Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sysmon-modular — A repository of sysmon configuration modules | Kitploit
Tools/GitHubGitHub/olafhartong/sysmon-modular
Defensive ToolsDigital ForensicsIntrusion DetectionIncident ResponseLog Analysis
GitHubolafhartong/sysmon-modular

sysmon-modular

A repository of sysmon configuration modules

View Repository
3.1k6532011 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

sysmon-modular | A Sysmon configuration repository for everybody to customise

license Maintenance GitHub last commit Build Sysmon configurations Twitter Discord Shield

Sysmon Modular is a configuration repository for Microsoft Sysinternals Sysmon. Small XML modules make it easier to select, review and maintain the telemetry that is useful to your organisation. The sysmon-modular Go tool builds configurations from those modules and helps validate, analyse and compare them.

Every configuration is a starting point. Review and tune it for your applications, endpoint roles, detection needs and logging budget before deploying it widely. Use a manageable set of profiles for workstations, servers and domain controllers, and measure their behaviour on representative machines.

This project would not have been possible without SwiftOnSecurity's original configuration, which inspired Sysmon Modular and remains part of its foundation.

Contents

  • Pre-generated configurations
  • Get the tooling
  • Generating a config
  • Validate, analyse and compare
  • Generate modules from KQL and MDE
  • Use
  • CI/CD and releases
  • Documentation
  • Contributing
  • Sysmon community
  • More information

Pre-generated configurations

Download the regular starting configurations from the latest GitHub Release. These consolidated XML files are generated from the source modules and distributed as release assets instead of being stored in the repository.

ProfileDownloadCollection goal
Balancedsysmonconfig.xmlThe regular starting configuration, without FileDelete archiving.
Balanced with FileDeletesysmonconfig-with-filedelete.xmlAdds FileDelete collection and file archiving. Account for the archive's disk requirements.
Excludes onlysysmonconfig-excludes-only.xmlA very verbose profile built from exclusion modules. Expect substantial event volume and tune before production use.

All three profiles are generated for Sysmon 15.21, 14.16, 13.34 and 12.03. Versioned filenames include the target, such as sysmonconfig-14.16.xml; the unversioned names above are aliases for 15.21. Select the version installed on your endpoints. For controlled rollouts, pin a specific release rather than automatically deploying latest.

Two profiles remain separate examples in the repository:

  • Research configuration: extremely verbose collection for short, controlled research sessions. It can consume substantial CPU, memory and logging capacity; load a lighter configuration when the investigation is complete.
  • MDE-augment configuration: selected collection intended to complement Microsoft Defender for Endpoint with less overlap. It does not enable every Sysmon event. See the MDE-augment generation guide to rebuild and review its exclusion list.

The release also includes prebuilt tools, an ATT&CK Navigator layer derived from the balanced 15.21 configuration, and a SHA256SUMS manifest.

Get the tooling

The Go CLI is the supported generator. The examples in this README run from the repository root and use a binary saved in tooling. Start with a local checkout if you want to generate configurations from the source modules:

git clone https://github.com/olafhartong/sysmon-modular.git
cd sysmon-modular

Prebuilt binaries

Download the binary for your operating system and architecture from GitHub Releases. Go is not required to use these binaries.

SystemRelease asset
Windows x64sysmon-modular-windows-amd64.exe
Windows ARM64sysmon-modular-windows-arm64.exe
Linux x64sysmon-modular-linux-amd64
Linux ARM64sysmon-modular-linux-arm64
macOS Intelsysmon-modular-darwin-amd64
macOS Apple siliconsysmon-modular-darwin-arm64

Save the download as tooling/sysmon-modular, or tooling/sysmon-modular.exe on Windows. On Linux and macOS, make it executable once:

chmod +x tooling/sysmon-modular

Build

Building from source requires Go 1.22 or newer and uses only the Go standard library.

From the repository root on Linux or macOS:

go -C tooling build -o "$PWD/tooling/sysmon-modular" ./cmd/sysmon-modular

From PowerShell on Windows:

go -C tooling build -o "$PWD\tooling\sysmon-modular.exe" ./cmd/sysmon-modular

You can also run commands directly with Go. For example:

go -C tooling run ./cmd/sysmon-modular --version

go -C tooling run runs the program from the tooling directory. Use absolute paths when adapting repository-root examples to that form, or follow the tooling-relative examples in the command reference.

Version and help

The tooling starts at build version 1.0:

./tooling/sysmon-modular --version
./tooling/sysmon-modular help
./tooling/sysmon-modular merge --help

version and --version print sysmon-modular 1.0. The build version also appears in top-level and command-specific help. It identifies the tooling; --sysmon-version selects the target Sysmon executable instead.

The default is defined in version.go. Local and release builds include it automatically. To override it for a particular build:

go -C tooling build -ldflags="-X main.buildVersion=1.1" \
  -o "$PWD/tooling/sysmon-modular" ./cmd/sysmon-modular

On Windows, use ./tooling/sysmon-modular.exe in the commands below. Multi-line PowerShell examples are available in the custom configuration guide.

Generating a config

Download Tool