Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search
Enterprise BusinessLog 320x200 1
Enterprise BusinessLog 970x120 1
Sysmon will finally be integrated into Windows 11 and Windows Server 2025 in 2026

Sysmon will finally be integrated into Windows 11 and Windows Server 2025 in 2026

Redazione RHC : 22 November 2025 08:53

Microsoft has announced that it will integrate the popular Sysmon tool directly into Windows 11 and Windows Server 2025 in 2026. The announcement was made by Sysinternals creator Mark Russinovich.

Sysmon (System Monitor) is a free tool from Microsoft Sysinternals for monitoring and blocking suspicious activity in Windows. Events are logged in the Windows Event Log, making the tool indispensable for detecting threats and diagnosing problems.

By default, Sysmon tracks basic events like process creation and termination, but you can use custom configuration files to monitor process tampering, DNS queries, executable file creation, clipboard changes, automatic backups of deleted files, and more.

Currently, Sysmon must be installed individually on each device, making it difficult to manage in large IT environments.

Native support should solve this issue, as users will be able to install the tool via Windows 11 optional features and receive updates directly through Windows Update.

Microsoft promises to retain all standard features, including support for custom configurations and advanced event filtering.

Once installed, administrators can enable Sysmon via the command line ( sysmon -i for monitoring with a custom configuration sysmon -i ).

Microsoft officials also announced that they will release full Sysmon documentation in 2026, adding new enterprise management capabilities and AI-powered threat detection capabilities.

Immagine del sitoRedazione
The editorial team of Red Hot Cyber consists of a group of individuals and anonymous sources who actively collaborate to provide early information and news on cybersecurity and computing in general.

Lista degli articoli