Disable SysMon (registry)

/static/assets/windows-logo.svg
Windows Management Instrumentation (WMI) allows you to interact with the registery. This procedure attempts to use this access to remove the current configuration of the SysMon tool which logs everything on the computer, including security events.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)