Deploy Sysmon for Windows Endpoint Telemetry
Sysmon writes selected system activity to the Windows event log. It does not block threats. The default install is a small starting point: it hashes process images with SHA-1 and does not enable network connection monitoring. Process, network, and file event coverage depends on the active Sysmon configuration.
This walkthrough installs Sysmon on an authorized Windows test endpoint, checks its service and event channel, and explains how to move from the default configuration to a reviewed organization-wide policy.
Step 1: Download and Verify the Microsoft Package
Get Sysmon from the Official Source
Trusted ToolsDownload the official Sysmon ZIP from Microsoft Sysinternals, extract it into a controlled administrative working directory, and verify the 64-bit executable signature before running it. This command uses Microsoft’s stable download URL; do not use copies from third-party download sites.
$workDir = Join-Path $PWD 'Sysmon'New-Item -ItemType Directory -Path $workDir -Force | Out-NullInvoke-WebRequest 'https://download.sysinternals.com/files/Sysmon.zip' -OutFile (Join-Path $workDir 'Sysmon.zip')Expand-Archive -LiteralPath (Join-Path $workDir 'Sysmon.zip') -DestinationPath $workDir -ForceGet-AuthenticodeSignature (Join-Path $workDir 'Sysmon64.exe') | Format-List Status, SignerCertificate❯ View Expected Console Output
Status : ValidSignerCertificate : [Microsoft Corporation signing certificate]Step 2: Install Sysmon on the Test Endpoint
Install the Service with the Default Configuration
Endpoint SetupRun elevated PowerShell from the working directory where Step 1 created the Sysmon subfolder. The default configuration is useful for validating installation, but it does not provide general network telemetry. A production rollout should use a version-controlled configuration reviewed by the detection team.
.\Sysmon\Sysmon64.exe -accepteula -iGet-Service Sysmon64❯ View Expected Console Output
Status Name DisplayName------ ---- -----------Running Sysmon64 Sysmon64Step 3: Confirm Events Are Being Written
Inspect the Sysmon Operational Channel
Telemetry CheckRead recent events from the dedicated Sysmon channel. Event ID 1 records process creation when enabled by the active configuration. No results may mean the service has not generated events yet, the channel is unavailable, or the configuration does not include the event.
Get-WinEvent -LogName 'Microsoft-Windows-Sysmon/Operational' -MaxEvents 20 | Select-Object TimeCreated, Id, ProviderName, Message | Format-List❯ View Expected Console Output
TimeCreated : 10/04/2026 09:15:00Id : 1ProviderName : Microsoft-Windows-SysmonMessage : Process creation event ...
Figure 1: Event Viewer shows Sysmon Operational process-creation events and the selected event’s details.
Step 4: Plan Configuration and Central Forwarding
Move from a Local Test to Managed Collection
OperationsSelect a maintained Sysmon configuration, pin the release and configuration revision, test event volume on a representative pilot group, and define how the Windows event channel will reach your SIEM or event collector. Add network connection or file events only when the approved configuration enables them. Document exclusions and change ownership.
# Review current configuration and service state before changing policy..\Sysmon\Sysmon64.exe -cGet-WinEvent -ListLog 'Microsoft-Windows-Sysmon/Operational' | Select-Object LogName, RecordCount, MaximumSizeInBytes
# Apply only a reviewed, approved configuration file..\Sysmon\Sysmon64.exe -c .\Sysmon\sysmon-approved.xml❯ View Expected Console Output
Configuration state and channel capacity are visible for the pilot review.For centrally managed environments, use Windows Event Forwarding or your approved endpoint telemetry agent, restrict access to collected data, and alert on service removal or unexpected configuration changes.