Microsoft has announced significant enhancements to Windows 11 and Windows Server 2025, including the native integration of Sysmon, a powerful system monitoring tool previously available only as a standalone Sysinternals utility. With this integration, administrators will be able to deploy and manage Sysmon directly through Windows features and updates, simplifying large-scale monitoring and threat detection. Sysmon's advanced event filtering and custom configuration capabilities will remain intact, enabling organizations to monitor for suspicious activity, process tampering, and other security-relevant events without the need for separate installations.
In addition to Sysmon integration, Microsoft introduced two new recovery features for Windows 11: Cloud Rebuild and Point-in-Time Restore (PITR). These tools are designed to minimize downtime and streamline recovery from system failures or problematic updates. PITR allows users and IT administrators to quickly roll back systems to healthy snapshots, restoring not only the OS but also local files and applications. Cloud Rebuild enables remote, cloud-based reinstallation of Windows 11, leveraging Intune and Autopilot for zero-touch provisioning and rapid restoration of user data and settings. Both features are set to be integrated with Microsoft Intune, providing enterprise admins with robust, remote recovery and remediation capabilities.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced new Windows 11 recovery capabilities called Cloud Rebuild and Point-in-Time Restore, aimed at improving system recovery and restoration options.
Microsoft said it will integrate Sysmon directly into Windows 11 and Windows Server 2025, bringing the security monitoring tool into the operating system rather than keeping it as a separate Sysinternals utility.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.