@markrussinovich@SwiftOnSecurity Our new #Sysmon Registry dashboard allows you to drill into registry events like registry_value_set and registry_create_delete:
@markrussinovich@SwiftOnSecurity Our new #Sysmon Process dashboards allows you to drill into process events like process_creation, process_access, and process_terminated:
@markrussinovich@SwiftOnSecurity Our new #Sysmon File dashboard allows you to drill into file events like file_create, file_create_stream_hash, and process_changed_file:
If you want the quickest and easiest way to try out #SecurityOnion, just follow the screenshots below to install an Import node and then optionally enable the Analyst Workstation. This can be done in a minimal VM with only 4GB RAM!