Download sysmon:
NEW: Sysmon 6.0 is available ! : https://technet.microsoft.com/en-us/sysinternals/sysmon and how to use it:
Installation and usage:
Mark russinovitch’s RSA conference: https://onedrive.live.com/view.aspx?resid=D026B4699190F1E6!2843&ithint=file%2cpptx&app=PowerPoint&authkey=!AMvCRTKB_V1J5ow
Sysmon config files explained:
https://github.com/SwiftOnSecurity/sysmon-config
https://www.bsk-consulting.de/2015/02/04/sysmon-example-config-xml/
Else other install guides:
http://www.darkoperator.com/blog/2014/8/8/sysinternals-sysmon
Detecting APT with Sysmon:
https://www.root9b.com/sites/default/files/whitepapers/R9B_blog_005_whitepaper_01.pdf
Sysmon with Splunk:
http://blogs.splunk.com/2014/11/24/monitoring-network-traffic-with-sysmon-and-splunk/
https://securitylogs.org/tag/sysmon/
Sysmon log analyzer/parsing sysmon event log:
https://github.com/CrowdStrike/Forensics/blob/master/sysmon_parse.cmd
https://digital-forensics.sans.org/blog/2014/08/12/sysmon-in-malware-analysis-lab
https://github.com/JamesHabben/sysmon-queries
http://blog.crowdstrike.com/sysmon-2/
logparser: http://www.microsoft.com/en-us/download/confirmation.aspx?id=24659
logparser GUI: http://lizard-labs.com/log_parser_lizard.aspx
