<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Sysmon Tool &#8211; Winsides.com</title>
	<atom:link href="https://winsides.com/tag/sysmon-tool/feed/" rel="self" type="application/rss+xml" />
	<link>https://winsides.com</link>
	<description>Windows Insides</description>
	<lastBuildDate>Tue, 03 Mar 2026 06:42:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://winsides.com/wp-content/uploads/2024/05/cropped-android-chrome-512x512-1-150x150.png</url>
	<title>Sysmon Tool &#8211; Winsides.com</title>
	<link>https://winsides.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How to Enable Sysmon Tool on Windows 11?</title>
		<link>https://winsides.com/how-to-enable-sysmon-tool-on-windows-11/</link>
					<comments>https://winsides.com/how-to-enable-sysmon-tool-on-windows-11/#respond</comments>
		
		<dc:creator><![CDATA[Vigneshwaran Vijayakumar]]></dc:creator>
		<pubDate>Tue, 03 Mar 2026 06:42:18 +0000</pubDate>
				<category><![CDATA[Windows Security]]></category>
		<category><![CDATA[Sysmon Tool]]></category>
		<guid isPermaLink="false">https://winsides.com/?p=7158</guid>

					<description><![CDATA[Sysmon Tool on Windows 11: System Monitor, shortly known as Sysmon, is a Windows system monitoring utility that runs as a background service and records detailed information about system activity into the Windows Event Log, helping admins and security professionals track what is happening on a machine. Earlier, it was not built into Windows. However, [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p><strong>Sysmon Tool on Windows 11</strong>: System Monitor, shortly known as Sysmon, is a <strong>Windows system monitoring utility</strong> that runs as a background service and records detailed information about system activity into the Windows Event Log, helping admins and security professionals track what is happening on a machine. Earlier, it was not built into Windows. However, it can be downloaded and installed separately. Microsoft recently introduced Sysmon Tool as an optional Feature on Windows 11 that can be enabled via the <strong>Windows Features</strong> dialog.</p>



<h2 class="wp-block-heading">Different Methods to Enable Sysmon Tool on Windows 11 PCs &amp; Servers</h2>



<ol class="wp-block-list">
<li><strong>Enable System Monitoring Tool on Windows 11 using Windows Features &#8211; GUI Method</strong></li>



<li><strong>Turn on Sysmon on Windows 11 using CMD and PowerShell &#8211; CLI Methods</strong></li>
</ol>



<h2 class="wp-block-heading">Enable Sysmon Tool on Windows 11 using Windows Features &#8211; GUI Method</h2>



<p>On supported versions of Windows 11, you can follow the steps below to enable the System Monitoring Tool on your Windows 11. </p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>My OS and Build Information</strong>: Windows 11 Version: 25H2, OS Build: 26220.7872 Experience: Windows Feature Experience Pack 1000.26100.333.0. Kindly note that my device is set to get Insider Preview Builds. </p>
</blockquote>



<ul class="wp-block-list">
<li>There are <span style="box-sizing: border-box; margin: 0px; padding: 0px;">several ways to access&nbsp;<strong>Windows Optional Features on Windows 11</strong></span>. Here, we will use the Run Command and access it via <code>appwiz.cpl</code>.</li>
</ul>



<figure class="wp-block-image aligncenter size-full is-resized"><img fetchpriority="high" decoding="async" width="1116" height="429" src="https://winsides.com/wp-content/uploads/2026/02/appwiz.cpl_.webp" alt="appwiz.cpl" class="wp-image-7141" style="width:768px" title="How to Enable Sysmon Tool on Windows 11? 1" srcset="https://winsides.com/wp-content/uploads/2026/02/appwiz.cpl_.webp 1116w, https://winsides.com/wp-content/uploads/2026/02/appwiz.cpl_-300x115.webp 300w, https://winsides.com/wp-content/uploads/2026/02/appwiz.cpl_-1024x394.webp 1024w, https://winsides.com/wp-content/uploads/2026/02/appwiz.cpl_-768x295.webp 768w" sizes="(max-width: 1116px) 100vw, 1116px" /><figcaption class="wp-element-caption">appwiz.cpl</figcaption></figure>



<ul class="wp-block-list">
<li>From the left pane, click on <strong>Turn Windows Features on or off</strong>. </li>
</ul>



<figure class="wp-block-image aligncenter size-full is-resized"><img decoding="async" width="1275" height="872" src="https://winsides.com/wp-content/uploads/2026/02/Turn-Windows-Features-on-of-off.webp" alt="Turn Windows Features on of off" class="wp-image-7142" style="width:768px" title="Turn Windows Features on of off" srcset="https://winsides.com/wp-content/uploads/2026/02/Turn-Windows-Features-on-of-off.webp 1275w, https://winsides.com/wp-content/uploads/2026/02/Turn-Windows-Features-on-of-off-300x205.webp 300w, https://winsides.com/wp-content/uploads/2026/02/Turn-Windows-Features-on-of-off-1024x700.webp 1024w, https://winsides.com/wp-content/uploads/2026/02/Turn-Windows-Features-on-of-off-768x525.webp 768w, https://winsides.com/wp-content/uploads/2026/02/Turn-Windows-Features-on-of-off-220x150.webp 220w" sizes="(max-width: 1275px) 100vw, 1275px" /><figcaption class="wp-element-caption">Turn Windows Features on or off</figcaption></figure>



<ul class="wp-block-list">
<li>The <strong>Windows Features</strong> dialog will open now. From the list, locate <strong>Sysmon</strong>. Click on the checkbox next to it to enable it. Finally, click <strong>OK</strong>.</li>
</ul>



<figure class="wp-block-image aligncenter size-full is-resized"><img decoding="async" width="1050" height="654" src="https://winsides.com/wp-content/uploads/2026/03/Enable-Sysmon-Tool-on-Windows-11.webp" alt="Enable Sysmon Tool on Windows 11" class="wp-image-7160" style="width:768px" title="Enable Sysmon Tool on Windows 11" srcset="https://winsides.com/wp-content/uploads/2026/03/Enable-Sysmon-Tool-on-Windows-11.webp 1050w, https://winsides.com/wp-content/uploads/2026/03/Enable-Sysmon-Tool-on-Windows-11-300x187.webp 300w, https://winsides.com/wp-content/uploads/2026/03/Enable-Sysmon-Tool-on-Windows-11-1024x638.webp 1024w, https://winsides.com/wp-content/uploads/2026/03/Enable-Sysmon-Tool-on-Windows-11-768x478.webp 768w" sizes="(max-width: 1050px) 100vw, 1050px" /><figcaption class="wp-element-caption">Enable Sysmon Tool on Windows 11</figcaption></figure>



<ul class="wp-block-list">
<li>Windows will search for the required files and apply the necessary changes. </li>
</ul>



<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="1031" height="767" src="https://winsides.com/wp-content/uploads/2026/02/Applying-changes.webp" alt="Applying changes" class="wp-image-7147" style="width:768px" title="How to Enable Sysmon Tool on Windows 11? 2" srcset="https://winsides.com/wp-content/uploads/2026/02/Applying-changes.webp 1031w, https://winsides.com/wp-content/uploads/2026/02/Applying-changes-300x223.webp 300w, https://winsides.com/wp-content/uploads/2026/02/Applying-changes-1024x762.webp 1024w, https://winsides.com/wp-content/uploads/2026/02/Applying-changes-768x571.webp 768w" sizes="auto, (max-width: 1031px) 100vw, 1031px" /><figcaption class="wp-element-caption">Applying changes</figcaption></figure>



<ul class="wp-block-list">
<li>Finally, you must restart your PC to complete the installation of the requested changes. Kindly save your work, and click <strong>Restart now</strong>. </li>



<li>Sysmon Tool is now ready to use on your Windows 11 rig. </li>
</ul>



<h2 class="wp-block-heading">Turn on Sysmon Tool using Command Prompt &amp; Windows PowerShell &#8211; CLI Methods</h2>



<p>To enable System Monitoring Tool on Windows using Command Prompt, we will use the <strong>Deployment Image Servicing and Management</strong> Tool. Hence, we have to run Command Prompt and Windows PowerShell as Administrator. </p>



<h3 class="wp-block-heading">Command Prompt Command to install Sysmon Tool on Windows 11</h3>



<p><code><strong>dism /online /Enable-Feature /FeatureName:Sysmon /All</strong></code></p>



<h3 class="wp-block-heading">Windows PowerShell Command to Install Sysmon Tool on Windows 11</h3>



<p><code><strong>Enable-WindowsOptionalFeature -Online -FeatureName Sysmon -All</strong></code></p>



<h2 class="wp-block-heading">How to Use Sysmon Tool on Windows 11?</h2>



<p>Once the feature is enabled on your Windows 11 PC or Server, you can access the System Monitoring Tool using <strong>Windows PowerShell</strong>. The service logs events immediately, and the driver installs as a boot-start driver to capture activity from early in the boot that the service will write to the event log when it starts.</p>



<ul class="wp-block-list">
<li>We have to run <a href="https://winsides.com/how-to-run-windows-powershell-as-administrator-with-elevated-rights/" data-type="post" data-id="3691"><strong>Windows PowerShell as an Administrator</strong></a>. </li>



<li>In PowerShell, execute the following command. <code><strong>sysmon -i</strong></code></li>



<li>This command will start <strong>SysmonDRV</strong>, and you can perform various actions like <strong>Installation</strong>, <strong>Update Configuration</strong>, <strong>Install Event Manifest</strong>, <strong>Print Schema</strong>, and <strong>Uninstall</strong>. </li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong><em>Command</em></strong></td><td><em><strong>Usage</strong></em></td></tr><tr><td><code>sysmon -i</code></td><td>Installation</td></tr><tr><td><code>sysmon -c</code></td><td>Update Configuration</td></tr><tr><td><code>sysmon -m</code></td><td>Install Event Manifest</td></tr><tr><td><code>sysmon -s</code></td><td>Print Schema</td></tr><tr><td><code>sysmon -u</code></td><td>Uninstall Sysmon</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Take Away</h2>



<p><strong>Sysmon</strong> is a powerful system monitoring tool from <strong>Microsoft</strong> that logs detailed information about activity on a Windows system. Unlike standard Windows Logs, it provides detailed data such as Hash Values of Files, Parent and Child process relationships, Full command-line arguments used to launch programs, and more. <a href="https://www.microsoft.com/" target="_blank" rel="noreferrer noopener">Microsoft</a> recognizes the importance of detailed system telemetry in defending against modern threats, and it may encourage more organizations and users to adopt stronger security monitoring practices.</p>



<h2 class="wp-block-heading">Have Queries?</h2>



<p>The above article provides detailed information on how to enable Sysmon Tool on Windows 11. We hope you are satisfied with our article, and if you have queries, kindly let us know in the comments. For more interesting articles, stay tuned to <a href="https://winsides.com">Winsides.com</a>. <strong>Happy Computing! Peace out!</strong></p>
]]></content:encoded>
					
					<wfw:commentRss>https://winsides.com/how-to-enable-sysmon-tool-on-windows-11/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
