System Monitor or Sysmon is a Windows system service and device driver that provides event data on process creation, network connections and file alterations. It is one of the most powerful tools available for security monitoring and gives detailed insight on what is happening on an endpoint.
Sysmon can be started from the command line, with a specific set of modules and processes to monitor but will in most cases be installed as a service … Read more.