← All cheat sheets

SYSMON

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

Sysmon (System Monitor) is a Windows system service for security monitoring.
Essential for endpoint detection and forensics.

INSTALLATION#


            

DOWNLOAD#

# From Sysinternals
https://docs.microsoft.com/sysinternals/downloads/sysmon

INSTALL#

# Basic install
sysmon64.exe -i

# With config
sysmon64.exe -i config.xml

# Accept EULA
sysmon64.exe -accepteula -i config.xml

UPDATE CONFIG#

sysmon64.exe -c config.xml

UNINSTALL#

sysmon64.exe -u

CHECK STATUS#

sysmon64.exe -s

EVENT IDS#


            

EVENT ID 1 - PROCESS CREATION#

# Logs when a process is created
# Key fields:
- ProcessId
- Image (path)
- CommandLine
- ParentImage
- ParentCommandLine
- User
- Hashes
- CurrentDirectory
- IntegrityLevel

EVENT ID 2 - FILE CREATION TIME CHANGED#

# Timestomping detection
# Key fields:
- TargetFilename
- CreationUtcTime
- PreviousCreationUtcTime

EVENT ID 3 - NETWORK CONNECTION#

# TCP/UDP connections
# Key fields:
- Image
- SourceIp, SourcePort
- DestinationIp, DestinationPort
- Protocol
- User

EVENT ID 4 - SYSMON SERVICE STATE#

# Sysmon service state changes

EVENT ID 5 - PROCESS TERMINATED#

# Process termination
# Key fields:
- ProcessId
- Image

EVENT ID 6 - DRIVER LOADED#

# Kernel driver loaded
# Key fields:
- ImageLoaded
- Hashes
- Signed
- Signature

EVENT ID 7 - IMAGE LOADED (DLL)#

# DLL loaded into process
# Key fields:
- Image
- ImageLoaded
- Hashes
- Signed

EVENT ID 8 - CREATE REMOTE THREAD#

# Thread created in another process
# Key fields:
- SourceImage
- TargetImage
- NewThreadId
- StartAddress

EVENT ID 9 - RAW ACCESS READ#

# Raw disk access
# Key fields:
- Image
- Device

EVENT ID 10 - PROCESS ACCESS#

# Process opened by another process
# Key fields:
- SourceImage
- TargetImage
- GrantedAccess
- CallTrace

EVENT ID 11 - FILE CREATE#

# File created
# Key fields:
- Image
- TargetFilename
- CreationUtcTime

EVENT ID 12 - REGISTRY EVENT (CREATE/DELETE)#

# Registry key/value created or deleted
# Key fields:
- EventType
- Image
- TargetObject

EVENT ID 13 - REGISTRY VALUE SET#

# Registry value set
# Key fields:
- Image
- TargetObject
- Details

EVENT ID 14 - REGISTRY RENAME#

# Registry key/value renamed

EVENT ID 15 - FILE CREATE STREAM HASH#

# Alternate data stream created
# Key fields:
- TargetFilename
- Hash
- Contents

EVENT ID 17 - PIPE CREATED#

# Named pipe created
# Key fields:
- Image
- PipeName

EVENT ID 18 - PIPE CONNECTED#

# Named pipe connection
# Key fields:
- Image
- PipeName

EVENT ID 19 - WMI EVENT FILTER#

# WMI event filter registered

EVENT ID 20 - WMI EVENT CONSUMER#

# WMI event consumer registered

EVENT ID 21 - WMI EVENT CONSUMER TO FILTER#

# WMI consumer bound to filter

EVENT ID 22 - DNS QUERY#

# DNS query (Win 8.1+)
# Key fields:
- Image
- QueryName
- QueryResults

EVENT ID 23 - FILE DELETE (ARCHIVED)#

# File deleted and archived to recycle bin

EVENT ID 24 - CLIPBOARD CHANGE#

# Clipboard contents captured

EVENT ID 25 - PROCESS TAMPERING#

# Process hollowing/herpaderping

EVENT ID 26 - FILE DELETE LOGGED#

# File deletion logged

EVENT ID 27 - FILE BLOCK EXECUTABLE#

# Blocked executable write

EVENT ID 28 - FILE BLOCK SHREDDING#

# Blocked file shredding

EVENT ID 29 - FILE EXECUTABLE DETECTED#

# Executable file detected

CONFIGURATION#


            

SAMPLE CONFIG#

<Sysmon schemaversion="4.90">
  <HashAlgorithms>md5,sha256,IMPHASH</HashAlgorithms>
  <CheckRevocation/>
  <EventFiltering>
    <!-- Process Creation -->
    <RuleGroup name="" groupRelation="or">
      <ProcessCreate onmatch="include">
        <Image condition="end with">powershell.exe</Image>
        <Image condition="end with">cmd.exe</Image>
        <CommandLine condition="contains">-enc</CommandLine>
      </ProcessCreate>
    </RuleGroup>

    <!-- Network Connections -->
    <RuleGroup name="" groupRelation="or">
      <NetworkConnect onmatch="include">
        <DestinationPort>4444</DestinationPort>
        <DestinationPort>5555</DestinationPort>
      </NetworkConnect>
    </RuleGroup>
  </EventFiltering>
</Sysmon>

FILTER CONDITIONS#

is                  Exact match
is not              Not exact match
contains            Contains string
contains any        Contains any of
contains all        Contains all of
excludes            Does not contain
excludes any        Excludes any of
excludes all        Excludes all of
begin with          Starts with
end with            Ends with
less than           Numeric less than
more than           Numeric more than
image               Process path match

            

SYSMON-MODULAR#

# https://github.com/olafhartong/sysmon-modular
# Modular configuration

SWIFTONSECURITY#

# https://github.com/SwiftOnSecurity/sysmon-config
# Community maintained config

HUNTING QUERIES#


            

POWERSHELL ENCODED#

Event ID 1
CommandLine contains "-enc" OR "-encoded"

PROCESS INJECTION#

Event ID 8 (CreateRemoteThread)
Event ID 10 (Process Access with specific access rights)

LSASS ACCESS#

Event ID 10
TargetImage contains "lsass.exe"
GrantedAccess: 0x1010, 0x1038, 0x1fffff

SUSPICIOUS PARENTS#

Event ID 1
ParentImage contains "winword.exe"
Image contains "powershell.exe" OR "cmd.exe"

NAMED PIPE#

Event ID 17, 18
PipeName contains "\\msagent" OR "\\isapi" (Cobalt Strike)

WMI PERSISTENCE#

Event ID 19, 20, 21

DNS QUERIES#

Event ID 22
QueryName length > 50 (potential tunneling)

SCHEDULED TASKS#

Event ID 1
Image contains "schtasks.exe"
CommandLine contains "/create"

LOG LOCATIONS#

# Event Viewer path
Applications and Services Logs
  -> Microsoft
    -> Windows
      -> Sysmon
        -> Operational

# Log file
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Sysmon%4Operational.evtx

POWERSHELL QUERIES#

# Get all Sysmon events
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational"

# Process creation
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" |
Where-Object {$_.Id -eq 1}

# Filter by time
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" -MaxEvents 100 |
Where-Object {$_.TimeCreated -gt (Get-Date).AddHours(-1)}

# Search command line
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" |
Where-Object {$_.Id -eq 1 -and $_.Message -like "*powershell*"}

QUICK REFERENCE#

sysmon64.exe -i config.xml           # Install with config
sysmon64.exe -c config.xml           # Update config
sysmon64.exe -s                      # Check status
sysmon64.exe -u                      # Uninstall

Event ID 1:  Process Create
Event ID 3:  Network Connect
Event ID 7:  Image Load (DLL)
Event ID 8:  CreateRemoteThread
Event ID 10: Process Access
Event ID 11: File Create
Event ID 12-14: Registry
Event ID 22: DNS Query

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.