locked
Deploy Sysmon at scale RRS feed

  • Question

  • Hi,

    I would like to deploy Sysmon at scale and also want to have ability manage configuration files if required using central distribution point...

    Does anybody know the best way how to to achieve this?

    Also I would like to keep everything as simple as I can... 

    I know that I can use GPO or make scripts, but wanted to know what is preferred way of doing this.

    The installation should be done on Win7 and Win10 desktop PCs.

    Regards,

    Audrius

    Tuesday, January 24, 2017 6:29 AM

All replies

  • Hello Audrius,

    This is a forum for Microsoft Advanced Threat Analytics, and I can't find any relationship with Sysmon. To better support for your question, I would recommend to post your question to the forum below.

    https://forum.sysinternals.com/

    Also, I would recommend to walk through the product System Center Configuration Manager, which may provide the feature you required. 

    https://www.microsoft.com/en-us/cloud-platform/system-center-configuration-manager


    Best regards,
    Andy Liu

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.


    Wednesday, January 25, 2017 5:13 AM
  • Hi Andy,

    thanks for your reply. I posted it on different forum, but advised it to post here.

    From my point of view, Sysmon is used to help detecting threats and is some cases it should fit here (at least it was the best candidate from all available technet forums).

    But if I am wrong, sorry, I will re post it as advised.

    Regards,

    Audrius

    Wednesday, January 25, 2017 9:26 AM
  • Hi Audrius,

    I would recommend to post the question to the website I mentioned previously, and also you can find other Sysmon related questions from the sub-forum Miscellaneous Utilities there. 

    Thanks for your understanding.

    Best regards,

    Andy Liu


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, January 26, 2017 7:20 AM