#蓝队工具 Sysmon 事件模拟实用程序,可用于模拟攻击以生成 Sysmon 事件日志,以测试 Blue 团队的 EDR 检测和关联规则
https://github.com/ScarredMonk/SysmonSimulator
https://github.com/ScarredMonk/SysmonSimulator
GitHub
GitHub - ScarredMonk/SysmonSimulator: Sysmon event simulation utility which can be used to simulate the attacks to generate the…
Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams. - ScarredMonk/SysmonS...