Skip to main content

Sysmon - Uninstall

Summary​

This script checks if Sysmon is installed and removes it using the built in uninstall switch.

Sample Run​

Image

Dependencies​

Task Creation​

Script Details​

Step 1​

Navigate to Automation ➞ Tasks
step1

Step 2​

Create a new Script Editor style task by choosing the Script Editor option from the Add dropdown menu
step2

The New Script page will appear on clicking the Script Editor button:
step3

Step 3​

Fill in the following details in the Description section:

  • Name: Sysmon - Uninstall
  • Description: This script checks if Sysmon is installed and removes it using the built in uninstall switch.
  • Category: Application

Image

Script Editor​

Click the Add Row button in the Script Editor section to start creating the script
AddRow

A blank function will appear:
BlankFunction

Row 1 Function: PowerShell Script​

Search and select the PowerShell Script function.

PowerShell Function Selected

The following function will pop up on the screen:
PowerShell Function Example

Paste in the following PowerShell script and set the Expected time of script execution in seconds to 600 seconds. Click the Save button.

PowerShell Script

Image

Row 2 Function: Script Log​

Add a new row by clicking the Add Row button.
Add Row

A blank function will appear.
Blank Function

Search and select the Script Log function.
Script Log Search

In the script log message, simply type %output% and click the Save button.
Script Log Save

Save Task​

Click the Save button at the top-right corner of the screen to save the script.
SaveButton

Completed Task​

Image

Output​

  • Script Logs

Changelog​

2026-03-26​

  • Initial version of the document