diff --git a/README.md b/README.md
index ec7f864..8d9526e 100644
--- a/README.md
+++ b/README.md
@@ -1214,6 +1214,10 @@ _return-to-libc techniques_
JPCERTCC/LogonTracer |
Investigate malicious Windows logon by visualizing and analyzing Windows event log |
+
+ JPCERTCC/SysmonSearch |
+ Investigate suspicious activity by visualizing Sysmon's event log |
+
IllusiveNetworks-Labs/HistoricProcessTree |
An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree view. |