Kunai: Keep an Eye on your Linux Hosts Activity, (Mon, Jul 8th)

This post was originally published on this site

Microsoft has a very popular tool (part of the SysInternals) called Sysmon[1]. It is a system service and device driver designed to monitor and log system activity, including very useful events like process creations, network connections, DNS requests, file changes, and more. This tool is deployed by many organizations because it’s a great companion to expand the visibility of your Windows environments. Many SOCs rely on it to perform investigations and hunting.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.