Skip to content
Sysmon

Sysmon Event ID 5: Process terminated

Process terminatedSysmon event 5 records a process exiting, with ProcessGuid and image path. Pairs with event 1 to measure lifetime and close out process timelines.
5
Event ID
5
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 5 means

Sysmon event 5 is logged when a process ends. It carries the same ProcessGuid as the matching event 1, so the two together give the exact lifetime of a process.

On its own the event says little. Its value is in timelines: short-lived processes (a few seconds between 1 and 5) are typical of discovery commands and droppers, while a process that never terminates can point to a long-running implant. Many configurations exclude it to save volume.

When it is logged

Audit policy / configuration

Sysmon installed; controlled with a <ProcessTerminate> rule in the configuration (many shared configurations disable it).

Key fields

FieldWhat it tells you
UtcTimeExit time.
ProcessGuidSame GUID as in the process's event 1.
ProcessIdPID of the exiting process.
ImageExecutable of the exiting process.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Every normal program exit — this event is as frequent as event 1 when enabled.
  • Short-lived helper processes spawned by installers and updaters.

What attackers do that produces it

  • Burst of very short-lived whoami, net, nltest or ipconfig processes during discovery.
  • Security tools terminating unexpectedly shortly after suspicious activity.

Investigation tips

  • Join with event 1 on ProcessGuid to compute process lifetime.
  • Check whether a suspicious process is still running (no event 5 yet) before responding.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading