Sysmon installs a service and a driver that allows for logging system activity to the Windows event log. It monitors process creation, network connections, and changes to the file creation time of a file, among other things. From a Windows logging perspective, this may be one of the most useful logs to generate that is not on by default. The following table lists events in the Microsoft-Windows-Sysmon/Operational log.
Number of occurrences in rules | Eventid | Event source or category |
|---|---|---|
11 | 1 | Microsoft-Windows-Sysmon/Operational |
1 | 2 | Microsoft-Windows-Sysmon/Operational |