I Hacked Myself & Analyzed It with Sysmon

Поділитися
Вставка
  • Опубліковано 17 січ 2025

КОМЕНТАРІ • 14

  • @ricseeds4835
    @ricseeds4835 13 годин тому +2

    There's not enough or any good practical tutorials covering the SysInternals suite. Definitely appreciate this

  • @KREWAY
    @KREWAY 14 годин тому +1

    Thank you for dropping this! Definitely been searching for an updated video to learn about sysmon

  • @Cyb3r6h0st19
    @Cyb3r6h0st19 4 години тому +1

    This is golden! Keep up the good work! Next one should be with LimaCharlie

  • @ricseeds4835
    @ricseeds4835 3 години тому

    I have questions:
    - Can you export the log to some centralized logging system with a better interface?
    - The config file made the results easy to manage but does it mean sysmon didn't log those events or are they just hidden?
    - Will there be more videos on Sysinternals programs? I really hope so!
    I'm sure I'll have more questions once I watch this for the 15th time.

  • @BadrBentaleb
    @BadrBentaleb 11 годин тому

    Amazing content thanks :)!
    Quick question: what if you added a command that will delete all the logs? What will you still be able to see?

    • @MalwareCube
      @MalwareCube 11 годин тому +2

      Sysmon is installed as a protected service so it's somewhat tamper-resistant (to an extent) but it is definitely possible to clear the logs as an elevated user/with sufficient privileges. Clearing the logs will leave its own artifacts behind though like Security Event ID 1102 which shows that the logs were cleared. This is another reason why it's important to forward endpoint logs like this to a centralized logging server. :)

  • @syedfuzail731
    @syedfuzail731 11 годин тому +1

    I appreciate mam, you did really good job to making this video thank you for sharing your knowledge with us❤

  • @erdalkah
    @erdalkah 10 годин тому

    Thank you so much!

  • @RozzClips
    @RozzClips 8 годин тому +2

    TCM ROCKS!!!!!!!!!

  • @nasyaramadhana6788
    @nasyaramadhana6788 13 годин тому

    Interesting

  • @synacktime
    @synacktime 13 годин тому +1

    Love sysmon, wrote a script for our NinjaRMM that deploys it for everyone!

  • @Student2Hacking
    @Student2Hacking 14 годин тому

    First

  • @PlayButtonWithNoViews
    @PlayButtonWithNoViews 10 годин тому

    Oh no I accidentally clicked a windows video. Get me out of here

  • @Death-hack-trust
    @Death-hack-trust 14 годин тому +1

    Frist view first comment 🤡