Windows 8 and 8.1 Forums

Sysinternals new Sysmon tool looks for intruder traces

  1. #1

    Posts : 21,868
    64-bit Windows 10

    Sysinternals new Sysmon tool looks for intruder traces

    For the first time in almost two years, Microsoft's Mark Russinovich has added a new tool to the Sysinternals tool suite. The new tool is Sysmon which monitors for and logs certain specific events.

    Sysinternals is a set of Windows utility programs first released in 1996, long before Russinovich joined Microsoft. Almost all were written by Russinovich and his then-partner Bruce Cogswell. Sysmon, written by Russinovich and Thomas Garnier, also of Microsoft, is the 73rd tool in the set, and has been used internally at Microsoft for some time.

    The point of Sysmon is to monitor for three specific system events which are often used by malicious processes and which can be difficult to separate from the flood of events in a normal Windows system. Sysmon runs as a service using the Local System account and loads very early in the boot process in order to give the best chance of finding the origin of any problems.
    Read more at: Sysinternals new Sysmon tool looks for intruder traces | ZDNet

      My System SpecsSystem Spec

  2. #2

    Posts : 1,338
    Windows 7 Ultimate SP1 (64 bit), Linux Mint 17.1 MATE (64 bit)

    I like Sysinternals utilities.
    I have Process Explorer installed on my machine (and most of my VMs).
      My System SpecsSystem Spec

Sysinternals new Sysmon tool looks for intruder traces

Similar Threads
Thread Forum
Two New Releases from Sysinternals
Microsoft has released Version 16.02 of the free Process Explorer utility, which is a more detailed version of Task Manager. This version adds a refresh button to the threadís stack dialog and fixes an issue with the Virus Total terms of agreement dialog box. Microsoft has updated the free...
Software and Apps
Quirky issue with copying sysinternals to System32
So I usually copy the sysinternals suite to /windows. This in order to make it easy to use the tools in bat files and soI can quickly open them. Anyways in win 7 I didnt have a problem with this. In win 8 I had some issues copying these files to %windir% but system32 was fine. I think this was...
Software and Apps
Virtual Desktops for W8 like old sysinternals app for XP
Hi there Is there any Virtual desktop software out there for W8 -- the old sysinternals program on XP / W2k3 server was great (4 Virtual desktops). Screenshot enc running on W2K3 server Virtual Machine Desktops Linux users have had this type of software for YEARS. Note --NOT VIRTUAL...
Software and Apps
Intruder alert or paranoia?
Hi, my new Win 8 system is showing, on the Desktop Network view under the heading Computer (2), an ASUS Nexus 7 occasionally when I power up. When I checked the properties and got the MAC address and then Google'd the info the device disappears. It is labelled NASAKI or something like that. It's...
Network & Sharing
dose Sysinternals Process Monitor v3.03 work on win 8 pro
Hi was curious if Process Monitor from sysinternals works on Win 8 i cant seams to find anything about it on this so thought i would ask here thanks all.
Software and Apps
Defragmenting Pagefile using Sysinternals Contig
My first post here so please be gentle! Having installed Windows 8 on an old Windows XP PC, and having had problems in the past with fragmented pagefile.sys, I was wondering how to defragment it, or at least find out if it's fragmented in the first place. I think I may have found a way......
Performance & Maintenance
App installation traces befor uninstalling
Here's the thing, I download a 100 MB app, install it save some preferences, then uninstall it. Days later, install it again: This is what chagnes, 1st: Didn't download it again, because it took 20 seconds to install so: Where are this files saved locally? 2nd: The preferences didn't reset so:...
Software and Apps

Eight Forums Android App Eight Forums IOS App Follow us on Facebook