You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Sysmon64.exe与配置文件打包为自动执行安装的MSI?

为Sysmon创建自动安装MSI的最简方法

要实现打包Sysmon64.exe和sysmonconfig.xml并自动执行Sysmon64.exe -i sysmonconfig.xml -accepteula命令,最简方案是使用WiX Toolset(免费开源的MSI打包工具),通过自定义动作触发安装命令。以下是具体步骤:

步骤1:准备文件

  • 将下载好的Sysmon64.exe和你的sysmonconfig.xml放在同一本地目录。

步骤2:编写WiX配置文件(sysmon.wxs)

创建如下XML配置文件,替换其中的三个GUID(可通过guidgen.exe生成):

<?xml version="1.0" encoding="UTF-8"?>
<Wix xmlns="http://schemas.microsoft.com/wix/2006/wi">
  <Product Id="*" Name="Sysmon Auto Installer" Language="1033" Version="1.0.0.0" Manufacturer="YourOrg" UpgradeCode="YOUR-UPGRADE-GUID">
    <Package InstallerVersion="200" Compressed="yes" InstallScope="perMachine" />
    <MediaTemplate EmbedCab="yes" />

    <Directory Id="TARGETDIR" Name="SourceDir">
      <Directory Id="ProgramFilesFolder">
        <Directory Id="INSTALLFOLDER" Name="Sysmon" />
      </Directory>
    </Directory>

    <DirectoryRef Id="INSTALLFOLDER">
      <Component Id="SysmonExe" Guid="YOUR-EXE-COMPONENT-GUID">
        <File Id="Sysmon64.exe" Source="Sysmon64.exe" KeyPath="yes" />
      </Component>
      <Component Id="SysmonConfig" Guid="YOUR-CONFIG-COMPONENT-GUID">
        <File Id="sysmonconfig.xml" Source="sysmonconfig.xml" KeyPath="yes" />
      </Component>
    </DirectoryRef>

    <Feature Id="ProductFeature" Title="Sysmon Auto Installer" Level="1">
      <ComponentRef Id="SysmonExe" />
      <ComponentRef Id="SysmonConfig" />
    </Feature>

    <!-- 自定义动作:执行Sysmon安装命令 -->
    <CustomAction Id="InstallSysmon" BinaryKey="WixCA" DllEntry="CAQuietExec" Execute="deferred" Return="check" Impersonate="no" />
    <CustomAction Id="SetInstallCmd" Property="InstallSysmon" Value="&quot;[INSTALLFOLDER]Sysmon64.exe&quot; -i &quot;[INSTALLFOLDER]sysmonconfig.xml&quot; -accepteula" />

    <InstallExecuteSequence>
      <Custom Action="SetInstallCmd" Before="InstallSysmon" />
      <Custom Action="InstallSysmon" After="InstallFiles">NOT Installed</Custom>
    </InstallExecuteSequence>
  </Product>
</Wix>

步骤3:编译生成MSI

  1. 安装WiX Toolset并确保其工具链已加入系统PATH。
  2. 在命令行中进入文件目录,执行:
candle sysmon.wxs
light sysmon.wixobj

完成后会生成Sysmon Auto Installer.msi,运行即可自动完成Sysmon的配置化安装。

无脚本替代方案

若不想编写XML,可使用Advanced Installer免费版:

  • 新建Simple项目,添加Sysmon64.exe和sysmonconfig.xml到安装目录。
  • 进入「Custom Actions」面板,添加「Launch File」动作,设置参数为-i sysmonconfig.xml -accepteula,触发时机选「After Install Files」。
  • 导出MSI文件即可。

内容的提问来源于stack exchange,提问作者lisa1987

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 10:52:35