Windows Sysmon Configuration Change (Event ID 16)

Alerts on Sysmon configuration changes via Sysmon Event ID 16 on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Service
sysmon
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-12
Updated
2026-07-30

What it detects

This rule flags Sysmon events indicating a configuration change (Sysmon Event ID 16) on Windows. Attackers may alter Sysmon settings to blind or reduce visibility, or to evade monitoring after gaining access. The detection relies on Sysmon’s own event logging for configuration update activities.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.