Ross ROSS = Recommend OSS · open-source software intelligence for agents

microsoft/SysmonForLinux

Sysmon for Linux observed · 2026-08-28

github.com/microsoft/SysmonForLinux · C · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

86/100

  • Activity 92
  • Release rhythm 71
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 44
  • age_days: 2135
  • days_rel: 118
  • days_push: 51
  • n_releases_24m: 8

Full methodology

Adoption not part of the score

2153 stars · 221 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Sysmon for Linux is a Sysinternals tool that monitors and logs system activity such as process lifetime, network connections, and file system writes. It uses advanced filtering to help identify malicious activity and understand how intruders and malware operate.

Use cases

  • monitor process creation and termination on linux servers
  • log network connections made by processes
  • detect malware and intruder activity on linux hosts
  • audit file system writes across reboots
  • feed sysmon events into a SIEM for threat hunting

When to choose

  • you need detailed, configurable system activity telemetry on linux
  • you want a windows Sysmon-equivalent for cross-platform detection engineering
  • you are building security monitoring or detection rules for linux endpoints

When to avoid

  • you only need lightweight metrics rather than security-focused event logging
  • you cannot install kernel-level monitoring components on the host
  • you need a GUI-based monitoring solution

Facets

cli-tool · maturity active

monitoring logging security security monitoring operating-systems developer-tools sysinternals system-monitoring edr kernel event-logging threat-detection linux

1 source

Member repositories

RepositoryRoleHealth v2
microsoft/SysmonForLinuxmain86

For agents

markdown · JSON · MCP: product_card(name="microsoft/SysmonForLinux")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem