Microsoft Adds Sysmon To Windows - Slashdot
Close
binspam
dupe
notthebest
offtopic
slownewsday
stale
stupid
fresh
funny
insightful
interesting
maybe
offtopic
flamebait
troll
redundant
overrated
insightful
interesting
informative
funny
underrated
descriptive
typo
dupe
error
180732392
story
Microsoft has finally delivered on its promise to integrate Sysmon -- the long-standing system monitoring tool from its Sysinternals suite --
directly into Windows
, a move that should make life considerably easier for enterprise administrators who have struggled with deploying and managing the utility across thousands of endpoints.
The functionality landed this week in Windows Insider builds 26300.7733 (Dev channel) and 26220.7752 (Beta channel). Sysmon allows administrators to capture system events through custom configuration files, filter for specific activity, and pipe the data into standard Windows event logs for pickup by security tools and SIEM pipelines. Mark Russinovich, Microsoft technical fellow and Winternals co-founder, has previously noted the lack of official customer support for Sysmon in production environments -- a gap this integration addresses. The feature ships disabled by default and requires PowerShell to enable. Microsoft notes that any existing Sysmon installation must be uninstalled before activating the built-in version.
You may like to read:
Russian Spy Satellites Have Intercepted EU Communications Satellites
Does a Gas-Guzzler Revival Risk Dead-End Futures for US Automakers?
Americans' Junk-Filled Garages Are Hurting EV Adoption, Study Says
Americans are Buying Twice as Many Hybrids as Fully Electric Vehicles. Is The Next Step Synthetic Fuels?
EV Sales Keep Growing In the US, Represent 20% of Global Car Sales and Half in China
China Is Mass-Producing Hypersonic Missiles For $99,000
BMW Commits To Subscriptions Even After Heated Seat Debacle
This discussion has been archived.
No new comments can be posted.
Microsoft Adds Sysmon To Windows
More
Microsoft Adds Sysmon To Windows
Comments Filter:
All
Insightful
Informative
Interesting
Funny
The Fine Print:
The following comments are owned by whoever posted them. We are not responsible for them in any way.
More Likely for MS to Take Control of Your Machine
Score:
by
BrendaEM
( 871664 )
writes:
Let's face it: Microsoft can no longer be trusted with your data. On a fresh Windows installation, just how long does it take to attempt to de-clap it?
Re:
Score:
by
geekmux
( 1040042 )
writes:
Let's face it: Microsoft can no longer be trusted with your data. On a fresh Windows installation, just how long does it take to attempt to de-clap it?
Let's face it: Microsoft took
twenty fucking years
to integrate this tool.
They
don't seem to be in a hurry to utilize the damn thing, regardless of how useful the rest of us find it.
Re:
Score:
by
gweihir
( 88907 )
writes:
My take is they have a long list of minor and tiny changes they can push as great "innovations" to obscure the fact that they are pushing an ancient obsolete system design with a mediocre, unreliable and insecure implementation on their users.
Re:
Score:
by
Targon
( 17348 )
writes:
You ignore that Apple is so locked into it's own designs that they are afraid to make any changes. User interface, software compatibility, and in general, users wanting to feel comfortable using a new device makes it where it will take over 20 years before it is safe to remove old and obsolete stuff.
Re:
Score:
by
gweihir
( 88907 )
writes:
You do not what OS-X is based on, right? Well, you probably do not know.
Despite your inept attempt to deviate attention away from my statement, I am not ignoring anything. Windows is a crumbling mess and cannot be fixed anymore.
Re:
Score:
by
AcidFnTonic
( 791034 )
writes:
Dude, OS X these days is the easy system compared to windows. One simple place to configure stuff, not the multitude of places these days in windows land.
And this is sad to say as I was not originally kind to Apple or anything they make but I can call a spade a spade. They leapfrogged windows.
Re:
Score:
by
jbmartin6
( 1232050 )
writes:
Why would they be, anyone who wants to use it just installs it.
Re:
Score:
by
unixisc
( 2429386 )
writes:
Will this be only there on Windows Pro, or will it be available in Windows Home editions as well?
Re:
Score:
by
thegarbz
( 1787294 )
writes:
just how long does it take to attempt to de-clap it?
0 hours, since it's not something that 99.99% of users do, especially not in corporations (which is what this story is about).
Re:
Score:
by
Zero__Kelvin
( 151819 )
writes:
Show me where he said "typical user", then you would be attempting to make a point that was consistent with his post. Of course the fact that most non-corporate "admins" are also users who don't have a basic understanding of any of this, and are regularly lied to by Microsoft when they are told skill isn't required, while forcing an insecure by default OS onto systems via past anti-trust violations that led to user lock-in and rake in money from naive customers, doesn't make your ridiculous "point" any bet
Re:
Score:
by
thegarbz
( 1787294 )
writes:
My point is not consistent with his post. My point is consistent with the story and my point was that his post is an off topic anti MS rant. Hope you got my point now too.
Re:
Score:
by
Zero__Kelvin
( 151819 )
writes:
I already made it clear that I understand that you didn't have a "point." Now you just need to figure that out.
Re:More Likely for MS to Take Control of Your Mach
Score:
, Insightful)
by
nightflameauto
( 6607976 )
writes:
on Thursday February 05, 2026 @09:57AM (
#65970164
Let's face it: Microsoft can no longer be trusted with your data. On a fresh Windows installation, just how long does it take to attempt to de-clap it?
I'm far from Microsoft's biggest fan, but when they do one ever so slightly positive thing that people have actually wanted, we don't have to immediately assume the worst. Give it a week and we'll have a report about the worst, but the announcement gives us a brief respite from, "When are they going to do something we've actually asked for?" We can celebrate that vanishingly small victory for a few seconds before we find out the nefarious part.
Right?
Riiiiiiiight?
Parent
Share
Re:
Score:
by
Waccoon
( 1186667 )
writes:
I remember using the old version of Process Explorer on Windows7. Then SysInternals was bought by Microsoft. When the new version of Process Explorer was released, it showed you a LOT less stuff that was going on in the background, showing an idle Win10 system with 0% CPU utilization. The old version of Process Explorer on an idle Win10 system lights up like a Christmas tree.
Yeah, I always assume the worst, because that's just reality.
PS - Yeah, I'm still stuck on Windows. Linux is a PITA.
Re:
Score:
by
slaker
( 53818 )
writes:
I modify my installation ISO to remove the most egregious matters and use an autounattend.xml to make sure the installation is as I wish it to be. I have sysprep images that are appropriate for things I deal with professionally and my generic installation ISO works well enough to handle one-off installs that I can use the same single file for at least anything up to a Ryzen HX370/Zen5 or 15th-gen Intel.
Schneegan's AutoUnattend generator is extremely helpful in this regard. I've recently found Winhance, whi
What?
Score:
, Funny)
by
RitchCraft
( 6454710 )
writes:
on Wednesday February 04, 2026 @11:52PM (
#65969696
They haven't renamed it CoPilot Sysmon yet?
Share
Re:
Score:
by
martin-boundary
( 547041 )
writes:
@: Looks like you want to rename Sysmon to CopilotSysmon! Would you like some help with that?
[OK] [Cancel]
Re:
Score:
by
Deal In One
( 6459326 )
writes:
Don't give them ideas.
Very soon we may end up with Windows CoPilot after Windows 11.
And since CoPilot is supposedly AI enabled, it will self improve over time, and be the last OS from MS. We promise this time!
Re:
Score:
by
Tony Isaac
( 1301187 )
writes:
They haven't figured out yet exactly what that Copilot button would do if you did click it, beyond a fancy interactive help system to tell you how to use it.
Re:
Score:
by
theendlessnow
( 516149 )
writes:
Actually it's been renamed to m365 in order to avoid confusion.
Why was this a challenge to admins?
Score:
by
gweihir
( 88907 )
writes:
Oh, right, WINDOWS. Yuck. No ssh-ing down the list with a nice small script and all done. No idea why this limited and defective toy is used in any professional context.
Re:
Score:
by
Viol8
( 599362 )
writes:
"No ssh-ing down the list with a nice small script and all done"
Poettering and the distro sheep have done their best to make linux admin much harder than it was before or needs to be, so I'm not sure a small script would work now on a penguin box.
Re:
Score:
by
bn-7bc
( 909819 )
writes:
Ok I must have missed that, can you give concrete examples (besiddes systemd hate, and the remaining phalanges of the x-11 to wauland transition) ?
Re:
Score:
by
gweihir
( 88907 )
writes:
It still works quite well and it will continue to work because it is a major advantage. Also, there is no need to run Poetterix.
Too little to late
Score:
by
njmarine2001
( 946297 )
writes:
Considering how they've been destroying customer trust in Windows. This small move doesnt bring a lot of love for MS.
I miss the old times
Score:
by
djgl
( 6202552 )
writes:
Will the executable now shrink back to its pre-EULA size?
Re:
Score:
by
bn-7bc
( 909819 )
writes:
I don't think the EULA size is significant, it's just text after all. and I'm not even shoure the eula is stored in the executable (well it's obviously stored in the self extracting installer executable but that's another matter)
Re:
Score:
by
djgl
( 6202552 )
writes:
[exetools.com]
Related Links
Top of the:
day
week
month
384
comments
Does a Gas-Guzzler Revival Risk Dead-End Futures for US Automakers?
377
comments
Americans' Junk-Filled Garages Are Hurting EV Adoption, Study Says
363
comments
Americans are Buying Twice as Many Hybrids as Fully Electric Vehicles. Is The Next Step Synthetic Fuels?
323
comments
EV Sales Keep Growing In the US, Represent 20% of Global Car Sales and Half in China
314
comments
China Is Mass-Producing Hypersonic Missiles For $99,000
next
BMW Commits To Subscriptions Even After Heated Seat Debacle
170
comments
previous
Russian Spy Satellites Have Intercepted EU Communications Satellites
85
comments
Slashdot Top Deals
Excessive login or logout messages are a sure sign of senility.
Close
Working...