Threat Hunting & Endpoint Analysis¶
Collect, hunt, and time-line evidence from live hosts, disk images, and memory.
Sysmon config¶
reference
SwiftOnSecurity's battle-tested Sysmon logging configuration, ready to deploy.
Sysinternals suite¶
staged
Autoruns, Process Monitor, Process Explorer, TCPView — staged, not run here.