Tool Path
Sysmon
See what happens on an endpoint. Read process creation and parent/child lineage, network and file and registry activity, tell noise from signal, and correlate events into a short attack timeline — on safe synthetic telemetry.
Curriculum
- 01Available
Process Creation & Lineage
What Sysmon provides, and how process-creation events (with parent, command line and hash) let you reconstruct who spawned what.
- 02Available
Network, File & Registry Activity
Beyond processes: network connections, file creation and registry changes tie an action to what it touched and where it reached out.
- 03Available
Configuration, Noise & Correlation
Sysmon is only as useful as its config: what to include, what to exclude, and how to correlate related events by process GUID and time.
- 04Available
Investigation Workflow
Put it together: from an alert on one event, pivot on the process, gather its lineage/network/file activity, and build the short timeline — then work real telemetry.