Quiz Entry - updated: 2026.09.24
What do Sysmon events 8 (CreateRemoteThread) and 10 (ProcessAccess) detect, and why are they so valuable?
Event 8 records one process starting a thread inside another, the classic code-injection technique; event 10 records one process opening another with specific access rights, which is how credential dumpers read LSASS memory.
* Both events catch one process reaching into another. *
Both capture a process reaching into another process, something ordinary applications rarely need to do.
- Event 8, CreateRemoteThread. Malware that wants to hide injects its code into a trusted process (
explorer.exe,svchost.exe) and starts a thread there. The event names the source and target images and the thread's start address and module. A thread starting in no known module is a strong sign of injected shellcode. - Event 10, ProcessAccess. Tools like Mimikatz open
lsass.exe, the process holding logged-on users' credentials, to read its memory. The event recordsSourceImage,TargetImage, theGrantedAccessbitmask (masks such as0x1010or0x1FFFFFon LSASS are well-known red flags) and aCallTraceshowing which DLLs made the call.
Event 10 is extremely noisy if logged unfiltered, since security products and system processes open each other all the time. A good configuration includes only access to sensitive targets such as LSASS and excludes known-good sources.
Go deeper:
MITRE ATT&CK T1055 — Process Injection — the injection family event 8 helps detect.
MITRE ATT&CK T1003.001 — LSASS Memory — credential dumping from LSASS, with detection guidance.
DLL injection — Wikipedia — how CreateRemoteThread is used to load code into another process.