Microsoft Adds Sysmon To Windows
2 31Microsoft has finally delivered on its promise to integrate Sysmon -- the long-standing system monitoring tool from its Sysinternals suite -- directly into Windows, a move that should make life considerably easier for enterprise administrators who have struggled with deploying and managing the utility across thousands of endpoints.
The functionality landed this week in Windows Insider builds 26300.7733 (Dev channel) and 26220.7752 (Beta channel). Sysmon allows administrators to capture system events through custom configuration files, filter for specific activity, and pipe the data into standard Windows event logs for pickup by security tools and SIEM pipelines. Mark Russinovich, Microsoft technical fellow and Winternals co-founder, has previously noted the lack of official customer support for Sysmon in production environments -- a gap this integration addresses. The feature ships disabled by default and requires PowerShell to enable. Microsoft notes that any existing Sysmon installation must be uninstalled before activating the built-in version.
2 comments
Re:More Likely for MS to Take Control of Your Mach (Score: 5, Insightful)
by nightflameauto ( 6607976 ) on Thursday February 05, 2026 @08:57AM (#65970164)
Let's face it: Microsoft can no longer be trusted with your data. On a fresh Windows installation, just how long does it take to attempt to de-clap it?
I'm far from Microsoft's biggest fan, but when they do one ever so slightly positive thing that people have actually wanted, we don't have to immediately assume the worst. Give it a week and we'll have a report about the worst, but the announcement gives us a brief respite from, "When are they going to do something we've actually asked for?" We can celebrate that vanishingly small victory for a few seconds before we find out the nefarious part.
Right?
Riiiiiiiight?
What? (Score: 5, Funny)
by RitchCraft ( 6454710 ) on Wednesday February 04, 2026 @10:52PM (#65969696)
They haven't renamed it CoPilot Sysmon yet?