RDPSoft

Remote Desktop and Terminal Server Software

We Monitor, Manage & Fix RDS, AVD, Citrix and Parallels RAS
  • Products / Services
    • Not Sure Where To Start?
    • The Complete Monitoring and Management Bundle For End User Computing
    • RDS / AVD Monitoring & Reporting
      • Remote Desktop Commander Suite
      • Sysmundo
    • RDS / AVD Management and RMM Tools
      • Remote Desktop Commander Lite (Free RDS/AVD Management Tool)
      • Remote Assistance RMM Tool + Delegation of Management for RDS/AVD Support Desk
      • Automatic Resolution of Locked Profiles and Stuck Sessions
    • RDS/AVD Synthetic Login Monitoring / Connection Time / Uptime Monitoring Tools
      • Remote Desktop Canary
    • RDS/AVD/Citrix Profile and Session Problem Remediation
      • Fix My Session
    • Digital Forensics and Incident Response Tools
      • Sysmundo
    • Consulting and Professional Services
      • RDS Performance Audits, Security Audits, and General RDS Consulting
      • Custom Report Design Services
      • Training and Other Professional Services
  • Download
    • RDC Lite: Free RDS/Citrix Session and Farm Manager
    • RDC Lite With Premium Management Features
    • RDC Suite: Installer and Release Notes
    • Remote Desktop Canary – Request a Demo/Trial
    • Sysmundo
    • Request Upgrade To New Version
  • Buy
    • The Complete RDS/AVD Monitoring and Management Bundle Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Remote Desktop Commander Suite Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
      • Buy Perpetual License(s)
    • Premium Management Features Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Remote Desktop Canary Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Fix My Session Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Sysmundo Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Buy Incident Based Support Packages
    • Pricing
  • Blog
  • Support
    • Contact Support / Submit Ticket
    • RDPSoft Knowledge Base
  • Contact
  • Partners

How To Deploy Sysmon The Easy Way

January 30, 2024 By Andy Milford Leave a Comment

Whether you’re a member of your company’s security team or incident response team, you no doubt understand the importance of getting Microsoft’s Sysmon utility installed on your Windows systems. It seems like every few months there is another guide or article published by CISA reemphasizing the importance of deploying Sysmon to help prevent ransomware, or at a minimum, making Sysmon logs available during an incident response post compromise.

Fortunately, we here at RDPSoft have created a nifty utility called Sysmundo for system administrators and security team members that makes deploying Sysmon, reconfiguring Sysmon, and uninstalling Sysmon across your Windows systems very easy to do. It does not require any scripting, and all actions are driven by a GUI. Best of all, these specific features do not require you to purchase a license from us – you can leverage our tool to do install, reconfigure, or uninstall Sysmon whenever you need it to. Here’s how it works.

Step 1 – Deploying Sysmon

First, download a copy of our Sysmundo utility and install it. When you run Sysmundo for the first time, it will attempt to automatically download the Sysmon and PSExec utilities from the Sysinternals Tools site at Microsoft.

Sysmundo automatically downloads the latest Sysmon utility from Microsoft
Sysmundo will automatically download the Sysmon and PSExec tools for you. It will also continue to check at start up to see if there is a newer version of Sysmon, and if so, prompt you to download it.

Once you click “OK” to install a copy of Sysmon locally, you will then want to define the group of Windows computers you want to deploy Sysmon to, remotely. You can build a manual list of computers, or you can link to OUs or containers in your Active Directory.

Select the computers you want to deploy Sysmon to.
Select the computers where you want to install Sysmon

While you’re building your computer groups, we recommend creating a staging computer group that holds a single server or workstation that you can do some pre-deployment testing on. Meaning, you can deploy Sysmon with a specific configuration file to that test system first, then observe to get an idea of logging volume and CPU use on that test system. Once you’ve tweaked your Sysmon configuration file the way you want based on your testing results, then you can deploy Sysmon to your remaining systems en masse.

With your computers defined, go to the Deployment & Collection menu, and select Deploy/Remove Sysmon on Systems In This Network to launch the Sysmon Deployment Wizard. Choose the Deploy/Redeploy Sysmon On Target Hosts option.

Use the Sysmon Deployment Wizard to push out Sysmon to multiple systems at once.

Then, obtain a Sysmon XML configuration file to define what activity Sysmon will log. Conveniently, Sysmundo already has downloadable links to the most popular Sysmon repos on GitHub, such as those maintained by SwiftOnSecurity, Florian Roth, and Olaf Hartong. You can download one of these repo config files, test it, tweak it, and redeploy your refined version as needed.

Download commonly used Sysmon config files from popular repos on Github.
Download a Sysmon config file from a Github repo, or select one you’ve already created/modified.
Easily download Sysmon config files some of the most popular repos for initial testing

Finally, select the computers you wish to deploy Sysmon to (with the associated configuration file), click Deploy, and Sysmundo’s wizard will do the rest, leveraging PSExec, another Sysinternals tool.

Step 2 – Reconfiguring Sysmon

Undoubtedly, the scope of activities you want to audit with Sysmon will change over time. New programs may generate events that are not relevant, and you’ll need to suppress them by tweaking your Sysmon XML config file. When that time comes, you can quickly push out your new config file to all of the systems in your computer groupings. Again, like I mentioned above in the section on deploying Sysmon, you’ll want to test a new configuration file on a staging system first, before deploying it to all of your computers.

Launch the Sysmon Deployment Wizard again, and this time select the Change Sysmon Config File on Target Hosts option. Select your new Sysmon config file and the servers you are reconfiguring, and then click the Deploy button. All selected Sysmon hosts will be reconfigured to use the new configuration file immediately.

Quickly reconfigure Sysmon operating filters on multiple computers at once.

Step 3 – Uninstalling Sysmon

Once you have Sysmon deployed on your Windows systems as part of your incident response strategy, chances are you won’t be in a rush to uninstall Sysmon any time soon. And of course, if you need to install a newly released version of Sysmon, you can choose the Deploy/Redeploy Sysmon on Target Hosts option of Sysmundo’s wizard instead.

However, should you need to remove Sysmon from one or more of your systems, launch the Sysmon Deployment Wizard, and this time choose the Remove Sysmon From Target Hosts option. Then, select the computer groups you want to remove Sysmon from, and click the Remove button.

You can also quickly uninstall Sysmon from multiple systems at once.

Next Steps

With Sysmon deployed successfully and easily to your Windows systems, the next step is to centrally collect and index that data, so that you can build reports, examine user and program behavior, perform threat hunting and searching for indicators of compromise, plus respond to any incidents. The licensed version of Sysmundo helps you do just that, without requiring you to pay for the ingestion or storage costs of a traditional SIEM solution. To learn more, watch this Setting Up Sysmundo video, and please visit the links below to download and/or start a subscription to our tool.

Sysmundo Product Page

Download Sysmundo

Start a Monthly Sysmundo Subscription

Filed Under: Sysmon Tagged With: analyzing sysmon events, how to configure sysmon, how to deploy sysmon, how to install sysmon, how to uninstall sysmon, sysmon, sysmon reports

About Andy Milford

Andy Milford is the CEO and Founder of RDPSoft, and is a Microsoft MVP in the Enterprise Mobility / Remote Desktop Services area. Prior to starting RDPSoft, Andy was the CEO and Founder of Dorian Software, a log management company acquired by Ipswitch in late 2009. He loves creating easy-to-use yet powerful software solutions for SMBs and emerging enterprise companies.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Email
  • Google+
  • LinkedIn
  • Twitter
  • YouTube

Not Sure Where To Start?

In just a few moments, you can find the right fit of solutions and even services for your needs.

> Get Going Now.

Help Documents

Remote Desktop Commander
Help and Users Guide
Release Notes (ver 6.x)

Sign Up for Remote Desktop Tips and RDPSoft Updates

Blog Topic Categories

  • Azure RemoteApp
  • Azure Virtual Desktop
  • citrix edgesight
  • Citrix Edgesight Replacement
  • Citrix Shadowing
  • Cloud RDP Monitoring
  • DEX
  • Performance
  • RDP Disconnects
  • RDP Latency
  • RDP Login Time
  • RDP Login Tracking
  • RDP Logon Failure Tracking
  • RDP Logs
  • RDP Loss Rate
  • RDP Security
  • RDP Transmission Rate
  • RDS Infrastructure
  • RDS License Metering
  • RDS Licensing
  • Remote Desktop Bandwidth
  • Remote Desktop CPU
  • Remote Desktop Management
  • Remote Desktop Memory
  • Remote Desktop Memory Usage
  • Remote Desktop Monitoring
  • Remote Desktop Performance
  • Remote Desktop Protocol
  • Remote Desktop Reporting
  • Remote Desktop Security
  • Remote Desktop Services
  • Remote Desktop Services Free Tools
  • Remote Desktop Services Hotfix
  • Sensitive Data
  • Server 2012 TSAdmin Replacement
  • Shadow User
  • Software Releases
  • SPLA Reporting
  • Synthetic RDP
  • Sysmon
  • Telecommuting/Teleworking
  • Terminal Server Logging
  • Terminal Server Monitoring
  • Uncategorized
  • User Activity Monitoring
  • User Productivity
  • User Profiles
  • Windows 2008 Terminal Server
  • Windows Virtual Desktop
  • WVD Login Time
  • XenApp Monitoring
  • XenApp Reporting

Recent Posts

  • Fix My Session v1 Now Available!
  • How To Perform User Activity Monitoring in Azure Virtual Desktop
  • Remote Desktop Commander v7 Now Available!
  • How To Deploy Sysmon The Easy Way
  • Remote Desktop Canary v4.0 Now Available!

From the RDPSoft Blog

  • Fix My Session v1 Now Available!
  • How To Perform User Activity Monitoring in Azure Virtual Desktop
  • Remote Desktop Commander v7 Now Available!
  • How To Deploy Sysmon The Easy Way
  • Remote Desktop Canary v4.0 Now Available!
  • Email
  • Google+
  • LinkedIn
  • Twitter
  • YouTube

We Do “Single Pane of Glass” Monitoring and Management for RDS

Top Level Deployment Dashboard

One of the biggest criticisms leveled against Microsoft's Remote Desktop Services as an end user computing (EUC) platform is its complete lack of integrated management and monitoring tools. … Learn more about our centralized RDS monitoring and management >

Reach Out

For fastest response, reach out via our sales and support contact forms.

Sales
US: 1-855-738-8457 x1
Outside the US: 1-702-749-4325 x1

Support
for Evaluators and Priority Support Customers
US: 1-855-738-8457 x2
Outside the US: 1-702-749-4325 x2

© Copyright 2013–2025 RDPSoft. All Rights Reserved. RDPSoft is the sole authorized publisher and distributor of the following software titles: Remote Desktop Commander, Premium Management Features, Remote Desktop Canary · Sitemap