Skip to content

Commit 169d300

Browse files
committed
docs: rule development note - sysmon config for lab
1 parent d3dbadd commit 169d300

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

README.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,10 @@ Run with administrator rights
5656
sysmon.exe -u
5757
```
5858

59+
## Rule Development
60+
61+
For rule development we use a very extensive [Sysmon config](https://github.com/OTRF/Blacksmith/blob/master/resources/configs/sysmon/sysmon.xml) provided by @Cyb3rWarD0g in our lab that logs almost any event on an end system.
62+
5963
## Credits
6064

6165
Since we wanted to be able to receive new pull requests this repository, we had to squash all open(!) pull requests of the original reposiory into a single commit on this one.

0 commit comments

Comments
 (0)