sysmon.exe vs sysmon64.exe

Gary Portnoy 0 Reputation points
2024-09-20T12:33:02.8733333+00:00

I'd like to once and for all understand the difference between the 3 sysmon executables contained in sysmon.zip (sysmon.exe, sysmon64.exe and sysmon64a.exe).

At one point I believed that sysmon64 was the Itanium (ia64) version and that running the plain old sysmon.exe installer automatically chose either the x32 or the x64 build and correctly installed the appropriate image. This is confirmed by checking to see that sysmon is running in 64bit mode after install using sysmon.exe. But I see lots of people on this forum running sysmon64.exe directly to install, so now I am not so sure.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,169 questions
{count} votes

1 answer

Sort by: Most helpful
  1. JAMES GILLESPIE 5 Reputation points
    2024-09-23T02:30:18.6833333+00:00

    sysmon64a.exe is for the 64-bit ARM architecture, I think sysmon.exe has support for both x86 and x64, and of course sysmon64.exe is just for x64.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.