Problem Statement
Why do defenders deploy Sysmon on Windows endpoints?
Explanation
Sysmon is a Sysinternals service and driver that persists across reboots and writes rich security-relevant events to the Windows Event Log, such as process creation and network connections.
Code Solution
SolutionRead Only
sysmon.exe -i sysmonconfig.xml // then ship Microsoft-Windows-Sysmon/Operational
