$ winget install --id Microsoft.Sysinternals.Sysmon --exact --version 15.20Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.
For Intune admins
Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.
Start free 30-day trialNo credit card required.
System Monitor (Sysmon) is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log.
Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.
3 known CVEs via NVD
SysInternals Sysmon for Windows Elevation of Privilege Vulnerability
Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
See a CVE that affects your fleet? Push the patched version to Intune in one click with Pckgr.
More from Sysinternals or browse sysinternals.