LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

What do Sysmon events 8 (CreateRemoteThread) and 10 (ProcessAccess) detect, and why are they so valuable?

Event 8 records one process starting a thread inside another, the classic code-injection technique; event 10 records one process opening another with specific access rights, which is how credential dumpers read LSASS memory.

Event 8: dropper.exe creates a remote thread in explorer.exe; event 10: mimikatz.exe opens lsass.exe with access 0x1010

* Both events catch one process reaching into another. *

Both capture a process reaching into another process, something ordinary applications rarely need to do.

  • Event 8, CreateRemoteThread. Malware that wants to hide injects its code into a trusted process (explorer.exe, svchost.exe) and starts a thread there. The event names the source and target images and the thread's start address and module. A thread starting in no known module is a strong sign of injected shellcode.
  • Event 10, ProcessAccess. Tools like Mimikatz open lsass.exe, the process holding logged-on users' credentials, to read its memory. The event records SourceImage, TargetImage, the GrantedAccess bitmask (masks such as 0x1010 or 0x1FFFFF on LSASS are well-known red flags) and a CallTrace showing which DLLs made the call.

Event 10 is extremely noisy if logged unfiltered, since security products and system processes open each other all the time. A good configuration includes only access to sensitive targets such as LSASS and excludes known-good sources.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026