Quiz Entry - updated: 2026.09.24
Which Sysmon event IDs should you know, and what does each one record?
1 process create, 3 network connection, 5 process terminated, 7 image (DLL) loaded, 8 CreateRemoteThread, 10 process access, 11 file create, 12–14 registry, 22 DNS query, 23 file delete, plus 2 for changed file creation times.
| ID | Event | Why it is interesting |
|---|---|---|
| 1 | Process creation | What ran, with which command line and parent |
| 2 | File creation time changed | Timestomping, hiding a dropped file |
| 3 | Network connection | Which process talks to where |
| 4 | Sysmon service state changed | Someone stopping the sensor |
| 5 | Process terminated | Process lifetime |
| 6 | Driver loaded | Rootkits, unsigned drivers |
| 7 | Image loaded | DLL side-loading, injected libraries |
| 8 | CreateRemoteThread | Code injection into another process |
| 9 | RawAccessRead | Reading a disk directly, bypassing file locks |
| 10 | ProcessAccess | Credential dumping from LSASS |
| 11 | FileCreate | Dropped payloads |
| 12 / 13 / 14 | Registry create-delete / value set / rename | Persistence in Run keys, services |
| 15 | FileCreateStreamHash | Alternate data streams, downloaded-file markers |
| 17 / 18 | Pipe created / connected | Lateral movement tooling |
| 19–21 | WMI event filter / consumer / binding | WMI persistence |
| 22 | DNS query | Which process resolved which domain |
| 23 | FileDelete | Deleted files (archived) |
Tip: the low numbers follow a process's life: born (1), talks (3), dies (5). The high-value attack signals cluster around 8 and 10 (touching another process) and 12–14 (the registry).