Quiz Entry - updated: 2026.09.24
How is a Sysmon configuration file structured?
An XML file with a <Sysmon schemaversion="…"> root, global settings such as <HashAlgorithms>, and an <EventFiltering> section of <RuleGroup>s, each containing per-event rules with onmatch="include" or onmatch="exclude".
* Root, global options, then filters nested down to one field condition. *
<Sysmon schemaversion="4.22">
<HashAlgorithms>md5,sha256,IMPHASH</HashAlgorithms>
<EventFiltering>
<RuleGroup name="" groupRelation="or">
<RegistryEvent onmatch="include">
<TargetObject name="T1060,RunKey" condition="contains">CurrentVersion\Run</TargetObject>
</RegistryEvent>
</RuleGroup>
<RuleGroup name="" groupRelation="or">
<FileCreateTime onmatch="include">
<Image name="T1099" condition="begin with">C:\Users</Image>
<TargetFilename name="T1099" condition="end with">.exe</TargetFilename>
</FileCreateTime>
</RuleGroup>
</EventFiltering>
</Sysmon>
How to read it:
schemaversiontells Sysmon which rule format the file uses, so newer binaries can still parse older configs.Sysmon64.exe -? configshows the current schema.HashAlgorithmsselects which hashes to compute for images.- Each event element (
RegistryEvent,FileCreateTime,ProcessCreate, …) hasonmatch:includelogs only matching events,excludelogs everything except matching ones. - Each condition compares one field (
Image,TargetObject,TargetFilename) using an operator such asis,contains,begin with,end with,image. groupRelationdecides whether the conditions inside a group are combined withororand.
The name attributes are free-text labels that end up in the event's RuleName field. Here they carry MITRE ATT&CK technique IDs (T1060 Registry Run Keys, T1099 Timestomp), so an analyst sees immediately why an event was logged.
A new file is applied with Sysmon64.exe -c config.xml.