Free Tool Converts Sysmon Rules to uberAgent ESA Activity Monitoring
We’re excited to announce that the Sysmon to uberAgent ESA rule converter tool is available. The converter translates Sysmon rules into the format used by uberAgent ESA.
Sysmon is one of the most popular endpoint detection tools. Numerous quality rulesets are maintained by the security community. The Sysmon converter makes those rulesets available for use with uberAgent ESA.
We’re working hard to make uberAgent ESA the better Sysmon alternative. Take a look at this comparison for info on how the two stack up against each other.
Converting rules from Sysmon to uberAgent is possible because uberAgent’s versatile uAQL query language can be used to replicate the capabilities of Sysmon’s configuration – and much more. Take a look at this blog post for an introduction to uAQL.
The converter reads Sysmon XML configuration files and translates the rules to the file format used by uberAgent ESA’s Activity Monitoring Engine.
The converter is flexible: it can convert individual Sysmon rules from a single source file, but it can also read entire directories with Sysmon configuration files. In other words: the converter supports single-file Sysmon configurations like SwiftOnSecurity’s just as well as Olaf Hartong’s modular Sysmon repo.
Take a look at the converter’s readme for usage information.
The Sysmon to uberAgent ESA converter is a free open-source tool developed and maintained by vast limits. To download the Sysmon converter, head over to the releases section of its GitHub repository.
uberAgent is an innovative Windows and macOS user experience monitoring (UXM) and endpoint security analytics (ESA) product.
uberAgent UXM highlights include detailed information about boot and logon duration, application unresponsiveness detection, network reliability drill-downs, process startup duration, application usage metering, browser performance, web app metrics, and Citrix insights. All these varied aspects of system performance and reliability are smartly brought together in the Experience Score dashboard.
uberAgent ESA excels with a sophisticated activity monitoring engine, the uAQL query language, detection of risky activity, DNS query monitoring, hash calculation, registry monitoring, and Authenticode signature verification. uberAgent ESA comes with Sysmon and Sigma rule converters, a graphical rule editor, and uses a simple yet powerful query language instead of XML.
About vast limits
vast limits GmbH is the company behind uberAgent, the innovative user experience monitoring and endpoint security analytics product. vast limits’ customer list includes organizations from industries like finance, healthcare, professional services, and education, ranging from medium-sized businesses to global enterprises. vast limits’ network of qualified solution partners ensures best-in-class service and support anywhere in the world.