Sysinternals Sysmon suspicious activity guide https://blogs.technet.microsoft.com/motiba/2017/12/07/sysinternals-sysmon-suspicious-activity-guide/ #DFIR #blueteam #infosec #forensics https://t.co/Km8LnZparq