source
- readme: https://github.com/trustedsec/SysmonCommunityGuide · fetched 2026-08-28 · 44101ebbbeb5
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| trustedsec/SysmonCommunityGuide | main | 71 |
For agents
markdown · JSON · MCP: product_card(name="trustedsec/SysmonCommunityGuide")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem