15 Juli 2026
Information:
I have for a long time been writing detection for the
Sysmon made by
Sysinternals by Microsoft. The config file is very well tested
on live attacks and a lot of malware. Tested with
Atomic-Red test
tools as well. It have been tested in
Blue-teams/ Red-Team pen-tests with
high success. It is used in forensic cases to monitor behavior on hacked
/ malware infected systems.
There have been a focus on, only to log what is importent.
If you log everything that Sysmon can log, you will get way to many
logs from the endpoints send to your SIEM system. That can have
big impact on licenses in SIEM systems.
Use of undocumented Sysmon Config files
If you use "undocumented" config files, you basically don´t known
why something is logged in the first place. This config is documnted
in it self, with rule names and references to MITRE, LOBAS, LOLBINS and so
on. You will know why and what is logged and send to SIEM. From
there you can build near Real-Time Alerting in Splunk, Elastic. You
can combine this with validation on things like HASH values, IP's
from other TI systems like
Recorded
Future,
MISP
VirusTotal and others.
VT is recommended..
Rule based detections
Sinse Sysmon support "rule based detections". Many of the rules have
been written as souch. This help to keep the amount of logs send to
SIEM down and collection of logs very accurate.
Detection types
All detections are made with rule names, and are related to MITRE,
LOLAPPS, LOLBAS, LOLDRIVERS, Industrial protocols and more.
AutoRuns
Sysinternals AutoRuns is a tool that is very good at keeping an
eye on what is happening in the regestry on Windows Systems. An
implementation of Sysinternal Autoruns detections, have been added
as well to the Sysmon config file. So the Sysmon config will work as
AutoRuns.
Recommendation for Event ID 3: Network connection
Note: You will need to customize network detections in Event ID 3 to
match your needs. I have added a lot of common detection to the
sysmon config file for a start. You can have other demands. But
there is monitoring for Industrial protocol ports, Some remote admin
tools, commonn malware start locations and lot more.
Event ID 255 - Error
For a long time I have dropped event ID 255 ERROR for collection to
SIEM, because of a lot of noice, when updating Windows or updating
sysmon configs. There are one event I now look for in SIEM. It is
the ONLY event you will get if someone crashes your sysmon. This is
also a known LOLBAS. I have collected some known event id 255
error codes and the mening of them.
Event id 255 -
Sysmon.pdf
Look for this in SIEM
"Failed to retrieve events - Last
error: The I/O operation has been aborted because of either a thread
exit or an application request"
Not Covered
"Event ID 24: ClipboardChange" are not covered. Because this can be
a security risk in most environments. You don't what to have copyed
password in clear txt into an accessible folder. But
this can be very useful in other scenarios, like
malware testing.
Supported Sysmon version
The Sysmon config can be used on Sysmon from version 15.21.
(Sysmon schema version: 4.91)
This also cover Sysmon Native from windows 11 25H2 (Sysmon schema
version: 4.91)
SIEM system
Logs send to SIEM systems like
Security Onion (elastic) or
Splunk works verry well. But I
reccormed to use it with
Winlogbeat from elastic and sending your logs to
Security Onion. And i also reccormed that you use proper Windows
logging set by Security policys in Windows as GPO's. I can recommend
to follow the
NSACyber guide.
Then you will have a very good logging system togheter win
IDS destection.
Sysmon install / uninstall / Auto update Config file
Sysmon Install / Uinstall / Config Update script is
included.
This makes it verry easy to Install / uninstall Sysmon and update
the Sysmon Config file on clients and servers just by changing 1
file on a central location. I can reccormend the use of your own
web-server. You can auto update all clients and servers with my
lates config file by using Task Scheduler in Windows. Config files
for Task Scheduler is included for you to import to Task Scheduler.
You just have to change from where you want hosts to get the config
file from in the PowerShell script.
For Windows 11 25H2 i can highly reccormend using the Native
version. This makes all deploy and installation and maintenance
easy.
Monitoring of Sysmon alerts.
It is easy to monitor Sysmon alerts and create Notables in Splunk
ore Alerts Dashboards in Security Onion.

Sysmon with install / uninstall
scripts and auto update scripts.
Windows 11 - Windows Server 2025 (Native Sysmon)
Filename: Sysmon_Win11-Serv2025_Config_173.zip
SHA1: 34a45ca136ed65ea481a20d7e588f7f5d08fea8b
Windows 10 - Windows Server 2016 higher (Sysinternals)
Filename: Sysmon_15.21_Config_173.zip
SHA1: e25939eafc0a59bd2c64c4803d575c1b7f96c051
Sysmon Cheatsheet
Filename: Sysmon-Cheatsheet.pdf
SHA1:e573f2c2b46a5abef726b73f3690005b04780e5e
15-07-2026
Changes:
- Sysmon Config 173
- Event ID 22 Tuning
11-07-2026
Changes:
- Sysmon Config 172
- Event ID 2 Tuning
10-07-2026
Changes:
- Sysmon Config 171
- Event ID 26 updates
09-07-2026
Changes:
- Sysmon Config 170
- Event ID 26 updates
02-07-2026
Changes:
- Sysmon Config 168
- Rules optimized for SIEM
29-06-2026
Changes:
- Sysmon Config 167
- Bypass User Account Control
26-06-2026
Changes:
- Sysmon Config 166
- Cobalt Strike post-exploitation jobs
- Data Encrypted for Impact - BitLocker Manager
- Impair Defenses - AV Provider
- Windows Defender Tamper protection OFF
- Account Manipulation
- AppLocker EnforcementMode
24-06-2026
Changes:
- Sysmon Config 165
- Sysmon 15.21
- Impair Defenses
- Disable or Modify Tools
22-06-2026
Changes:
- Sysmon Config 164
- hosts files deleted
- hosts files created
- Event ID 26 optimized
19-06-2026
Changes:
- Sysmon Config 163
- App Store Disabled
- AppLocker Disabled
12-05-2026
Changes:
- Sysmon Config 162
- GHOSTLOCK
30-04-2026
Changes:
- Sysmon Config 161
- Dns query - exclude Danish domains update
18-04-2026
Changes:
- Sysmon Config 160
- LOLRMM
- Network detection - OT
16-04-2026
Changes:
- Sysmon Config 159
- Enhanced detection for WSL
14-04-2026
Changes:
- Sysmon Config 158
- Network detection - OT
05-04-2026
Changes:
- Sysmon Config 157
- Data Encrypted for Impact
04-04-2026
Changes:
- Sysmon Config 156
- Download sysmon config change
- Additional Cloud Credentials
03-04-2026
Changes:
- Sysmon Config 155
- Local Data Staging