ICS Watch Dog

ICS Watch Dog

Usable Sysmon configurations for enterprise IT and ICS/OT environments. From IT baseline to OT advanced, mapped to the SANS ICS 5 Critical Controls.

A Cutaway Security Project

Why ICS Watch Dog?

Microsoft Sysinternals Sysmon is one of the best tools for improving visibility into what happens on your Windows servers and workstations. But for many ICS/OT teams, Sysmon's configuration files are complex and intimidating -- especially for Windows administrators who haven't worked with them before.

Configuration Files

IT Workstation

Desktops and Laptops

Enterprise workstation monitoring with remote access tool detection. Start here for endpoints.

Sysmon v13+ | Schema 4.50
IT Server

General Servers

Server-appropriate exclusions, minimal desktop noise. Start here for servers.

Sysmon v13+ | Schema 4.50
Server Services

Database + Web Server

Covers all common database and web engines. Webshell detection, xp_cmdshell, backup monitoring.

Sysmon v13+ | Schema 4.50
OT Baseline

ICS/OT Monitoring

Adds OT vendor software monitoring and ICS-specific file type detection.

Sysmon v13+ | Schema 4.50
OT Enhanced

Industrial Ports

Modbus, EtherNet/IP, OPC-UA, DNP3, S7comm, and more. Process-to-port visibility.

Sysmon v13+ | Schema 4.50
Jump Host

Bastion / Kiosk

Comprehensive monitoring for OT remote access chokepoints. Clipboard tracking, minimal exclusions.

Sysmon v15+ | Schema 4.90

New to Sysmon? Read the Getting Started guide for an overview of what Sysmon is, why it matters for ICS/OT, and step-by-step deployment instructions.

Important: All configurations are starting points. Administrators MUST tune these configs for their specific environments and test before production deployment.

Project Sponsor

This project was developed and is supported by Cutaway Security, LLC. in collaboration with each contributor.

Contributors