SYSMON
Sysmon (System Monitor) is a Windows system service for security monitoring. Essential for endpoint detection and forensics.
INSTALLATION#
DOWNLOAD#
# From Sysinternals https://docs.microsoft.com/sysinternals/downloads/sysmon
INSTALL#
# Basic install sysmon64.exe -i # With config sysmon64.exe -i config.xml # Accept EULA sysmon64.exe -accepteula -i config.xml
UPDATE CONFIG#
sysmon64.exe -c config.xml
UNINSTALL#
sysmon64.exe -u
CHECK STATUS#
sysmon64.exe -s
EVENT IDS#
EVENT ID 1 - PROCESS CREATION#
# Logs when a process is created # Key fields: - ProcessId - Image (path) - CommandLine - ParentImage - ParentCommandLine - User - Hashes - CurrentDirectory - IntegrityLevel
EVENT ID 2 - FILE CREATION TIME CHANGED#
# Timestomping detection # Key fields: - TargetFilename - CreationUtcTime - PreviousCreationUtcTime
EVENT ID 3 - NETWORK CONNECTION#
# TCP/UDP connections # Key fields: - Image - SourceIp, SourcePort - DestinationIp, DestinationPort - Protocol - User
EVENT ID 4 - SYSMON SERVICE STATE#
# Sysmon service state changes
EVENT ID 5 - PROCESS TERMINATED#
# Process termination # Key fields: - ProcessId - Image
EVENT ID 6 - DRIVER LOADED#
# Kernel driver loaded # Key fields: - ImageLoaded - Hashes - Signed - Signature
EVENT ID 7 - IMAGE LOADED (DLL)#
# DLL loaded into process # Key fields: - Image - ImageLoaded - Hashes - Signed
EVENT ID 8 - CREATE REMOTE THREAD#
# Thread created in another process # Key fields: - SourceImage - TargetImage - NewThreadId - StartAddress
EVENT ID 9 - RAW ACCESS READ#
# Raw disk access # Key fields: - Image - Device
EVENT ID 10 - PROCESS ACCESS#
# Process opened by another process # Key fields: - SourceImage - TargetImage - GrantedAccess - CallTrace
EVENT ID 11 - FILE CREATE#
# File created # Key fields: - Image - TargetFilename - CreationUtcTime
EVENT ID 12 - REGISTRY EVENT (CREATE/DELETE)#
# Registry key/value created or deleted # Key fields: - EventType - Image - TargetObject
EVENT ID 13 - REGISTRY VALUE SET#
# Registry value set # Key fields: - Image - TargetObject - Details
EVENT ID 14 - REGISTRY RENAME#
# Registry key/value renamed
EVENT ID 15 - FILE CREATE STREAM HASH#
# Alternate data stream created # Key fields: - TargetFilename - Hash - Contents
EVENT ID 17 - PIPE CREATED#
# Named pipe created # Key fields: - Image - PipeName
EVENT ID 18 - PIPE CONNECTED#
# Named pipe connection # Key fields: - Image - PipeName
EVENT ID 19 - WMI EVENT FILTER#
# WMI event filter registered
EVENT ID 20 - WMI EVENT CONSUMER#
# WMI event consumer registered
EVENT ID 21 - WMI EVENT CONSUMER TO FILTER#
# WMI consumer bound to filter
EVENT ID 22 - DNS QUERY#
# DNS query (Win 8.1+) # Key fields: - Image - QueryName - QueryResults
EVENT ID 23 - FILE DELETE (ARCHIVED)#
# File deleted and archived to recycle bin
EVENT ID 24 - CLIPBOARD CHANGE#
# Clipboard contents captured
EVENT ID 25 - PROCESS TAMPERING#
# Process hollowing/herpaderping
EVENT ID 26 - FILE DELETE LOGGED#
# File deletion logged
EVENT ID 27 - FILE BLOCK EXECUTABLE#
# Blocked executable write
EVENT ID 28 - FILE BLOCK SHREDDING#
# Blocked file shredding
EVENT ID 29 - FILE EXECUTABLE DETECTED#
# Executable file detected
CONFIGURATION#
SAMPLE CONFIG#
<Sysmon schemaversion="4.90">
<HashAlgorithms>md5,sha256,IMPHASH</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Process Creation -->
<RuleGroup name="" groupRelation="or">
<ProcessCreate onmatch="include">
<Image condition="end with">powershell.exe</Image>
<Image condition="end with">cmd.exe</Image>
<CommandLine condition="contains">-enc</CommandLine>
</ProcessCreate>
</RuleGroup>
<!-- Network Connections -->
<RuleGroup name="" groupRelation="or">
<NetworkConnect onmatch="include">
<DestinationPort>4444</DestinationPort>
<DestinationPort>5555</DestinationPort>
</NetworkConnect>
</RuleGroup>
</EventFiltering>
</Sysmon>
FILTER CONDITIONS#
is Exact match is not Not exact match contains Contains string contains any Contains any of contains all Contains all of excludes Does not contain excludes any Excludes any of excludes all Excludes all of begin with Starts with end with Ends with less than Numeric less than more than Numeric more than image Process path match
POPULAR CONFIGS#
SYSMON-MODULAR#
# https://github.com/olafhartong/sysmon-modular # Modular configuration
SWIFTONSECURITY#
# https://github.com/SwiftOnSecurity/sysmon-config # Community maintained config
HUNTING QUERIES#
POWERSHELL ENCODED#
Event ID 1 CommandLine contains "-enc" OR "-encoded"
PROCESS INJECTION#
Event ID 8 (CreateRemoteThread) Event ID 10 (Process Access with specific access rights)
LSASS ACCESS#
Event ID 10 TargetImage contains "lsass.exe" GrantedAccess: 0x1010, 0x1038, 0x1fffff
SUSPICIOUS PARENTS#
Event ID 1 ParentImage contains "winword.exe" Image contains "powershell.exe" OR "cmd.exe"
NAMED PIPE#
Event ID 17, 18 PipeName contains "\\msagent" OR "\\isapi" (Cobalt Strike)
WMI PERSISTENCE#
Event ID 19, 20, 21
DNS QUERIES#
Event ID 22 QueryName length > 50 (potential tunneling)
SCHEDULED TASKS#
Event ID 1 Image contains "schtasks.exe" CommandLine contains "/create"
LOG LOCATIONS#
# Event Viewer path
Applications and Services Logs
-> Microsoft
-> Windows
-> Sysmon
-> Operational
# Log file
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Sysmon%4Operational.evtx
POWERSHELL QUERIES#
# Get all Sysmon events
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational"
# Process creation
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" |
Where-Object {$_.Id -eq 1}
# Filter by time
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" -MaxEvents 100 |
Where-Object {$_.TimeCreated -gt (Get-Date).AddHours(-1)}
# Search command line
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" |
Where-Object {$_.Id -eq 1 -and $_.Message -like "*powershell*"}
QUICK REFERENCE#
sysmon64.exe -i config.xml # Install with config sysmon64.exe -c config.xml # Update config sysmon64.exe -s # Check status sysmon64.exe -u # Uninstall Event ID 1: Process Create Event ID 3: Network Connect Event ID 7: Image Load (DLL) Event ID 8: CreateRemoteThread Event ID 10: Process Access Event ID 11: File Create Event ID 12-14: Registry Event ID 22: DNS Query
SYSMON CHEATSHEET
=================
Source: https://cheatsheet.johlem.net
Sysmon (System Monitor) is a Windows system service for security monitoring.
Essential for endpoint detection and forensics.
INSTALLATION
============
DOWNLOAD
--------
# From Sysinternals
https://docs.microsoft.com/sysinternals/downloads/sysmon
INSTALL
-------
# Basic install
sysmon64.exe -i
# With config
sysmon64.exe -i config.xml
# Accept EULA
sysmon64.exe -accepteula -i config.xml
UPDATE CONFIG
-------------
sysmon64.exe -c config.xml
UNINSTALL
---------
sysmon64.exe -u
CHECK STATUS
------------
sysmon64.exe -s
EVENT IDS
=========
EVENT ID 1 - PROCESS CREATION
-----------------------------
# Logs when a process is created
# Key fields:
- ProcessId
- Image (path)
- CommandLine
- ParentImage
- ParentCommandLine
- User
- Hashes
- CurrentDirectory
- IntegrityLevel
EVENT ID 2 - FILE CREATION TIME CHANGED
---------------------------------------
# Timestomping detection
# Key fields:
- TargetFilename
- CreationUtcTime
- PreviousCreationUtcTime
EVENT ID 3 - NETWORK CONNECTION
-------------------------------
# TCP/UDP connections
# Key fields:
- Image
- SourceIp, SourcePort
- DestinationIp, DestinationPort
- Protocol
- User
EVENT ID 4 - SYSMON SERVICE STATE
---------------------------------
# Sysmon service state changes
EVENT ID 5 - PROCESS TERMINATED
-------------------------------
# Process termination
# Key fields:
- ProcessId
- Image
EVENT ID 6 - DRIVER LOADED
--------------------------
# Kernel driver loaded
# Key fields:
- ImageLoaded
- Hashes
- Signed
- Signature
EVENT ID 7 - IMAGE LOADED (DLL)
-------------------------------
# DLL loaded into process
# Key fields:
- Image
- ImageLoaded
- Hashes
- Signed
EVENT ID 8 - CREATE REMOTE THREAD
---------------------------------
# Thread created in another process
# Key fields:
- SourceImage
- TargetImage
- NewThreadId
- StartAddress
EVENT ID 9 - RAW ACCESS READ
----------------------------
# Raw disk access
# Key fields:
- Image
- Device
EVENT ID 10 - PROCESS ACCESS
----------------------------
# Process opened by another process
# Key fields:
- SourceImage
- TargetImage
- GrantedAccess
- CallTrace
EVENT ID 11 - FILE CREATE
-------------------------
# File created
# Key fields:
- Image
- TargetFilename
- CreationUtcTime
EVENT ID 12 - REGISTRY EVENT (CREATE/DELETE)
--------------------------------------------
# Registry key/value created or deleted
# Key fields:
- EventType
- Image
- TargetObject
EVENT ID 13 - REGISTRY VALUE SET
--------------------------------
# Registry value set
# Key fields:
- Image
- TargetObject
- Details
EVENT ID 14 - REGISTRY RENAME
-----------------------------
# Registry key/value renamed
EVENT ID 15 - FILE CREATE STREAM HASH
-------------------------------------
# Alternate data stream created
# Key fields:
- TargetFilename
- Hash
- Contents
EVENT ID 17 - PIPE CREATED
--------------------------
# Named pipe created
# Key fields:
- Image
- PipeName
EVENT ID 18 - PIPE CONNECTED
----------------------------
# Named pipe connection
# Key fields:
- Image
- PipeName
EVENT ID 19 - WMI EVENT FILTER
------------------------------
# WMI event filter registered
EVENT ID 20 - WMI EVENT CONSUMER
--------------------------------
# WMI event consumer registered
EVENT ID 21 - WMI EVENT CONSUMER TO FILTER
------------------------------------------
# WMI consumer bound to filter
EVENT ID 22 - DNS QUERY
-----------------------
# DNS query (Win 8.1+)
# Key fields:
- Image
- QueryName
- QueryResults
EVENT ID 23 - FILE DELETE (ARCHIVED)
------------------------------------
# File deleted and archived to recycle bin
EVENT ID 24 - CLIPBOARD CHANGE
------------------------------
# Clipboard contents captured
EVENT ID 25 - PROCESS TAMPERING
-------------------------------
# Process hollowing/herpaderping
EVENT ID 26 - FILE DELETE LOGGED
--------------------------------
# File deletion logged
EVENT ID 27 - FILE BLOCK EXECUTABLE
-----------------------------------
# Blocked executable write
EVENT ID 28 - FILE BLOCK SHREDDING
----------------------------------
# Blocked file shredding
EVENT ID 29 - FILE EXECUTABLE DETECTED
--------------------------------------
# Executable file detected
CONFIGURATION
=============
SAMPLE CONFIG
-------------
<Sysmon schemaversion="4.90">
<HashAlgorithms>md5,sha256,IMPHASH</HashAlgorithms>
<CheckRevocation/>
<EventFiltering>
<!-- Process Creation -->
<RuleGroup name="" groupRelation="or">
<ProcessCreate onmatch="include">
<Image condition="end with">powershell.exe</Image>
<Image condition="end with">cmd.exe</Image>
<CommandLine condition="contains">-enc</CommandLine>
</ProcessCreate>
</RuleGroup>
<!-- Network Connections -->
<RuleGroup name="" groupRelation="or">
<NetworkConnect onmatch="include">
<DestinationPort>4444</DestinationPort>
<DestinationPort>5555</DestinationPort>
</NetworkConnect>
</RuleGroup>
</EventFiltering>
</Sysmon>
FILTER CONDITIONS
-----------------
is Exact match
is not Not exact match
contains Contains string
contains any Contains any of
contains all Contains all of
excludes Does not contain
excludes any Excludes any of
excludes all Excludes all of
begin with Starts with
end with Ends with
less than Numeric less than
more than Numeric more than
image Process path match
POPULAR CONFIGS
===============
SYSMON-MODULAR
--------------
# https://github.com/olafhartong/sysmon-modular
# Modular configuration
SWIFTONSECURITY
---------------
# https://github.com/SwiftOnSecurity/sysmon-config
# Community maintained config
HUNTING QUERIES
===============
POWERSHELL ENCODED
------------------
Event ID 1
CommandLine contains "-enc" OR "-encoded"
PROCESS INJECTION
-----------------
Event ID 8 (CreateRemoteThread)
Event ID 10 (Process Access with specific access rights)
LSASS ACCESS
------------
Event ID 10
TargetImage contains "lsass.exe"
GrantedAccess: 0x1010, 0x1038, 0x1fffff
SUSPICIOUS PARENTS
------------------
Event ID 1
ParentImage contains "winword.exe"
Image contains "powershell.exe" OR "cmd.exe"
NAMED PIPE
----------
Event ID 17, 18
PipeName contains "\\msagent" OR "\\isapi" (Cobalt Strike)
WMI PERSISTENCE
---------------
Event ID 19, 20, 21
DNS QUERIES
-----------
Event ID 22
QueryName length > 50 (potential tunneling)
SCHEDULED TASKS
---------------
Event ID 1
Image contains "schtasks.exe"
CommandLine contains "/create"
LOG LOCATIONS
=============
# Event Viewer path
Applications and Services Logs
-> Microsoft
-> Windows
-> Sysmon
-> Operational
# Log file
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Sysmon%4Operational.evtx
POWERSHELL QUERIES
==================
# Get all Sysmon events
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational"
# Process creation
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" |
Where-Object {$_.Id -eq 1}
# Filter by time
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" -MaxEvents 100 |
Where-Object {$_.TimeCreated -gt (Get-Date).AddHours(-1)}
# Search command line
Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" |
Where-Object {$_.Id -eq 1 -and $_.Message -like "*powershell*"}
QUICK REFERENCE
---------------
sysmon64.exe -i config.xml # Install with config
sysmon64.exe -c config.xml # Update config
sysmon64.exe -s # Check status
sysmon64.exe -u # Uninstall
Event ID 1: Process Create
Event ID 3: Network Connect
Event ID 7: Image Load (DLL)
Event ID 8: CreateRemoteThread
Event ID 10: Process Access
Event ID 11: File Create
Event ID 12-14: Registry
Event ID 22: DNS Query
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.