LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Which Sysmon event IDs should you know, and what does each one record?

1 process create, 3 network connection, 5 process terminated, 7 image (DLL) loaded, 8 CreateRemoteThread, 10 process access, 11 file create, 12–14 registry, 22 DNS query, 23 file delete, plus 2 for changed file creation times.

ID Event Why it is interesting
1 Process creation What ran, with which command line and parent
2 File creation time changed Timestomping, hiding a dropped file
3 Network connection Which process talks to where
4 Sysmon service state changed Someone stopping the sensor
5 Process terminated Process lifetime
6 Driver loaded Rootkits, unsigned drivers
7 Image loaded DLL side-loading, injected libraries
8 CreateRemoteThread Code injection into another process
9 RawAccessRead Reading a disk directly, bypassing file locks
10 ProcessAccess Credential dumping from LSASS
11 FileCreate Dropped payloads
12 / 13 / 14 Registry create-delete / value set / rename Persistence in Run keys, services
15 FileCreateStreamHash Alternate data streams, downloaded-file markers
17 / 18 Pipe created / connected Lateral movement tooling
19–21 WMI event filter / consumer / binding WMI persistence
22 DNS query Which process resolved which domain
23 FileDelete Deleted files (archived)

Tip: the low numbers follow a process's life: born (1), talks (3), dies (5). The high-value attack signals cluster around 8 and 10 (touching another process) and 12–14 (the registry).

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026