Skip to content

Hodgegoblin/Graylog_Sysmon

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

67 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Graylog_Sysmon

Advanced configuration for Graylog w/Sysmon

I'll be adding more documentation to this as time permits ;)

Ransomware Detection from: https://fsrm.experiant.ca/

Pipeline Order

Stage 1

sysmon cleanup (gl2_source_fix)
sysmon cleanup

Stage 2

sysmon threatintel
detect ransomware
threat indicators
network threat indicators
add file_created field

Stage 3

sysmon threatintel inflate

Set Message Processor Configuration to the following order:

Message Filter Chain

Pipeline

GeIP Resolver

About

Advanced Threat detection Configurations for Graylog

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Batchfile 100.0%