Windows already has an event log. Why do defenders install Sysmon on top of it?
Because Windows' built-in logging is thin exactly where investigations need detail: it does not hash executables, does not record network connections per process, and by default does not log command lines, while Sysmon fills those gaps.
The standard Security log can record a process start (event 4688), but out of the box without the command line, without a file hash and without the parent's command line. Network connections are not tied to processes at all unless extra auditing is enabled. Those are the very details an analyst needs to answer "what ran, who started it, what did it talk to?"
| Question | Default Windows logging | With Sysmon |
|---|---|---|
| What was executed, with which arguments? | Often no command line | Full command line (event 1) |
| Is this binary known malware? | No hash | SHA256/MD5/IMPHASH of the image |
| Who launched it? | Parent PID only | Parent image and parent command line |
| Which process opened this connection? | Not recorded | Process, IPs, ports, hostnames (event 3) |
| Did anything touch LSASS memory? | Not recorded | ProcessAccess with access mask (event 10) |
Default Windows logging is not that advanced, and Sysmon can easily fill those gaps. Forwarding both to a SIEM gives the best picture.
Go deeper:
Microsoft Learn — Event 4688: a new process has been created — what the built-in process-creation event contains, and what it needs extra policy for.