LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

What is Sysmon, and what kinds of activity does it record on a Windows host?

Sysmon (System Monitor) is a free Sysinternals tool that runs as a Windows service plus a kernel driver and writes detailed security-relevant activity into the Windows Event Log: process starts with command lines, network connections, file hashes, DLL loads, registry changes and more.

Sysmon at the centre with its event families: processes, network, DNS, files, registry, DLLs and drivers, cross-process access, WMI and pipes, each with its event IDs

* One sensor, eight families of evidence; the numbers are the Sysmon event IDs. *

It was written by Mark Russinovich as part of the Sysinternals suite, now published by Microsoft. What it logs:

  • Process creation, with the full command line, the parent process and its command line, the user, and the hash of the executable.
  • Network connections, with the process that opened them, source and destination IPs, ports and hostnames.
  • Hashes of process images (SHA1, MD5, SHA256 or IMPHASH), so a binary can be checked against threat intelligence even if it was renamed.
  • DLL and driver loading, with hashes and signature status.
  • File changes, including the tell-tale case of a process rewriting a file's creation time.
  • Registry changes, named pipes, WMI persistence, DNS queries, file deletions and more.

A quick look at these events is often enough to spot malware, intrusions and breaches. The data is only valuable if someone reads it, though, which is why the next step is always to ship it to a central search tool such as Splunk or Elasticsearch.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026