Sysmon Event ID 16: Configuration changed
- Event ID
- 16
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Log integrity
- Default logging
- Needs configuration
What event 16 means
Sysmon event 16 is logged when the Sysmon configuration is updated, for example with sysmon -c <file>. It gives the path of the configuration file and its hash.
Planned configuration pushes produce this event across the fleet at once. A change on a single host, or a hash that does not match your approved configuration, can mean an attacker loaded a permissive config to stop specific events from being logged while leaving the service running.
When it is logged
Sysmon installed. This event cannot be filtered by the configuration.
Key fields
| Field | What it tells you |
|---|---|
| UtcTime | Time of the change. |
| Configuration | Path of the configuration file that was applied. |
| ConfigurationFileHash | Hash of the configuration file. Compare it with the hash of your approved config. |
Common benign sources
- Fleet-wide configuration updates pushed by the security team or a management tool.
- Configuration applied during Sysmon installation or upgrade.
What attackers do that produces it
- Loading a minimal or empty configuration to stop logging of process, network or registry events.
- Running
sysmon -cfrom an unusual path or by an unexpected user.
Investigation tips
- Compare ConfigurationFileHash with your known-good configurations.
- Look at Security 4688 or Sysmon 1 for the
sysmon -ccommand that applied it. - Check for a drop in Sysmon event volume after the change.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- Medium · 1
- HighSysmon Configuration ModificationRule by frack113, SigmaHQ, DRL 1.1
- MediumSysmon Configuration ChangeRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.