microsoft/SysmonForLinux
Sysmon for Linux observed · 2026-08-28
Health v2 · maintenance only
86/100
- Activity 92
- Release rhythm 71
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 44
- age_days: 2135
- days_rel: 118
- days_push: 51
- n_releases_24m: 8
Adoption not part of the score
2153 stars · 221 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Sysmon for Linux is a Sysinternals tool that monitors and logs system activity such as process lifetime, network connections, and file system writes. It uses advanced filtering to help identify malicious activity and understand how intruders and malware operate.
Use cases
- monitor process creation and termination on linux servers
- log network connections made by processes
- detect malware and intruder activity on linux hosts
- audit file system writes across reboots
- feed sysmon events into a SIEM for threat hunting
When to choose
- you need detailed, configurable system activity telemetry on linux
- you want a windows Sysmon-equivalent for cross-platform detection engineering
- you are building security monitoring or detection rules for linux endpoints
When to avoid
- you only need lightweight metrics rather than security-focused event logging
- you cannot install kernel-level monitoring components on the host
- you need a GUI-based monitoring solution
Facets
cli-tool · maturity active
monitoring logging security security monitoring operating-systems developer-tools sysinternals system-monitoring edr kernel event-logging threat-detection linux
1 source
- readme: https://github.com/microsoft/SysmonForLinux · fetched 2026-08-28 · 6988380b0573
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| microsoft/SysmonForLinux | main | 86 |
For agents
markdown · JSON · MCP: product_card(name="microsoft/SysmonForLinux")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem