By Mark Russinovich and Thomas Garnier Published: February 13, 2024 Download Sysmon (4.6 MB) Download Sysmon for Linux (GitHub) Introduction System Monitor (Sysmon) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log. It provides detailed information about process creation
![Sysmon - Sysinternals](https://cdn-ak-scissors.b.st-hatena.com/image/square/d6e4cb632c7025e9f5e05fd314fbf6dcd6144e8d/height=288;version=1;width=512/https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmedia%2Fopen-graph-image.png)