Sysmon is a Microsoft application that allows for the monitoring of a system's status and events. It provides detailed control over various system activities such as process creation, network connections, and file creation and deletion.
The program is typically installed through the command line. To do this, one must open CMD.exe as an administrator in the installation path and input the necessary command to install it.
After installation, users can access the Windows Event Viewer and navigate to the path Applications and Services Logs/Microsoft/Windows/Sysmon/Operational to view all system events. The program is capable of recording various types of process events including process creation, file creation time, network connections, process terminations, loaded drivers, and more.
In total, there are 26 different types of events that Sysmon can monitor, ranging from process tampering to DNS queries to changes in the clipboard content. This comprehensive monitoring tool provides users with a thorough insight into the various activities taking place on their system.
Discover more apps
TrayButton for WhatsApp
TrayButton for WhatsApp adds convenient features to UWP WhatsApp for Windows.
G-Business Extractor - Google Maps Data Extractor
G-Business Extractor: gathers Google Maps data efficiently for marketing and analysis.
Grand Rogue Auto
Grand Rogue Auto: sandbox roguelike with different city generating modes.
3D Magic Mahjongg Holidays
New release of Chinese game with extra features and scenery options.
Rogue's Souls
'Rogue's Souls' is a challenging roguelike inspired by Dark Souls.
Message Viewer Lite
Message Viewer Lite: view MSG and EML email files easily for 15 days.
Drumtronic
Drumtronic lets you play drums, choose difficulty level, and improve skills.
Alternate File Shredder
Alternate File Shredder permanently deletes files, cannot be recovered, easy to use.