Graylog_Sysmon Advanced configuration for Graylog w/Sysmon I'll be adding documentation to this as time permits ;) Ransomware Detection from: https://fsrm.experiant.ca/