LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

How is a Sysmon configuration file structured?

An XML file with a <Sysmon schemaversion="…"> root, global settings such as <HashAlgorithms>, and an <EventFiltering> section of <RuleGroup>s, each containing per-event rules with onmatch="include" or onmatch="exclude".

Nested structure of a Sysmon config: root with schemaversion, HashAlgorithms, EventFiltering, RuleGroup, an event element with onmatch, and a condition

* Root, global options, then filters nested down to one field condition. *

<Sysmon schemaversion="4.22">
  <HashAlgorithms>md5,sha256,IMPHASH</HashAlgorithms>
  <EventFiltering>
    <RuleGroup name="" groupRelation="or">
      <RegistryEvent onmatch="include">
        <TargetObject name="T1060,RunKey" condition="contains">CurrentVersion\Run</TargetObject>
      </RegistryEvent>
    </RuleGroup>
    <RuleGroup name="" groupRelation="or">
      <FileCreateTime onmatch="include">
        <Image name="T1099" condition="begin with">C:\Users</Image>
        <TargetFilename name="T1099" condition="end with">.exe</TargetFilename>
      </FileCreateTime>
    </RuleGroup>
  </EventFiltering>
</Sysmon>

How to read it:

  1. schemaversion tells Sysmon which rule format the file uses, so newer binaries can still parse older configs. Sysmon64.exe -? config shows the current schema.
  2. HashAlgorithms selects which hashes to compute for images.
  3. Each event element (RegistryEvent, FileCreateTime, ProcessCreate, …) has onmatch: include logs only matching events, exclude logs everything except matching ones.
  4. Each condition compares one field (Image, TargetObject, TargetFilename) using an operator such as is, contains, begin with, end with, image.
  5. groupRelation decides whether the conditions inside a group are combined with or or and.

The name attributes are free-text labels that end up in the event's RuleName field. Here they carry MITRE ATT&CK technique IDs (T1060 Registry Run Keys, T1099 Timestomp), so an analyst sees immediately why an event was logged.

A new file is applied with Sysmon64.exe -c config.xml.

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026