Parsing Sysmon Logs on Microsoft Sentinel
ID: 0037d59e-6100-5a5f-8af7-c1e96abf4695
STIX ID: report--0037d59e-6100-5a5f-8af7-c1e96abf4695
Feed Name: Black Hills Infosec Blog
The report is a technical walkthrough for defenders on enabling and parsing Sysmon Event IDs 27 (block executable files) and 28 (file delete/shredding restrictions) within Microsoft Sentinel. It covers updating the Sysmon schema/config, demonstrating controls that block execution from user download folders and detect SDelete-based shredding, and creating a reusable Sentinel function to normalize and query Sysmon logs, with links to community parsers and Sysmon Modular resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
