Jump to content

Sysmon Setup


JosephKing

Recommended Posts

Sysmon is essential and sets up in just a minute.

https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon

Download Sysmon and put in any directory. Open cmd and cd to the directory.
Cmd>  Sysmon.exe -I -h sha256 -n /accepteula

Done.

Open Event Viewer: Microsoft\Windows\Sysmon.

Enjoy! There's a lot of different config.xml files out there to create different info in the event logs. 

https://www.blumira.com/enable-sysmon/

 

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...