Skip to content
Sysmon

Sysmon Event ID 16: Configuration changed

ServiceConfigurationChangeSysmon event 16 records a change to the Sysmon configuration, with the config file and its hash. An unexpected change may be an attempt to blind monitoring.
16
Event ID
16
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Log integrity
Default logging
Needs configuration

What event 16 means

Sysmon event 16 is logged when the Sysmon configuration is updated, for example with sysmon -c <file>. It gives the path of the configuration file and its hash.

Planned configuration pushes produce this event across the fleet at once. A change on a single host, or a hash that does not match your approved configuration, can mean an attacker loaded a permissive config to stop specific events from being logged while leaving the service running.

When it is logged

Audit policy / configuration

Sysmon installed. This event cannot be filtered by the configuration.

Key fields

FieldWhat it tells you
UtcTimeTime of the change.
ConfigurationPath of the configuration file that was applied.
ConfigurationFileHashHash of the configuration file. Compare it with the hash of your approved config.

Common benign sources

  • Fleet-wide configuration updates pushed by the security team or a management tool.
  • Configuration applied during Sysmon installation or upgrade.

What attackers do that produces it

  • Loading a minimal or empty configuration to stop logging of process, network or registry events.
  • Running sysmon -c from an unusual path or by an unexpected user.

Investigation tips

  • Compare ConfigurationFileHash with your known-good configurations.
  • Look at Security 4688 or Sysmon 1 for the sysmon -c command that applied it.
  • Check for a drop in Sysmon event volume after the change.

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading