Skip to content
Sysmon

Sysmon Event ID 3: Network connection

Network connectionSysmon event 3 ties each TCP/UDP connection to the process that made it: source, destination, ports and ProcessGuid. Key for C2 and lateral movement.
3
Event ID
3
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Network
Default logging
Needs configuration

What event 3 means

Sysmon event 3 records a TCP or UDP connection together with the process responsible for it. That is the piece firewall and proxy logs miss: not just that the host talked to an address, but which executable did it and under which account.

Initiated tells the direction: true means the local process opened the connection (outbound), false means it accepted one. Host names are filled by reverse DNS lookup when DnsLookup is enabled, so they may not match what the process actually resolved — use event 22 for that.

The event is disabled by default because of its volume. Good configurations include connections from script hosts, LOLBins and user-writable paths, and exclude browsers and known agents.

When it is logged

Audit policy / configuration

Sysmon installed with network monitoring enabled (-n switch or a <NetworkConnect> rule in the configuration).

Host names depend on reverse DNS (DnsLookup configuration entry). Compare with Windows Filtering Platform event 5156 when that audit subcategory is enabled.

Key fields

FieldWhat it tells you
ProcessGuidProcess that made or accepted the connection; pivot to its event 1.
ImageExecutable behind the connection.
UserAccount of the process.
ProtocolTransport protocol.
ValueMeaning
tcpTCP connection.
udpUDP traffic.
InitiatedDirection of the connection.
ValueMeaning
trueThe local process initiated the connection (outbound).
falseThe local process accepted an inbound connection.
SourceIpSource address.
SourcePortSource port.
DestinationIpDestination address.
DestinationHostnameDestination name from reverse DNS, when available. Not necessarily the name the process queried.
DestinationPortDestination port.
DestinationPortNameService name for well-known ports, e.g. https or microsoft-ds.
SourceIsIpv6true when the connection uses IPv6.

Common benign sources

  • Browsers, Office, Teams and update agents talking to cloud services on 443.
  • Domain members connecting to domain controllers on 88, 389, 445 and 135.
  • Management and backup agents polling their servers.

What attackers do that produces it

  • Script hosts or LOLBins (powershell.exe, rundll32.exe, regsvr32.exe, mshta.exe, certutil.exe) making outbound connections to the internet.
  • Beaconing — regular connections from the same process to a rare external IP.
  • Lateral movement from a workstation to other hosts on 445 (SMB), 135 (RPC/WMI), 5985/5986 (WinRM) or 3389 (RDP).
  • Processes from %TEMP%, Downloads or ProgramData connecting out on non-standard ports.

Investigation tips

  • Pivot on ProcessGuid to event 1 to see the command line and parent of the connecting process.
  • Correlate with event 22 from the same ProcessGuid to learn which domain name was resolved.
  • Group by Image and DestinationIp to find rare pairs across the fleet.
  • For inbound lateral movement, match the destination host's Security 4624 (LogonType 3 or 10) at the same time.

MITRE ATT&CK techniques

TechniqueTactics
T1071 Application Layer ProtocolCommand and Control
T1105 Ingress Tool TransferCommand and Control
T1571 Non-Standard PortCommand and Control
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

51 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.

  • High · 24
  • Medium · 25
  • Low · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideSysmon Event ID 3: Network connection detected (C2 hunting)

Sources and further reading