Title: Host-based threat hunting framework for log analysis

Authors: Parag Shukla; Sandesh Ajgekar; Jay Teraiya

Addresses: School of Computing, Kaushalya – The Skill University, Gujarat, India ' School of Cybersecurity and Digital Forensics, National Forensic Sciences University, Gujarat, India ' School of Cybersecurity and Digital Forensics, National Forensic Sciences University, Gujarat, India

Abstract: Sysmon is a Windows system service and device driver. It is designed to persistently monitor and record system activity in the Windows event log. Sysmon tool is a data source for host-based intrusion detection, and it is open-source and free. Being a sophisticated logging tool for Windows, Sysmon lacks suspicious activity identification, log parsing and analysis capabilities. We also need to check the reliability of Sysmon in intrusion detection as an endpoint visibility tool. Hence, as a supporting tool we developed the Huntmon framework for log parsing and to provide some basic capabilities that might be crucial in any type of investigation. This framework is a general multi-purpose Sysmon log parser tool. Along with the Sysmon log parsing, the Huntmon framework provides dynamic analysis of Sysmon logs. This tool is compared with other traditional tools with the same test objects. The outputs of both tools are discussed in this paper.

Keywords: system activity monitoring; host-based intrusion detection; log analysis; VirusTotal Lookup; portable executable headers; portable executable strings; process execution block; dynamic analysis.

DOI: 10.1504/IJESDF.2026.152241

International Journal of Electronic Security and Digital Forensics, 2026 Vol.18 No.2, pp.197 - 216

Received: 19 Apr 2024
Accepted: 23 May 2024

Published online: 12 Mar 2026 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article