HomeUpdatesMicrosoft will add Sysmon natively to Windows 11

Microsoft will add Sysmon natively to Windows 11

Microsoft is strengthening the tools available to cybersecurity professionals and threat hunters in the Windows. With the new Windows 11 Insider Preview Build 26300.7733 (KB5074178) on the Dev Channel, the company is making a move that many analysts consider historic: integrating System Monitor (Sysmon) directly into the operating system.

Microsoft Sysmon Windows 11

Until now, Sysmon was only available as a standalone tool through the popular Sysinternals suite. Now, Microsoft is bringing it natively to Windows, making it significantly easier to develop advanced mechanisms for logging and detecting malicious activity.

Sysmon: A key tool for SOC and Incident Response

For years, Sysmon has been considered an essential tool for Incident Response (IR) and Security Operations Centers (SOC), as it offers deep visibility into critical system functions.

See also: Microsoft: Scanner to detect backdoors in open-weight LLMs

Among other things, it records:

This information forms the foundation for detecting attacks that would otherwise go unnoticed in traditional Windows logs.

Native Sysmon Integration: What Changes in Practice

Integrating Sysmon into the operating system means that security teams no longer need to download separate binaries from the Sysinternals website, nor worry about additional installations on each endpoint.

The native version maintains the core functionality that professionals know, recording important events directly to the Windows Event Log. This ensures full compatibility with existing SIEM, EDR platforms , and other monitoring tools.

In other words, Microsoft is making advanced telemetry more accessible and more "standardized" across all Windows endpoints.

Microsoft will add Sysmon natively to Windows 11

Customization via XML and limiting “log noise”

One of the biggest advantages of Sysmon is the ability to use custom XML configuration files. Administrators can filter which events will be recorded, avoiding the huge amount of data that can create “noise” in the analyses.

See also: Microsoft Publisher Content Marketplace: A new AI licensing hub

This way, defenders can focus on truly suspicious actions, such as:

  • executing PowerShell scripts
  • unusual child processes
  • communication with unknown IPs
  • lateral movement attempts

“Secure by default”: Disabled by default

Microsoft follows a “secure by default”, meaning that the built-in Sysmon is disabled initially. Administrators must enable it to avoid inadvertently recording data or unnecessarily burdening systems.

Activation can be done in two ways:

Method 1: Through Settings (GUI)

Users go to:
Settings > System > Optional features > More Windows features > Sysmon

Method 2: Via PowerShell/DISM

For corporate environments and automated deployment, the command is used:

Dism /Online /Enable-Feature /FeatureName:Sysmon

Then the service installation is required:

sysmon -i

Attention for those using the old standalone version

Microsoft warns that those who already have the classic version of Sysmon from Sysinternals installed should first uninstall it and then enable the built-in feature to avoid performance issues.

See also: Microsoft disables NTLM protocol in Windows

Microsoft will add Sysmon natively to Windows 11

Additional stability improvements in the new build

In addition to security, this Insider build also brings significant stability. Among them, a serious bug that caused applications to freeze when interacting with files in OneDrive or Dropbox has been resolved.

There have also been improvements to File Explorer, such as better keyboard navigation and fixes to folder renaming issues.

A step towards “default” advanced defense in Windows

The integration of Sysmon is a significant step for Microsoft, making advanced event logging a new standard for Windows endpoints. In an era where cyberattacks are becoming increasingly sophisticated, organizations now have an inherent advantage against high-level threat actors.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS