Skip to content

Deploy Sysmon for Windows Endpoint Telemetry

Sysmon writes selected system activity to the Windows event log. It does not block threats. The default install is a small starting point: it hashes process images with SHA-1 and does not enable network connection monitoring. Process, network, and file event coverage depends on the active Sysmon configuration.

This walkthrough installs Sysmon on an authorized Windows test endpoint, checks its service and event channel, and explains how to move from the default configuration to a reviewed organization-wide policy.


Step 1: Download and Verify the Microsoft Package

01

Get Sysmon from the Official Source

Trusted Tools

Download the official Sysmon ZIP from Microsoft Sysinternals, extract it into a controlled administrative working directory, and verify the 64-bit executable signature before running it. This command uses Microsoft’s stable download URL; do not use copies from third-party download sites.

Terminal window
$workDir = Join-Path $PWD 'Sysmon'
New-Item -ItemType Directory -Path $workDir -Force | Out-Null
Invoke-WebRequest 'https://download.sysinternals.com/files/Sysmon.zip' -OutFile (Join-Path $workDir 'Sysmon.zip')
Expand-Archive -LiteralPath (Join-Path $workDir 'Sysmon.zip') -DestinationPath $workDir -Force
Get-AuthenticodeSignature (Join-Path $workDir 'Sysmon64.exe') |
Format-List Status, SignerCertificate
❯ View Expected Console Output
Status : Valid
SignerCertificate : [Microsoft Corporation signing certificate]

Step 2: Install Sysmon on the Test Endpoint

02

Install the Service with the Default Configuration

Endpoint Setup

Run elevated PowerShell from the working directory where Step 1 created the Sysmon subfolder. The default configuration is useful for validating installation, but it does not provide general network telemetry. A production rollout should use a version-controlled configuration reviewed by the detection team.

Terminal window
.\Sysmon\Sysmon64.exe -accepteula -i
Get-Service Sysmon64
❯ View Expected Console Output
Status Name DisplayName
------ ---- -----------
Running Sysmon64 Sysmon64

Step 3: Confirm Events Are Being Written

03

Inspect the Sysmon Operational Channel

Telemetry Check

Read recent events from the dedicated Sysmon channel. Event ID 1 records process creation when enabled by the active configuration. No results may mean the service has not generated events yet, the channel is unavailable, or the configuration does not include the event.

Terminal window
Get-WinEvent -LogName 'Microsoft-Windows-Sysmon/Operational' -MaxEvents 20 |
Select-Object TimeCreated, Id, ProviderName, Message |
Format-List
❯ View Expected Console Output
TimeCreated : 10/04/2026 09:15:00
Id : 1
ProviderName : Microsoft-Windows-Sysmon
Message : Process creation event ...
Windows Event Viewer Sysmon Operational channel with Process Create event details

Figure 1: Event Viewer shows Sysmon Operational process-creation events and the selected event’s details.


Step 4: Plan Configuration and Central Forwarding

04

Move from a Local Test to Managed Collection

Operations

Select a maintained Sysmon configuration, pin the release and configuration revision, test event volume on a representative pilot group, and define how the Windows event channel will reach your SIEM or event collector. Add network connection or file events only when the approved configuration enables them. Document exclusions and change ownership.

Terminal window
# Review current configuration and service state before changing policy.
.\Sysmon\Sysmon64.exe -c
Get-WinEvent -ListLog 'Microsoft-Windows-Sysmon/Operational' |
Select-Object LogName, RecordCount, MaximumSizeInBytes
# Apply only a reviewed, approved configuration file.
.\Sysmon\Sysmon64.exe -c .\Sysmon\sysmon-approved.xml
❯ View Expected Console Output
Configuration state and channel capacity are visible for the pilot review.

For centrally managed environments, use Windows Event Forwarding or your approved endpoint telemetry agent, restrict access to collected data, and alert on service removal or unexpected configuration changes.

Comments