#sysmon
I wanted a script I could run on a new Windows box that would install sysmon with @olafhartong.nl's configs, and set logging best practices with Zach Mathis' (Yamato Security) "EnableWindowsLogSettings" configs.

So I made one! Feel free to inspect it and repurpose.

gist.github.com/ecapuano/42f...
A PowerShell script for installing Sysmon and enabling best-practice audit logs.
A PowerShell script for installing Sysmon and enabling best-practice audit logs. - better_event_logging.ps1
gist.github.com
March 1, 2025 at 8:12 PM
Microsoft is adding Sysmon directly into Windows. The Sysinternals utility will make it easier for security teams to detect and respond to threats www.theverge.com/news/822023/...
Microsoft is adding Sysmon into Windows.
Sysmon was first released in 2014 as a utility for security analysis into the Windows Event Log. Built by Microsoft technical fellow Mark Russinovich with assistance from Thomas Garnier, Sysmon is now...
www.theverge.com
November 18, 2025 at 4:06 PM
sysmon magic FTW 👇🤓🔥
I wanted a script I could run on a new Windows box that would install sysmon with @olafhartong.nl's configs, and set logging best practices with Zach Mathis' (Yamato Security) "EnableWindowsLogSettings" configs.

So I made one! Feel free to inspect it and repurpose.

gist.github.com/ecapuano/42f...
A PowerShell script for installing Sysmon and enabling best-practice audit logs.
A PowerShell script for installing Sysmon and enabling best-practice audit logs. - better_event_logging.ps1
gist.github.com
March 1, 2025 at 8:48 PM
ANNOUNCEMENT: Sysmon coming to Windows 11 and Windows Server 2025

techcommunity.microsoft.com/blog/Windows...
Native Sysmon functionality coming to Windows | Microsoft Community Hub
Learn how to eliminate manual deployment and reduce operational risk with Sysmon functionality in Windows.     
techcommunity.microsoft.com
November 25, 2025 at 9:48 AM
This generated **terabytes** of logs at a control center where we recorded every registry change on operator consoles.

It took way too much arm twisting to get approval to filter that out of Sysmon.
December 20, 2025 at 9:08 PM
Microsoft actually does something useful, adds Sysmon to Windows
Microsoft actually does something useful, adds Sysmon to Windows
After years of bolting AI onto everything, Redmond remembers admins exist There is good news for administrators: Microsoft has delivered on its promise to build Sysmon functionality into Windows.…
dlvr.it
February 4, 2026 at 1:36 PM
Trying to get EDR-level coverage with a DIY Sysmon install...
November 5, 2024 at 4:34 PM
There is at least one computer security product on the market (probably multiple) that very obviously copy and paste my Sysmon ruleset. Because they included a typo I made and never fixed.
Frankly the ego boost is worth way more to me than being mad about it. I think that's a lot funnier anyway.
wait what? I don't know this bit of lore
May 3, 2025 at 11:15 PM
Thank for your Sysmon-config 🫡
May 18, 2025 at 11:56 PM
Fun fact I made a typo in sysmon-config many years ago, when I was working in helpdesk.

I got my shot and was hired to the big firm with the big fancy expensive tools I would've never dreamed of.

Do you know what I find in that tool?

My typo. They pasted it in.

I was always good enough.
March 27, 2026 at 7:51 PM
lol probably :D but don't worry, some of us know why :) #SYSMON #WARRIOR
May 2, 2025 at 7:22 AM
ICYMI: Microsoft actually does something useful, adds Sysmon to Windows
Microsoft actually does something useful, adds Sysmon to Windows
After years of bolting AI onto everything, Redmond remembers admins exist There is good news for administrators: Microsoft has delivered on its promise to build Sysmon functionality into Windows.…
dlvr.it
February 5, 2026 at 7:37 PM
Refusing to deploy EDR "because we have Sysmon"
June 10, 2023 at 8:18 PM
Detection Engineering with Wazuh! A demo configuring Sysmon, reviewing event logs, building a proof-of-concept detection rule, and then leveling up with detectors for the DeerStealer malware.🙂 https://jh.live/nSOqU1iX5oQ
January 16, 2025 at 2:00 PM
I got to compile and test Venture on my Mac. I loaded a 120MB sysmon log, and it loaded instantly 🤯😱

It also filters incredibly fast, which makes it great for a quick peek into a sus activity.

Repo: github.com/mttaggart/ve...
January 23, 2025 at 6:53 PM
Microsoft announced today that it is integrating Sysmon natively into Windows 11 and Windows Server 2025 next year, making it unnecessary to deploy the standalone Sysinternals tools.
Microsoft is bringing native Sysmon support to Windows 11, Server 2025
Microsoft announced today that it is integrating Sysmon natively into Windows 11 and Windows Server 2025 next year, making it unnecessary to deploy the standalone Sysinternals tools.
www.bleepingcomputer.com
November 18, 2025 at 5:25 PM
"Mastering Sysmon: Deploying, Configuring, and Fine-Tuning"
A free mini eBook for #DFIR professionals with practical steps to deploy, fine-tune, and start logging with Sysmon.

dfirinsights.com/2024/11/27/m...

#infosec #blueteam
Mastering Sysmon free DFIR e-book release - DFIR Insights
Today is the day! I'm announcing the release of my guide: "Mastering Sysmon: Deploying, Configuring, and Fine-Tuning", a free mini eBook designed specifically for digital forensics and incident respon...
dfirinsights.com
December 16, 2024 at 11:18 AM
Mark Russinovich hat angekündigt, dass das Diagnosetool Sysmon im kommenden Jahr Windows-Bestandteil wird. #Windows
Sysmon wird Windows-Bestandteil
Mark Russinovich hat angekündigt, dass das Diagnosetool Sysmon im kommenden Jahr Windows-Bestandteil wird.
www.heise.de
November 19, 2025 at 1:23 PM
Microsoft has started rolling out built-in Sysmon functionality to some Windows 11 systems enrolled in the Windows Insider program.
Microsoft rolls out native Sysmon monitoring in Windows 11
Microsoft has started rolling out built-in Sysmon functionality to some Windows 11 systems enrolled in the Windows Insider program.
www.bleepingcomputer.com
February 4, 2026 at 12:58 PM
CVE-2025-49144 is a local privilege escalation in the Notepad++ installer that abuses how regsvr32.exe is called during setup.
We break down:
• what it looks like on real systems
• why Sysmon catches it cleanly
• a high-signal Graylog search + Sigma rule
graylog.org/post/detecti...
Detecting Notepad++ CVE-2025-49144 Using Sysmon Logs
How to detect CVE-2025-49144, a local privilege escalation vulnerability, using Sysmon logs with Graylog searches and Sigma Rules.
graylog.org
February 12, 2026 at 3:59 PM
Chasse à la menace sur Linux, utiliser Sysmon et auditd et détecter des webshells.
-> pberba.github.io/sec...
April 8, 2024 at 12:30 PM