Detecting Sysmon on the Victim Host
Exploring ways to detect Sysmon presence on the victim system
Processes
PS C:\> Get-Process | Where-Object { $_.ProcessName -eq "Sysmon" }
Services

Windows Events

Filters

Sysmon Tools + Accepted Eula

Sysmon -c

Config File on the Disk

Get-SysmonConfiguration



Bypassing Sysmon
Unloading Sysmon DriverReferences
https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmonwww.darkoperator.com
Last updated