> For the complete documentation index, see [llms.txt](https://docs.plura.io/ja/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.plura.io/ja/agents/edr/windows/sysmon.md).

# Sysmon

{% hint style="info" %}
Sysmon（System Monitor）は、Microsoftが提供する高度なシステム監視ツールであり、ETW（Event Tracing for Windows）に基づいてプロセスの生成、ネットワーク接続、イメージの読み込みなどの重要なセキュリティイベントを詳細に記録します。\
ETWと連携したSysmonのログは、ファイルレス攻撃や権限昇格などの脅威行為を精密に分析するための非常に有用なセキュリティデータとして活用されます。
{% endhint %}

{% hint style="info" %}
**エージェントのインストール時にAdministrator権限が必要です**。\
PLURAサポートオペレーティングシステム

[https://docs.plura.io/ja/faq/comm/support\_os](https://docs.plura.io/ja/faq/common/support_os)

Sysmon 対応オペレーティングシステム\
クライアント：Windows 10 以降\
サーバー　　：Windows Server 2016 以降
{% endhint %}

## インストール案内 <a href="#id-1" id="id-1"></a>

### 1. Sysmon ダウンロード <a href="#id-1-1" id="id-1-1"></a>

* 事前に[**Windowsエージェント**](https://docs.plura.io/ja/agents/edr)のインストールが必須です。
* 最新バージョンのダウンロードリンクをご利用ください。 [\[**Sysmon**\]](https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon)

### 2. Sysmonのインストール <a href="#id-1-2" id="id-1-2"></a>

* ダウンロードしたファイルのパスで、cmdコマンドウィンドウを使って実行します。

```bash
cd "C:\Program Files\PLURA\"
sysmon.exe -accepteula -i "C:\Program Files\PLURA\sysmon-plura.xml"
```

### 3. PLURA Agent UIで設定を確認 <a href="#id-1-3" id="id-1-3"></a>

<figure><img src="/files/jqGq9F2JTfMhqCljvl7S" alt=""><figcaption></figcaption></figure>

## 設置案内 <a href="#id-2" id="id-2"></a>

### &#x20;1. Sysmon インストール <a href="#id-2-1" id="id-2-1"></a>

{% embed url="<https://www.youtube.com/embed/L9S62RldenU?si=CQ071gVMqsNafq3Y>" %}
