The adversary is actively targeting end-users and endpoints and they are getting quite proficient at bypassing traditional methods of prevention, such as antivirus. To detect advanced attack vectors, more than ever, defenders need visibility into endpoint activities to monitor behaviors and spot abnormal activity that can be indicative of malicious activity. While commercial products can provide organizations insight into this endpoint activity, they also can be cost-prohibitive. So what options are available to companies that don't have the hundreds of thousands of dollars necessary to purchase a commercial product? This presentation will show that with the combination of Sysmon (free SysInternls system monitoring tool) and the Elastic Stack (open source data analytics platform) the insight into endpoint activity across the enterprise can be obtained without huge licensing costs. Sysmon grants defenders the capability to record endpoint activity such as process creations, network connections, file writes, process injections, and registry modifications. Combine this with Elastic Stack's ability to ingest, enrich, store, search, visualize, and alert on these records from across the enterprise and suddenly defenders can obtain enterprise-wide endpoint insight at a low cost. Given the power of Sysmon + Elastic Stack, defenders can start to identify malicious scripting, credential theft, scanning, lateral movement, attacker persistence, and attackers covering their tracks throughout their environments.