EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Sysmon Events



Source
  • Microsoft-Windows-Sysmon (1)
Category
  • Process Create (rule: ProcessCreate) (1)
Tags

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Message
1 Process Create: RuleName: %1!s! UtcTime: %2!s! ProcessGuid: %3!s! ProcessId: %4!s! Image: %5!s! FileVersion: %6!s! Description: %7!s! Product: %8!s! Company: %9!s! OriginalFileName: %10!s! CommandLine: %11!s! CurrentDirectory: %12!s! User: %13!s! LogonGuid: %14!s! LogonId: %15!s! TerminalSessionId: %16!s! IntegrityLevel: %17!s! Hashes: %18!s! ParentProcessGuid: %19!s! ParentProcessId: %20!s! ParentImage: %21!s! ParentCommandLine: %22!s! ParentUser: %23!s!



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | AppLocker | Privacy Policy