diff --git a/README.md b/README.md index ec7f864..8d9526e 100644 --- a/README.md +++ b/README.md @@ -1214,6 +1214,10 @@ _return-to-libc techniques_ JPCERTCC/LogonTracer Investigate malicious Windows logon by visualizing and analyzing Windows event log + + JPCERTCC/SysmonSearch + Investigate suspicious activity by visualizing Sysmon's event log + IllusiveNetworks-Labs/HistoricProcessTree An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree view.