olafhartong/sysmon-modular

A repository of sysmon configuration modules

View on GitHub ↗Jump to charts ↓

Data as of . Signed-in members get hourly updates — create a free account.

Summary Information

Updated 25 minutes ago
Added to GitGenius on September 22nd, 2026
Created on January 13th, 2018
Open Issues & Pull Requests: 50 (+0)
GitHub issues: Enabled
Number of forks: 663
Total Stargazers: 3,141 (+0)
Total Subscribers: 163 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 20.5 hours
Mean response time: 27.8 days
90th percentile: 132.1 days
Tracked items: 8

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 8
New in 7 days: 1
Closed in 7 days: 0
Avg open age: 340 days
Stale 30+ days: 7
Stale 90+ days: 6

Recent activity

Opened in 7 days: 1
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

Sign in to see which issues are moving.
Sign in

Detailed Description

Sysmon-modular is a collection of modular Sysmon configuration files designed to enable flexible and composable system monitoring for threat detection and incident response.

The tool addresses the challenge of managing complex Sysmon configurations by breaking them into discrete, reusable modules organized around specific detection objectives and MITRE ATT&CK techniques. Rather than maintaining a single monolithic configuration file, operators can select and combine only the modules relevant to their environment and threat model. This modular approach allows teams to customize their monitoring posture without duplicating effort or managing unwieldy configuration files.

Teams should adopt this tool if they run Sysmon for endpoint monitoring and want to move beyond static, one-size-fits-all configurations. It suits organizations that need to balance comprehensive logging with the operational overhead of processing high event volumes, since selective module inclusion lets them tune what gets monitored. The project is particularly valuable for threat hunters and incident responders who need to quickly adjust monitoring based on emerging threats or investigation findings.

The project shows consistent maintenance with regular updates to modules and configuration files. The codebase demonstrates active refinement of existing detection logic rather than rapid feature expansion. Development activity centers on improving the quality and coverage of individual modules, with attention to keeping configurations aligned with current threat landscapes. The repository maintains documentation that supports operators in understanding module purposes and integration patterns.