Splunk
SPLK-5002 · Question #74
Below is an example of a sysmon process create log. Which EventCode would be associated to this log entry?
The correct answer is C. EventCode=1. In Sysmon, EventCode=1 corresponds to a Process Create event. The log provided shows details of a new process creation (powershell.exe) including ProcessGuid, ProcessId, CommandLine, ParentProcessId, and ParentImage, which are all fields specific to a Process
Advanced Threat Hunting and Analytics
Question
Below is an example of a sysmon process create log. Which EventCode would be associated to this log entry?
Exhibit
Options
- AEventCode=4
- BEventCode=2
- CEventCode=1
- DEventCode=3
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C71% (15)
- D19% (4)
Explanation
In Sysmon, EventCode=1 corresponds to a Process Create event. The log provided shows details of a new process creation (powershell.exe) including ProcessGuid, ProcessId, CommandLine, ParentProcessId, and ParentImage, which are all fields specific to a Process
Topics
#Sysmon#EventCode#process creation#Windows logging
Community Discussion
No community discussion yet for this question.
