Sysmon Event ID 1: Process creation
- Event ID
- 1
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 1 means
Sysmon event 1 is written each time a process starts. Compared with Security event 4688 it is richer by default: the full CommandLine, the ParentImage and ParentCommandLine, file hashes, PE version information (OriginalFileName, Description, Company) and the IntegrityLevel all come in one record, without extra audit policy.
The key field is ProcessGuid. Process IDs are reused, but the GUID is unique per process instance, so it links this record to everything the process did afterwards in Sysmon: network connections (3), image loads (7), file creations (11), registry writes (12–14), DNS queries (22) and termination (5). ParentProcessGuid walks the tree upwards.
LogonId matches the TargetLogonId of the Security 4624 that created the session, which ties a process back to a logon type and source IP. On busy hosts event 1 is high volume; most configurations exclude well-known system and software-update processes.
When it is logged
Sysmon installed; process creation is logged by default once Sysmon runs. Filter with <ProcessCreate onmatch="include|exclude"> rules in the Sysmon configuration.
Hashes is only filled when HashAlgorithms is configured (MD5, SHA1, SHA256, IMPHASH or *). ParentUser was added in later Sysmon versions; older logs lack it. Events live in Microsoft-Windows-Sysmon/Operational.
Key fields
| Field | What it tells you |
|---|---|
| UtcTime | Process start time in UTC, as recorded by Sysmon (independent of the event's TimeCreated). |
| ProcessGuid | Unique ID of this process instance. Pivot on it across all Sysmon events. |
| ProcessId | PID of the new process. Reused by Windows, so prefer ProcessGuid for correlation. |
| Image | Full path of the executable. Check for system binary names running from user-writable folders. |
| OriginalFileName | Internal file name from the PE version resource. If it differs from the Image file name (for example Image is svchost.exe but OriginalFileName is PsExec.exe), the binary was renamed. |
| CommandLine | Full command line. The most valuable field for spotting encoded PowerShell, LOLBins and tool arguments. |
| CurrentDirectory | Working directory of the process; temp or public folders are worth a look. |
| User | Account the process runs as, in DOMAIN\user form. |
| LogonId | Logon session of the process; matches TargetLogonId in Security 4624. |
| IntegrityLevel | Mandatory integrity level of the process token, e.g. Low, Medium, High (elevated administrator) or System. |
| Hashes | Comma-separated hashes of the image, e.g. SHA256=...,IMPHASH=..., depending on HashAlgorithms. Use them for reputation lookups and fleet-wide prevalence. |
| ParentProcessGuid | ProcessGuid of the parent. Use it to rebuild the process tree. |
| ParentImage | Path of the parent process. Unusual parent-child pairs are a classic detection. |
| ParentCommandLine | Command line of the parent, useful when the parent is a script host or service wrapper. |
| ParentUser | Account of the parent process (newer Sysmon versions). |
Common benign sources
- Software updaters, installers (
msiexec.exe) and management agents spawning many short-lived processes. - Administrators running
cmd.exe,powershell.exeand built-in tools from an elevated console. - Scheduled tasks started by
svchost.exeand services started byservices.exe.
What attackers do that produces it
- Office applications, browsers or PDF readers spawning
cmd.exe,powershell.exe,wscript.exe,mshta.exeorrundll32.exeafter a user opens a malicious document. - PowerShell with
-EncodedCommand,-nop -w hiddenor download cradles in the CommandLine. - Remote execution artifacts such as
wmiprvse.exespawningcmd.exe,services.exespawning a random binary fromC:\Windows, orPSEXESVC.exechildren. - Renamed tools where
OriginalFileNamedoes not match theImagename. - Credential dumping commands such as
rundll32.exe comsvcs.dll, MiniDumpagainst LSASS.
Investigation tips
- Rebuild the process tree with ProcessGuid and ParentProcessGuid instead of PIDs.
- Look up
Hashesfor reputation and count how many hosts ran the same hash. - Pivot on ProcessGuid to events 3, 11, 13 and 22 to see what the process connected to, wrote and resolved.
- Match LogonId to Security 4624 to learn how the user logged on and from where.
- Compare
Imagepath,OriginalFileNameandCompanyto catch masquerading binaries.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1059 Command and Scripting Interpreter | Execution |
| T1059.001 Command and Scripting Interpreter: PowerShell | Execution |
| T1059.003 Command and Scripting Interpreter: Windows Command Shell | Execution |
| T1218 System Binary Proxy Execution | Stealth |
| T1036.003 Masquerading: Rename Legitimate Utilities | Stealth |
| T1047 Windows Management Instrumentation | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1182 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- Critical · 24
- High · 587
- Medium · 512
- Low · 58
- Info · 1
- CriticalDumpStack.log Defender EvasionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - DInjector PowerShell Cradle ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Dumpert Process Dumper ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Empire PowerShell UAC BypassRule by Ecco, SigmaHQ, DRL 1.1
- CriticalHackTool - F-Secure C3 Load by Rundll32Rule by Alfie Champion (ajpc500), SigmaHQ, DRL 1.1
- CriticalHackTool - Inveigh ExecutionRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - PurpleSharp ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Rubeus ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SafetyKatz ExecutionRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SecurityXploded ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SharpUp PrivEsc Tool ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Sliver C2 Implant Activity PatternRule by Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - SysmonEOP ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHackTool - Windows Credential Editor (WCE) ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalHacktool Execution - ImphashRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalPersistence Via Sticky Key BackdoorRule by Sreeman, SigmaHQ, DRL 1.1
- CriticalPotential Credential Dumping Via LSASS Process CloneRule by Florian Roth (Nextron Systems), Samir Bousseaden, SigmaHQ, DRL 1.1
- CriticalPotential SMB Relay Attack Tool ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalRenamed Whoami ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalSticky Key Like Backdoor ExecutionRule by Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, SigmaHQ, DRL 1.1
- CriticalSuspicious Child Process Of Veeam DabataseRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalSuspicious PowerShell Mailbox Export to ShareRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalTrustedPath UAC Bypass PatternRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- CriticalWMI Backdoor Exchange Transport AgentRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighAADInternals PowerShell Cmdlets Execution - ProccessCreationRule by Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.