The Finest Hand-Selected Downloads
Individually reviewed & tested
Store News

Sysmon 12.0

Record network connections and launched programs

Rating:
(0)
Operating Systems:
Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8
License:
Freeware
Developer:
Windows Sysinternals
Software Cost:
Free
Category
System & Desktop Tools
Date Updated:
18 September 2020
Downloads To Date:
3016
Languages:
English
Download Size:
1.04 MB

Sysmon is a Windows service and driver which records process and file creations, registry modifications, attempts to change a file creation date, network connections and more. It's intended to help you identify malicious activity, but could also be helpful with general troubleshooting, or if you need to know some basic details on how a PC is being used.

To install Sysmon, launch it from an elevated command prompt. Use Sysmon -i to install it and log process creations only, or Sysmon -i -n to monitor network connections as well.

If everything has worked correctly, the Sysinternals EULA will be displayed. Agree to it, then reboot to run your first test.

Once Windows has started again, launch the Event Viewer (Eventvwr.msc), and browse to Applications and Services Logs\Microsoft\Windows\Sysmon\Operational.

You should now see multiple events listing Sysmon as a source, along with their date and time, giving you much more detail about what happened during your system boot.

Basic log management tasks can be carried out in Event Viewer, as usual. You're able to filter the log, display just the events you need, search for something important, disable logging when it's no longer needed, save the events to a file, and more: right-click Sysmon\Operational for the full list.

You can also change Sysmon to use its default configuration (no network connection logging) by running Sysmon -c -- , or uninstall it entirely with  Sysmon -u  . The service and driver are removed immediately, and there's no reboot required.

Verdict:

Tools like Process Monitor give you more information and are easier to set up and use, but Sysmon is a better choice for long-term use. It launches early in the boot process to capture the maximum possible detail, and saves information to the Event Log for easier analysis later.

Your Comments & Opinion

Doesnt work?
17 February 2017 21:55, Paul Bartley
I cant get this to run? it just closes instantly...both x32 and x64
Related Downloads Other Downloads From This Category

Find out exactly what's running on your PC with this feature-packed Task Manager alternative

Freeware

View and take control of the programs running on your PC

Open Source

Find out exactly what the programs running on your PC are doing

Freeware

Get easier access to protected Windows processes

Open Source

Find out precisely what your applications are doing with this powerful Windows API monitor

Freeware
33,986,746
Downloads
Secure & Tested Software
6,161
Reviews
Instant Download 24/7
298,833
Members
10+ Years of Service