Unable to stop Sysmon 15.0

sreejesh chethil 40 Reputation points
2023-08-11T12:23:54.7966667+00:00

Hello,

After we migrate Sysmon to v15.0, everything works fine as expected, but it is unstoppable. During patching cycles or some other maintenance window, we need to stop Sysmon for a short duration. When we try to stop it through Services with administrative role, it is showing an " Error 5: Access Denied". Is that by design or bug or some other way to stop for a short duration? Thanks in advance.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
{count} votes

Accepted answer
  1. John Stephens 366 Reputation points Microsoft Employee
    2023-08-14T19:55:16+00:00

    This is by design. Starting with v15.0, the Sysmon service runs as a protected process and therefore cannot be stopped externally. However, Sysmon can still be uninstalled. Is it feasible to uninstall Sysmon, during maintenance, and reinstall it after?


0 additional answers

Sort by: Most helpful