Sysmon service - security descriptors and recover options

Gary Portnoy 0 Reputation points
2024-09-19T19:51:35.4433333+00:00

To prevent user tampering and recover from process crashes, when installing sysmon I used to modify the security descriptors on the service to remove Admin's ability to stop it and set the recovery options to restart after 1st, 2nd and subsequent failures.
Now that sysmon has PPL protection, are either of those actions needed? It feels like security descriptors on the service are redundant, since the process can't be killed, even by Admin, but what about the Recovery Options? It seems like they are grayed out and can't be set after installing 15.14. Is that because of PPL protections?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,163 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.