Sep 13 2021 08:40 AM
I'm trying to get opinions if sysmon is worth using alongside Defender ATP? The logs would be going into Splunk, if that helps, but just in general.
(Disclaimer: I have asked this in a couple blue team slack chats as well).
Sep 13 2021 01:40 PM
Sep 18 2021 01:44 AM - edited Sep 18 2021 01:45 AM
Hi,
I think this highly depends on your needs. I had some discussions with researchers and the conclusion was that Defender ATP (MDE) detects a lot of things that Sysmon does, but Sysmon can get even a bit more data and you are more flexible in distributing this data to your siem.
It highly depends on your needs and your environment.
Sep 20 2021 05:21 AM
Sep 21 2021 05:38 PM