Sysinternals: System Monitor deep dive (demo) | Sysmon, device, driver, Windows | Microsoft

preview_player
Показать описание
System Monitor (Sysmon) is a Windows system service and device driver that provides detailed information about process creations, network connections, and changes to file creation time. By collecting the events it generates, you can identify malicious or anomalous activity and understand how intruders and malware operate on your network.

In this video, Sysmon expert Thomas Garnier provides a closer look at System Monitor, a popular utility from the Microsoft Sysinternals suite, through demos and tips.

Рекомендации по теме
Комментарии
Автор

Great overview but a deep dive with an example would have been nice.

QQ_Victory
Автор

Hey,

can you please share the links presented in this video

mihirsingh