Detecting Sysmon on the Victim Host
Exploring ways to detect Sysmon presence on the victim system
Processes
PS C:\> Get-Process | Where-Object { $_.ProcessName -eq "Sysmon" }
Services

Windows Events

Filters

Sysmon Tools + Accepted Eula

Sysmon -c

Config File on the Disk

Get-SysmonConfiguration



Bypassing Sysmon
Unloading Sysmon DriverReferences
Last updated