Trends in Tech
2 weeks ago
Microsoft Merges Sysmon with 2025 Windows & Servers
Microsoft announced today that it will integrate Sysmon natively into Windows 11 and Windows Server 2025 next year, making it unnecessary to deploy the standalone Sysinternals tools.
Microsoft Merges Sysmon with 2025 Windows & Servers
Microsoft has made a significant move by integrating Sysmon directly into Windows 11 and Windows Server 2025, effective next year. This integration means that the standalone Sysinternals tools, which have been a go-to for security professionals, will no longer need to be installed separately on each device. Instead, Sysmon will be available as a native feature within Windows updates, streamlining deployment and management for IT administrators.
The announcement from Sysinternals creator Mark Russinovich highlights the enhanced capabilities of this native integration. Sysmon now allows users to configure custom event filters through configuration files, enabling detailed monitoring and logging of specific activities such as process tampering, DNS queries, and file creation. This level of customization was previously achieved by installing Sysmon separately, which can be cumbersome in large environments.
By embedding Sysmon into Windows updates, Microsoft is addressing a common pain point for IT teams-managing multiple tools across numerous devices. The built-in nature of Sysmon ensures that users and administrators can easily enable it via the Windows Update settings, receiving regular updates directly through Windows. This not only simplifies deployment but also enhances security by ensuring that all devices are running the latest version of a robust monitoring tool.
Once enabled, Sysmon retains its comprehensive feature set, including support for custom configuration files and advanced event filtering. Administrators can now leverage this powerful tool to proactively hunt for threats and diagnose issues more effectively, all within the familiar Windows ecosystem. This move by Microsoft underscores the company's commitment to making security tools more accessible and user-friendly.