Jonathan Johnson a372806ee6 Initial Commit
2022-11-10 10:02:36 -06:00
2022-11-10 10:02:36 -06:00
2022-11-10 10:02:36 -06:00
2022-11-10 10:02:36 -06:00
2022-11-10 10:02:36 -06:00

TelemetrySource

Project created to map functions repsonsible for triggering events from various telemetry sources.

Currently mapped sources:

Sysmon

Sysmon-Overview

Window Security Events (Microsoft-Windows-Security-Auditing)

WSE-Overview

  • Each source has it's own README file with the necessary information needed to understand how the mappings work.

Feedback:

If anyone has suggestions on how this data could be exposed differently to better help defenders or any other feedback, please reach out! The goal with this project is to help defenders understand how data is generated, so that we can be more informed in our decisions when leveraging that data.

To-Dos:

  • Update Sysmon to v14
  • Expand events in Microsoft-Windows-Security-Auditing
S
Description
Automated archival mirror of github.com/jsecurity101/TelemetrySource
Readme GPL-3.0 3.5 MiB
Languages
SVG 100%