Skip to content
Sysmon

Sysmon Event ID 10: Process accessed

ProcessAccessSysmon event 10 logs one process opening a handle to another, with the access mask and call stack. The go-to event for LSASS credential dumping.
10
Event ID
10
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 10 means

Sysmon event 10 records a process opening another process, with the rights it obtained (GrantedAccess) and the call stack that led to the open (CallTrace). Reading or writing another process's memory always starts with such a handle.

Its best-known use is detecting credential theft from lsass.exe: tools like Mimikatz, ProcDump or comsvcs.dll MiniDump must open LSASS with memory-read rights. The CallTrace adds context — a stack through dbghelp.dll or dbgcore.dll points to a minidump, and UNKNOWN frames mean the call came from memory not backed by a module, such as injected shellcode.

Unfiltered, the event is extremely noisy (security products and system processes open other processes constantly). Configure it for sensitive targets such as lsass.exe and exclude known scanners.

When it is logged

Audit policy / configuration

Sysmon installed with a <ProcessAccess> rule in the configuration, typically including TargetImage lsass.exe and excluding known security tools.

Key fields

FieldWhat it tells you
SourceProcessGUIDGUID of the process that opened the handle (note the upper-case GUID in this event).
SourceProcessIdPID of the source process.
SourceThreadIdThread that opened the handle.
SourceImageExecutable of the source process.
TargetProcessGUIDGUID of the process that was opened.
TargetImageExecutable of the target, e.g. C:\Windows\system32\lsass.exe.
GrantedAccessAccess mask granted. Bits of interest are PROCESS_VM_READ (0x10), PROCESS_VM_WRITE (0x20), PROCESS_VM_OPERATION (0x8) and PROCESS_CREATE_THREAD (0x2).
ValueMeaning
0x1000PROCESS_QUERY_LIMITED_INFORMATION only. Very common and usually benign.
0x1010Limited query + VM_READ. Enough to read LSASS memory; the classic mask of Mimikatz sekurlsa commands.
0x1410Query information + limited query + VM_READ. Also associated with credential dumping tools, but used by some legitimate software.
0x1438Query + VM_READ, VM_WRITE and VM_OPERATION — memory read and write, as used before injection.
0x1FFFFFPROCESS_ALL_ACCESS. Full control; suspicious against LSASS from anything but trusted tools.
CallTracePipe-separated stack of module+offset frames. Look for dbghelp.dll/dbgcore.dll (minidump), comsvcs.dll, or UNKNOWN frames (unbacked memory).
SourceUserAccount of the source process (newer Sysmon versions).
TargetUserAccount of the target process (newer Sysmon versions).

Common benign sources

  • Antivirus/EDR, MsMpEng.exe, and system processes such as csrss.exe, wininit.exe and svchost.exe querying LSASS.
  • Task Manager, Process Explorer and performance tools with query-only masks such as 0x1000.
  • Windows Error Reporting (WerFault.exe) reading a crashing process.

What attackers do that produces it

  • Mimikatz or a clone opening lsass.exe with 0x1010 or 0x1410.
  • rundll32.exe loading comsvcs.dll and calling MiniDump on LSASS, or procdump.exe -ma lsass.exe, with a CallTrace through dbghelp.dll/dbgcore.dll.
  • Injection preparation — a process gaining 0x1438 or wider on another process before event 8.

Investigation tips

  • Filter on TargetImage lsass.exe and exclude a baseline of known SourceImage values.
  • Read the CallTrace; UNKNOWN frames and minidump DLLs are strong indicators.
  • Pivot on SourceProcessGUID to event 1 and look for a dump file written by the same process (event 11).
  • Follow up with the account's logons from other hosts (Security 4624, 4648) after the dump time.

MITRE ATT&CK techniques

TechniqueTactics
T1003.001 OS Credential Dumping: LSASS MemoryCredential Access
T1055 Process InjectionStealth, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

23 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 18
  • Medium · 4
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideSysmon Event IDs 8 and 10: process injection and LSASS access

Sources and further reading