Sysmon Configuration and Tuning
Turn Windows into a sensor you can trust.
Native Windows logging notes that a process ran. It rarely tells you what the process was, what launched it, or what it reached out to, which is the detail detection depends on. Sysmon fills that gap, but only if you configure it well: a default install floods a log no one reads, and an untuned one buries the signal you deployed it to catch. This course teaches the whole capability end to end. You learn what Sysmon records, build and tune a config that captures attacker behavior without the noise, deploy it across a fleet, feed its events to a SIEM, map them to detections tied to ATT&CK, prove those detections fire, and operate the sensor so your coverage stays real.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Course Orientation
What Sysmon Configuration and Tuning teaches: turn Windows endpoints into a detection sensor by building a tuned Sysmon config, deploying it across a fleet, feeding it to a SIEM, mapping its events to Sigma and ATT&CK, validating coverage, and operating it day to day. The discipline, the toolchain, the config you build, and how the course is structured. Start here.
Phase 1: The Telemetry
What Sysmon records, event by event, before you decide what to log. The gap in native Windows logging, the driver-service-log architecture and the ProcessGuid that ties events together, and every event class an investigator relies on: process creation, credential access and injection, network and DNS, file and registry, image and driver loads, pipes and WMI.
Show 10 lessonsHide lessons
- 1.11.1 What Windows Misses, and What Sysmon Captures
- 1.21.2 The Architecture: Driver, Service, and Log
- 1.31.3 Process Events: Creation and Termination
- 1.41.4 Credential and Injection Events
- 1.51.5 Network and DNS Events
- 1.61.6 File and Registry Events
- 1.71.7 Image Loads, Drivers, Pipes, and WMI
- 1.81.8 The Remaining Events, and the Decision
- 1.9Module Summary
- 1.10Check My Knowledge
Phase 2: Configuration and Tuning
How a Sysmon config actually controls what gets logged. The file structure and the compiled registry copy, the include and exclude filtering model and its two idioms, the condition operators and their exact matching, rule groups and compound conditions, the precedence rule that decides every conflict, the field reference, and building a working config from scratch.
Show 9 lessonsHide lessons
Where a config meets a real environment. The community baselines and how to read one as a peer, the economics of noise, a repeatable measure-first tuning method, the over-exclusion trap that silently deletes detections, taming the loudest events, and tuning a config to each host role. The module that earns the course its name.
Show 10 lessonsHide lessons
- 3.13.1 The Community Baselines
- 3.23.2 Two Baselines Compared
- 3.33.3 Reading a Baseline in Depth
- 3.43.4 The Economics of Noise
- 3.53.5 A Tuning Methodology
- 3.63.6 Safe Exclusions and the Over-Exclusion Trap
- 3.73.7 Taming the Loudest Events
- 3.83.8 Environment-Specific Tuning
- 3.9Module Summary
- 3.10Check My Knowledge
Phase 3: Deploy, Detect, and Operate
Getting a tuned config off your bench and into a working detection capability. At-scale deployment, the native Windows Sysmon feature, feeding a SIEM, mapping events to Sigma and ATT&CK, validating coverage with atomic tests, operating the sensor's health, and a capstone that runs the whole arc end to end. The module that turns a good config into a capability you can prove.
Phase 0: Course Resources
The event IDs, the config schema, the operators that behave unexpectedly, and the exclusions that quietly remove your coverage.
Ordered procedures for the work: first deployment, tuning a noisy estate, adding coverage, and updating a config safely.
Show 4 lessonsHide lessons
Four cases reasoned end to end, including the ones where the config was valid and collecting the wrong thing.
One Windows machine, a config you write yourself, and the checks that make the practice real.
Every Sysmon command, event type, condition operator, config idiom, and operational pattern from the course in one place, organized by stage: install and reconfigure, the event catalog, filtering, measurement, deployment, collection, detection, validation, and health. The working kit you carry out of the course.
Show 1 lessonHide lessons
Microsoft and Sysinternals documentation, the community Sysmon baselines, the Sigma detection toolchain, Atomic Red Team, and MITRE ATT&CK: the external sources used throughout the Sysmon Configuration and Tuning course, with stable top-level locations.
Show 1 lessonHide lessons
Course Completion
Sysmon Configuration and Tuning end-of-course exam: a config review where the volume figures are accurate and all three submitted edits are wrong, testing whether you can read what an exclusion actually removes and find the change that silently inverts collection.
Show 1 lessonHide lessons
Course overview
Sysmon Configuration and Tuning teaches you to run Sysmon as a real detection capability, not a checkbox. You build a tuned config and take it all the way to a live, validated, monitored deployment, and you keep the config you build. Across the course you learn how to:
By the end you can stand up endpoint visibility that catches attacker behavior, prove it works, and keep it working.
How this course works
Sysmon is a configuration file and a decision about what you are willing to store. This course runs the same four-step loop for every event type it covers, because a config written without it produces either a blind spot nobody knows about or a volume bill nobody predicted.
1. Know what the event actually carries. Each Sysmon event ID records a different set of fields, and the ones you can filter on are not always the ones you want to alert on. Read the schema before writing a rule against it.
2. Write the include and the exclude together. Every exclusion is a new blind spot, and a config that only includes is a config that fills a disk. The two halves are one decision.
3. Baseline before you tune. Deploy in a permissive state, measure what normal looks like in your estate, then cut. Tuning against an assumed baseline tunes against somebody else's environment.
4. Prove the event still fires. After every exclusion, re-run the behavior it was meant to catch. A config that stopped generating noise and stopped generating evidence look identical on a dashboard.
The output is a config you can defend line by line, and a written record of what each exclusion gave up.
What this course assumes
No minimum experience and no prerequisite course. Every concept is explained where it is first used, including what an event ID is and why Sysmon exists alongside the Windows Security log rather than replacing it.
What makes it go faster: a Windows machine you can install on, even a virtual one, and enough comfort reading XML to recognize a nested element. Neither is required, and the course walks through the install from nothing.
What this course does not cover: writing detection rules in a SIEM, which is a separate discipline, and endpoint forensics. Sysmon is the telemetry layer, and this course is about producing telemetry worth querying rather than about querying it.
Who this course is for
This course is for anyone who wants to learn Sysmon properly, from a SOC analyst or detection engineer to a system administrator or architect who wants real endpoint visibility. There is no minimum experience and no gatekeeping. Every concept is explained at first use, so you can start here whether Sysmon is new to you or you have run it for years and want to tune it well. It is for you if you want to:
What you'll learn
By the end of Sysmon Configuration and Tuning you will be able to:
Key course takeaways
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Things you need to know
What are the prerequisites for this course?
None that gate you. Comfort reading a command line and a config file helps, but every concept is explained at first use, and an experienced reader can skip past what they already know. The course is for anyone who wants to learn Sysmon, from newcomer to experienced cybersecurity professional.
Do I need a lab to follow along?
A Windows environment to practice on gets the most from the course, and a SIEM helps for the collection and detection stages, though the concepts stand without one. The validation stage uses a dedicated test host that mirrors production, never a live machine.
Is this vendor-specific?
Sysmon is a Windows sensor, but the detection work is vendor-neutral. You write detections in Sigma and convert them to whichever SIEM you run, so the skill travels regardless of platform.
How does this course fit with the rest of the catalog?
Sysmon is the telemetry source that makes endpoint detection work, so this course is a foundation for the detection, hunting, and investigation courses. Get the sensor right here, and the detections you build elsewhere have the events they need to fire.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.