From b5a4c07e09bfbff0ac30199e3aedd162cca9dce0 Mon Sep 17 00:00:00 2001 From: pe3zx Date: Thu, 10 Dec 2020 16:34:24 +0700 Subject: [PATCH] Add polylogyx/PolyMon to DFIR section --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 0d7545c..4be48a6 100644 --- a/README.md +++ b/README.md @@ -1136,6 +1136,10 @@ This repository is created as an online bookmark for useful links, resources and philhagen/sof-elk Configuration files for the SOF-ELK VM, used in SANS FOR572 + + polylogyx/PolyMon + PolyLogyx Monitoring Agent (PolyMon) is a Windows software that leverages the osquery tool and the PolyLogyx Extension to osquery, to provide a view into detailed information about process creations, network connections, file system changes and many other activities on the system. + ptresearch/AttackDetection The Attack Detection Team searches for new vulnerabilities and 0-days, reproduces it and creates PoC exploits to understand how these security flaws work and how related attacks can be detected on the network layer. Additionally, we are interested in malware and hackers’ TTPs, so we develop Suricata rules for detecting all sorts of such activities.