Has anyone deployed sysmon as a service then capturing process creation/termination with image file hash and/or network connections via the BigFix event log inspectors ?
BigFix competitors are doing something similar, under the hood it appears to be no more than sysmon …
Looking for sample relevance to adapt if possible to demonstrate power of BigFix as an EDR.
It should be relatively straightforward to update this for the latest version of Sysmon, then create analyses to return the data of interest from the event logs.