Source: BleepingComputer
Author: Lawrence Abrams
URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-is-bringing-native-sysmon-support-to-windows-11-server-2025/
ONE SENTENCE SUMMARY:
Microsoft will integrate Sysmon natively into Windows 11 and Windows Server 2025, simplifying monitoring, deployment, and management.
MAIN POINTS:
- Sysmon will be native in Windows 11 and Server 2025, eliminating standalone deployment.
- Integration announced by Sysinternals creator, Mark Russinovich.
- Sysmon logs events to the Windows Event Log for security applications.
- Advanced configuration enables monitoring of process tampering, DNS, file creation, and clipboard changes.
- Previously required individual installation, complicating management in large environments.
- Native integration allows installation via Windows 11 “Optional features” and updates through Windows Update.
- Command line activation with
sysmon -ior custom config files enhances functionality. - Example configuration logs executable creation in specific directories.
- Key events logged: process creation, network connections, process access, file creation, and tampering.
- Comprehensive documentation, enterprise features, and AI threat detection planned for next year.
TAKEAWAYS:
- Native Sysmon simplifies monitoring in Windows environments.
- Easier deployment and management through Windows Update.
- Supports custom configurations for detailed event filtering.
- Enhances threat detection and diagnostics in IT environments.
- Comprehensive documentation and AI capabilities forthcoming.