!ProcessCreate |
Sysmon EventType ProcessCreate |
!FileCreateTime |
Sysmon EventType FileCreateTime |
!NetworkConnect |
Sysmon EventType NetworkConnect |
!ProcessTerminate |
Sysmon EventType ProcessTerminate |
!DriverLoad |
Sysmon EventType DriverLoad |
!ImageLoad |
Sysmon EventType ImageLoad |
!CreateRemoteThread |
Sysmon EventType CreateRemoteThread |
!RawAccessRead |
Sysmon EventType RawAccessRead |
!ProcessAccess |
Sysmon EventType ProcessAccess |
!FileCreate |
Sysmon EventType FileCreate |
!RegistryEvent |
Sysmon EventType RegistryEvent |
!FileCreateStreamHash |
Sysmon EventType FileCreateStreamHash |
!PipeEvent |
Sysmon EventType PipeEvent |
!WmiEvent |
Sysmon EventType WmiEvent |
!DnsQuery |
Sysmon EventType DnsQuery |
!CallTrace |
Sysmon event field CallTrace filter |
!CommandLine |
Sysmon event field CommandLine filter |
!Company |
Sysmon event field Company filter |
!Configuration |
Sysmon event field Configuration filter |
!ConfigurationFileHash |
Sysmon event field ConfigurationFileHash filter |
!Consumer |
Sysmon event field Consumer filter |
!CurrentDirectory |
Sysmon event field CurrentDirectory filter |
!Description |
Sysmon event field Description filter |
!Destination |
Sysmon event field Destination filter |
!DestinationHostname |
Sysmon event field DestinationHostname filter |
!DestinationIp |
Sysmon event field DestinationIp filter |
!DestinationIsIpv6 |
Sysmon event field DestinationIsIpv6 filter |
!DestinationPort |
Sysmon event field DestinationPort filter |
!DestinationPortName |
Sysmon event field DestinationPortName filter |
!Details |
Sysmon event field Details filter |
!Device |
Sysmon event field Device filter |
!EventNamespace |
Sysmon event field EventNamespace filter |
!EventType |
Sysmon event field EventType filter |
!FileVersion |
Sysmon event field FileVersion filter |
!Filter |
Sysmon event field Filter filter |
!GrantedAccess |
Sysmon event field GrantedAccess filter |
!Hash |
Sysmon event field Hash filter |
!Hashes |
Sysmon event field Hashes filter |
!ID |
Sysmon event field ID filter |
!Image |
Sysmon event field Image filter |
!ImageLoaded |
Sysmon event field ImageLoaded filter |
!Initiated |
Sysmon event field Initiated filter |
!IntegrityLevel |
Sysmon event field IntegrityLevel filter |
!Name |
Sysmon event field Name filter |
!NewName |
Sysmon event field NewName filter |
!Operation |
Sysmon event field Operation filter |
!OriginalFileName |
Sysmon event field OriginalFileName filter |
!ParentCommandLine |
Sysmon event field ParentCommandLine filter |
!ParentImage |
Sysmon event field ParentImage filter |
!PipeName |
Sysmon event field PipeName filter |
!PreviousCreationUtcTime |
Sysmon event field PreviousCreationUtcTime filter |
!Product |
Sysmon event field Product filter |
!Protocol |
Sysmon event field Protocol filter |
!Query |
Sysmon event field Query filter |
!QueryName |
Sysmon event field QueryName filter |
!QueryResults |
Sysmon event field QueryResults filter |
!QueryStatus |
Sysmon event field QueryStatus filter |
!SchemaVersion |
Sysmon event field SchemaVersion filter |
!Signature |
Sysmon event field Signature filter |
!SignatureStatus |
Sysmon event field SignatureStatus filter |
!Signed |
Sysmon event field Signed filter |
!SourceHostname |
Sysmon event field SourceHostname filter |
!SourceImage |
Sysmon event field SourceImage filter |
!SourceIp |
Sysmon event field SourceIp filter |
!SourceIsIpv6 |
Sysmon event field SourceIsIpv6 filter |
!SourcePort |
Sysmon event field SourcePort filter |
!SourcePortName |
Sysmon event field SourcePortName filter |
!SourceThreadId |
Sysmon event field SourceThreadId filter |
!StartAddress |
Sysmon event field StartAddress filter |
!StartFunction |
Sysmon event field StartFunction filter |
!StartModule |
Sysmon event field StartModule filter |
!State |
Sysmon event field State filter |
!TargetFilename |
Sysmon event field TargetFilename filter |
!TargetImage |
Sysmon event field TargetImage filter |
!TargetObject |
Sysmon event field TargetObject filter |
!Type |
Sysmon event field Type filter |
!User |
Sysmon event field User filter |
!Version |
Sysmon event field Version filter |