Microsoft Ported Sysmon to Linux and Made it Open Source | Linux Today

Microsoft Ported Sysmon to Linux and Made it Open Source

Written By
L
LinuxStoney
Oct 18, 2021

Microsoft has ported the Sysmon activity monitoring service to the Linux platform. To monitor the work of Linux, the eBPF subsystem is used, which allows you to run handlers that work at the kernel level of the operating system. The SysinternalsEBPF library is being developed separately, which includes functions useful for creating BPF handlers for monitoring system events. The toolkit code is open under the MIT license, and the BPF programs are under the GPLv2 license. The packages.microsoft.com repository contains ready-made RPM and DEB packages suitable for popular Linux distributions. Learn more about this open-source move for Sysmon here.

L

LinuxStoney

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.