Sysmon & telemetry
Sysmon (System Monitor, from Sysinternals) is the most valuable free endpoint telemetry source on Windows: it records rich events (processes with hash and command line, connections, DLL loads, registry changes) that the default security log doesn’t provide. It’s the basis of detection (Detection & logging) and hunting (Threat hunting).
Why Sysmon
Section titled “Why Sysmon”The default Security log is limited; Sysmon adds:- process creation WITH hash, full command line, and parent process (Event 1)- network connections per process (Event 3)- image/DLL loads with signature (Event 7)- CreateRemoteThread (8) and process access (10) -> injection and LSASS access- registry changes (12/13/14), file creation (11), WMI (19/20/21)- DNS (22) and pipe creation (17/18)Key events for detection
Section titled “Key events for detection”Event 1 Process Create -> anomalous command line, LOLBins, odd Office childrenEvent 3 Network Connect -> beaconing, outbound connections from unusual processes (mal-c2)Event 7 Image Load -> unsigned DLL / sideloadingEvent 8 CreateRemoteThread-> code injection (see mal-evasion)Event 10 ProcessAccess -> access to lsass.exe (credential dumping, ad-creds)Event 11 FileCreate -> drops, ransomware, persistenceEvent 13 RegistrySet -> persistence in Run keys (mal-persist)Event 22 DNSQuery -> DGA/odd domains, tunnelingConfiguration (the key to everything)
Section titled “Configuration (the key to everything)”- Sysmon is worth as much as its CONFIG: without a good XML, noise or blind spots- reference baselines: SwiftOnSecurity/sysmon-config and Olaf Hartong's (modular)- filter the noisy stuff in Sysmon itself so you don't drown the SIEM- deploy via GPO/MDM to the whole fleet and version the config as codesysmon -accepteula -i sysmonconfig.xml # install with configsysmon -c sysmonconfig.xml # update configIntegration and analysis
Section titled “Integration and analysis”- forward Sysmon (Microsoft-Windows-Sysmon/Operational channel) to the SIEM (def-siem) via WEF/agent- write Sigma detections over these events (def-deteccion)- correlate 1+3+10+13 to reconstruct an attack chainBlue Team / operation
Section titled “Blue Team / operation”- The config is 90% of the value: maintain it, version it, adapt it to new TTPs.
- Full fleet coverage; watch for hosts without Sysmon or with an old config.
- Balance volume (SIEM cost) by filtering noise at the source without creating blind spots.
- Combine with EDR (EDR / XDR): Sysmon gives cheap, open telemetry; the EDR adds response and kernel.
Real-world cases
Section titled “Real-world cases”- Sysmon is a standard IR and hunting tool to reconstruct attacks (injection, lateral, C2).
- Detecting LSASS access (Event 10) against Mimikatz/dumps is a classic use case (Credential Dumping).
- Sysmon configs (SwiftOnSecurity/Hartong) have been a community reference for years.
Testing checklist
Section titled “Testing checklist”- Sysmon deployed across the whole fleet (GPO/MDM)
- Config based on a reference (SwiftOnSecurity/Hartong) and versioned
- Key events active (1,3,7,8,10,11,13,22)
- Forwarding to the SIEM (WEF/agent) verified
- Sigma detections over key events
- Noise filtering without blind spots
- Validate with Atomic Red Team that TTPs generate events