This should be fixes with today's 13.01 release.
Sysmon 13.0 Config (System Error 1067)
Is Sysmon 13.0 backwards compatible with older configs ? Using SwiftOnSecurity's config with Sysmon 13.0 yields an error when trying to start the Sysmon64 service. No errors about the config are thrown when installing Sysmon 13.0, however upon trying to start the service an error occurs.
During the install Sysmon says the configuration file has been validated, but seems to cause issues when starting the service.
Steps to reproduce:
- Download Sysmon 13.0
- Download SwiftOnSecurity config, save as config.xml
- Sysmon64.exe -i config.xml
- net start Sysmon64
"The Sysmon64 service is starting.
The Sysmon64 service could not be started.
A system error has occurred.
System error 1067 has occurred.
The process terminated unexpectedly."
Tested on a fresh Windows 10 install.