Data Source: Sysmon EventID 1

Description

Logs the creation of a new process, including details such as process ID, parent process, command line arguments, and hashes of the executable.

Details

Property Value
Source XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sourcetype XmlWinEventLog
Separator EventID
Name ▲▼ Technique ▲▼ Type ▲▼
Python Network Traffic During Package Build Python, Compromise Software Supply Chain Anomaly
Windows RDP File Execution Remote Desktop Protocol, Spearphishing Attachment TTP
Windows Suspicious QEMU Execution Data Obfuscation, Masquerading, Malicious File, Run Virtual Instance TTP
Python Site Hooks Creation During Package Installation Compromise Software Supply Chain, Event Triggered Execution TTP
Python PTH File Creation During Package Installation Compromise Software Supply Chain, Event Triggered Execution Anomaly
Windows Alternate DataStream - Process Execution NTFS File Attributes TTP
Windows Potato Privilege Escalation Tool Execution Exploitation for Privilege Escalation TTP
Process Deleting Its Process File Path Indicator Removal TTP
Windows Vulnerable 3CX Software Compromise Software Supply Chain TTP
Windows SoftEther VPN Masquerading as Legitimate Binary Masquerading, Protocol Tunneling TTP
Windows RMM Tool Execution Remote Access Tools Anomaly
Windows Privilege Escalation System Process Without System Parent Exploitation for Privilege Escalation, Access Token Manipulation, Abuse Elevation Control Mechanism TTP
Python PYTHONPATH Modification During Package Installation Compromise Software Supply Chain, Path Interception by PATH Environment Variable TTP
Windows Bypass UAC via Pkgmgr Tool Bypass User Account Control Anomaly
Headless Browser Mockbin or Mocky Request Hidden Window TTP
Windows Protocol Tunneling with Plink SSH, Protocol Tunneling TTP
Windows Audit Policy Security Descriptor Tampering via Auditpol Disable or Modify Windows Event Log Anomaly
Windows Chromium Process with Disabled Extensions Virtualization/Sandbox Evasion Anomaly
Windows Modify Registry Regedit Silent Reg Import Modify Registry Anomaly
Windows Explorer LNK Exploit Process Launch With Padding PowerShell, Malicious File TTP
Windows Suspicious Child Process Spawned From WebServer Web Shell Anomaly
Windows SQLCMD Execution Windows Command Shell Hunting
Detect Remote Access Software Usage Process Remote Access Tools Anomaly
Credential Dumping via Copy Command from Shadow Copy NTDS TTP
System Info Gathering Using Dxdiag Application Gather Victim Host Information Hunting
Windows WMI Reconnaissance Class Query Windows Management Instrumentation Anomaly
GetLocalUser with PowerShell Local Account Hunting
Windows Excessive Service Stop Attempt Service Stop TTP
Domain Account Discovery with Wmic Domain Account TTP
Windows Execution of Microsoft MSC File In Suspicious Path MMC Anomaly
GetCurrent User with PowerShell System Owner/User Discovery Hunting
Wmic NonInteractive App Uninstallation Disable or Modify Tools Hunting
Windows Remote Assistance Spawning Process Process Injection TTP
Recursive Delete of Directory In Batch CMD File Deletion TTP
Windows COM Hijacking InprocServer32 Modification Component Object Model Hijacking TTP
Windows NirSoft Utilities Tool Hunting
ServicePrincipalNames Discovery with SetSPN Kerberoasting TTP
Windows Explorer.exe Spawning PowerShell or Cmd PowerShell, Malicious File Hunting
Disable Logs Using WevtUtil Clear Windows Event Logs TTP
Detect mshta renamed Mshta Hunting
Allow File And Printing Sharing In Firewall Cloud Firewall TTP
Windows Scheduled Task with Highest Privileges Scheduled Task TTP
Wermgr Process Spawned CMD Or Powershell Process Command and Scripting Interpreter TTP
Malicious PowerShell Process With Obfuscation Techniques PowerShell TTP
FodHelper UAC Bypass Modify Registry, Bypass User Account Control TTP
Detect Renamed 7-Zip Archive via Utility Hunting
Windows System LogOff Commandline System Shutdown/Reboot Anomaly
Windows Steal Authentication Certificates CertUtil Backup Steal or Forge Authentication Certificates Anomaly
Windows Disable or Stop Browser Process Disable or Modify Tools TTP
Detect Regasm Spawning a Process Regsvcs/Regasm TTP
Windows Office Product Dropped Cab or Inf File Spearphishing Attachment TTP
Windows DNS Gather Network Info DNS Anomaly
Attacker Tools On Endpoint OS Credential Dumping, Match Legitimate Resource Name or Location, Active Scanning TTP
ICACLS Grant Command File and Directory Permissions Modification Anomaly
Windows User Disabled Via Net Account Access Removal Anomaly
Conti Common Exec parameter User Execution TTP
Windows Office Product Spawned Child Process For Download Spearphishing Attachment TTP
Windows SymbolicLink-Testing-Tools Utility Execution File and Directory Permissions Modification, NTFS File Attributes TTP
Detect mshta inline hta execution Mshta TTP
Windows Browser Process Launched with Unusual Flags Browser Session Hijacking Anomaly
Deleting Shadow Copies Inhibit System Recovery TTP
Windows Service Initiation on Remote Endpoint Windows Service TTP
Windows Indirect Command Execution Via forfiles Indirect Command Execution TTP
Windows Set Account Password Policy To Unlimited Via Net Service Stop Anomaly
Local Account Discovery With Wmic Local Account Hunting
Domain Group Discovery With Wmic Domain Groups Hunting
Windows Defender ASR or Threat Configuration Tamper Disable or Modify Tools TTP
Windows Indirect Command Execution Via Series Of Forfiles Indirect Command Execution Anomaly
Windows Sqlservr Spawning Shell SQL Stored Procedures Hunting
Windows Indicator Removal Via Rmdir Indicator Removal Anomaly
Windows Shell or Script Execution From IIS Directory Exploit Public-Facing Application, IIS Components Anomaly
Headless Browser Usage Virtualization/Sandbox Evasion, Hidden Window Anomaly
Windows SOAPHound Binary Execution Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Windows Local LLM Framework Execution Create or Modify System Process Hunting
Suspicious Rundll32 PluginInit Rundll32 TTP
Windows Set Custom DNS ServerLevelPlugin Via Dnscmd Hijack Execution Flow Anomaly
Prevent Automatic Repair Mode using Bcdedit Inhibit System Recovery TTP
Advanced IP or Port Scanner Execution Network Service Discovery, Network Share Discovery Anomaly
Windows Entra User Management Via Azure CLI Cloud Accounts, Account Manipulation, Create Account Anomaly
Windows Wmic Network Discovery System Information Discovery Anomaly
Windows EventLog Recon Activity Using Log Query Utilities Log Enumeration Anomaly
Suspicious Process Executed From Container File Masquerade File Type, Malicious File TTP
Windows Security Account Manager Stopped Service Stop TTP
Malicious PowerShell Process - Encoded Command Obfuscated Files or Information Hunting
Windows DLL Side-Loading Process Child Of Calc DLL Anomaly
Windows Audit Policy Excluded Category via Auditpol Disable or Modify Windows Event Log Anomaly
Unknown Process Using The Kerberos Protocol Use Alternate Authentication Material TTP
Excessive Usage of NSLOOKUP App Exfiltration Over Alternative Protocol Anomaly
Windows Rasautou DLL Execution Dynamic-link Library Injection, System Binary Proxy Execution TTP
Windows OneDrive Share Mounted via Net Exfiltration to Cloud Storage Anomaly
Windows Phishing Outlook Drop Dll In FORM Dir Phishing TTP
Windows Unusual SysWOW64 Process Run System32 Executable Break Process Trees Anomaly
Windows WSUS Spawning Shell Exploit Public-Facing Application, Web Shell TTP
Windows Process With NamedPipe CommandLine Process Injection Anomaly
Windows Create Local Administrator Account Via Net Local Account Anomaly
Detect HTML Help Renamed Compiled HTML File Hunting
Process Kill Base On File Path Disable or Modify Tools TTP
Windows System Script Proxy Execution Syncappvpublishingserver System Script Proxy Execution, System Binary Proxy Execution TTP
WBAdmin Delete System Backups Inhibit System Recovery TTP
Windows MSIExec Remote Download Msiexec Anomaly
Windows Process Execution From ProgramData Match Legitimate Resource Name or Location Hunting
DLLHost with no Command Line Arguments with Network Process Injection TTP
Get-DomainTrust with PowerShell Domain Trust Discovery TTP
Windows File and Directory Permissions Enable Inheritance Windows Permissions Hunting
SLUI Spawning a Process Bypass User Account Control TTP
Windows SubInAcl Execution Windows Permissions Anomaly
Windows Office Product Spawned Uncommon Process Spearphishing Attachment TTP
Windows Server Software Component GACUtil Install to GAC IIS Components TTP
Detect HTML Help URL in Command Line Compiled HTML File TTP
Powershell Defender Threat Actions Set to Allow PowerShell TTP
Windows Chromium Process Launched with Logging Disabled Virtualization/Sandbox Evasion Anomaly
Windows MSTSC RDP Commandline Remote Desktop Protocol Anomaly
Windows Proxy Execution of .NET Utilities via Scripts System Binary Proxy Execution Anomaly
Windows Attempt To Stop Security Service Disable or Modify Tools TTP
Nishang PowershellTCPOneLine PowerShell TTP
Windows Ldifde Directory Object Behavior Domain Groups, Ingress Tool Transfer TTP
Windows Process With NetExec Command Line Parameters Pass the Ticket, Kerberoasting, AS-REP Roasting TTP
Windows WinLogon with Public Network Connection Bootkit Hunting
CertUtil With Decode Argument Deobfuscate/Decode Files or Information TTP
Windows Guest Account Enabled Via Net.EXE Default Accounts Anomaly
Windows Mustang Panda USB Tool Execution Automated Exfiltration, Malicious File, DLL TTP
Windows Service Create with Tscon Windows Service, RDP Hijacking TTP
Windows WinRAR Launched Outside Default Installation Directory Windows Management Instrumentation Anomaly
GetDomainComputer with PowerShell Remote System Discovery TTP
Windows User Deletion Via Net Account Access Removal Anomaly
Mshta spawning Rundll32 OR Regsvr32 Process Mshta TTP
Services Escalate Exe Abuse Elevation Control Mechanism TTP
Remote Process Instantiation via WMI Windows Management Instrumentation TTP
Scheduled Task Creation on Remote Endpoint using At At TTP
Windows Steal Authentication Certificates Export PfxCertificate Steal or Forge Authentication Certificates Anomaly
Windows MpCmdRun RemoveDefinitions Execution Disable or Modify Tools Anomaly
NLTest Domain Trust Discovery Domain Trust Discovery TTP
Windows Change File Association Command To Notepad Change Default File Association TTP
Windows MsiExec HideWindow Rundll32 Execution Msiexec TTP
Schtasks Run Task On Demand Scheduled Task/Job Anomaly
Windows PowerShell FakeCAPTCHA Clipboard Execution PowerShell, Windows Command Shell, Malicious Link TTP
Windows Command Obfuscation with Environment Variable Substrings Command Obfuscation Anomaly
Windows WinDBG Spawning AutoIt3 Command and Scripting Interpreter TTP
Windows Azure Storage Utility Execution Via CLI Exfiltration to Cloud Storage Anomaly
Windows PowerShell Script From WindowsApps Directory PowerShell, Malicious File TTP
Windows AutoIt3 Execution Command and Scripting Interpreter TTP
Windows InstallUtil in Non Standard Path Rename Legitimate Utilities, InstallUtil TTP
Suspicious Rundll32 StartW Rundll32 TTP
Spoolsv Writing a DLL Print Processors TTP
System User Discovery With Query System Owner/User Discovery Hunting
Windows LOLBAS Executed Outside Expected Path Match Legitimate Resource Name or Location, Rundll32 Anomaly
Windows System Reboot CommandLine System Shutdown/Reboot Hunting
Clop Common Exec Parameter User Execution TTP
Windows File Collection Via Copy Utilities Automated Collection Anomaly
Windows Privilege Escalation User Process Spawn System Process Exploitation for Privilege Escalation, Access Token Manipulation, Abuse Elevation Control Mechanism TTP
Windows WMI Process And Service List Windows Management Instrumentation Anomaly
Windows Audit Policy Restored via Auditpol Disable or Modify Windows Event Log Anomaly
Detect Path Interception By Creation Of program exe Path Interception by Unquoted Path TTP
Scheduled Task Initiation on Remote Endpoint Scheduled Task TTP
Windows Suspicious Child Process of Consent.EXE Command and Scripting Interpreter, Exploitation for Privilege Escalation, Bypass User Account Control Anomaly
Creation of Shadow Copy NTDS TTP
Disable Schedule Task Disable or Modify Tools Anomaly
Detect Prohibited Applications Spawning cmd exe Windows Command Shell Hunting
Suspicious DLLHost no Command Line Arguments Process Injection TTP
Scheduled Task Deleted Or Created via CMD Scheduled Task Anomaly
Windows Process Execution From RDP Share Remote Desktop Protocol, Command and Scripting Interpreter, Ingress Tool Transfer Anomaly
BITSAdmin Download File Ingress Tool Transfer, BITS Jobs TTP
Windows Identify Protocol Handlers Command and Scripting Interpreter Hunting
Windows Cisco Secure Endpoint Unblock File Via Sfc Disable or Modify Tools Anomaly
Windows File Association Modification via Ftype Windows Command Shell Anomaly
Suspicious mshta child process Mshta TTP
Windows Gdrive Binary Activity Exfiltration Over Web Service TTP
Suspicious Copy on System32 Rename Legitimate Utilities Anomaly
Suspicious PlistBuddy Usage Launch Agent TTP
Windows Remote Management Execute Shell Windows Remote Management Anomaly
Potential System Network Configuration Discovery Activity System Network Configuration Discovery Anomaly
Change To Safe Mode With Network Config Inhibit System Recovery TTP
Windows Credentials from Password Stores Query Credentials from Password Stores Anomaly
Windows Curl Upload to Remote Destination Ingress Tool Transfer TTP
Rundll32 with no Command Line Arguments with Network Rundll32 TTP
SearchProtocolHost with no Command Line with Network Process Injection TTP
Windows Private Keys Discovery Private Keys Anomaly
Ryuk Wake on LAN Command Windows Command Shell TTP
Windows Privilege Escalation Suspicious Process Elevation Exploitation for Privilege Escalation, Access Token Manipulation, Abuse Elevation Control Mechanism TTP
WinRAR Spawning Shell Application Ingress Tool Transfer TTP
Windows Process Injection In Non-Service SearchIndexer Process Injection TTP
Windows PsTools Recon Usage Remote System Discovery, Network Service Discovery, System Information Discovery Anomaly
Windows System Time Discovery W32tm Delay System Time Discovery Anomaly
Wscript Or Cscript Suspicious Child Process Process Injection, Parent PID Spoofing, Create or Modify System Process Anomaly
GetDomainController with PowerShell Remote System Discovery Hunting
Sdelete Application Execution File Deletion, Data Destruction TTP
GetWmiObject DS User with PowerShell Domain Account Anomaly
Windows DiskCryptor Usage Data Encrypted for Impact Hunting
Windows Scheduled Task Created Via XML Scheduled Task Anomaly
Windows Findstr GPP Discovery Group Policy Preferences TTP
Windows ComputerDefaults Spawning a Process Bypass User Account Control TTP
Suspicious msbuild path Rename Legitimate Utilities, MSBuild TTP
Windows Group Discovery Via Net Local Groups, Domain Groups Hunting
BCDEdit Failure Recovery Modification Inhibit System Recovery TTP
Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc Disable or Modify Tools Anomaly
XSL Script Execution With WMIC XSL Script Processing TTP
Windows Steal Authentication Certificates Export Certificate Steal or Forge Authentication Certificates Anomaly
Windows System Network Config Discovery Display DNS System Network Configuration Discovery Anomaly
Unusually Long Command Line None Anomaly
Windows Modify System Firewall with Notable Process Path Disable or Modify System Firewall TTP
Windows UAC Bypass Suspicious Escalation Behavior Bypass User Account Control TTP
Windows Office Product Spawned Control Spearphishing Attachment TTP
Runas Execution in CommandLine Token Impersonation/Theft Hunting
Outbound Network Connection from Java Using Default Ports External Remote Services, Exploit Public-Facing Application TTP
Windows ConHost with Headless Argument Hidden Window, Run Virtual Instance TTP
Uninstall App Using MsiExec Msiexec TTP
Windows Excessive Usage Of Net App Account Access Removal Anomaly
Windows Rundll32 Apply User Settings Changes Rundll32 Anomaly
Get DomainPolicy with Powershell Password Policy Discovery TTP
Esentutl SAM Copy Security Account Manager Hunting
Windows Audit Policy Cleared via Auditpol Disable or Modify Windows Event Log TTP
Suspicious SQLite3 LSQuarantine Behavior Data Staged TTP
Icacls Deny Command File and Directory Permissions Modification Anomaly
Windows Netspy Network Scanner Execution Remote System Discovery, Active Scanning Anomaly
Possible Lateral Movement PowerShell Spawn Distributed Component Object Model, Windows Remote Management, Windows Management Instrumentation, Scheduled Task, PowerShell, MMC, Windows Service Anomaly
Windows Rundll32 WebDAV Request Exfiltration Over Unencrypted Non-C2 Protocol Hunting
Windows Excel Spawning Microsoft Project Application Distributed Component Object Model Anomaly
Detect Regsvcs with No Command Line Arguments Regsvcs/Regasm TTP
Curl Execution with Percent Encoded URL Obfuscated Files or Information, Ingress Tool Transfer Anomaly
Remote WMI Command Attempt Windows Management Instrumentation TTP
Windows Chromium Process Loaded Extension via Command-Line Browser Session Hijacking Anomaly
Hiding Files And Directories With Attrib exe Windows Permissions TTP
Domain Controller Discovery with Nltest Remote System Discovery TTP
Suspicious wevtutil Usage Clear Windows Event Logs TTP
Detect Regasm with no Command Line Arguments Regsvcs/Regasm TTP
Get ADUserResultantPasswordPolicy with Powershell Password Policy Discovery TTP
Windows Office Product Spawned Rundll32 With No DLL Spearphishing Attachment TTP
Windows Suspicious VMWare Tools Child Process Command and Scripting Interpreter TTP
Resize ShadowStorage volume Inhibit System Recovery TTP
Windows Steal or Forge Kerberos Tickets Klist Steal or Forge Kerberos Tickets Hunting
Detect Outlook exe writing a zip file Spearphishing Attachment Anomaly
Windows Metasploit Confluence Plugin Execution Exploit Public-Facing Application, Web Shell, Stage Capabilities TTP
Winhlp32 Spawning a Process Process Injection TTP
PowerShell Get LocalGroup Discovery Local Groups Hunting
Windows Command and Scripting Interpreter Hunting Path Traversal Command and Scripting Interpreter Hunting
Windows Odbcconf Hunting Odbcconf Hunting
Windows Schtasks Create Run As System Scheduled Task TTP
WMIC XSL Execution via URL XSL Script Processing TTP
GPUpdate with no Command Line Arguments with Network Process Injection TTP
Windows Default Group Policy Object Modified with GPME Group Policy Modification TTP
Wsmprovhost LOLBAS Execution Process Spawn Windows Remote Management TTP
Windows TinyCC Shellcode Execution Obfuscated Files or Information, Masquerading, Windows Command Shell TTP
Windows DotNet Binary in Non Standard Path Rename Legitimate Utilities, InstallUtil TTP
Network Connection Discovery With Netstat System Network Connections Discovery Hunting
Windows SpeechRuntime Suspicious Child Process Distributed Component Object Model TTP
Excessive Usage Of Taskkill Disable or Modify Tools Anomaly
Windows Advanced Installer MSIX with AI_STUBS Execution Malicious File, System Binary Proxy Execution, Mark-of-the-Web Bypass TTP
Windows Process Commandline Discovery Process Discovery Hunting
Windows Default RDP File Creation By Non MSTSC Process Remote Desktop Protocol Anomaly
Suspicious Image Creation In Appdata Folder Screen Capture TTP
Windows System Remote Discovery With Query System Owner/User Discovery Hunting
File Download or Read to Pipe Execution Ingress Tool Transfer TTP
Windows List ENV Variables Via SET Command From Uncommon Parent Process Injection Anomaly
Windows Deleted Registry By A Non Critical Process File Path Modify Registry Anomaly
Windows Archive Collected Data via Rar Archive via Utility Anomaly
Windows MOF Event Triggered Execution via WMI Windows Management Instrumentation Event Subscription TTP
Notepad with no Command Line Arguments Process Injection TTP
Windows AppCertDLL Modification Via Command Line AppCert DLLs Anomaly
Windows Impair Defense Add Xml Applocker Rules Disable or Modify Tools Hunting
Get DomainUser with PowerShell Domain Account TTP
Windows Ngrok Reverse Proxy Usage Proxy, Web Service, Protocol Tunneling Anomaly
Windows Time Based Evasion via Choice Exec Time Based Checks Anomaly
Dump LSASS via procdump LSASS Memory TTP
Windows Suspicious Process File Path Match Legitimate Resource Name or Location, Create or Modify System Process TTP
Suspicious mshta spawn Mshta TTP
Windows Proxy Via Netsh Internal Proxy Anomaly
Windows Process Execution in Temp Dir Match Legitimate Resource Name or Location, Create or Modify System Process Anomaly
Windows MSIExec DLLRegisterServer Msiexec TTP
Schtasks scheduling job on remote system Scheduled Task TTP
Windows InstallUtil Remote Network Connection InstallUtil Anomaly
Impacket Lateral Movement Commandline Parameters SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service TTP
Get ADDefaultDomainPasswordPolicy with Powershell Password Policy Discovery Hunting
7zip CommandLine To SMB Share Path Archive via Utility Hunting
Excessive number of service control start as disabled Disable or Modify Tools Anomaly
GetAdComputer with PowerShell Remote System Discovery Hunting
Windows Privilege Escalation Attempt Via MSI Rollback Exploitation for Privilege Escalation TTP
Windows Cached Domain Credentials Reg Query Cached Domain Credentials Anomaly
Windows Scheduled Task Service Spawned Shell Scheduled Task, Command and Scripting Interpreter TTP
Permission Modification using Takeown App File and Directory Permissions Modification Anomaly
Windows Raccine Scheduled Task Deletion Disable or Modify Tools TTP
Suspicious IcedID Rundll32 Cmdline Rundll32 TTP
Detect RClone Command-Line Usage Automated Exfiltration TTP
Windows NirSoft AdvancedRun Tool TTP
SecretDumps Offline NTDS Dumping Tool NTDS TTP
Windows File Download Via PowerShell PowerShell, Ingress Tool Transfer Anomaly
Windows Dir Piped to Findstr Activity Automated Collection Hunting
Windows New Service Security Descriptor Set Via Sc.EXE Hide Artifacts Anomaly
Windows Execute Arbitrary Commands with MSDT System Binary Proxy Execution TTP
Detect Regsvr32 Application Control Bypass Regsvr32 TTP
Check Elevated CMD using whoami System Owner/User Discovery TTP
Jscript Execution Using Cscript App JavaScript TTP
Suspicious microsoft workflow compiler rename Rename Legitimate Utilities, Trusted Developer Utilities Proxy Execution Hunting
Windows IOBit Unlocker Extension DLL Registration via Regsvr32 Regsvr32 TTP
Ntdsutil Export NTDS NTDS TTP
Windows Service Stop Attempt Service Stop Hunting
Powershell Disable Security Monitoring Disable or Modify Tools TTP
Windows Wermgr Spawning System Integrity Process Exploitation for Privilege Escalation, Token Impersonation/Theft TTP
Windows Wmic Systeminfo Discovery System Information Discovery Anomaly
Windows Process Injection Wermgr Child Process Process Injection Anomaly
Windows AdFind Exe Remote System Discovery TTP
Excessive Usage Of SC Service Utility Service Execution Anomaly
Windows Binary Execution from an Archive Malicious File Anomaly
Remote Process Instantiation via WMI and PowerShell Windows Management Instrumentation TTP
Windows MSIExec Spawn Discovery Command Msiexec Anomaly
Unload Sysmon Filter Driver Disable or Modify Tools TTP
Remote Process Instantiation via WinRM and PowerShell Windows Remote Management TTP
Remote Process Instantiation via WinRM and Winrs Windows Remote Management TTP
Windows Masquerading Msdtc Process Masquerading TTP
Windows Process Executed From Removable Media Data from Removable Media, Replication Through Removable Media, Hardware Additions Anomaly
Windows TeamCity Payload Execution from Temp Directory Command and Scripting Interpreter, Exploit Public-Facing Application, Web Shell TTP
Windows Office Product Dropped Uncommon File Spearphishing Attachment Anomaly
Windows Apache Benchmark Binary Command and Scripting Interpreter Anomaly
Fsutil Zeroing File Indicator Removal TTP
Detect Renamed RClone Automated Exfiltration Hunting
Windows NorthStar C2 Agent Execution Malicious File, Registry Run Keys / Startup Folder, Stage Capabilities TTP
Windows IIS Components Add New Module IIS Components Anomaly
User Discovery With Env Vars PowerShell System Owner/User Discovery Hunting
Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc Disable or Modify Tools Anomaly
GetAdGroup with PowerShell Domain Groups Hunting
Windows Chromium Browser with Custom User Data Directory Virtualization/Sandbox Evasion Anomaly
Windows BitLocker Suspicious Command Usage Data Encrypted for Impact, Inhibit System Recovery TTP
Vbscript Execution Using Wscript App Visual Basic TTP
Detect Certify Command Line Arguments Ingress Tool Transfer, Steal or Forge Authentication Certificates TTP
Windows MSC EvilTwin Directory Path Manipulation Match Legitimate Resource Name or Location, Exploitation for Client Execution, System Binary Proxy Execution TTP
Windows System User Privilege Discovery System Owner/User Discovery Hunting
Windows Registry Entries Restored Via Reg Query Registry Hunting
Suspicious Rundll32 no Command Line Arguments Rundll32 TTP
Windows WMI Process Call Create Windows Management Instrumentation Hunting
Windows Credentials in Registry Reg Query Credentials in Registry Anomaly
Windows Potential Cloudflared Tunnel Execution Protocol Tunneling Anomaly
Windows New Deny Permission Set On Service SD Via Sc.EXE Hide Artifacts Anomaly
Windows Compatibility Telemetry Suspicious Child Process Scheduled Task, Event Triggered Execution TTP
Windows RDP Client Launched with Admin Session Remote Desktop Protocol Anomaly
Windows Wmic DiskDrive Discovery System Information Discovery Anomaly
Windows Regsvr32 Renamed Binary Regsvr32 TTP
Windows PuTTY Suite Utility Execution SSH Anomaly
Windows InstallUtil Uninstall Option InstallUtil TTP
Windows SSH Proxy Command PowerShell, Ingress Tool Transfer, Protocol Tunneling Anomaly
Windows PaperCut NG Spawn Shell Command and Scripting Interpreter, External Remote Services, Exploit Public-Facing Application TTP
Windows LOLBAS Executed As Renamed File Rename Legitimate Utilities, Rundll32 TTP
Execute Javascript With Jscript COM CLSID Visual Basic TTP
Mimikatz PassTheTicket CommandLine Parameters Pass the Ticket TTP
GetDomainGroup with PowerShell Domain Groups TTP
Windows Registry Entries Exported Via Reg Query Registry Hunting
Excessive distinct processes from Windows Temp Command and Scripting Interpreter Anomaly
Windows DISM Install PowerShell Web Access Bypass User Account Control TTP
Windows Eventlog Cleared Via Wevtutil Clear Windows Event Logs Anomaly
Windows Renamed Powershell Execution Rename Legitimate Utilities TTP
Certutil exe certificate extraction Steal or Forge Authentication Certificates TTP
Remote System Discovery with Wmic Remote System Discovery TTP
Reg exe Manipulating Windows Services Registry Keys Services Registry Permissions Weakness TTP
Modify ACL permission To Files Or Folder File and Directory Permissions Modification Anomaly
Windows Parent PID Spoofing with Explorer Parent PID Spoofing TTP
Windows Rundll32 Load DLL in Temp Dir Rundll32 Anomaly
CSC Net On The Fly Compilation Compile After Delivery Hunting
Windows Mimikatz Binary Execution OS Credential Dumping TTP
Malicious PowerShell Process - Execution Policy Bypass PowerShell Anomaly
Create or delete windows shares using net exe Network Share Connection Removal TTP
Windows Command and Scripting Interpreter Path Traversal Exec Command and Scripting Interpreter TTP
Firewall Allowed Program Enable Disable or Modify System Firewall Anomaly
Windows Remote Create Service Windows Service Anomaly
GetWmiObject User Account with PowerShell Local Account Hunting
Windows Rundll32 with Non-Standard File Extension Rundll32 Anomaly
Rubeus Command Line Parameters Pass the Ticket, Kerberoasting, AS-REP Roasting TTP
Control Loading from World Writable Directory Control Panel TTP
Windows Password Managers Discovery Password Managers Anomaly
BITS Job Persistence BITS Jobs TTP
Windows Cabinet File Extraction Via Expand Ingress Tool Transfer TTP
WinRM Spawning a Process Exploit Public-Facing Application TTP
Hunting 3CXDesktopApp Software Compromise Software Supply Chain Hunting
Windows ScManager Security Descriptor Tampering Via Sc.EXE Service Execution TTP
Windows Symlink Evaluation Change via Fsutil Windows Permissions Anomaly
USN Journal Deletion Indicator Removal TTP
Windows Wmic Memory Chip Discovery System Information Discovery Anomaly
Windows Service Creation on Remote Endpoint Windows Service TTP
Windows DISM Remove Defender Disable or Modify Tools TTP
Excessive number of taskhost processes Command and Scripting Interpreter Anomaly
Suspicious MSBuild Rename Rename Legitimate Utilities, MSBuild Hunting
Windows MSIExec Spawn WinDBG Msiexec TTP
Domain Account Discovery with Dsquery Domain Account Anomaly
Windows System Discovery Using Qwinsta System Owner/User Discovery Hunting
Windows Audit Policy Auditing Option Disabled via Auditpol Disable or Modify Windows Event Log TTP
Windows FFmpeg DirectShow Video Capture Video Capture Anomaly
Domain Group Discovery With Dsquery Domain Groups Anomaly
Detect SharpHound Command-Line Arguments Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Detect RTLO In Process Right-to-Left Override TTP
Windows Crowdstrike RTR Script Execution PowerShell Anomaly
Windows Suspicious React or Next.js Child Process PowerShell, Windows Command Shell, Exploit Public-Facing Application TTP
Windows PowerShell Process Implementing Manual Base64 Decoder Command Obfuscation, PowerShell Anomaly
Wmic Group Discovery Local Groups Anomaly
Windows Disable Windows Event Logging Disable HTTP Logging IIS Components, Disable or Modify Windows Event Log Anomaly
Windows Disable Internet Explorer Addons Browser Extensions Anomaly
Windows InstallUtil URL in Command Line InstallUtil TTP
Windows HTTP Network Communication From MSIExec Msiexec Anomaly
Elevated Group Discovery With Wmic Domain Groups TTP
Suspicious GPUpdate no Command Line Arguments Process Injection TTP
Suspicious MSBuild Spawn MSBuild TTP
Windows File Download Via CertUtil Ingress Tool Transfer TTP
Windows Suspicious Child Process of TieringEngineService.exe Exploitation for Privilege Escalation TTP
Network Connection Discovery With Arp System Network Connections Discovery Hunting
Impacket Lateral Movement smbexec CommandLine Parameters SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service TTP
Rundll32 LockWorkStation Rundll32 Anomaly
Mmc LOLBAS Execution Process Spawn Distributed Component Object Model, MMC TTP
Execution of File with Multiple Extensions Rename Legitimate Utilities TTP
CMD Carry Out String Command Parameter Windows Command Shell Hunting
Windows DLL Search Order Hijacking with iscsicpl DLL TTP
Detect AzureHound Command-Line Arguments Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Windows Command Shell DCRat ForkBomb Payload Windows Command Shell TTP
Windows File and Directory Permissions Remove Inheritance Windows Permissions Anomaly
Windows File and Directory Enable ReadOnly Permissions Windows Permissions TTP
Spoolsv Spawning Rundll32 Print Processors TTP
Verclsid CLSID Execution Verclsid Hunting
Windows Chromium Browser No Security Sandbox Process Virtualization/Sandbox Evasion TTP
Revil Common Exec Parameter User Execution TTP
MacOS - Re-opened Applications None TTP
Detect Remote Access Software Usage FileInfo Remote Access Tools Anomaly
DSQuery Domain Discovery Domain Trust Discovery TTP
Windows Chromium Browser Launched with Small Window Size Virtualization/Sandbox Evasion TTP
Windows PowerShell Process With Malicious String PowerShell TTP
Detect MSHTA Url in Command Line Mshta TTP
DNS Exfiltration Using Nslookup App Exfiltration Over Alternative Protocol TTP
Windows Debugger Tool Execution Masquerading Hunting
System Information Discovery Detection System Information Discovery TTP
Windows Files and Dirs Access Rights Modification Via Icacls Windows Permissions Anomaly
Windows User Discovery Via Net Local Account, Domain Account Hunting
Windows Spearphishing Attachment Onenote Spawn Mshta Spearphishing Attachment TTP
Process Execution via WMI Windows Management Instrumentation TTP
Services LOLBAS Execution Process Spawn Windows Service TTP
Windows FFmpeg Audio and Video Device Discovery Video Capture Anomaly
Excessive Usage Of Cacls App File and Directory Permissions Modification Anomaly
Windows WBAdmin File Recovery From Backup Inhibit System Recovery, Stored Data Manipulation Anomaly
Windows Delete or Modify System Firewall Disable or Modify System Firewall Hunting
Dump LSASS via comsvcs DLL LSASS Memory TTP
Windows Rundll32 Execution With Log.DLL Hijack Execution Flow Anomaly
Windows System User Discovery Via Quser System Owner/User Discovery Hunting
Creation of Shadow Copy with wmic and powershell NTDS TTP
Remote Desktop Process Running On System Remote Desktop Protocol Hunting
Suspicious Rundll32 dllregisterserver Rundll32 TTP
Suspicious writes to windows Recycle Bin Masquerading TTP
Web Servers Executing Suspicious Processes System Information Discovery TTP
Windows Defacement Modify Transcodedwallpaper File Defacement Anomaly
Windows Certutil Root Certificate Addition Digital Certificates TTP
Possible Browser Pass View Parameter Credentials from Web Browsers Hunting
Windows SQL Spawning CertUtil Ingress Tool Transfer TTP
Ping Sleep Batch Command Time Based Checks Anomaly
Windows Credential Target Information Structure in Commandline DNS, Forced Authentication, Name Resolution Poisoning and SMB Relay TTP
Windows Indirect Command Execution Via pcalua Indirect Command Execution TTP
Windows Phishing PDF File Executes URL Link Spearphishing Attachment Anomaly
Windows Time Based Evasion Time Based Checks TTP
Windows Svchost.exe Parent Process Anomaly Break Process Trees Anomaly
Potential Telegram API Request Via CommandLine Exfiltration Over C2 Channel, Bidirectional Communication Anomaly
Suspicious SearchProtocolHost no Command Line Arguments Process Injection TTP
Windows Masquerading Explorer As Child Process DLL TTP
Windows Binary Proxy Execution Mavinject DLL Injection Mavinject TTP
Get ADUser with PowerShell Domain Account Hunting
Remote System Discovery with Dsquery Remote System Discovery Anomaly
Windows Service Create Kernel Mode Driver Exploitation for Privilege Escalation, Windows Service TTP
Windows Credentials from Password Stores Deletion Credentials from Password Stores TTP
CMD Echo Pipe - Escalation Windows Command Shell, Windows Service TTP
Suspicious microsoft workflow compiler usage Trusted Developer Utilities Proxy Execution TTP
Windows MSIExec Unregister DLLRegisterServer Msiexec TTP
Windows Curl Download to Suspicious Path Ingress Tool Transfer TTP
Windows Password Policy Discovery with Net Password Policy Discovery Hunting
Windows Modify Registry Qakbot Binary Data Registry Modify Registry Anomaly
Detection of tools built by NirSoft Software Deployment Tools Anomaly
Web or Application Server Spawning a Shell External Remote Services, Exploit Public-Facing Application TTP
Detect Rundll32 Inline HTA Execution Mshta TTP
Detect Rare Executables User Execution Anomaly
RunDLL Loading DLL By Ordinal Rundll32 TTP
Child Processes of Spoolsv exe Exploitation for Privilege Escalation TTP
Wmiprvse LOLBAS Execution Process Spawn Windows Management Instrumentation TTP
Suspicious Reg exe Process Modify Registry Anomaly
Bcdedit Command Back To Normal Mode Boot Inhibit System Recovery TTP
PowerShell Start-BitsTransfer BITS Jobs TTP
Detect Use of cmd exe to Launch Script Interpreters Windows Command Shell Anomaly
Windows Default Rdp File Unhidden Remote Desktop Protocol Anomaly
Windows ESX Admins Group Creation via Net Local Account, Domain Account TTP
Detect Regsvcs Spawning a Process Regsvcs/Regasm TTP
Remote Process Instantiation via DCOM and PowerShell Distributed Component Object Model TTP
Detect Renamed PSExec Service Execution Hunting
Windows Powershell RemoteSigned File PowerShell Anomaly
MSBuild Suspicious Spawned By Script Process MSBuild TTP
Windows TOR Client Execution Multi-hop Proxy Anomaly
Windows BitLockerToGo Process Execution System Binary Proxy Execution Hunting
Allow Network Discovery In Firewall Cloud Firewall TTP
Windows Credentials from Password Stores Creation Credentials from Password Stores TTP
Detect SharpHound Usage Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Windows EDRSilencer Execution Disable or Modify Tools Anomaly
Windows Account Access Removal via Logoff Exec PowerShell, Account Access Removal Anomaly
Windows System Discovery Using ldap Nslookup System Owner/User Discovery Anomaly
Windows Shell Process from CrushFTP PowerShell, Windows Command Shell, Exploit Public-Facing Application, Server Software Component TTP
Windows Application Whitelisting Bypass Attempt via Rundll32 Rundll32 TTP
Windows UAC Bypass Suspicious Child Process Bypass User Account Control TTP
Shim Database Installation With Suspicious Parameters Application Shimming TTP
Suspicious Scheduled Task from Public Directory Scheduled Task Anomaly
Excessive Attempt To Disable Services Service Stop Anomaly
Windows System Shutdown CommandLine System Shutdown/Reboot Anomaly
Domain Controller Discovery with Wmic Remote System Discovery Hunting
Windows Remote Service Rdpwinst Tool Execution Remote Desktop Protocol TTP
Windows Get-Variable.EXE Execution from WindowsApps Folder Path Interception by Search Order Hijacking Anomaly
Windows Diskshadow Proxy Execution System Binary Proxy Execution TTP
Windows Information Discovery Fsutil System Information Discovery Anomaly
GetNetTcpconnection with PowerShell System Network Connections Discovery Hunting
Windows Disable or Modify Tools Via Taskkill Disable or Modify Tools Anomaly
Windows Audit Policy Disabled via Legacy Auditpol Disable or Modify Windows Event Log Anomaly
Detect PsExec With accepteula Flag SMB/Windows Admin Shares TTP
Windows Chromium process Launched with Disable Popup Blocking Virtualization/Sandbox Evasion Anomaly
Windows Odbcconf Load DLL Odbcconf TTP
Credential Dumping via Symlink to Shadow Copy NTDS TTP
Anomalous usage of 7zip Archive via Utility Anomaly
Rundll32 Control RunDLL World Writable Directory Rundll32 TTP
Detect Renamed WinRAR Archive via Utility Hunting
GetWmiObject Ds Computer with PowerShell Remote System Discovery Anomaly
System Processes Run From Unexpected Locations Rename Legitimate Utilities Anomaly
Windows System Network Connections Discovery Netsh System Network Connections Discovery Anomaly
Rundll32 Control RunDLL Hunt Rundll32 Hunting
Get-ForestTrust with PowerShell Domain Trust Discovery TTP
Schtasks used for forcing a reboot Scheduled Task TTP
Detect HTML Help Using InfoTech Storage Handlers Compiled HTML File TTP
Windows Net System Service Discovery System Service Discovery Hunting
Suspicious Curl Network Connection Ingress Tool Transfer TTP
Windows Cmdline Tool Execution From Non-Shell Process JavaScript Anomaly
Windows Remote Services Allow Rdp In Firewall Remote Desktop Protocol Anomaly
Windows Network Connection Discovery Via Net System Network Connections Discovery Hunting
Windows Network Sniffing Tool Executed Network Sniffing Anomaly
Disabling Firewall with Netsh Disable or Modify Tools Anomaly
GetWmiObject Ds Group with PowerShell Domain Groups Anomaly
Windows Credential Dumping LSASS Memory Createdump LSASS Memory TTP
Windows Ingress Tool Transfer Using Explorer Ingress Tool Transfer Anomaly
Windows Remote Host Computer Management Access Windows Remote Management Anomaly
Suspicious Regsvr32 Register Suspicious Path Regsvr32 TTP
Windows Sensitive Group Discovery With Net Domain Groups Anomaly
Windows Sensitive Registry Hive Dump Via CommandLine Security Account Manager TTP
Regsvr32 Silent and Install Param Dll Loading Regsvr32 Anomaly
Windows Service Stop By Deletion Service Stop Hunting
Windows System Binary Proxy Execution Compiled HTML File Decompile Compiled HTML File TTP
Suspicious WAV file in Appdata Folder Screen Capture TTP
Impacket Lateral Movement WMIExec Commandline Parameters SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service TTP
Single Letter Process On Endpoint Malicious File TTP
Network Discovery Using Route Windows App Internet Connection Discovery Hunting
Windows Office Product Spawned MSDT Spearphishing Attachment TTP
Svchost LOLBAS Execution Process Spawn Scheduled Task TTP
Rundll32 Shimcache Flush Modify Registry TTP
Windows Wmic CPU Discovery System Information Discovery Anomaly
Windows Rundll32 WebDav With Network Connection Exfiltration Over Unencrypted Non-C2 Protocol TTP
System User Discovery With Whoami System Owner/User Discovery Hunting
Windows Devtunnels Execution Proxy Anomaly
SLUI RunAs Elevated Bypass User Account Control TTP
Add or Set Windows Defender Exclusion Disable or Modify Tools TTP
Windows Global Object Access Audit List Cleared Via Auditpol Disable or Modify Windows Event Log TTP
Windows Security Support Provider Reg Query Security Support Provider Anomaly
Script Execution via WMI Windows Management Instrumentation TTP
Windows EFI Volume Mount Attempt Via Mountvol Malicious File, Pre-OS Boot, Safe Mode Boot Anomaly
Windows Chrome Enable Extension Loading via Command-Line Browser Session Hijacking Anomaly
Get WMIObject Group Discovery Local Groups Hunting
Windows Odbcconf Load Response File Odbcconf TTP
Windows Service Execution RemCom Service Execution TTP
Windows PowGoop Beacon Decoding Data Obfuscation, PowerShell TTP
Windows Network Share Interaction Via Net Data from Network Shared Drive, Network Share Discovery Hunting
Windows Audit Policy Disabled via Auditpol Disable or Modify Windows Event Log Anomaly
Windows WMIC Shadowcopy Delete Inhibit System Recovery Anomaly
Clear Unallocated Sector Using Cipher App File Deletion TTP
MS Exchange Mailbox Replication service writing Active Server Pages External Remote Services, Exploit Public-Facing Application, Web Shell TTP
Detect HTML Help Spawn Child Process Compiled HTML File TTP
First Time Seen Child Process of Zoom Exploitation for Privilege Escalation Anomaly

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
  <span class="pill kill-chain">Channel</span>
  
  <span class="pill kill-chain">CommandLine</span>
  
  <span class="pill kill-chain">Company</span>
  
  <span class="pill kill-chain">Computer</span>
  
  <span class="pill kill-chain">CurrentDirectory</span>
  
  <span class="pill kill-chain">Description</span>
  
  <span class="pill kill-chain">EventChannel</span>
  
  <span class="pill kill-chain">EventCode</span>
  
  <span class="pill kill-chain">EventData_Xml</span>
  
  <span class="pill kill-chain">EventDescription</span>
  
  <span class="pill kill-chain">EventID</span>
  
  <span class="pill kill-chain">EventRecordID</span>
  
  <span class="pill kill-chain">FileVersion</span>
  
  <span class="pill kill-chain">Guid</span>
  
  <span class="pill kill-chain">Hashes</span>
  
  <span class="pill kill-chain">IMPHASH</span>
  
  <span class="pill kill-chain">Image</span>
  
  <span class="pill kill-chain">IntegrityLevel</span>
  
  <span class="pill kill-chain">Keywords</span>
  
  <span class="pill kill-chain">Level</span>
  
  <span class="pill kill-chain">LogonGuid</span>
  
  <span class="pill kill-chain">LogonId</span>
  
  <span class="pill kill-chain">MD5</span>
  
  <span class="pill kill-chain">Name</span>
  
  <span class="pill kill-chain">Opcode</span>
  
  <span class="pill kill-chain">OriginalFileName</span>
  
  <span class="pill kill-chain">ParentCommandLine</span>
  
  <span class="pill kill-chain">ParentImage</span>
  
  <span class="pill kill-chain">ParentProcessGuid</span>
  
  <span class="pill kill-chain">ParentProcessId</span>
  
  <span class="pill kill-chain">ProcessGuid</span>
  
  <span class="pill kill-chain">ProcessID</span>
  
  <span class="pill kill-chain">ProcessId</span>
  
  <span class="pill kill-chain">Product</span>
  
  <span class="pill kill-chain">RecordID</span>
  
  <span class="pill kill-chain">RecordNumber</span>
  
  <span class="pill kill-chain">RuleName</span>
  
  <span class="pill kill-chain">SHA256</span>
  
  <span class="pill kill-chain">SecurityID</span>
  
  <span class="pill kill-chain">SystemTime</span>
  
  <span class="pill kill-chain">System_Props_Xml</span>
  
  <span class="pill kill-chain">Task</span>
  
  <span class="pill kill-chain">TerminalSessionId</span>
  
  <span class="pill kill-chain">ThreadID</span>
  
  <span class="pill kill-chain">TimeCreated</span>
  
  <span class="pill kill-chain">User</span>
  
  <span class="pill kill-chain">UserID</span>
  
  <span class="pill kill-chain">UtcTime</span>
  
  <span class="pill kill-chain">Version</span>
  
  <span class="pill kill-chain">action</span>
  
  <span class="pill kill-chain">date_hour</span>
  
  <span class="pill kill-chain">date_mday</span>
  
  <span class="pill kill-chain">date_minute</span>
  
  <span class="pill kill-chain">date_month</span>
  
  <span class="pill kill-chain">date_second</span>
  
  <span class="pill kill-chain">date_wday</span>
  
  <span class="pill kill-chain">date_year</span>
  
  <span class="pill kill-chain">date_zone</span>
  
  <span class="pill kill-chain">dest</span>
  
  <span class="pill kill-chain">dvc_nt_host</span>
  
  <span class="pill kill-chain">event_id</span>
  
  <span class="pill kill-chain">eventtype</span>
  
  <span class="pill kill-chain">host</span>
  
  <span class="pill kill-chain">id</span>
  
  <span class="pill kill-chain">index</span>
  
  <span class="pill kill-chain">linecount</span>
  
  <span class="pill kill-chain">original_file_name</span>
  
  <span class="pill kill-chain">os</span>
  
  <span class="pill kill-chain">parent_process</span>
  
  <span class="pill kill-chain">parent_process_exec</span>
  
  <span class="pill kill-chain">parent_process_guid</span>
  
  <span class="pill kill-chain">parent_process_id</span>
  
  <span class="pill kill-chain">parent_process_name</span>
  
  <span class="pill kill-chain">parent_process_path</span>
  
  <span class="pill kill-chain">process</span>
  
  <span class="pill kill-chain">process_current_directory</span>
  
  <span class="pill kill-chain">process_exec</span>
  
  <span class="pill kill-chain">process_guid</span>
  
  <span class="pill kill-chain">process_hash</span>
  
  <span class="pill kill-chain">process_id</span>
  
  <span class="pill kill-chain">process_integrity_level</span>
  
  <span class="pill kill-chain">process_name</span>
  
  <span class="pill kill-chain">process_path</span>
  
  <span class="pill kill-chain">punct</span>
  
  <span class="pill kill-chain">signature</span>
  
  <span class="pill kill-chain">signature_id</span>
  
  <span class="pill kill-chain">source</span>
  
  <span class="pill kill-chain">sourcetype</span>
  
  <span class="pill kill-chain">splunk_server</span>
  
  <span class="pill kill-chain">tag</span>
  
  <span class="pill kill-chain">tag::eventtype</span>
  
  <span class="pill kill-chain">timeendpos</span>
  
  <span class="pill kill-chain">timestartpos</span>
  
  <span class="pill kill-chain">user</span>
  
  <span class="pill kill-chain">user_id</span>
  
  <span class="pill kill-chain">vendor_product</span>
  
</div>

Example Log

1<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>1</EventID><Version>5</Version><Level>4</Level><Task>1</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime='2020-10-08T11:03:46.617920300Z'/><EventRecordID>4522</EventRecordID><Correlation/><Execution ProcessID='2912' ThreadID='3424'/><Channel>Microsoft-Windows-Sysmon/Operational</Channel><Computer>win-dc-6764986.attackrange.local</Computer><Security UserID='S-1-5-18'/></System><EventData><Data Name='RuleName'>-</Data><Data Name='UtcTime'>2020-10-08 11:03:46.615</Data><Data Name='ProcessGuid'>{96128EA2-F212-5F7E-E400-000000007F01}</Data><Data Name='ProcessId'>2296</Data><Data Name='Image'>C:\Windows\System32\cmd.exe</Data><Data Name='FileVersion'>10.0.14393.0 (rs1_release.160715-1616)</Data><Data Name='Description'>Windows Command Processor</Data><Data Name='Product'>Microsoft® Windows® Operating System</Data><Data Name='Company'>Microsoft Corporation</Data><Data Name='OriginalFileName'>Cmd.Exe</Data><Data Name='CommandLine'>"C:\Windows\system32\cmd.exe" /c "reg save HKLM\sam %%temp%%\ sam &amp; reg save HKLM\system %%temp%%\system &amp; reg save HKLM\security %%temp%%\security" </Data><Data Name='CurrentDirectory'>C:\Users\ADMINI~1\AppData\Local\ Temp\</Data><Data Name='User'>ATTACKRANGE\Administrator</Data><Data Name='LogonGuid'>{96128EA2-F210-5F7E-ACD4-080000000000}</Data><Data Name='LogonId'>0x8d4ac</Data><Data Name='TerminalSessionId'>0</Data><Data Name='IntegrityLevel'>High</Data><Data Name='Hashes'>MD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A</Data><Data Name='ParentProcessGuid'>{96128EA2-F211-5F7E-DF00-000000007F01}</Data><Data Name='ParentProcessId'>4624</Data><Data Name='ParentImage'>C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe</Data><Data Name='ParentCommandLine'>"powershell.exe" -noninteractive -encodedcommand WwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQBuAGcAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAZQB4AHQALgBVAFQARgA4AEUAbgBjAG8AZABpAG4AZwAgACQAZgBhAGwAcwBlADsAIABJAG0AcABvAHIAdAAtAE0AbwBkAHUAbABlACAAIgBDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAaQBuAHYAbwBrAGUALQBhAHQAbwBtAGkAYwByAGUAZAB0AGUAYQBtAFwASQBuAHYAbwBrAGUALQBBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAC4AcABzAGQAMQAiACAALQBGAG8AcgBjAGUACgBJAG4AdgBvAGsAZQAtAEEAdABvAG0AaQBjAFQAZQBzAHQAIAAiAFQAMQAwADAAMwAuADAAMAAyACIAIAAtAEMAbwBuAGYAaQByAG0AOgAkAGYAYQBsAHMAZQAgAC0AVABpAG0AZQBvAHUAdABTAGUAYwBvAG4AZABzACAAMwAwADAAIAAtAEUAeABlAGMAdQB0AGkAbwBuAEwAbwBnAFAAYQB0AGgAIABDADoAXABBAHQAbwBtAGkAYwBSAGUAZABUAGUAYQBtAFwAYQB0AGMAXwBlAHgAZQBjAHUAdABpAG8AbgAuAGMAcwB2AA==</Data></EventData></Event>

Required Output Fields

  • action

  • dest

  • original_file_name

  • parent_process

  • parent_process_exec

  • parent_process_guid

  • parent_process_id

  • parent_process_name

  • parent_process_path

  • process

  • process_exec

  • process_guid

  • process_hash

  • process_id

  • process_integrity_level

  • process_name

  • process_path

  • user

  • user_id

  • vendor_product


Source: GitHub | Version: 4