Skip to content

Trace a Suspicious Process with Sysmon

Sysmon process-creation event ID 1 records the image, command line, user, hashes, process GUID, and parent-process context when those fields are available. Follow that evidence as a timeline: identify the parent, understand the command, then look for related file, network, or DNS events.

This guide assumes Sysmon is installed and the Microsoft-Windows-Sysmon/Operational channel is collected. Network, DNS, and file events depend on the active configuration. Do not change the deployed configuration during triage unless the owner approves it.

Windows Event Viewer Sysmon Operational channel with Event ID 1 showing a PowerShell process, command line, process GUID, and explorer.exe parent

Process Create: Use the parent, command line, user, and process GUID to place an Event ID 1 record in context.


Step 1: Confirm the Host and Sysmon Event Channel

01

Check That the Expected Telemetry Is Available

Telemetry

Confirm the alert’s host name and event time, then check that the Sysmon Operational channel is enabled and has records. If the channel is absent or empty, check the deployment and forwarding health before interpreting silence as normal activity.

Terminal window
Get-WinEvent -ListLog 'Microsoft-Windows-Sysmon/Operational' |
Select-Object LogName, IsEnabled, RecordCount, MaximumSizeInBytes
$start = (Get-Date).AddHours(-2)
$events = Get-WinEvent -FilterHashtable @{
LogName = 'Microsoft-Windows-Sysmon/Operational'
Id = 1
StartTime = $start
} -MaxEvents 500
❯ View Expected Console Output
LogName : Microsoft-Windows-Sysmon/Operational
IsEnabled : True
RecordCount : 28416

Step 2: Build a Readable Process-Creation Timeline

02

Extract Process and Parent Fields

Process Tree

Event ID 1 stores named values in event XML. The script below extracts the common process and parent fields while retaining the original timestamp and record ID. Missing values can mean that the event version or configuration does not provide that field; inspect the original event before drawing a conclusion.

Terminal window
$rows = foreach ($event in $events) {
[xml]$xml = $event.ToXml()
$fields = @{}
foreach ($item in $xml.Event.EventData.Data) {
$name = $item.GetAttribute('Name')
if ($name) {
$fields[$name] = $item.InnerText
}
}
[pscustomobject]@{
TimeUtc = $event.TimeCreated.ToUniversalTime().ToString('o')
Computer = $event.MachineName
RecordId = $event.RecordId
ProcessGuid = $fields.ProcessGuid
ProcessId = $fields.ProcessId
User = $fields.User
Image = $fields.Image
CommandLine = $fields.CommandLine
Hashes = $fields.Hashes
ParentProcessGuid = $fields.ParentProcessGuid
ParentImage = $fields.ParentImage
ParentCommandLine = $fields.ParentCommandLine
}
}
$rows | Sort-Object TimeUtc | Format-List TimeUtc, Computer, RecordId,
ProcessGuid, ProcessId, User, Image, CommandLine, Hashes,
ParentProcessGuid, ParentImage, ParentCommandLine
❯ View Expected Console Output
TimeUtc : 2026-10-05T09:22:18.0000000Z
Computer : WS-042
RecordId : 81022
ProcessGuid : {example-process-guid}
ProcessId : 6840
User : CORP\jlee
Image : C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
CommandLine : powershell.exe -NoProfile -File C:\Users\jlee\Downloads\review.ps1
Hashes : SHA256=[example hash]
ParentProcessGuid : {example-parent-guid}
ParentImage : C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
ParentCommandLine : "C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE" ...

Step 3: Reconstruct the Parent-Child Relationship

03

Read the Chain from Parent to Child

Behavior Review

Start with the process that triggered the alert and follow its ParentProcessGuid to the parent event’s ProcessGuid. Review the parent image and command line, then inspect the child image, complete command line, user, integrity level, and hash. A familiar executable name alone is weak evidence; its path, signer, parent, arguments, account, and timing matter.

Trigger process:
Image and full command line
User and host
ProcessGuid and hash
Parent process:
ParentImage and ParentCommandLine
ParentProcessGuid
Expected application or management workflow?
Child and follow-on activity:
New processes, files, network connections, or alerts
❯ View Expected Console Output
The parent is an office application, but the user's workflow and
document origin are not yet confirmed. Keep the finding unresolved.

Step 4: Correlate Optional Network, DNS, and File Events

04
Correlation

Sysmon event ID 3 records network connections, event ID 22 records DNS queries, and event ID 11 records file creation when those events are enabled. Review the events near the process start and correlate on ProcessGuid where present. Event ID 3 is disabled by default in Sysmon’s standard behavior and may also be excluded by the deployed rules.

Terminal window
$relatedEvents = Get-WinEvent -FilterHashtable @{
LogName = 'Microsoft-Windows-Sysmon/Operational'
Id = @(3, 11, 22)
StartTime = $start
} -MaxEvents 1000
$relatedEvents |
Select-Object TimeCreated, Id, RecordId, MachineName, Message |
Format-List
❯ View Expected Console Output
Event ID 3: network connection details, including process correlation
Event ID 22: DNS query details
Event ID 11: file creation details
No result can mean the event type is not configured or retained.

Step 5: Verify File Context and Document the Decision

05

Check the On-Disk File Without Running It

Safe Validation

If the file still exists and your evidence procedure permits live inspection, calculate its current hash and check its Authenticode signature. These checks describe the file as it exists now; they do not prove it was unchanged since the event. Do not launch a suspicious file to test it.

Terminal window
$path = 'C:\Path\To\ObservedProgram.exe'
Get-FileHash -LiteralPath $path -Algorithm SHA256
Get-AuthenticodeSignature -FilePath $path |
Select-Object Status, StatusMessage, SignerCertificate
❯ View Expected Console Output
Algorithm Hash Path
--------- ---- ----
SHA256 [record the resulting hash] C:\Path\To\ObservedProgram.exe
Status: Valid / NotSigned / UnknownError

Comments