Should I block it?
No, this file is 100% safe to run.
 
Relationships
Parent process
Child process
     
    
        sysmon.exe
| MD5: | f56018b4f2e60794c89198a061398132 | 
| SHA1: | 57353f1b6f9bf328a4e45137cd6762a325be49c6 | 
Overview
sysmon.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. It adds run once key to the current user's profile so that the file will execute the next time the user logs into Windows (it will delete the entry after it runs once). The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This particular version is usually found on Windows 7 Home Premium (6.1.7601.65536).
 Details
Details
| File name: | sysmon.exe | 
| Typical file path: | C:\users\user\appdata\roaming\microsoft\windows\sysmon.exe | 
| Size: | 14 KB (14,336 bytes) | 
| Build date: | 10/10/2013 1:51 PM | 
| Digital DNA | 
| File packed: | No | 
| Code language: | Microsoft Visual C# / Basic .NET | 
| .NET CLR: | Yes | 
| .NET NGENed: | No | 
More details
 Behaviors
Behaviors
Startup files (user) run once
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce'
- 'System Monitor Control' → C:\users\user\appdata\Roaming\Microsoft\Windows\sysmon.exe
 Resource utilization
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
| CPU | 
| Total CPU: | 0.00006084% |  | 
| Kernel CPU: | 0.00001965% |  | 
| User CPU: | 0.00004119% |  | 
| Kernel CPU time: | 15,642,298,271 ms/min |  | 
| CPU cycles: | 32,824,503/sec |  | 
| Memory | 
| Private memory: | 14.63 MB |  | 
| Private (maximum): | 11.59 MB |  | 
| Private (minimum): | 4.31 MB |  | 
| Non-paged memory: | 14.63 MB |  | 
| Virtual memory: | 130.26 MB |  | 
| Virtual memory (peak): | 231.75 MB |  | 
| Working set: | 5.79 MB |  | 
| Working set (peak): | 16.16 MB |  | 
| Page faults: | 17,244,144/min |  | 
| I/O | 
| I/O read transfer: | 15 Bytes/sec |  | 
| I/O read operations: | 1/sec |  | 
| I/O other transfer: | 53 Bytes/sec |  | 
| I/O other operations: | 1/sec |  | 
| Resource allocations | 
| Threads: | 6 |  | 
| Handles: | 172 |  | 
| GUI GDI count: | 6 |  | 
| GUI GDI peak: | 6 |  | 
| GUI USER count: | 1 |  | 
| GUI USER peak: | 2 |  | 
 
 Process properties
Process properties
 Distribution by Windows OS
Distribution by Windows OS
| OS version | distribution | 
| Windows 7 Home Premium | 100.00% |  | 
 Distribution by PC manufacturer
Distribution by PC manufacturer
| PC Manufacturer | distribution | 
| MSI | 100.00% |  |