HomeinetMicrosoft: Linux version of Windows Sysmon tool released

Microsoft: Linux version of Windows Sysmon tool released

Microsoft has released a Linux version of its very popular Sysmon system monitoring utility for Windows , allowing Linux administrators to monitor their devices for malicious activity.

Microsoft Linux

See also: Microsoft turns Windows Subsystem (Linux) into a Windows 11 app

For those unfamiliar with Sysmon (also known as System Monitor), it is a Sysinternals tool that monitors a system for malicious activity and then records any suspicious behavior in system logs.

Sysmon's flexibility comes from the ability to create custom configuration files, which administrators can use to monitor specific system events that may indicate malicious activity is occurring on the system.

Today, Mark Russinovich and co-founder of the Sysinternals utility suite announced that Microsoft had released the Linux version of Sysmon as an open source project on GitHub.

Unlike Sysmon for Windows, Linux users will need to compile the program themselves and ensure they have all the required components, with instructions provided on the project's GitHub page.

It is important to note that in order to compile Sysmon, you must first also install SysinternalsEBPF.

See also: Microsoft and Nvidia created the most powerful language model in the world

Once Sysmon is compiled, you can view a help file by typing sudo ./sysmon –h.

To use the program, you must first accept the end-user license agreement with the following command:

sudo ./sysmon -accepteula

You can then start Sysmon with or without a configuration file using one of the following commands:

Without configuration file:

sudo ./sysmon -i

With configuration file:

sudo ./sysmon -i CONFIG_FILE

To create your own Sysmon configuration file, you should use the command ./sysmon –s, to see the configuration of the current version, as well as what instructions are available.

Sysmon

To learn more about creating a Sysmon configuration file, you can consult the official instructions or use the SwiftOnSecurity as an example.

Once started, Sysmon will log events to the file /var/log/syslog. If you did not specify a configuration file to limit what it logs, you will find that the syslog file grows quickly as new processes start and stop.

See also: FontOnLake malware: Targets Linux systems via trojanized utilities

To make it easier to filter logs for specific events, you can use the sysmonLogView to display the events you want.

Sysmon is a powerful tool widely used in Windows environments as part of an organization's security toolbox.

By adding it to Linux, a whole new segment of system administrators can use it to provide free system monitoring for malicious activity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS