Sysmon, part of the extremely useful SysInternals from Microsoft, is a popular system monitor (or Sysmon) that monitors and logs system activity in the Windows event log. That's why many, especially security experts, like to use it to collect useful data that they then pass through SIEM, where they have a handful of options for analysis.