Skip to content
Sysmon

Sysmon Event ID 1: Process creation

Process creationSysmon event 1 logs every new process with full command line, hashes, parent process and a ProcessGuid for correlation. The backbone of endpoint hunting.
1
Event ID
1
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 1 means

Sysmon event 1 is written each time a process starts. Compared with Security event 4688 it is richer by default: the full CommandLine, the ParentImage and ParentCommandLine, file hashes, PE version information (OriginalFileName, Description, Company) and the IntegrityLevel all come in one record, without extra audit policy.

The key field is ProcessGuid. Process IDs are reused, but the GUID is unique per process instance, so it links this record to everything the process did afterwards in Sysmon: network connections (3), image loads (7), file creations (11), registry writes (12–14), DNS queries (22) and termination (5). ParentProcessGuid walks the tree upwards.

LogonId matches the TargetLogonId of the Security 4624 that created the session, which ties a process back to a logon type and source IP. On busy hosts event 1 is high volume; most configurations exclude well-known system and software-update processes.

When it is logged

Audit policy / configuration

Sysmon installed; process creation is logged by default once Sysmon runs. Filter with <ProcessCreate onmatch="include|exclude"> rules in the Sysmon configuration.

Hashes is only filled when HashAlgorithms is configured (MD5, SHA1, SHA256, IMPHASH or *). ParentUser was added in later Sysmon versions; older logs lack it. Events live in Microsoft-Windows-Sysmon/Operational.

Key fields

FieldWhat it tells you
UtcTimeProcess start time in UTC, as recorded by Sysmon (independent of the event's TimeCreated).
ProcessGuidUnique ID of this process instance. Pivot on it across all Sysmon events.
ProcessIdPID of the new process. Reused by Windows, so prefer ProcessGuid for correlation.
ImageFull path of the executable. Check for system binary names running from user-writable folders.
OriginalFileNameInternal file name from the PE version resource. If it differs from the Image file name (for example Image is svchost.exe but OriginalFileName is PsExec.exe), the binary was renamed.
CommandLineFull command line. The most valuable field for spotting encoded PowerShell, LOLBins and tool arguments.
CurrentDirectoryWorking directory of the process; temp or public folders are worth a look.
UserAccount the process runs as, in DOMAIN\user form.
LogonIdLogon session of the process; matches TargetLogonId in Security 4624.
IntegrityLevelMandatory integrity level of the process token, e.g. Low, Medium, High (elevated administrator) or System.
HashesComma-separated hashes of the image, e.g. SHA256=...,IMPHASH=..., depending on HashAlgorithms. Use them for reputation lookups and fleet-wide prevalence.
ParentProcessGuidProcessGuid of the parent. Use it to rebuild the process tree.
ParentImagePath of the parent process. Unusual parent-child pairs are a classic detection.
ParentCommandLineCommand line of the parent, useful when the parent is a script host or service wrapper.
ParentUserAccount of the parent process (newer Sysmon versions).

Common benign sources

  • Software updaters, installers (msiexec.exe) and management agents spawning many short-lived processes.
  • Administrators running cmd.exe, powershell.exe and built-in tools from an elevated console.
  • Scheduled tasks started by svchost.exe and services started by services.exe.

What attackers do that produces it

  • Office applications, browsers or PDF readers spawning cmd.exe, powershell.exe, wscript.exe, mshta.exe or rundll32.exe after a user opens a malicious document.
  • PowerShell with -EncodedCommand, -nop -w hidden or download cradles in the CommandLine.
  • Remote execution artifacts such as wmiprvse.exe spawning cmd.exe, services.exe spawning a random binary from C:\Windows, or PSEXESVC.exe children.
  • Renamed tools where OriginalFileName does not match the Image name.
  • Credential dumping commands such as rundll32.exe comsvcs.dll, MiniDump against LSASS.

Investigation tips

  • Rebuild the process tree with ProcessGuid and ParentProcessGuid instead of PIDs.
  • Look up Hashes for reputation and count how many hosts ran the same hash.
  • Pivot on ProcessGuid to events 3, 11, 13 and 22 to see what the process connected to, wrote and resolved.
  • Match LogonId to Security 4624 to learn how the user logged on and from where.
  • Compare Image path, OriginalFileName and Company to catch masquerading binaries.

MITRE ATT&CK techniques

TechniqueTactics
T1059 Command and Scripting InterpreterExecution
T1059.001 Command and Scripting Interpreter: PowerShellExecution
T1059.003 Command and Scripting Interpreter: Windows Command ShellExecution
T1218 System Binary Proxy ExecutionStealth
T1036.003 Masquerading: Rename Legitimate UtilitiesStealth
T1047 Windows Management InstrumentationExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1182 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • Critical · 24
  • High · 587
  • Medium · 512
  • Low · 58
  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideSysmon Event ID 1 explained: process creation for DFIR triage

Sources and further reading