Sysmon Event ID 5: Process terminated
- Event ID
- 5
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 5 means
Sysmon event 5 is logged when a process ends. It carries the same ProcessGuid as the matching event 1, so the two together give the exact lifetime of a process.
On its own the event says little. Its value is in timelines: short-lived processes (a few seconds between 1 and 5) are typical of discovery commands and droppers, while a process that never terminates can point to a long-running implant. Many configurations exclude it to save volume.
When it is logged
Sysmon installed; controlled with a <ProcessTerminate> rule in the configuration (many shared configurations disable it).
Key fields
| Field | What it tells you |
|---|---|
| UtcTime | Exit time. |
| ProcessGuid | Same GUID as in the process's event 1. |
| ProcessId | PID of the exiting process. |
| Image | Executable of the exiting process. |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Every normal program exit — this event is as frequent as event 1 when enabled.
- Short-lived helper processes spawned by installers and updaters.
What attackers do that produces it
- Burst of very short-lived
whoami,net,nltestoripconfigprocesses during discovery. - Security tools terminating unexpectedly shortly after suspicious activity.
Investigation tips
- Join with event 1 on ProcessGuid to compute process lifetime.
- Check whether a suspicious process is still running (no event 5 yet) before responding.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.