17 June 2019 | 31,677,713 Downloads | 5,644 Reviews | 333,016 Members | Login or Register

RSS Feed

Please wait while my feed loads

See more posts...

Newsletter

Subscribe to either one of our two newsletters for regular updates and information

Downloads newsletter

This is a weekly newsletter with download news, updates and other information

This is a monthly newsletter with software store information, offers and deals

Sysmon 10.1

Record network connections and launched programs

by Mike Williams

Our Rating:
Your Rating:
Login to rate
Based on 0 ratings
License: Freeware
Operating Systems: Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8, Windows Server
Requirements:

Languages: English
Software Cost: Free
Date Updated: 17 June 2019
Watchlist: Add download to my watchlist
Downloads To Date: 2714
Developer: Windows Sysinternals
RSS News Feed: http://blogs.technet.com/b/sysinternals/rss.aspx
Keep your PC maintained with iolo System Mechanic 18 for only $24.95, saving 58% from store.pcauthority.com.au
Sysmon
Record network connections and launched programs

Sysmon is a Windows service and driver which records process and file creations, registry modifications, attempts to change a file creation date, network connections and more. It's intended to help you identify malicious activity, but could also be helpful with general troubleshooting, or if you need to know some basic details on how a PC is being used.

To install Sysmon, launch it from an elevated command prompt. Use Sysmon -i to install it and log process creations only, or Sysmon -i -n to monitor network connections as well.

If everything has worked correctly, the Sysinternals EULA will be displayed. Agree to it, then reboot to run your first test.

Once Windows has started again, launch the Event Viewer (Eventvwr.msc), and browse to Applications and Services Logs\Microsoft\Windows\Sysmon\Operational.

You should now see multiple events listing Sysmon as a source, along with their date and time, giving you much more detail about what happened during your system boot.

Basic log management tasks can be carried out in Event Viewer, as usual. You're able to filter the log, display just the events you need, search for something important, disable logging when it's no longer needed, save the events to a file, and more: right-click Sysmon\Operational for the full list.

You can also change Sysmon to use its default configuration (no network connection logging) by running Sysmon -c -- , or uninstall it entirely with  Sysmon -u  . The service and driver are removed immediately, and there's no reboot required.

What's new in 10 (see Sysinternals blog for more)?

- Adds DNS query logging, reports OriginalFileName in process create and load image events, adds ImageName to named pipe events, logs pico process creates and terminates, and fixes several bugs.

Verdict:

Tools like Process Monitor give you more information and are easier to set up and use, but Sysmon is a better choice for long-term use. It launches early in the boot process to capture the maximum possible detail, and saves information to the Event Log for easier analysis later.

Your Comments & Opinion
 

Doesnt work?

Posted by: Paul Bartley, 17 February 2017 21:55

I cant get this to run? it just closes instantly...both x32 and x64

Related Download Articles
 
Process Explorer

Process Explorer 16.25

Freeware

Find out exactly what's running on your PC with this feature-packed Task Manager alternative

Process Hacker

Process Hacker 2.39

Open Source

View and take control of the programs running on your PC

Process Monitor

Process Monitor 3.50 Rev 2

Freeware

Find out exactly what the programs running on your PC are doing

ProcessCritical 1.0.0.0

ProcessCritical 1.0.0.0

Open Source

Get easier access to protected Windows processes

Other Download Articles From This Category
Don't Sleep

Don't Sleep 5.41

Freeware

Temporarily prevent Windows from hibernating, sleeping, shutting down or restarting

Argus Monitor

Argus Monitor 4.2.05

Trial Software

Track your system temperature, hard drive S.M.A.R.T. details, CPU frequency and more

FastStone Capture

FastStone Capture 9.0

Trial Software

Copy, annotate and save just about anything on your screen with this comprehensive capture tool

DesktopOK

DesktopOK 6.34 (64-bit)

Freeware

Preserve your desktop icon layout with this handy backup tool

PC & Tech Authority Software News

Please wait while my feed loads

See more posts...

Our Price: $19.95
RRP: $49.95
Saving 60%
Buy Now
Offer Ends In:
 

Spotlight: Free Full Software

Windows 10 May 2019 Update ISO (build 1903)

Free Full Commercial Software

This is the latest version of Windows May 2019 Update. it's a media creation tool that can be used to upgrade an existing installation of Windows or create installation media for another PC. Just make your choice after launching the tool and it'll do the rest.

What was new in Windows 10, when it was released? The OS brought back the Start Menu, though with a twist: live tiles keep you up-to-date with the latest news while also providing an easy way to launch apps. (Don't worry if you prefer the Start Screen, it's still there and you can boot into it if you prefer.)

Apps now work much more like regular desktop programs. They have minimise, maximise, restore and close buttons, and can be resized (to a degree) and organised however you like.

If you've still lost track of a program in the mass of open windows, a new Task Spaces feature can help. Click its taskbar button and you'll see thumbnails for everything running now, a little like OS X's Mission Control - just click something to switch to it.

Better still, Task Spaces also supports virtual desktops. Add extra desktops as required and it'll display thumbnails of each one, making it easy to identify whatever you're after and switch to it.

There's also smarter snapping, new customisation options, and even a bunch of experimental additions to the command prompt.

May 2019 Update brings a whole host of new features for Windows 10. See the Microsoft Blog for more information.

The Windows 10 ISO will give you build 1903 which is the May 2019 Update.

[...]
Value:
Free
Rating: