%3CLINGO-SUB%20id%3D%22lingo-sub-1649402%22%20slang%3D%22en-US%22%3ESysmon%20v12.0%2C%20Process%20Monitor%20v3.60%2C%20Procdump%20v10.0%20and%20ARM64%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1649402%22%20slang%3D%22en-US%22%3E%3CDIV%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsysinternals%2Fdownloads%2Fsysmon%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%3ESysmon%20v12.0%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%3E%3CSPAN%3EIn%20addition%20to%20several%20bug%20fixes%2C%20this%20major%20update%20to%20Sysmon%20adds%20support%20for%20capturing%20clipboard%20operations%20to%20help%20incident%20responders%20retrieve%20attacker%20RDP%20file%20and%20command%20drops%2C%20including%20originating%20remote%20machine%20IP%20addresses.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsysinternals%2Fdownloads%2Fprocmon%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%3EProcess%20Monitor%20v3.60%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%3E%3CSPAN%3EThis%20update%20to%20Process%20Monitor%2C%20a%20utility%20that%20logs%20process%20file%2C%20network%20and%20registry%20activity%2C%20adds%20support%20for%20multiple%20filter%20item%20selection%2C%20as%20well%20as%20decoding%20for%20new%20file%20system%20control%20operations%20and%20error%20status%20codes.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsysinternals%2Fdownloads%2Fprocdump%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%3EProcdump%20v10.0%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%3E%3CSPAN%3EThis%20release%20of%20Procdump%2C%20a%20flexible%20tool%20for%20manual%20and%20trigger-based%20process%20dump%20generation%2C%20adds%20support%20for%20dump%20cancellation%20and%20CoreCLR%20processes.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdownload.sysinternals.com%2Ffiles%2FSysinternalsSuite-ARM64.zip%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CSPAN%3EARM64%20ports%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%3E%3CSPAN%3EIn%20addition%2C%20several%20tools%20have%20been%20newly%20ported%20to%20and%20are%20now%20available%20for%20ARM64.%20These%20include%3A%20AdInsight%20v1.2%2C%20AutoLogon%20v3.1%2C%20Autoruns%20v13.98%2C%20ClockRes%20v2.1%2C%20DebugView%20v4.9%2C%20DiskExt%20v1.2%2C%20FindLinks%20v1.1%2C%20Handle%20v4.22%2C%20Hex2Dec%20v1.1%2C%20Junction%20v1.07%2C%20PendMoves%20v1.02%2C%20PipeList%20v1.02%2C%20Procdump%20v10.0%2C%20Process%20Explorer%20v16.32%2C%20RegDelNull%20v1.11%2C%20RU%20v1.2%2C%20Sigcheck%20v2.8%2C%20Streams%20v1.6%2C%20Sync%20v2.2%2C%20VMMap%20v3.26%2C%20WhoIs%20v1.21%20and%20ZoomIt%20v4.52.%20Download%20all%20ARM64%20tools%20in%20a%20single%20download%20with%20the%20%3CA%20href%3D%22https%3A%2F%2Fdownload.sysinternals.com%2Ffiles%2FSysinternalsSuite-ARM64.zip%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3ESysinternals%20Suite%20for%20ARM64%3C%2FA%3E.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1649402%22%20slang%3D%22en-US%22%3E%3CDIV%3E%0A%3CDIV%3E%3CSPAN%3ELearn%20about%20the%20latest%20changes%20to%20Sysmon%20(v12.0)%2C%20Process%20Monitor%20(v3.60)%2C%20Procdump%20(v10.0)%20and%20several%20ARM64%20ports%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1712158%22%20slang%3D%22en-US%22%3ERe%3A%20Sysmon%20v12.0%2C%20Process%20Monitor%20v3.60%2C%20Procdump%20v10.0%20and%20ARM64%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1712158%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20maybe%20the%20wrong%20place%20to%20ask%2C%20but%20is%20there%20a%20way%20to%20disable%20the%20CopyOnDelete%20function%20in%20Sysmon%20(or%20do%20I%20have%20to%20stay%20with%20version%2010)%3F%3C%2FP%3E%3CP%3EBest%20regards%2C%20%2F%2F%20Mikael%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1776054%22%20slang%3D%22en-US%22%3ERe%3A%20Sysmon%20v12.0%2C%20Process%20Monitor%20v3.60%2C%20Procdump%20v10.0%20and%20ARM64%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1776054%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F808712%22%20target%3D%22_blank%22%3E%40Runsten%3C%2FA%3E%26nbsp%3Bthanks%20for%20your%20comment.%20The%20forums%20are%20generally%20the%20best%20place%20to%20provide%20feature%20suggestions%20and%20get%20help%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsocial.technet.microsoft.com%2FForums%2Fen-US%2Fhome%3Fcategory%3Dsysinternals%26amp%3Bfilter%3Dalltypes%26amp%3Bsort%3Dlastpostdesc%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsocial.technet.microsoft.com%2FForums%2Fen-US%2Fhome%3Fcategory%3Dsysinternals%26amp%3Bfilter%3Dalltypes%26amp%3Bsort%3Dlastpostdesc%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Sysmon v12.0

In addition to several bug fixes, this major update to Sysmon adds support for capturing clipboard operations to help incident responders retrieve attacker RDP file and command drops, including originating remote machine IP addresses.
 

Process Monitor v3.60

This update to Process Monitor, a utility that logs process file, network and registry activity, adds support for multiple filter item selection, as well as decoding for new file system control operations and error status codes.
 

Procdump v10.0

This release of Procdump, a flexible tool for manual and trigger-based process dump generation, adds support for dump cancellation and CoreCLR processes.
 

ARM64 ports

In addition, several tools have been newly ported to and are now available for ARM64. These include: AdInsight v1.2, AutoLogon v3.1, Autoruns v13.98, ClockRes v2.1, DebugView v4.9, DiskExt v1.2, FindLinks v1.1, Handle v4.22, Hex2Dec v1.1, Junction v1.07, PendMoves v1.02, PipeList v1.02, Procdump v10.0, Process Explorer v16.32, RegDelNull v1.11, RU v1.2, Sigcheck v2.8, Streams v1.6, Sync v2.2, VMMap v3.26, WhoIs v1.21 and ZoomIt v4.52. Download all ARM64 tools in a single download with the Sysinternals Suite for ARM64.
2 Comments
Occasional Visitor

Hi, maybe the wrong place to ask, but is there a way to disable the CopyOnDelete function in Sysmon (or do I have to stay with version 10)?

Best regards, // Mikael

Microsoft

@Runsten thanks for your comment. The forums are generally the best place to provide feature suggestions and get help https://social.technet.microsoft.com/Forums/en-US/home?category=sysinternals&filter=alltypes&sort=la...