Media Summary: In this video, Carlos covers how to leverage The most reliable way to check device posture is to verify that all security products on an endpoint are active and correctly ... Research Practice Lead Carlos Perez goes into "

Learning Sysmon Tracking Wmi Permanent - Detailed Analysis & Overview

In this video, Carlos covers how to leverage The most reliable way to check device posture is to verify that all security products on an endpoint are active and correctly ... Research Practice Lead Carlos Perez goes into " You Need to Learn Sysmon NOW! Tracking down EVIL in endpoint logs! In this video, Research Team Lead Carlos Perez provides methods and recommendations for setting up a baseline in order to get ... In this video, Research Team Lead Carlos Perez talks about

We are all familiar with Microsoft Windows style logging in the form of Event Logs (EV). How many of you have had to decipher an ...

Photo Gallery

Learning Sysmon - Tracking WMI Permanent Events (Video 20)
Learning Sysmon - Tracking DNS Queries (Video 19)
Learning Sysmon -  Process Tracking (Video 6)
How to Check Device Posture? | WMI vs osquery vs Sysmon vs Windows Security Center
Sysmon Guides: Monitoring Sysmon
Learning Sysmon - Tracking Registry Actions (Video 22)
You Need to Learn Sysmon NOW! Tracking down EVIL in endpoint logs!
Learning Sysmon - Tracking When Drivers Are Loaded (Video 9)
Sysmon 101: Leveling Up Windows Security
Learning Sysmon - What is Sysmon? (Video 1)
Using Sysmon to Improve your Incident Response and Threat Hunting Capabilities
Enhance Visibility with Sysmon
View Detailed Profile
Learning Sysmon - Tracking WMI Permanent Events (Video 20)

Learning Sysmon - Tracking WMI Permanent Events (Video 20)

In this video, Carlos covers how to leverage

Learning Sysmon - Tracking DNS Queries (Video 19)

Learning Sysmon - Tracking DNS Queries (Video 19)

In this video, Carlos goes over how

Learning Sysmon -  Process Tracking (Video 6)

Learning Sysmon - Process Tracking (Video 6)

Process

How to Check Device Posture? | WMI vs osquery vs Sysmon vs Windows Security Center

How to Check Device Posture? | WMI vs osquery vs Sysmon vs Windows Security Center

The most reliable way to check device posture is to verify that all security products on an endpoint are active and correctly ...

Sysmon Guides: Monitoring Sysmon

Sysmon Guides: Monitoring Sysmon

Research Practice Lead Carlos Perez goes into "

Learning Sysmon - Tracking Registry Actions (Video 22)

Learning Sysmon - Tracking Registry Actions (Video 22)

In this video, Carlos covers how to leverage

You Need to Learn Sysmon NOW! Tracking down EVIL in endpoint logs!

You Need to Learn Sysmon NOW! Tracking down EVIL in endpoint logs!

You Need to Learn Sysmon NOW! Tracking down EVIL in endpoint logs!

Learning Sysmon - Tracking When Drivers Are Loaded (Video 9)

Learning Sysmon - Tracking When Drivers Are Loaded (Video 9)

In this video, Research Team Lead Carlos Perez provides methods and recommendations for setting up a baseline in order to get ...

Sysmon 101: Leveling Up Windows Security

Sysmon 101: Leveling Up Windows Security

Sysmon

Learning Sysmon - What is Sysmon? (Video 1)

Learning Sysmon - What is Sysmon? (Video 1)

In this video, Research Team Lead Carlos Perez talks about

Using Sysmon to Improve your Incident Response and Threat Hunting Capabilities

Using Sysmon to Improve your Incident Response and Threat Hunting Capabilities

We are all familiar with Microsoft Windows style logging in the form of Event Logs (EV). How many of you have had to decipher an ...

Enhance Visibility with Sysmon

Enhance Visibility with Sysmon

Introducing

What is Sysmon? 🔐 | Sysmon installation and configuration (2026)

What is Sysmon? 🔐 | Sysmon installation and configuration (2026)

Sysmon