Sysmon Event ID 25: Process tampering detected
- Event ID
- 25
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 25 means
Sysmon event 25 is generated when Sysmon detects process-hiding techniques: the in-memory image of a process no longer matches the file it was started from (process hollowing), or the file on disk was changed after the process was created (process herpaderping).
These techniques let malware run under the name of a legitimate executable, so event 1 alone may look clean. Type says what was detected. False positives exist — some software updates or self-modifying programs, and certain browsers or JIT-heavy applications — so baseline before alerting.
When it is logged
Sysmon 13.0 or later with a <ProcessTampering> rule in the configuration.
Key fields
| Field | What it tells you | ||||
|---|---|---|---|---|---|
| ProcessGuid | Process whose image was tampered with; pivot to its event 1. | ||||
| Image | Executable path the process claims to run. | ||||
| Type | Kind of tampering detected.
| ||||
| User | Account of the process. |
Common benign sources
- Some browsers, installers and applications that modify their own images, depending on the version.
What attackers do that produces it
- Loaders hollowing a legitimate process such as
svchost.exe,RegAsm.exeorexplorer.exeto host a payload. - Herpaderping tools that overwrite the file after starting the process to hide its real content.
Investigation tips
- Pivot on ProcessGuid to event 1 and check the parent; a hollowed system binary usually has an odd parent.
- Review the process's network (3) and DNS (22) activity, which reflects the real payload.
- Capture process memory before remediation if possible.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumPotential Process Hollowing ActivityRule by Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Sittikorn S, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.