sysmon-config icon indicating copy to clipboard operation
sysmon-config copied to clipboard

Sysmon configuration file template with default high-quality event tracing

Results 82 sysmon-config issues
Sort by recently updated
recently updated
newest added

When running the latest version of sysmon in conjunction with the config file, the program crashes (e.g. "Sysmon.exe -accepteula -i sysmonconfig-export.xml"). However, when installing it without the config file, it...

added a MiniNT regkey check, as it can be used to disable security event logging

Modification: Under group add: 0x1010 That will catch when tools like mimikatz trigger a credential dump. ![Screenshot-2020-12-23-12-15 (2)](https://user-images.githubusercontent.com/5200414/103021715-9cf89300-4518-11eb-96f7-9141b0958642.png)

Hi @all, is it planned to extend the configuration with event id 23?

Hi, Need help with installing Sysmon on Windows 10 and Windows Server 2012 R2. I am getting the following error after running the command: **_sysmon64.exe -i_** **ERROR** wevtutil.exe returned failure...

A bug in Sysmon 11.0, which is supposedly fixed in a soon to be released 11.10 version of Sysmon, causes crippling delays during network file open and save events when...

Dunno if you already decided this before, but can you add to the configuration of the event 15 the exe and dll files? I was trying to test manually this...

For custom rules as file overwrite / create which Event ID should we use to logs changes? Event ID 11 or 2? For example I need log file when changed...

In the Process Creation section, MS Edge is now out of Dev so the file path could be changed. Or a new path added?

After enabling the FileCreateStreamHash event in sysmon, I am downloading one file from the browser, but in the event viewer, it is showing N(sometimes 3,4) entries of the same file...