Sysmon Configuration and Tuning

Turn Windows into a sensor you can trust.

Native Windows logging notes that a process ran. It rarely tells you what the process was, what launched it, or what it reached out to, which is the detail detection depends on. Sysmon fills that gap, but only if you configure it well: a default install floods a log no one reads, and an untuned one buries the signal you deployed it to catch. This course teaches the whole capability end to end. You learn what Sysmon records, build and tune a config that captures attacker behavior without the noise, deploy it across a fleet, feed its events to a SIEM, map them to detections tied to ATT&CK, prove those detections fire, and operate the sensor so your coverage stays real.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 8 CPE Credits

What you'll be able to do

✓Choose what to log across every Sysmon event type, from process creation and credential access to network, DNS, file, and registry, based on what each one is worth
✓Write a config from a community baseline with precise include and exclude logic, the condition operators, rule groups, and the precedence rule that resolves every conflict
✓Tune a config to a real environment with a measure-first method that cuts noise without silently deleting the detections you depend on
✓Deploy at scale with versioning, staged rollout, and rollback, including the native Windows Sysmon feature, and forward events to a SIEM
✓Map Sysmon events to Sigma detections and ATT&CK, convert them with the Sysmon pipeline, and prove each one fires with atomic technique tests
✓Operate the sensor day to day and detect the silence of a host that has gone dark, the one health signal a stopped sensor cannot send for itself
SEC206 | Premium tier | 4 modules across 3 phases | 6–8 hours at your own pace | 8 CPE credits | All levels

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Course Orientation

Module 0Course OrientationCourse Preview

What Sysmon Configuration and Tuning teaches: turn Windows endpoints into a detection sensor by building a tuned Sysmon config, deploying it across a fleet, feeding it to a SIEM, mapping its events to Sigma and ATT&CK, validating coverage, and operating it day to day. The discipline, the toolchain, the config you build, and how the course is structured. Start here.

Phase 1: The Telemetry

Module 1The Telemetry

What Sysmon records, event by event, before you decide what to log. The gap in native Windows logging, the driver-service-log architecture and the ProcessGuid that ties events together, and every event class an investigator relies on: process creation, credential access and injection, network and DNS, file and registry, image and driver loads, pipes and WMI.

Show 10 lessonsHide lessons
  1. 1.11.1 What Windows Misses, and What Sysmon Captures
  2. 1.21.2 The Architecture: Driver, Service, and Log
  3. 1.31.3 Process Events: Creation and Termination
  4. 1.41.4 Credential and Injection Events
  5. 1.51.5 Network and DNS Events
  6. 1.61.6 File and Registry Events
  7. 1.71.7 Image Loads, Drivers, Pipes, and WMI
  8. 1.81.8 The Remaining Events, and the Decision
  9. 1.9Module Summary
  10. 1.10Check My Knowledge

Phase 2: Configuration and Tuning

Module 2Configuration

How a Sysmon config actually controls what gets logged. The file structure and the compiled registry copy, the include and exclude filtering model and its two idioms, the condition operators and their exact matching, rule groups and compound conditions, the precedence rule that decides every conflict, the field reference, and building a working config from scratch.

Show 9 lessonsHide lessons
  1. 2.12.1 The Configuration File: Structure and Hashing
  2. 2.22.2 Include and Exclude
  3. 2.32.3 Condition Operators
  4. 2.42.4 Rule Groups and Combining Conditions
  5. 2.52.5 Precedence: How Conflicts Resolve
  6. 2.62.6 The Field Reference
  7. 2.72.7 Building a Config from Scratch
  8. 2.8Module Summary
  9. 2.9Check My Knowledge
Module 3Baselines and Tuning

Where a config meets a real environment. The community baselines and how to read one as a peer, the economics of noise, a repeatable measure-first tuning method, the over-exclusion trap that silently deletes detections, taming the loudest events, and tuning a config to each host role. The module that earns the course its name.

Show 10 lessonsHide lessons
  1. 3.13.1 The Community Baselines
  2. 3.23.2 Two Baselines Compared
  3. 3.33.3 Reading a Baseline in Depth
  4. 3.43.4 The Economics of Noise
  5. 3.53.5 A Tuning Methodology
  6. 3.63.6 Safe Exclusions and the Over-Exclusion Trap
  7. 3.73.7 Taming the Loudest Events
  8. 3.83.8 Environment-Specific Tuning
  9. 3.9Module Summary
  10. 3.10Check My Knowledge

Phase 3: Deploy, Detect, and Operate

Module 4Deploy, Detect, and Operate

Getting a tuned config off your bench and into a working detection capability. At-scale deployment, the native Windows Sysmon feature, feeding a SIEM, mapping events to Sigma and ATT&CK, validating coverage with atomic tests, operating the sensor's health, and a capstone that runs the whole arc end to end. The module that turns a good config into a capability you can prove.

Show 9 lessonsHide lessons
  1. 4.14.1 Deploying at Scale
  2. 4.24.2 The Native Windows Sysmon Feature
  3. 4.34.3 Getting Events to the SIEM
  4. 4.44.4 Mapping Events to Detections
  5. 4.54.5 Validating Coverage
  6. 4.64.6 Operating Sysmon
  7. 4.74.7 Capstone: Build, Deploy, Validate
  8. 4.8Module Summary
  9. 4.9Check My Knowledge

Phase 0: Course Resources

ResourcesCheatsheets

The event IDs, the config schema, the operators that behave unexpectedly, and the exclusions that quietly remove your coverage.

Show 4 lessonsHide lessons
  1. 1The Events, and What Each One Costs
  2. 2The Config, and How It Actually Evaluates
  3. 3Tuning Without Losing Coverage
  4. 4Deploying and Proving It Works
ResourcesCookbooks

Ordered procedures for the work: first deployment, tuning a noisy estate, adding coverage, and updating a config safely.

Show 4 lessonsHide lessons
  1. 1Deploying Sysmon for the First Time
  2. 2Tuning a Noisy Estate
  3. 3Adding Coverage for a Technique
  4. 4Updating a Config Safely
ResourcesWalkthroughs

Four cases reasoned end to end, including the ones where the config was valid and collecting the wrong thing.

Show 4 lessonsHide lessons
  1. 1The Rule That Was Already Excluded
  2. 2The Estate Running Four Configs
  3. 3The Config Nobody Should Have Cut
  4. 4The Gap That Was Not Sysmon's
ResourcesPlayground

One Windows machine, a config you write yourself, and the checks that make the practice real.

ResourcesOperational Reference

Every Sysmon command, event type, condition operator, config idiom, and operational pattern from the course in one place, organized by stage: install and reconfigure, the event catalog, filtering, measurement, deployment, collection, detection, validation, and health. The working kit you carry out of the course.

Show 1 lessonHide lessons
  1. 1SM99.1 Operational Reference
ResourcesReferences & Further Reading

Microsoft and Sysinternals documentation, the community Sysmon baselines, the Sigma detection toolchain, Atomic Red Team, and MITRE ATT&CK: the external sources used throughout the Sysmon Configuration and Tuning course, with stable top-level locations.

Show 1 lessonHide lessons
  1. 1SM100.1 References & Further Reading

Course Completion

CompletionCourse Exam

Sysmon Configuration and Tuning end-of-course exam: a config review where the volume figures are accurate and all three submitted edits are wrong, testing whether you can read what an exclusion actually removes and find the change that silently inverts collection.

Show 1 lessonHide lessons
  1. 1Course Completion. Sysmon Configuration and Tuning

Course overview

Sysmon Configuration and Tuning teaches you to run Sysmon as a real detection capability, not a checkbox. You build a tuned config and take it all the way to a live, validated, monitored deployment, and you keep the config you build. Across the course you learn how to:

✓ Read what every Sysmon event records and decide which attacker behaviors earn a place in your log
✓ Write a config from a community baseline, with precise include and exclude logic, and tune it to your environment
✓ Deploy at scale with versioning, staged rollout, and rollback, including the native Windows Sysmon feature
✓ Feed events to a SIEM, map them to Sigma detections tied to ATT&CK, and validate coverage with atomic tests
✓ Operate the sensor and detect the silence of a host that has gone dark, the one health signal an attacker cannot fake

By the end you can stand up endpoint visibility that catches attacker behavior, prove it works, and keep it working.

How this course works

Sysmon is a configuration file and a decision about what you are willing to store. This course runs the same four-step loop for every event type it covers, because a config written without it produces either a blind spot nobody knows about or a volume bill nobody predicted.

1. Know what the event actually carries. Each Sysmon event ID records a different set of fields, and the ones you can filter on are not always the ones you want to alert on. Read the schema before writing a rule against it.

2. Write the include and the exclude together. Every exclusion is a new blind spot, and a config that only includes is a config that fills a disk. The two halves are one decision.

3. Baseline before you tune. Deploy in a permissive state, measure what normal looks like in your estate, then cut. Tuning against an assumed baseline tunes against somebody else's environment.

4. Prove the event still fires. After every exclusion, re-run the behavior it was meant to catch. A config that stopped generating noise and stopped generating evidence look identical on a dashboard.

The output is a config you can defend line by line, and a written record of what each exclusion gave up.

What this course assumes

No minimum experience and no prerequisite course. Every concept is explained where it is first used, including what an event ID is and why Sysmon exists alongside the Windows Security log rather than replacing it.

What makes it go faster: a Windows machine you can install on, even a virtual one, and enough comfort reading XML to recognize a nested element. Neither is required, and the course walks through the install from nothing.

What this course does not cover: writing detection rules in a SIEM, which is a separate discipline, and endpoint forensics. Sysmon is the telemetry layer, and this course is about producing telemetry worth querying rather than about querying it.

Who this course is for

This course is for anyone who wants to learn Sysmon properly, from a SOC analyst or detection engineer to a system administrator or architect who wants real endpoint visibility. There is no minimum experience and no gatekeeping. Every concept is explained at first use, so you can start here whether Sysmon is new to you or you have run it for years and want to tune it well. It is for you if you want to:

✓ Deploy Sysmon for the first time and get it right rather than shipping a default install
✓ Fix an untuned config that floods your log and buries the signal
✓ Turn events you already collect into detections you can prove actually fire
✓ Understand why your detection coverage depends on what your config chose to log

What you'll learn

By the end of Sysmon Configuration and Tuning you will be able to:

✓ Explain what each Sysmon event captures and what native Windows logging leaves out
✓ Write a config using include and exclude logic, the condition operators, rule groups, and precedence
✓ Read a community baseline as a peer and tune it with a measured, repeatable method
✓ Deploy at scale, use the native Windows Sysmon feature, and forward events to a SIEM
✓ Convert Sigma rules with the Sysmon pipeline and map your detections to ATT&CK for a coverage view
✓ Validate a detection with an atomic test and localize a failure to config, collection, or rule
✓ Monitor sensor health and detect the silence of a host that stops reporting

Key course takeaways

✓ A tuned Sysmon config you build and keep, ready to deploy in your own environment
✓ The judgment to decide what to log, because coverage is the events you log and the detections you run together
✓ The discipline to prove a detection fires rather than assuming it does
✓ The operating habit that keeps coverage real: watch sensor health and treat a host going dark as an alert

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

✓ Walkthroughs take a config problem to its cause: the rule that was already excluded, the estate running four configs, the config nobody should have cut, and the gap that was not Sysmon's.
✓ A cookbook for the four things you do to a config: deploying for the first time, tuning a noisy estate, adding coverage for a technique, and updating safely.
✓ A command cheatsheet on what each event costs, how the config actually evaluates, and proving a deployment works.
✓ An operational reference with the schema, the filter behavior and the deployment switches in one place.
✓ A playground that is the simplest in the catalog and one of the most useful: one Windows machine you can install Sysmon on. No corpus, no tenant, no subscription.
✓ A references module for the schema documentation and the community configurations worth reading.

Things you need to know

What are the prerequisites for this course?

None that gate you. Comfort reading a command line and a config file helps, but every concept is explained at first use, and an experienced reader can skip past what they already know. The course is for anyone who wants to learn Sysmon, from newcomer to experienced cybersecurity professional.

Do I need a lab to follow along?

A Windows environment to practice on gets the most from the course, and a SIEM helps for the collection and detection stages, though the concepts stand without one. The validation stage uses a dedicated test host that mirrors production, never a live machine.

Is this vendor-specific?

Sysmon is a Windows sensor, but the detection work is vendor-neutral. You write detections in Sigma and convert them to whichever SIEM you run, so the skill travels regardless of platform.

How does this course fit with the rest of the catalog?

Sysmon is the telemetry source that makes endpoint detection work, so this course is a foundation for the detection, hunting, and investigation courses. Get the sensor right here, and the detections you build elsewhere have the events they need to fire.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.