Take Your Windows Security Data to Elasticsearch
Be Brazen by Injecting and Executing Sysmon and Winlogbeat into any Windows Workload
BrazenCloud can inject virtually any binaries or scripts into both Windows or Linux Operating Systems to offer deeper monitoring through open source tools.
Inject, Execute and Collect data from tools like:
Sysmon - System Monitor (Sysmon) is a Windows system service allows administrators to monitor and log system activity to the Windows event log. It provides crucial detail and information about processes created, network connections, and changes to files, critical to security monitoring.
Winlogbeat - Winlogbeat reads event logs from Windows, filters the events leveraging user-defined criteria, then sends the event data to the configured outputs via BrazenCloud (to Elasticsearch or Logstash).
Brazen Agent and BrazenCloud Platform orchestrates streamed data back for deeper analysis by security operations personnel by securely transporting streamed data to their native Elasticsearch or analytics solutions.
Brazen Agent Operating Systems Supported
Windows
Linux
Workloads, Containers, Servers and Workstations
Want to Inject Applications into Workloads?