{"repo":"nshalabi/SysmonTools","free":true,"listed":false,"github":"https://github.com/nshalabi/SysmonTools","clone":"git clone https://github.com/nshalabi/SysmonTools.git","description":"Utilities for Sysmon","language":"TypeScript","stars":1657,"topics":["sysmon","threatintel","sysinternals","threat-hunting","windows","netsec","monitoring","logging","threat-intelligence"],"license":"GPL-3.0","category":"analytics","readme_excerpt":"Sysmon Tools A collection of utilities for analyzing, visualizing, and managing Microsoft Sysmon logs — designed for security analysts, DFIR specialists, and threat hunters. --- What's New in v2.0 Sysmon View has been rewritten from the ground up as a fully open-source desktop application — a long-requested change by the community. Built with Electron + React + TypeScript , the entire codebase is now open and free of commercial dependencies. Key improvements: - Modern dark-themed UI with a streamlined analyst workflow - Interactive session diagrams with freedom to move and arrange nodes - Collapsible nodes — collapse/expand sections of the event chain for focused analysis - Event type filtering — show/hide specific event types for a zoomed-in view of what matters - Pin mode — pin events of interest and filter to show only pinned events with configurable context range - Performance optimization — server-side pagination for large datasets, session threshold protection for diagram rendering - Hierarchical grouping in All Events — drag columns to group by machine, event type, session GUID, or any combination - Direct VirusTotal report links for hashes and IP addresses (no API key required for basic lookups) - GeoIP map view with multiple provider support - Cross-platform potential (Windows first, macOS/Linux possible) --- Content - Sysmon View - Getting Started - Building from Source - Legacy Tools - Third-Party Libraries - Support the Project - License - Contact --- Sysmon View ","default_branch":null,"files":null,"tree":[],"storefront":"/r/nshalabi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nshalabi/SysmonTools/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}