Youssef Moukadem

Cybersecurity Enthusiast | Computer Science Graduate | Cloud Enthusiast | Lifelong Learner

View on GitHub

📝 Case Study: Sysmon Event Analysis

🔹 Overview

This case study explores Sysmon, a Windows system monitoring tool that logs detailed events for endpoint and network activity.
The objective was to investigate Sysmon logs for USB devices, payloads, scheduled tasks, and network connections to identify suspicious activity and potential compromises.

Skills demonstrated:


🔍 Key Activities & Highlights

1. Cutting Out the Noise

Findings:


2. Practical Investigations

Investigation 1: USB Device

Investigation 2: Payload Analysis

Investigation 3.1: Endpoint Connection

Investigation 3.2: Scheduled Task

Investigation 4: Network Connections


✅ Conclusion


🔗 Navigation