Sysmon

Presentation by Josh Brower @DefensiveDepth at the Security Onion Conference 2015: Sysmon & Security Onion

A paper on the same topic: Using Sysmon to Enrich Security Onion’s Host-Level Capabilities