// REFERENCE
Sysmon 1 — Process creation
Log: Sysmon/Operational
High risk
Process creation logged by Sysmon, richer than 4688: it includes CommandLine, ParentImage, Hashes and OriginalFileName. It's the backbone of most endpoint hunting: anomalous parent-child chains, LOLBins and renamed binaries.
Related tools
Work with this in:
Related
3
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 10
Sysmon 10 — Process access 11
Sysmon 11 — File created 13
Sysmon 13 — Registry value set
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 10
Sysmon 10 — Process access 11
Sysmon 11 — File created 13
Sysmon 13 — Registry value set
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.