Microsoft is rolling out native Sysmon functionality to some Windows 11 devices in the Windows Insider program, integrating the Sysinternals System Monitor directly into the OS. Sysmon records security-relevant telemetry to the Windows Event Log (e.g., process creation/termination and, when configured, richer behaviors such as file creation, process tampering, clipboard changes, and deleted-file backup) to support threat detection and hunting; the built-in capability is disabled by default and must be explicitly enabled, with guidance to remove any separately installed Sysmon before turning on the native feature.
In parallel Windows 11 Insider builds, Microsoft is also changing Smart App Control (SAC) behavior so users can turn SAC off and later re-enable it without a full OS reinstall, reversing the prior “clean install only” design that permanently blocked reactivation after disablement. The change follows user-impacting false positives (e.g., SAC flagging ASUS Armoury Crate on ASUS ROG Ally), and Microsoft’s updated approach aims to reduce operational friction while still encouraging users to keep SAC enabled unless conflicts require disabling it.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft started rolling out built-in Sysmon support to Windows 11 Insider devices in the Beta and Dev channels through preview builds 26220.7752/KB5074177 and 26300.7733/KB5074178. The native feature writes security-relevant telemetry to the Windows Event Log, supports custom configuration files, and is disabled by default.
Microsoft updated Windows 11 Insider builds so Smart App Control can be turned off and later re-enabled without wiping and reinstalling the OS. The change applies starting with Windows 11 versions 24H2 and 25H2.
A Smart App Control false positive flagged the ASUS Armoury Crate utility on ASUS ROG Ally devices. Affected users had to choose between disabling SAC and losing its protection or waiting for a fix while device functionality was impaired.
Under Windows 11's original Smart App Control design, users could only enable the feature on a clean OS installation. If they turned it off, Windows treated the system as no longer clean, making SAC unavailable again unless Windows was reinstalled.
Microsoft said in November that it planned to bring Sysmon functionality directly into Windows 11 and Windows Server and would later publish detailed documentation. This marked the first disclosed step toward making the Sysinternals monitoring tool a built-in feature.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.