Should I block it?
No, this file is 100% safe to run.
Relationships
Parent process
Child process
sysmon.exe
MD5: | f56018b4f2e60794c89198a061398132 |
SHA1: | 57353f1b6f9bf328a4e45137cd6762a325be49c6 |
Overview
sysmon.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It adds run once key to the current user's profile so that the file will execute the next time the user logs into Windows (it will delete the entry after it runs once). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This particular version is usually found on Windows 7 Home Premium (6.1.7601.65536).
Details
File name: | sysmon.exe |
Typical file path: | C:\users\user\appdata\roaming\microsoft\windows\sysmon.exe |
Size: | 14 KB (14,336 bytes) |
Build date: | 10/10/2013 1:51 PM |
Digital DNA |
File packed: | No |
Code language: | Microsoft Visual C# / Basic .NET |
.NET CLR: | Yes |
.NET NGENed: | No |
More details
Behaviors
Startup files (user) run once
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce'
- 'System Monitor Control' → C:\users\user\appdata\Roaming\Microsoft\Windows\sysmon.exe
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00006084% | |
Kernel CPU: | 0.00001965% | |
User CPU: | 0.00004119% | |
Kernel CPU time: | 15,642,298,271 ms/min | |
CPU cycles: | 32,824,503/sec | |
Memory |
Private memory: | 14.63 MB | |
Private (maximum): | 11.59 MB | |
Private (minimum): | 4.31 MB | |
Non-paged memory: | 14.63 MB | |
Virtual memory: | 130.26 MB | |
Virtual memory (peak): | 231.75 MB | |
Working set: | 5.79 MB | |
Working set (peak): | 16.16 MB | |
Page faults: | 17,244,144/min | |
I/O |
I/O read transfer: | 15 Bytes/sec | |
I/O read operations: | 1/sec | |
I/O other transfer: | 53 Bytes/sec | |
I/O other operations: | 1/sec | |
Resource allocations |
Threads: | 6 | |
Handles: | 172 | |
GUI GDI count: | 6 | |
GUI GDI peak: | 6 | |
GUI USER count: | 1 | |
GUI USER peak: | 2 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Windows 7 Home Premium |
100.00% |
|
Distribution by PC manufacturer
PC Manufacturer | distribution |
MSI |
100.00% |
|