Add 'Sysinternals Sysmon suspicious activity guide' to Sysmon tutorial

This commit is contained in:
pe3zx 2017-12-14 22:33:50 +07:00
parent 8afe71b2c3
commit 235e4416fe

View File

@ -408,6 +408,7 @@ My curated list of awesome links, resources and tools
<td>Sysmon</td>
<td>
<ul>
<li><a href="https://blogs.technet.microsoft.com/motiba/2017/12/07/sysinternals-sysmon-suspicious-activity-guide/">Sysinternals Sysmon suspicious activity guide</a></li>
<li><a href="http://www.hexacorn.com/blog/2017/10/02/sysmon-doing-lines/">Sysmon doing lines</a></li>
<li><a href="https://github.com/MHaggis/sysmon-dfir">Mhaggis/sysmon-dfir</a></li>
<li><a href="http://syspanda.com/index.php/2017/02/28/deploying-sysmon-through-gpo/">Deploying Sysmon through Group Policy (GPO)</a></li>