
A repository of sysmon configuration modules
Sysmon Modular is a configuration repository for Microsoft Sysinternals Sysmon. Small XML modules make it easier to select, review and maintain the telemetry that is useful to your organisation. The sysmon-modular Go tool builds configurations from those modules and helps validate, analyse and compare them.
Every configuration is a starting point. Review and tune it for your applications, endpoint roles, detection needs and logging budget before deploying it widely. Use a manageable set of profiles for workstations, servers and domain controllers, and measure their behaviour on representative machines.
This project would not have been possible without SwiftOnSecurity's original configuration, which inspired Sysmon Modular and remains part of its foundation.
Download the regular starting configurations from the latest GitHub Release. These consolidated XML files are generated from the source modules and distributed as release assets instead of being stored in the repository.
| Profile | Download | Collection goal |
|---|---|---|
| Balanced | sysmonconfig.xml | The regular starting configuration, without FileDelete archiving. |
| Balanced with FileDelete | sysmonconfig-with-filedelete.xml | Adds FileDelete collection and file archiving. Account for the archive's disk requirements. |
| Excludes only | sysmonconfig-excludes-only.xml | A very verbose profile built from exclusion modules. Expect substantial event volume and tune before production use. |
All three profiles are generated for Sysmon 15.21, 14.16, 13.34 and 12.03. Versioned filenames include the target, such as sysmonconfig-14.16.xml; the unversioned names above are aliases for 15.21. Select the version installed on your endpoints. For controlled rollouts, pin a specific release rather than automatically deploying latest.
Two profiles remain separate examples in the repository:
The release also includes prebuilt tools, an ATT&CK Navigator layer derived from the balanced 15.21 configuration, and a SHA256SUMS manifest.
The Go CLI is the supported generator. The examples in this README run from the repository root and use a binary saved in tooling. Start with a local checkout if you want to generate configurations from the source modules:
git clone https://github.com/olafhartong/sysmon-modular.git
cd sysmon-modular
Download the binary for your operating system and architecture from GitHub Releases. Go is not required to use these binaries.
| System | Release asset |
|---|---|
| Windows x64 | sysmon-modular-windows-amd64.exe |
| Windows ARM64 | sysmon-modular-windows-arm64.exe |
| Linux x64 | sysmon-modular-linux-amd64 |
| Linux ARM64 | sysmon-modular-linux-arm64 |
| macOS Intel | sysmon-modular-darwin-amd64 |
| macOS Apple silicon | sysmon-modular-darwin-arm64 |
Save the download as tooling/sysmon-modular, or tooling/sysmon-modular.exe on Windows. On Linux and macOS, make it executable once:
chmod +x tooling/sysmon-modular
Building from source requires Go 1.22 or newer and uses only the Go standard library.
From the repository root on Linux or macOS:
go -C tooling build -o "$PWD/tooling/sysmon-modular" ./cmd/sysmon-modular
From PowerShell on Windows:
go -C tooling build -o "$PWD\tooling\sysmon-modular.exe" ./cmd/sysmon-modular
You can also run commands directly with Go. For example:
go -C tooling run ./cmd/sysmon-modular --version
go -C tooling run runs the program from the tooling directory. Use absolute paths when adapting repository-root examples to that form, or follow the tooling-relative examples in the command reference.
The tooling starts at build version 1.0:
./tooling/sysmon-modular --version
./tooling/sysmon-modular help
./tooling/sysmon-modular merge --help
version and --version print sysmon-modular 1.0. The build version also appears in top-level and command-specific help. It identifies the tooling; --sysmon-version selects the target Sysmon executable instead.
The default is defined in version.go. Local and release builds include it automatically. To override it for a particular build:
go -C tooling build -ldflags="-X main.buildVersion=1.1" \
-o "$PWD/tooling/sysmon-modular" ./cmd/sysmon-modular
On Windows, use ./tooling/sysmon-modular.exe in the commands below. Multi-line PowerShell examples are available in the custom configuration guide.