logo

Microsoft to Add Sysmon Threat Detection Feature Natively to Windows 11

ID: 762e44f2-94de-5727-a8b2-8d5f698b7b9c

STIX ID: report--762e44f2-94de-5727-a8b2-8d5f698b7b9c

Feed Name: cybersecurityNews.com

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Abinaya

...
...

Microsoft announced that Sysmon has been integrated natively into Windows 11 Insider Preview Build 26300.7733 (KB5074178). The native Sysmon retains core logging capabilities (process creation, network connections, file time changes) and writes to the Windows Event Log, is disabled by default, can be enabled via Settings or DISM/PowerShell and requires uninstalling the legacy Sysmon to avoid conflicts; the update also includes unrelated stability and File Explorer fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.