Detection Engineering
Windows behavioral detection with Sysmon
A published lab using Sysmon events and Wazuh rules to investigate LOLBin abuse.
SysmonWazuhWindows
Why this matters to a team
Attackers often misuse built-in Windows tools; behavior-based detections help surface that activity.
Problem
Legitimate Windows binaries can be abused in ways that ordinary file-based checks do not flag.
Documented approach
- 01Collect Sysmon events from a Windows host into Wazuh.
- 02Write Wazuh rules that match suspicious use of built-in binaries.
- 03Investigate the resulting alerts in a lab.
My contribution
Built the lab and published the walkthrough.
Evidence
Limitations
A lab investigation at the event and detection level; not a validated production rule set.