Skip to content

Sysmon & telemetry

Sysmon (System Monitor, from Sysinternals) is the most valuable free endpoint telemetry source on Windows: it records rich events (processes with hash and command line, connections, DLL loads, registry changes) that the default security log doesn’t provide. It’s the basis of detection (Detection & logging) and hunting (Threat hunting).

The default Security log is limited; Sysmon adds:
- process creation WITH hash, full command line, and parent process (Event 1)
- network connections per process (Event 3)
- image/DLL loads with signature (Event 7)
- CreateRemoteThread (8) and process access (10) -> injection and LSASS access
- registry changes (12/13/14), file creation (11), WMI (19/20/21)
- DNS (22) and pipe creation (17/18)
Event 1 Process Create -> anomalous command line, LOLBins, odd Office children
Event 3 Network Connect -> beaconing, outbound connections from unusual processes (mal-c2)
Event 7 Image Load -> unsigned DLL / sideloading
Event 8 CreateRemoteThread-> code injection (see mal-evasion)
Event 10 ProcessAccess -> access to lsass.exe (credential dumping, ad-creds)
Event 11 FileCreate -> drops, ransomware, persistence
Event 13 RegistrySet -> persistence in Run keys (mal-persist)
Event 22 DNSQuery -> DGA/odd domains, tunneling
- Sysmon is worth as much as its CONFIG: without a good XML, noise or blind spots
- reference baselines: SwiftOnSecurity/sysmon-config and Olaf Hartong's (modular)
- filter the noisy stuff in Sysmon itself so you don't drown the SIEM
- deploy via GPO/MDM to the whole fleet and version the config as code
sysmon -accepteula -i sysmonconfig.xml # install with config
sysmon -c sysmonconfig.xml # update config
- forward Sysmon (Microsoft-Windows-Sysmon/Operational channel) to the SIEM (def-siem) via WEF/agent
- write Sigma detections over these events (def-deteccion)
- correlate 1+3+10+13 to reconstruct an attack chain
  • The config is 90% of the value: maintain it, version it, adapt it to new TTPs.
  • Full fleet coverage; watch for hosts without Sysmon or with an old config.
  • Balance volume (SIEM cost) by filtering noise at the source without creating blind spots.
  • Combine with EDR (EDR / XDR): Sysmon gives cheap, open telemetry; the EDR adds response and kernel.
  • Sysmon is a standard IR and hunting tool to reconstruct attacks (injection, lateral, C2).
  • Detecting LSASS access (Event 10) against Mimikatz/dumps is a classic use case (Credential Dumping).
  • Sysmon configs (SwiftOnSecurity/Hartong) have been a community reference for years.
  • Sysmon deployed across the whole fleet (GPO/MDM)
  • Config based on a reference (SwiftOnSecurity/Hartong) and versioned
  • Key events active (1,3,7,8,10,11,13,22)
  • Forwarding to the SIEM (WEF/agent) verified
  • Sigma detections over key events
  • Noise filtering without blind spots
  • Validate with Atomic Red Team that TTPs generate events