ID Message
1 Process Create: RuleName: %1!s! UtcTime: %2!s! ProcessGuid: %3...
2 File creation time changed: RuleName: %1!s! UtcTime: %2!s! Pro...
3 Network connection detected: RuleName: %1!s! UtcTime: %2!s! Pr...
4 Sysmon service state changed: UtcTime: %1!s! State: %2!s! Vers...
5 Process terminated: RuleName: %1!s! UtcTime: %2!s! ProcessGuid...
6 Driver loaded: RuleName: %1!s! UtcTime: %2!s! ImageLoaded: %3!...
7 Image loaded: RuleName: %1!s! UtcTime: %2!s! ProcessGuid: %3!s...
8 CreateRemoteThread detected: RuleName: %1!s! UtcTime: %2!s! So...
9 RawAccessRead detected: RuleName: %1!s! UtcTime: %2!s! Process...
10 Process accessed: RuleName: %1!s! UtcTime: %2!s! SourceProcess...
11 File created: RuleName: %1!s! UtcTime: %2!s! ProcessGuid: %3!s...
12 Registry object added or deleted: RuleName: %1!s! EventType: %2!s! ...
13 Registry value set: RuleName: %1!s! EventType: %2!s! UtcTime: ...
14 Registry object renamed: RuleName: %1!s! EventType: %2!s! UtcT...
15 File stream created: RuleName: %1!s! UtcTime: %2!s! ProcessGui...
16 Sysmon config state changed: UtcTime: %1!s! Configuration: %2!s! ...
17 Pipe Created: RuleName: %1!s! EventType: %2!s! UtcTime: %3!s! ...
18 Pipe Connected: RuleName: %1!s! EventType: %2!s! UtcTime: %3!s...
19 WmiEventFilter activity detected: RuleName: %1!s! EventType: %2!s! ...
20 WmiEventConsumer activity detected: RuleName: %1!s! EventType: %2!s...
21 WmiEventConsumerToFilter activity detected: RuleName: %1!s! EventTy...
22 Dns query: RuleName: %1!s! UtcTime: %2!s! ProcessGuid: %3!s! ...
23 File Delete archived: RuleName: %1!s! UtcTime: %2!s! ProcessGu...
24 Clipboard changed: RuleName: %1!s! UtcTime: %2!s! ProcessGuid:...
25 Process Tampering: RuleName: %1!s! UtcTime: %2!s! ProcessGuid:...
26 File Delete logged: RuleName: %1!s! UtcTime: %2!s! ProcessGuid...
27 File Block Executable: RuleName: %1!s! UtcTime: %2!s! ProcessG...
28 File Block Shredding: RuleName: %1!s! UtcTime: %2!s! ProcessGu...
29 File Executable Detected: RuleName: %1!s! UtcTime: %2!s! Proce...
255 Error report: UtcTime: %1!s! ID: %2!s! Description: %3!s!