22 March 2018 | 29,130,719 Downloads | 5,520 Reviews | 318,364 Members | Login or Register

RSS Feed

Please wait while my feed loads

See more posts...


Subscribe to either one of our two newsletters for regular updates and information

Downloads newsletter

This is a weekly newsletter with download news, updates and other information

This is a monthly newsletter with software store information, offers and deals

Sysmon 7.0

Record network connections and launched programs

by Mike Williams

Our Rating:
Your Rating:
Login to rate
Based on 0 ratings
License: Freeware
Operating Systems: Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8, Windows Server

Languages: English
Software Cost: Free
Date Updated: 04 January 2018
Watchlist: Add download to my watchlist
Downloads To Date: 2313
Developer: Windows Sysinternals
RSS News Feed: http://blogs.technet.com/b/sysinternals/rss.aspx
Back up your data with Acronis True Image 2016 with a 1-PC LIFETIME license, only $34.99, saving 50%, from store.pcauthority.com.au
Record network connections and launched programs

Sysmon is a Windows service and driver which records process and file creations, registry modifications, attempts to change a file creation date, network connections and more. It's intended to help you identify malicious activity, but could also be helpful with general troubleshooting, or if you need to know some basic details on how a PC is being used.

To install Sysmon, launch it from an elevated command prompt. Use Sysmon -i to install it and log process creations only, or Sysmon -i -n to monitor network connections as well.

If everything has worked correctly, the Sysinternals EULA will be displayed. Agree to it, then reboot to run your first test.

Once Windows has started again, launch the Event Viewer (Eventvwr.msc), and browse to Applications and Services Logs\Microsoft\Windows\Sysmon\Operational.

You should now see multiple events listing Sysmon as a source, along with their date and time, giving you much more detail about what happened during your system boot.

Basic log management tasks can be carried out in Event Viewer, as usual. You're able to filter the log, display just the events you need, search for something important, disable logging when it's no longer needed, save the events to a file, and more: right-click Sysmon\Operational for the full list.

You can also change Sysmon to use its default configuration (no network connection logging) by running Sysmon -c -- , or uninstall it entirely with  Sysmon -u  . The service and driver are removed immediately, and there's no reboot required.

What's new in 7?

- Sysmon now logs file version information, and the option to dump the configuration schema adds the ability to dump an older schema or dump all historical schemas.


Tools like Process Monitor give you more information and are easier to set up and use, but Sysmon is a better choice for long-term use. It launches early in the boot process to capture the maximum possible detail, and saves information to the Event Log for easier analysis later.

Your Comments & Opinion

Doesnt work?

Posted by: Paul Bartley, 17 February 2017 21:55

I cant get this to run? it just closes instantly...both x32 and x64

Related Download Articles
Process Explorer

Process Explorer 16.21


Find out exactly what's running on your PC with this feature-packed Task Manager alternative

Process Hacker

Process Hacker 2.39

Open Source

View and take control of the programs running on your PC

Process Monitor

Process Monitor 3.50 Rev 2


Find out exactly what the programs running on your PC are doing



Open Source

Get easier access to protected Windows processes

Other Download Articles From This Category
Unzipper 1.0.0

Unzipper 1.0.0


This zip tool bears a striking resemblance to another program.

XYplorer 18.90

XYplorer 18.90

Trial Software

Manage your files and folders with this dual pane tabbed Explorer replacement

Auslogics BoostSpeed

Auslogics BoostSpeed 10.0.7

Trial Software

Clean, optimise, tune and tweak your PC to deliver its best possible performance

FastStone Capture

FastStone Capture 8.9

Trial Software

Copy, annotate and save just about anything on your screen with this comprehensive capture tool

PC & Tech Authority Software News

Please wait while my feed loads

See more posts...


Spotlight: Free Full Software

WhatsApp Messenger 2.18.31

Free Full Commercial Software

WhatsApp Messenger is the world's most popular instant messaging app for smartphones.

You can use it to send and receive text and voice messages, photos, videos, even call your friends in other countries, and because it uses your phone's internet connection it might not cost you anything at all (depending on whether you'll pay data charges).

It's easy to set up and use. There's no need to create and remember new account names or pins because it works with your phone number, and uses your regular address book to find and connect you with friends who use WhatsApp already.

You can talk one-to-one or in group chats, and because you're always logged in there's no way to miss messages. Even if your phone is turned off, WhatsApp will save your messages and display them as soon as you're back online.

There's plenty more (location sharing, contact exchange, message broadcasting) and the app is free for a year, currently $0.99/ year afterwards.

What's New in Version 2.18.30

- Bug fixes