Guest User

Untitled

a guest
Dec 18th, 2018
65
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.34 KB | None | 0 0
  1. 12/18/18 10:42:32 PM UTC , NULL ,
  2. {
  3. "@timestamp":"2018-12-18T22:42:32.841Z",
  4. "@metadata":
  5. {
  6. "beat":"winlogbeat",
  7. "type":"doc",
  8. "version":"6.5.3",
  9. "topic":"winlogbeat"
  10. },
  11. "opcode":"Info",
  12. "message":"Process Create:\x5CnRuleName: \x5CnUtcTime: 2018-12-18 22:42:32.826\x5CnProcessGuid: {1C9FDC81-77D8-5C19-0000-0010A8182800}\x5CnProcessId: 2620\x5CnImage: C:\x5C\x5CWindows\x5C\x5CSystem32\x5C\x5Ctaskhostw.exe\x5CnFileVersion: 10.0.17134.1 (WinBuild.160101.0800)\x5CnDescription: Host Process for Windows Tasks\x5CnProduct: Microsoft\xC2\xAE Windows\xC2\xAE Operating System\x5CnCompany: Microsoft Corporation\x5CnCommandLine: taskhostw.exe Logon\x5CnCurrentDirectory: C:\x5C\x5CWINDOWS\x5C\x5Csystem32\x5C\x5C\x5CnUser: RIVENDELL\x5C\x5Ccbrown\x5CnLogonGuid: {1C9FDC81-76A7-5C19-0000-00205D8E0900}\x5CnLogonId: 0x98E5D\x5CnTerminalSessionId: 1\x5CnIntegrityLevel: Medium\x5CnHashes: SHA1=2A594345FBCAAD453C72BD0937CBF67FB43A74DF,MD5=CE95E236FC9FE2D6F16C926C75B18BAF,SHA256=740122D338FFD2CBB0877F8AC17B28218EAD02F08A9B28D5266C94E33F938085,IMPHASH=3627BE269990D67CF76A03FA55EF9A08\x5CnParentProcessGuid: {1C9FDC81-7677-5C19-0000-00104A420100}\x5CnParentProcessId: 988\x5CnParentImage: C:\x5C\x5CWindows\x5C\x5CSystem32\x5C\x5Csvchost.exe\x5CnParentCommandLine: C:\x5C\x5CWINDOWS\x5C\x5Csystem32\x5C\x5Csvchost.exe -k netsvcs -p",
  13. "thread_id":3100,
  14. "computer_name":"DESKTOP-LFD11QP.RIVENDELL.local",
  15. "version":5,
  16. "task":"Process Create (rule: ProcessCreate)",
  17. "event_data":
  18. {
  19. "Hashes":"SHA1=2A594345FBCAAD453C72BD0937CBF67FB43A74DF,MD5=CE95E236FC9FE2D6F16C926C75B18BAF,SHA256=740122D338FFD2CBB0877F8AC17B28218EAD02F08A9B28D5266C94E33F938085,IMPHASH=3627BE269990D67CF76A03FA55EF9A08",
  20. "ProcessGuid":"{1C9FDC81-77D8-5C19-0000-0010A8182800}",
  21. "IntegrityLevel":"Medium",
  22. "UtcTime":"2018-12-18 22:42:32.826",
  23. "LogonId":"0x98e5d",
  24. "Description":"Host Process for Windows Tasks",
  25. "TerminalSessionId":"1",
  26. "CommandLine":"taskhostw.exe Logon",
  27. "ParentImage":"C:\x5C\x5CWindows\x5C\x5CSystem32\x5C\x5Csvchost.exe",
  28. "LogonGuid":"{1C9FDC81-76A7-5C19-0000-00205D8E0900}",
  29. "User":"RIVENDELL\x5C\x5Ccbrown",
  30. "FileVersion":"10.0.17134.1 (WinBuild.160101.0800)",
  31. "ParentProcessId":"988",
  32. "ParentCommandLine":"C:\x5C\x5CWINDOWS\x5C\x5Csystem32\x5C\x5Csvchost.exe -k netsvcs -p",
  33. "Product":"Microsoft\xC2\xAE Windows\xC2\xAE Operating System",
  34. "Image":"C:\x5C\x5CWindows\x5C\x5CSystem32\x5C\x5Ctaskhostw.exe",
  35. "ProcessId":"2620",
  36. "CurrentDirectory":"C:\x5C\x5CWINDOWS\x5C\x5Csystem32\x5C\x5C",
  37. "Company":"Microsoft Corporation",
  38. "ParentProcessGuid":"{1C9FDC81-7677-5C19-0000-00104A420100}"
  39. },
  40. "host":
  41. {
  42. "name":"DESKTOP-LFD11QP"
  43. },
  44. "type":"wineventlog",
  45. "provider_guid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}",
  46. "level":"Information",
  47. "event_id":1,
  48. "log_name":"Microsoft-Windows-Sysmon/Operational",
  49. "source_name":"Microsoft-Windows-Sysmon",
  50. "record_number":"3040257",
  51. "process_id":2160,
  52. "user":
  53. {
  54. "name":"SYSTEM",
  55. "domain":"NT AUTHORITY",
  56. "type":"User",
  57. "identifier":"S-1-5-18"
  58. },
  59. "beat":
  60. {
  61. "name":"DESKTOP-LFD11QP",
  62. "hostname":"DESKTOP-LFD11QP",
  63. "version":"6.5.3"
  64. }
  65. }
Add Comment
Please, Sign In to add comment