The System Monitor service ampamp driver Sysmon for short logs various events mostly in response to process activity that occurs on a system to the MicrosoftWindowsSysmon/Operational event log. Sysmon events are similar to the 4688

KB-ID 437
Category: Application Scheduler
Applies to: 4.1 and later

Sysmon is a free driverbased utility that supplements Windows39s builtin audit capabilities. Combining Sysmon with EventSentry39s monitoring capabilities enables users to detect a number of potential threats on their monitored servers and workstations. Scythehttps://www.scyt...

KB-ID 447
Category: Security
Applies to: 4.2.3 and later