JosephKing 3 Posted April 29, 2022 Share Posted April 29, 2022 Sysmon is essential and sets up in just a minute. https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon Download Sysmon and put in any directory. Open cmd and cd to the directory. Cmd> Sysmon.exe -I -h sha256 -n /accepteula Done. Open Event Viewer: Microsoft\Windows\Sysmon. Enjoy! There's a lot of different config.xml files out there to create different info in the event logs. https://www.blumira.com/enable-sysmon/ Link to comment Share on other sites More sharing options...
Recommended Posts