Sysmon Event ID 10: Process accessed
- Event ID
- 10
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 10 means
Sysmon event 10 records a process opening another process, with the rights it obtained (GrantedAccess) and the call stack that led to the open (CallTrace). Reading or writing another process's memory always starts with such a handle.
Its best-known use is detecting credential theft from lsass.exe: tools like Mimikatz, ProcDump or comsvcs.dll MiniDump must open LSASS with memory-read rights. The CallTrace adds context — a stack through dbghelp.dll or dbgcore.dll points to a minidump, and UNKNOWN frames mean the call came from memory not backed by a module, such as injected shellcode.
Unfiltered, the event is extremely noisy (security products and system processes open other processes constantly). Configure it for sensitive targets such as lsass.exe and exclude known scanners.
When it is logged
Sysmon installed with a <ProcessAccess> rule in the configuration, typically including TargetImage lsass.exe and excluding known security tools.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SourceProcessGUID | GUID of the process that opened the handle (note the upper-case GUID in this event). | ||||||||||||
| SourceProcessId | PID of the source process. | ||||||||||||
| SourceThreadId | Thread that opened the handle. | ||||||||||||
| SourceImage | Executable of the source process. | ||||||||||||
| TargetProcessGUID | GUID of the process that was opened. | ||||||||||||
| TargetImage | Executable of the target, e.g. C:\Windows\system32\lsass.exe. | ||||||||||||
| GrantedAccess | Access mask granted. Bits of interest are PROCESS_VM_READ (0x10), PROCESS_VM_WRITE (0x20), PROCESS_VM_OPERATION (0x8) and PROCESS_CREATE_THREAD (0x2).
| ||||||||||||
| CallTrace | Pipe-separated stack of module+offset frames. Look for dbghelp.dll/dbgcore.dll (minidump), comsvcs.dll, or UNKNOWN frames (unbacked memory). | ||||||||||||
| SourceUser | Account of the source process (newer Sysmon versions). | ||||||||||||
| TargetUser | Account of the target process (newer Sysmon versions). |
Common benign sources
- Antivirus/EDR,
MsMpEng.exe, and system processes such ascsrss.exe,wininit.exeandsvchost.exequerying LSASS. - Task Manager, Process Explorer and performance tools with query-only masks such as
0x1000. - Windows Error Reporting (
WerFault.exe) reading a crashing process.
What attackers do that produces it
- Mimikatz or a clone opening
lsass.exewith0x1010or0x1410. rundll32.exeloadingcomsvcs.dlland calling MiniDump on LSASS, orprocdump.exe -ma lsass.exe, with a CallTrace throughdbghelp.dll/dbgcore.dll.- Injection preparation — a process gaining
0x1438or wider on another process before event 8.
Investigation tips
- Filter on TargetImage
lsass.exeand exclude a baseline of known SourceImage values. - Read the CallTrace;
UNKNOWNframes and minidump DLLs are strong indicators. - Pivot on SourceProcessGUID to event 1 and look for a dump file written by the same process (event 11).
- Follow up with the account's logons from other hosts (Security 4624, 4648) after the dump time.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
23 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 18
- Medium · 4
- Low · 1
- HighCMSTP Execution Process AccessRule by Nik Seetharaman, SigmaHQ, DRL 1.1
- HighCredential Dumping Activity By Python Based ToolRule by Bhabesh Raj, Jonhnathan Ribeiro, SigmaHQ, DRL 1.1
- HighCredential Dumping Attempt Via SvchostRule by Florent Labouyrie, SigmaHQ, DRL 1.1
- HighCredential Dumping Attempt Via WerFaultRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - CobaltStrike BOF Injection PatternRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - Generic Process AccessRule by Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, SigmaHQ, DRL 1.1
- HighHackTool - HandleKatz Duplicating LSASS HandleRule by Bhabesh Raj (rule), @thefLinkk, SigmaHQ, DRL 1.1
- HighHackTool - LittleCorporal Generated Maldoc InjectionRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighHackTool - SysmonEnte ExecutionRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighLSASS Access From Potentially White-Listed ProcessesRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighLSASS Memory Access by Tool With Dump Keyword In NameRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighLsass Memory Dump via Comsvcs DLLRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighRemote LSASS Process Access Through Windows Remote ManagementRule by Patryk Prauze - ING Tech, SigmaHQ, DRL 1.1
- HighSuspicious LSASS Access Via MalSecLogonRule by Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Process Access of MsMpEng by WerFaultSecure - EDR-FreezeRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Process Access to LSASS with Dbgcore/Dbghelp DLLsRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Svchost Process AccessRule by Tim Burrell, SigmaHQ, DRL 1.1
- HighUAC Bypass Using WOW64 Logger DLL HijackRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- MediumFunction Call From Undocumented COM Interface EditionUpgradeManagerRule by oscd.community, Dmitry Uchakin, SigmaHQ, DRL 1.1
- MediumPotential Credential Dumping Activity Via LSASSRule by Samir Bousseaden, Michael Haag, SigmaHQ, DRL 1.1
- MediumPotential Direct Syscall of NtOpenProcessRule by Christian Burkard (Nextron Systems), Tim Shelton (FP), SigmaHQ, DRL 1.1
- MediumPotentially Suspicious GrantedAccess Flags On LSASSRule by Florian Roth, Roberto Rodriguez, Dimitrios Slamaris, Mark Russinovich, Thomas Patzke, Teymur Kheirkhabarov, Sherif Eldeeb, James Dickenson, Aleksey Potapov, oscd.community, SigmaHQ, DRL 1.1
- LowUncommon Process Access Rights For Target ImageRule by Nasreddine Bencherchali (Nextron Systems), frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.