Sysmon Event ID 3: Network connection
- Event ID
- 3
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Network
- Default logging
- Needs configuration
What event 3 means
Sysmon event 3 records a TCP or UDP connection together with the process responsible for it. That is the piece firewall and proxy logs miss: not just that the host talked to an address, but which executable did it and under which account.
Initiated tells the direction: true means the local process opened the connection (outbound), false means it accepted one. Host names are filled by reverse DNS lookup when DnsLookup is enabled, so they may not match what the process actually resolved — use event 22 for that.
The event is disabled by default because of its volume. Good configurations include connections from script hosts, LOLBins and user-writable paths, and exclude browsers and known agents.
When it is logged
Sysmon installed with network monitoring enabled (-n switch or a <NetworkConnect> rule in the configuration).
Host names depend on reverse DNS (DnsLookup configuration entry). Compare with Windows Filtering Platform event 5156 when that audit subcategory is enabled.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| ProcessGuid | Process that made or accepted the connection; pivot to its event 1. | ||||||
| Image | Executable behind the connection. | ||||||
| User | Account of the process. | ||||||
| Protocol | Transport protocol.
| ||||||
| Initiated | Direction of the connection.
| ||||||
| SourceIp | Source address. | ||||||
| SourcePort | Source port. | ||||||
| DestinationIp | Destination address. | ||||||
| DestinationHostname | Destination name from reverse DNS, when available. Not necessarily the name the process queried. | ||||||
| DestinationPort | Destination port. | ||||||
| DestinationPortName | Service name for well-known ports, e.g. https or microsoft-ds. | ||||||
| SourceIsIpv6 | true when the connection uses IPv6. |
Common benign sources
- Browsers, Office, Teams and update agents talking to cloud services on 443.
- Domain members connecting to domain controllers on 88, 389, 445 and 135.
- Management and backup agents polling their servers.
What attackers do that produces it
- Script hosts or LOLBins (
powershell.exe,rundll32.exe,regsvr32.exe,mshta.exe,certutil.exe) making outbound connections to the internet. - Beaconing — regular connections from the same process to a rare external IP.
- Lateral movement from a workstation to other hosts on 445 (SMB), 135 (RPC/WMI), 5985/5986 (WinRM) or 3389 (RDP).
- Processes from
%TEMP%,DownloadsorProgramDataconnecting out on non-standard ports.
Investigation tips
- Pivot on ProcessGuid to event 1 to see the command line and parent of the connecting process.
- Correlate with event 22 from the same ProcessGuid to learn which domain name was resolved.
- Group by Image and DestinationIp to find rare pairs across the fleet.
- For inbound lateral movement, match the destination host's Security 4624 (LogonType 3 or 10) at the same time.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
51 SigmaHQ detection rules (release r2026-07-01) target this event. Showing the 25 highest-severity rules.
- High · 24
- Medium · 25
- Low · 2
- HighCommunication To LocaltoNet Tunneling Service InitiatedRule by Andreas Braathen (mnemonic.io), SigmaHQ, DRL 1.1
- HighCommunication To Ngrok Tunneling Service InitiatedRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighNetwork Communication Initiated To File Sharing Domains From Process Located In Suspicious FolderRule by Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighNetwork Communication With Crypto Mining PoolRule by Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighNetwork Connection Initiated By AddinUtil.EXERule by Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), SigmaHQ, DRL 1.1
- HighNetwork Connection Initiated By Eqnedt32.EXERule by Max Altgelt (Nextron Systems), SigmaHQ, DRL 1.1
- HighNetwork Connection Initiated By IMEWDBLD.EXERule by frack113, SigmaHQ, DRL 1.1
- HighNetwork Connection Initiated From Process Located In Potentially Suspicious Or Uncommon LocationRule by Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighNetwork Connection Initiated via Finger.EXERule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighNetwork Connection Initiated Via Notepad.EXERule by EagleEye Team, SigmaHQ, DRL 1.1
- HighNew Connection Initiated To Potential Dead Drop Resolver DomainRule by Sorina Ionescu, X__Junior (Nextron Systems), SigmaHQ, DRL 1.1
- HighOutbound Network Connection Initiated By Cmstp.EXERule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighOutbound Network Connection Initiated By Microsoft DialerRule by CertainlyP, SigmaHQ, DRL 1.1
- HighOutbound Network Connection Initiated By Script InterpreterRule by frack113, Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighOutbound RDP Connections Over Non-Standard ToolsRule by Markus Neis, SigmaHQ, DRL 1.1
- HighPotential Remote PowerShell Session InitiatedRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- HighPotentially Suspicious Malware Callback CommunicationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighProcess Initiated Network Connection To Ngrok DomainRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighRDP Over Reverse SSH TunnelRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- HighRDP to HTTP or HTTPS Target PortsRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSilenttrinity Stager Msbuild ActivityRule by Kiran kumar s, oscd.community, SigmaHQ, DRL 1.1
- HighSuspicious Dropbox API UsageRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Network Connection Binary No CommandLineRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighUncommon Network Connection Initiated By Certutil.EXERule by frack113, Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumCommunication To Uncommon Destination PortsRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.