René's URL Explorer Experiment


Title: GitHub - trustedsec/SysmonCommunityGuide: TrustedSec Sysinternals Sysmon Community Guide

Open Graph Title: GitHub - trustedsec/SysmonCommunityGuide: TrustedSec Sysinternals Sysmon Community Guide

X Title: GitHub - trustedsec/SysmonCommunityGuide: TrustedSec Sysinternals Sysmon Community Guide

Description: TrustedSec Sysinternals Sysmon Community Guide. Contribute to trustedsec/SysmonCommunityGuide development by creating an account on GitHub.

Open Graph Description: TrustedSec Sysinternals Sysmon Community Guide. Contribute to trustedsec/SysmonCommunityGuide development by creating an account on GitHub.

X Description: TrustedSec Sysinternals Sysmon Community Guide. Contribute to trustedsec/SysmonCommunityGuide development by creating an account on GitHub.

Opengraph URL: https://github.com/trustedsec/SysmonCommunityGuide

X: @github

direct link

Domain: patch-diff.githubusercontent.com

route-pattern/:user_id/:repository
route-controllerfiles
route-actiondisambiguate
fetch-noncev2:3397e044-85df-19de-60ad-72b4d59e22d8
current-catalog-service-hashf3abb0cc802f3d7b95fc8762b94bdcb13bf39634c40c357301c4aa1d67a256fb
request-idA71E:C0C98:1A8655F:2283642:6976FA1C
html-safe-nonce0d07256462ef6cb344dfad95fc2b190dc7d71c3b2e28b0c700f308bec5d1d035
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBNzFFOkMwQzk4OjFBODY1NUY6MjI4MzY0Mjo2OTc2RkExQyIsInZpc2l0b3JfaWQiOiI1NTM5OTI5NTg2NDU3MzExNzcyIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0=
visitor-hmac9bab20927d27e9791aabe24151b5198ab890e9ce9aa0e10029fd1e13dedd92fd
hovercard-subject-tagrepository:235658546
github-keyboard-shortcutsrepository,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location//
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/trustedsec/SysmonCommunityGuide
twitter:imagehttps://opengraph.githubassets.com/0bf0d0d4728efda0a640d3fc144108bd45f734e7ea1137f8fe72fa8eea7c1bf8/trustedsec/SysmonCommunityGuide
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/0bf0d0d4728efda0a640d3fc144108bd45f734e7ea1137f8fe72fa8eea7c1bf8/trustedsec/SysmonCommunityGuide
og:image:altTrustedSec Sysinternals Sysmon Community Guide. Contribute to trustedsec/SysmonCommunityGuide development by creating an account on GitHub.
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
hostnamegithub.com
expected-hostnamegithub.com
None01d198479908d09a841b2febe8eb105a81af2af7d81830960fe0971e1f4adc09
turbo-cache-controlno-preview
go-importgithub.com/trustedsec/SysmonCommunityGuide git https://github.com/trustedsec/SysmonCommunityGuide.git
octolytics-dimension-user_id3160808
octolytics-dimension-user_logintrustedsec
octolytics-dimension-repository_id235658546
octolytics-dimension-repository_nwotrustedsec/SysmonCommunityGuide
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id235658546
octolytics-dimension-repository_network_root_nwotrustedsec/SysmonCommunityGuide
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
releasef752335dbbea672610081196a1998e39aec5e14b
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#start-of-content
https://patch-diff.githubusercontent.com/
Sign in https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Ftrustedsec%2FSysmonCommunityGuide
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Ftrustedsec%2FSysmonCommunityGuide
Sign up https://patch-diff.githubusercontent.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=trustedsec%2FSysmonCommunityGuide
Reloadhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
Reloadhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
Reloadhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
trustedsec https://patch-diff.githubusercontent.com/trustedsec
SysmonCommunityGuidehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
Notifications https://patch-diff.githubusercontent.com/login?return_to=%2Ftrustedsec%2FSysmonCommunityGuide
Fork 181 https://patch-diff.githubusercontent.com/login?return_to=%2Ftrustedsec%2FSysmonCommunityGuide
Star 1.4k https://patch-diff.githubusercontent.com/login?return_to=%2Ftrustedsec%2FSysmonCommunityGuide
1.4k stars https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/stargazers
181 forks https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/forks
Branches https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/branches
Tags https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tags
Activity https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/activity
Star https://patch-diff.githubusercontent.com/login?return_to=%2Ftrustedsec%2FSysmonCommunityGuide
Notifications https://patch-diff.githubusercontent.com/login?return_to=%2Ftrustedsec%2FSysmonCommunityGuide
Code https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
Issues 5 https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/issues
Pull requests 5 https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/pulls
Actions https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/actions
Projects 0 https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/projects
Security 0 https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/security
Insights https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/pulse
Code https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
Issues https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/issues
Pull requests https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/pulls
Actions https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/actions
Projects https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/projects
Security https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/security
Insights https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/pulse
Brancheshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/branches
Tagshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tags
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/branches
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tags
155 Commitshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/commits/master/
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/commits/master/
.github/workflowshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/.github/workflows
.github/workflowshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/.github/workflows
Buildhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/Build
Buildhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/Build
chaptershttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/chapters
chaptershttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/chapters
exampleshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/examples
exampleshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/tree/master/examples
.gitignorehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/.gitignore
.gitignorehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/.gitignore
BUILD.mdhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/BUILD.md
BUILD.mdhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/BUILD.md
Dockerfilehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/Dockerfile
Dockerfilehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/Dockerfile
Makefilehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/Makefile
Makefilehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/Makefile
README.mdhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/README.md
README.mdhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/README.md
SysmonGuide.pdfhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/SysmonGuide.pdf
SysmonGuide.pdfhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/SysmonGuide.pdf
build.shhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/build.sh
build.shhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/build.sh
build_guide.pyhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/build_guide.py
build_guide.pyhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/build_guide.py
chapters.jsonhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters.json
chapters.jsonhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters.json
docker-compose.ymlhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/docker-compose.yml
docker-compose.ymlhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/docker-compose.yml
READMEhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/media/tslogo.png
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#trustedsec-sysmon-community-guide
http://creativecommons.org/licenses/by-sa/4.0/
Creative Commons Attribution-ShareAlike 4.0 International Licensehttp://creativecommons.org/licenses/by-sa/4.0/
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#you-are-free-to
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#table-of-contents
What is Sysmonhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/what-is-sysmon.md
The Sysmon Driverhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/the-sysmon-driver.md
Install and Configurationhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/install_windows.md
sysinternalsEBPFhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/eBPF.md
Install and Configurationhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/install_linux.md
Configurationhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/configuration.md
Detection Engineering Fundamentalshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/detection-engineering.md
Process Eventshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/process-events.md
Process Creationhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/process-creation.md
Process Terminationhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/process-termination.md
Process Accesshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/process-access.md
File Createhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/file-create.md
File Create Time Changehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/file-create-time-change.md
File Stream Creation Hashhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/file-stream-creation-hash.md
File Deletehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/file-delete.md
File Delete Detectedhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/file_delete_detected.md
File Block EXEhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/file-block-exe.md
File Block Shreddinghttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/file-blockshredding.md
Named Pipeshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/named-pipes.md
Driver Loadinghttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/driver-loading.md
Registry Actionshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/registry-actions.md
Image Loadinghttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/image-loading.md
Network Connectionshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/network-connections.md
Create Remote Threadhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/create-remote-thread.md
Raw Access Readhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/raw-access-read.md
DNS Queryhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/dns-query.md
WMI Eventshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/WMI-events.md
Clipboard Capturehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/clipboard-capture.md
Process Image Tamperinghttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/blob/master/chapters/process-tampering.md
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#current-state
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#contributing
https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#credits
TrustedSec LLChttps://www.trustedsec.com/
Readme https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide#readme-ov-file
Please reload this pagehttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide
Activityhttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/activity
Custom propertieshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/custom-properties
1.4k starshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/stargazers
78 watchinghttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/watchers
181 forkshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/forks
Report repository https://patch-diff.githubusercontent.com/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2Ftrustedsec%2FSysmonCommunityGuide&report=trustedsec+%28user%29
Releases 5https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/releases
v2.0 Update for 2025 Latest Dec 15, 2025 https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/releases/tag/v2.0
+ 4 releaseshttps://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/releases
Packages 0https://patch-diff.githubusercontent.com/orgs/trustedsec/packages?repo_name=SysmonCommunityGuide
Contributors 14https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/graphs/contributors
https://github.com/darkoperator
https://github.com/Jarrod-L
https://github.com/olafhartong
https://github.com/2xyo
https://github.com/Reedtechno
https://github.com/codesavvysoftware
https://github.com/trustedsec
https://github.com/SimplyRyan
https://github.com/MattWeatherford
https://github.com/giomke
https://github.com/TareqAlKhatib
https://github.com/thejanit0r
https://github.com/tareq-alkhatib
https://github.com/ilan-kogan
Python 27.5% https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/search?l=python
Shell 26.2% https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/search?l=shell
TeX 19.4% https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/search?l=tex
CSS 17.9% https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/search?l=css
Makefile 6.2% https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/search?l=makefile
Dockerfile 2.8% https://patch-diff.githubusercontent.com/trustedsec/SysmonCommunityGuide/search?l=dockerfile
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.