Skip to content
Sysmon

Sysmon Event ID 25: Process tampering detected

ProcessTampering (Process image change)Sysmon event 25 fires when a process image is changed in memory or on disk, as in process hollowing or herpaderping. Rare and high-signal.
25
Event ID
25
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 25 means

Sysmon event 25 is generated when Sysmon detects process-hiding techniques: the in-memory image of a process no longer matches the file it was started from (process hollowing), or the file on disk was changed after the process was created (process herpaderping).

These techniques let malware run under the name of a legitimate executable, so event 1 alone may look clean. Type says what was detected. False positives exist — some software updates or self-modifying programs, and certain browsers or JIT-heavy applications — so baseline before alerting.

When it is logged

Audit policy / configuration

Sysmon 13.0 or later with a <ProcessTampering> rule in the configuration.

Key fields

FieldWhat it tells you
ProcessGuidProcess whose image was tampered with; pivot to its event 1.
ImageExecutable path the process claims to run.
TypeKind of tampering detected.
ValueMeaning
Image is replacedThe in-memory image differs from the file on disk (process hollowing and similar).
UserAccount of the process.

Common benign sources

  • Some browsers, installers and applications that modify their own images, depending on the version.

What attackers do that produces it

  • Loaders hollowing a legitimate process such as svchost.exe, RegAsm.exe or explorer.exe to host a payload.
  • Herpaderping tools that overwrite the file after starting the process to hide its real content.

Investigation tips

  • Pivot on ProcessGuid to event 1 and check the parent; a hollowed system binary usually has an odd parent.
  • Review the process's network (3) and DNS (22) activity, which reflects the real payload.
  • Capture process memory before remediation if possible.

MITRE ATT&CK techniques

TechniqueTactics
T1055.012 Process Injection: Process HollowingStealth, Privilege Escalation
T1055 Process InjectionStealth, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading