Sysmon

How to Analyze Sysmon Logs

What’s in a Sysmon event

Sysmon writes to the Windows Event Log under the Microsoft-Windows-Sysmon provider, using EventIDs 1 through 29 with Sysmon-specific EventData fields. LogTriage’s parser reads the XML export, resolves the provider namespace, and maps each EventID to a normalized event: EventID 1 (ProcessCreate) keeps the full CommandLine, EventID 3 (NetworkConnect) becomes DestinationIp:DestinationPort with the destination enriched against threat intelligence, EventID 10 (ProcessAccess) keeps the TargetImage, and EventID 22 (DNSQuery) keeps the QueryName. Because host telemetry has no user-agent, ASN, or web path, a curated host-attack signature set does the heavy scoring here.

What to look at first

  1. EventID 1 command lines. Search for -enc, -encodedcommand, FromBase64String, and other obfuscation. Encoded PowerShell floors to 70 in the scorer for a reason — it is rarely benign.
  2. EventID 10 with TargetImage: lsass.exe. A process opening LSASS is OS credential dumping; the SourceImage tells you the tool (a mimikatz.exe source is unambiguous).
  3. EventID 3 destinations. Cross-reference every DestinationIp against current threat intelligence; a non-standard port like 4444 corroborates a C2 beacon but the reputation of the destination is the detection.
  4. EventID 8 (CreateRemoteThread). Code injection into another process — a classic post-exploitation move that floors to 75.
  5. EventID 22 DNS queries. A QueryName like malware-c2.ru with a QueryResults matching a bad IP ties the domain and the connection together.

Common patterns and what they mean

PatternLikely meaning
EventID 1 with powershell -enc <base64>Obfuscated execution / loader (floor 70)
EventID 10 targeting lsass.exeCredential dumping (floor 80; Mimikatz source floors 90)
EventID 3 to a confirmed-malicious IP on port 4444C2 beaconing (TI floor 75)
EventID 8 CreateRemoteThread into a system processProcess injection (floor 75)
EventID 22 resolving a known-bad domainDNS-based C2 lookup

Where manual log review breaks down

Sysmon is deliberately verbose — it is meant to be a firehose for after-the-fact hunting — so the handful of events that represent an intrusion are buried in ordinary process and network activity. LogTriage applies its host-attack signatures to the normalized operation and target fields so that Mimikatz, LSASS access, process injection, and encoded PowerShell are floored to 70–90 regardless of whether the process ever touched an external IP, while EventID 3 destinations are floored via threat intelligence. The result is that a credential dump or a beacon is scored high even though a naive IP-and-path pipeline would score it near zero. See the Sysmon C2 beaconing use case and the published LSASS credential-dumping Sigma rule, LTR-0003.

Frequently Asked Questions

Which Sysmon EventIDs carry the most security value?
EventID 1 (ProcessCreate, with the full CommandLine), 3 (NetworkConnect, with DestinationIp/DestinationPort), 8 (CreateRemoteThread, a code-injection signal), 10 (ProcessAccess, which catches LSASS reads), and 22 (DNSQuery). LogTriage maps all of these; 8, 10, and 25 are treated as the highest-risk process events and 3 and 22 as network/DNS signals.
Why is EventID 1 CommandLine more useful than the image name?
Attackers routinely run legitimate binaries with malicious arguments — cmd.exe or powershell.exe with an encoded command. The image name alone (powershell.exe) looks benign; the command line (powershell -enc JABjAG...) does not. LogTriage's Sysmon parser deliberately prefers CommandLine over Image on EventID 1 so the high-signal payload is what downstream scoring sees.
How does Sysmon detect LSASS credential dumping?
EventID 10 (ProcessAccess) records one process opening a handle into another. When the TargetImage is lsass.exe, that is an attempt to read credential material from memory. LogTriage's host-attack signatures match lsass and floor the event's risk score to 80 (OS credential dumping, T1003.001); an offensive tool name like Mimikatz floors it to 90.
Does Sysmon namespaced XML parse correctly?
Yes. Sysmon writes each event under the Microsoft-Windows-Sysmon provider in the standard Windows event XML namespace. LogTriage's parser resolves both namespaced and bare element names, so EventID and TimeCreated are read correctly whether or not the export carries the namespace prefix.

Related Resources

See this detection run on a real report

Try the live demo with a pre-loaded malicious log set — no signup required — or upload your own log file and get a full AI-reviewed threat report in minutes.