Sysmon Event ID 8: Remote thread created
- Event ID
- 8
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Processes
- Default logging
- Needs configuration
What event 8 means
Sysmon event 8 records one process starting a thread inside another process. That is how many injection techniques get their code to run: allocate memory in the target, write a payload, then start a remote thread on it.
The event names the source and target processes and describes where the new thread starts: StartAddress, and when Sysmon can infer them, StartModule and StartFunction. A start function of LoadLibraryA or LoadLibraryW means a DLL is being injected; an empty StartModule means the thread starts in memory not backed by a loaded module, which is typical of shellcode.
Legitimate remote threads exist but are few, so the event is usually worth reviewing in full after excluding known pairs.
When it is logged
Sysmon installed; filter with <CreateRemoteThread> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| SourceProcessGuid | Process that created the thread. |
| SourceImage | Executable of the injecting process. |
| TargetProcessGuid | Process that received the thread. |
| TargetImage | Executable of the target. Injection into lsass.exe, explorer.exe, svchost.exe or browsers is common. |
| NewThreadId | ID of the new thread in the target. |
| StartAddress | Address where the thread starts. |
| StartModule | Module containing StartAddress, when known. Empty means unbacked memory. |
| StartFunction | Exported function at StartAddress, when known (e.g. LoadLibraryW). |
| SourceUser | Account of the source process (newer Sysmon versions). |
| TargetUser | Account of the target process (newer Sysmon versions). |
Common benign sources
csrss.execreating threads in console processes on Ctrl+C / Ctrl+Break (StartFunctionCtrlRoutine).- Debuggers, accessibility and some security or monitoring tools.
What attackers do that produces it
- Malware injecting a DLL (StartFunction
LoadLibraryA/LoadLibraryW) intoexplorer.exeor a browser. - Shellcode injection with an empty StartModule into a long-lived process for stealth.
- Post-exploitation frameworks migrating into another process.
Investigation tips
- Pivot on SourceProcessGuid to event 1 to see how the injector started.
- Look for event 10 from the same source to the same target just before (memory write access).
- Check the target's later network (3) and DNS (22) activity to see what the injected code did.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
11 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 8
- Medium · 3
- HighHackTool - CACTUSTORCH Remote Thread CreationRule by @SBousseaden (detection), Thomas Patzke (rule), SigmaHQ, DRL 1.1
- HighHackTool - Potential CobaltStrike Process InjectionRule by Olaf Hartong, Florian Roth (Nextron Systems), Aleksey Potapov, oscd.community, SigmaHQ, DRL 1.1
- HighPassword Dumper Remote Thread in LSASSRule by Thomas Patzke, SigmaHQ, DRL 1.1
- HighPotential Credential Dumping Attempt Via PowerShell Remote ThreadRule by oscd.community, Natalia Shornikova, SigmaHQ, DRL 1.1
- HighRare Remote Thread Creation By Uncommon Source ImageRule by Perez Diego (@darkquassar), oscd.community, SigmaHQ, DRL 1.1
- HighRemote Thread Created In KeePass.EXERule by Timon Hackenjos, SigmaHQ, DRL 1.1
- HighRemote Thread Creation In Mstsc.Exe From Suspicious LocationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighRemote Thread Creation Ttdinject.exe ProxyRule by frack113, SigmaHQ, DRL 1.1
- MediumRemote Thread Creation By Uncommon Source ImageRule by Perez Diego (@darkquassar), oscd.community, SigmaHQ, DRL 1.1
- MediumRemote Thread Creation In Uncommon Target ImageRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- MediumRemote Thread Creation Via PowerShell In Uncommon TargetRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.