awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to mhaggis/sysmon-dfir

Projects sharing features with Sysmon Dfir

16 open-source projects similar to mhaggis/sysmon-dfir, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • olafhartong/sysmon-modularolafhartong avatar

    olafhartong/sysmon-modular

    3,057View on GitHub↗

    A repository of sysmon configuration modules

    PowerShell
    View on GitHub↗3,057
  • swiftonsecurity/sysmon-configSwiftOnSecurity avatar

    SwiftOnSecurity/sysmon-config

    5,398View on GitHub↗

    sysmon-config provides configuration templates and exclusion rule sets designed to standardize system event tracing and reduce log noise on Windows hosts. It functions as a security configuration baseline that establishes a standard for tracing system events and process behaviors. The project focuses on providing pre-defined XML filters to highlight anomalous system changes while minimizing performance impact. It utilizes a collection of exclusion rules to remove trusted processes from event logs, which improves signal quality and reduces the volume of generated security data. These configur

    loggingmonitoringnetsec
    View on GitHub↗5,398
  • futurice/backend-best-practicesfuturice avatar

    futurice/backend-best-practices

    2,362View on GitHub↗

    This project provides a collection of architectural guidelines and operational standards for building secure, maintainable, and scalable server-side software systems. It establishes a framework for implementing consistent development environments, system observability, and data security practices across distributed application environments. The repository focuses on standardizing software engineering conventions to ensure environment parity and system transparency. It covers the implementation of aggregated health monitoring, request throttling, and secure data handling, including the use of

    best-practices
    View on GitHub↗2,362
  • kolide/fleetkolide avatar

    kolide/fleet

    1,098View on GitHub↗

    A flexible control server for osquery fleets

    hacktoberfesthost-instrumentationinfosec
    View on GitHub↗1,098

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • neo23x0/auditdNeo23x0 avatar

    Neo23x0/auditd

    1,854View on GitHub↗

    Best Practice Auditd Configuration

    Shell
    View on GitHub↗1,854
  • nshalabi/sysmontoolsnshalabi avatar

    nshalabi/SysmonTools

    1,650View on GitHub↗

    Utilities for Sysmon

    TypeScriptloggingmonitoringnetsec
    View on GitHub↗1,650
  • osquery/osqueryosquery avatar

    osquery/osquery

    23,113View on GitHub↗

    Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By representing hardware, network, and process activity as structured data, it allows users to retrieve system state and configuration information using standard SQL syntax. The system distinguishes itself through a cross-platform abstraction layer that normalizes disparate operating system interfaces into a consistent schema across Windows, macOS, and Linux. It supports both interactive local analysis via a command-line shell and distributed fleet orchestration, where recurring qu

    C++hacktoberfestintrusion-detectionmonitoring
    View on GitHub↗23,113
  • ossec/ossec-hidsO

    ossec/ossec-hids

    0View on GitHub↗

    OSSEC v4.1.0

    View on GitHub↗0
  • palantir/osquery-configurationP

    palantir/osquery-configuration

    0View on GitHub↗
    View on GitHub↗0
  • slackhq/go-auditslackhq avatar

    slackhq/go-audit

    1,660View on GitHub↗

    go-audit is an alternative to the auditd daemon that ships with many distros

    Go
    View on GitHub↗1,660
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • wazuh/wazuhwazuh avatar

    wazuh/wazuh

    14,779View on GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Ccloud-securitycomplianceconfiguration-assessement
    View on GitHub↗14,779
  • draios/sysdigdraios avatar

    draios/sysdig

    8,261View on GitHub↗

    Sysdig is a Linux system observability tool and kernel event analyzer designed for capturing and analyzing kernel-level system calls and operating system events. It functions as a system call tracer and container security monitor, providing deep visibility into the activity of machines, virtual machines, and containers. The project specializes in non-invasive container inspection, allowing for the monitoring of container activity and resource usage without modifying the container environment or adding instrumentation. It enables the recording of detailed system traces into binary files for re

    C++
    View on GitHub↗8,261
  • zeek/zeek-agentZ

    zeek/zeek-agent

    0View on GitHub↗
    View on GitHub↗0
  • google/santagoogle avatar

    google/santa

    4,510View on GitHub↗

    Santa is a binary authorization system for macOS designed to control and monitor which binaries can execute based on defined trust rules. It functions as application whitelisting software that prevents unauthorized programs from running by verifying them against cryptographic hashes and signing certificates. The system provides execution monitoring by recording every binary launch event to create a visible software execution trail. It enables centralized audit logging to track successful and denied application launches across multiple devices, ensuring enterprise device compliance through syn

    Objective-C++
    View on GitHub↗4,510
  • ion-storm/sysmon-configion-storm avatar

    ion-storm/sysmon-config

    826View on GitHub↗

    The file provided should function as a great starting point for system monitoring in a self-contained package. This configuration and results should give you a good idea of what's possible for Sysmon. Please beware that you may need to fine tune and add exclusions depending on your environment.…

    PowerShell
    View on GitHub↗826