Skip to content
Sysmon

Sysmon Event ID 8: Remote thread created

CreateRemoteThreadSysmon event 8 fires when a process creates a thread in another process — a classic code injection technique. Low volume, high signal.
8
Event ID
8
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Processes
Default logging
Needs configuration

What event 8 means

Sysmon event 8 records one process starting a thread inside another process. That is how many injection techniques get their code to run: allocate memory in the target, write a payload, then start a remote thread on it.

The event names the source and target processes and describes where the new thread starts: StartAddress, and when Sysmon can infer them, StartModule and StartFunction. A start function of LoadLibraryA or LoadLibraryW means a DLL is being injected; an empty StartModule means the thread starts in memory not backed by a loaded module, which is typical of shellcode.

Legitimate remote threads exist but are few, so the event is usually worth reviewing in full after excluding known pairs.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <CreateRemoteThread> rules in the configuration.

Key fields

FieldWhat it tells you
SourceProcessGuidProcess that created the thread.
SourceImageExecutable of the injecting process.
TargetProcessGuidProcess that received the thread.
TargetImageExecutable of the target. Injection into lsass.exe, explorer.exe, svchost.exe or browsers is common.
NewThreadIdID of the new thread in the target.
StartAddressAddress where the thread starts.
StartModuleModule containing StartAddress, when known. Empty means unbacked memory.
StartFunctionExported function at StartAddress, when known (e.g. LoadLibraryW).
SourceUserAccount of the source process (newer Sysmon versions).
TargetUserAccount of the target process (newer Sysmon versions).

Common benign sources

  • csrss.exe creating threads in console processes on Ctrl+C / Ctrl+Break (StartFunction CtrlRoutine).
  • Debuggers, accessibility and some security or monitoring tools.

What attackers do that produces it

  • Malware injecting a DLL (StartFunction LoadLibraryA/LoadLibraryW) into explorer.exe or a browser.
  • Shellcode injection with an empty StartModule into a long-lived process for stealth.
  • Post-exploitation frameworks migrating into another process.

Investigation tips

  • Pivot on SourceProcessGuid to event 1 to see how the injector started.
  • Look for event 10 from the same source to the same target just before (memory write access).
  • Check the target's later network (3) and DNS (22) activity to see what the injected code did.

MITRE ATT&CK techniques

TechniqueTactics
T1055 Process InjectionStealth, Privilege Escalation
T1055.001 Process Injection: Dynamic-link Library InjectionStealth, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

11 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 8
  • Medium · 3

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideSysmon Event IDs 8 and 10: process injection and LSASS access

Sources and further reading