Overcoming Domain Name Resolution Issue in Sysmon
Sysmon is a well known tool provided by Microsoft frequently used in the fields
of threat hunting, incident response and security monitoring. One of its best
features is that it allows one to log any network connection issued by
the processes running on the system. We will quickly review what information
is provided in those events and what is the issue we have noticed. In order
to overcome the issue we will present our work around which comes in a form of
a new feature called event hooks introduced in the latest version of
WHIDS.
more ...