Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Sysmon

Premium room

Learn how to utilize Sysmon to monitor and log your endpoints and environments.

easy

120 min

54,735

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

, a tool used to monitor and log events on Windows, is commonly used by enterprises as part of their monitoring and logging solutions. Part of the Windows Sysinternals package, is similar to Windows Event Logs with further detail and granular control.

Microsoft Security logo

This room uses a modified version of the Blue and Ice boxes, as well as logs from the Hololive network lab.

Before completing this room we recommend completing the Windows Event Log room. It is also recommended to complete the Blue and Ice rooms to get an understanding of vulnerabilities present however is not required to continue.

Answer the questions below
Complete the prerequisites listed above and jump into task 2.

Ready to learn Cyber Security?

The Sysmon room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.

Already have an account? Log in

We use cookies to ensure you get the best user experience. For more information see our cookie policy.