LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

How do you install Sysmon, and what does the default configuration log (and not log)?

From an administrator console run Sysmon64.exe -i; without a config file it hashes process images with SHA1 and does not monitor network connections.

Sysmon64.exe -h                  # show all options
Sysmon64.exe -accepteula -i      # install with the default configuration
Sysmon64.exe -accepteula -i config.xml   # install with your own configuration
Sysmon64.exe -c                  # dump the active configuration
Sysmon64.exe -c config.xml       # load a new configuration into a running install
Sysmon64.exe -u                  # uninstall

The installation registers two pieces: a service, and a boot-start driver. The driver is loaded very early in the boot process, so it captures events before most of Windows, and before the event-log service itself, is running. Malware that starts during boot is therefore still recorded.

The defaults are deliberately minimal. Network logging is off because it is noisy, and SHA1 is the only hash. In practice nobody runs Sysmon with the defaults: you install it with a tuned configuration file from the start.

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026