Sysmon Deep Dive: Real Detection Scenarios You Can Reproduce @FIRSTdotorg
Sysmon Deep Dive: Real Detection Scenarios You Can Reproduce  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 13 minutes ago
Peter Morin (PwC, CA)

This demo-driven session presents a production-grade Sysmon configuration and shows how to convert Sysmon events into reliable detections. Through curated demos (certutil/LOLBin download, CreateRemoteThread injection, and suspicious network callback correlation) and pre-prepared telemetry walkthroughs, attendees will learn practical detection patterns and how to operationalize them in modern SIEMs.

---

Peter Morin is a Senior Consultant specializing in OT/IoT cybersecurity, bringing over 25 years of industry experience to the table. With a robust background information technology and cybersecurity, Peter has become a trusted advisor to organizations navigating the complex and rapidly evolving landscape of operational technology security. His expertise encompasses the full spectrum of OT/IoT security, from risk assessment and vulnerability management to the design and implementation of comprehensive security frameworks to the deployment of OT passive monitoring solutions.

Peter has successfully led numerous high-profile projects across diverse sectors, including energy, manufacturing, and critical infrastructure, helping clients safeguard their systems against emerging threats. His hands-on experience in the field is complemented by a deep understanding of regulatory requirements and best practices, ensuring that his solutions are both effective and compliant.

In addition to his consulting work, Peter is a frequent speaker and educator, regularly presenting at industry conferences and contributing to leading cybersecurity publications. He holds multiple certifications, including CISSP, CISA, CGEIT, CRISC, CDPSE and GCFA, and is actively involved in professional organizations such as ISACA. Passionate about advancing the state of OT/IoT cybersecurity, Peter is dedicated to helping organizations build resilient systems that can withstand the challenges of today's dynamic threat environment.
Sysmon Deep Dive: Real Detection Scenarios You Can ReproduceThe PR3TACK Initiative: Building the World’s First Preemptive Tactics & Countermeasures KnowledgebasGuardians of the HypervisorBest Practices for Data Privacy Breach Response: Lessons Learned from Social Media Case StudiesThe Ontology for SOC Creation Assistance and Replication (OSCAR)Panel: Peak Performance Under Pressure: Building Cross-Functional Resilience in Incident ResponseYou Need Some Neurosparkle In Your SOCNavigating the Threat Actor Maze: A Tool for Mapping Names, Families and InsightsStepping up the ENISAs role in Support of EU Vulnerability ServicesFrom Zero to Prepared: Implementing a Weekly Incident Response Drill ProgramIndicator Message eXchange (IMX): Enabling Structured Cyber Threat Intelligence SharingEpisode 57: Vijay Sarvepalli and Christopher Cullen, FIRSTCON26 Speakers
FIRST |

Sysmon Deep Dive: Real Detection Scenarios You Can Reproduce

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER