---
title: "Sysmon: Detect Hidden Malware in Windows Event Logs"
description: "Deploy Sysinternals Sysmon with a tuned config, then use Get-WinEvent and Sysmon event IDs to catch process injection and C2 beaconing."
canonical: "https://adamtheautomator.com/sysmon-detect-hidden-malware/"
---

# Sysmon: Detect Hidden Malware in Windows Event Logs

> Deploy Sysinternals Sysmon with a tuned config, then use Get-WinEvent and Sysmon event IDs to catch process injection and C2 beaconing.

Source: https://adamtheautomator.com/sysmon-detect-hidden-malware/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![Sysmon: Detect Hidden Malware in Windows Event Logs](https://adamtheautomator.com/wp-content/uploads/publisher/3ec5d9c85b2b81c8a7f8e65f33231fa4/606223a2505919db35cb97858e8eafa9a96eb8d297bab790394df6d592d2af99.webp)

# Sysmon: Detect Hidden Malware in Windows Event Logs

[![](https://secure.gravatar.com/avatar/d0b9d42e21e5622713f8b693aa5c0f9244d5f7dd200ed29b8398f52dee5de337?s=192&d=mm&r=g)Adam Bertram](https://adamtheautomator.com/author/adam-bertram/)6 October 202613 min. read

Categories: [Information Security](/category/infosec/)

Tags:[Security](/tag/security/)[Windows](/tag/windows/)[Windows Events](/tag/windows-events/)[PowerShell](/tag/powershell/)

Table of Contents

*   [What Sysmon Sees That Windows Event 4688 Cannot](#what-sysmon-sees-that-windows-event-4688-cannot)
*   [Windows Event 4688 Falls Short on Context](#windows-event-4688-falls-short-on-context)
*   [Prerequisites: Rights, Host, and a Configuration](#prerequisites-rights-host-and-a-configuration)
*   [Deploy Sysmon and Apply a Tuned Configuration](#deploy-sysmon-and-apply-a-tuned-configuration)
*   [Choose the Standalone Binary or the Built-In Feature](#choose-the-standalone-binary-or-the-built-in-feature)
*   [Install and Apply the Configuration](#install-and-apply-the-configuration)
*   [The Event IDs That Reveal Hidden Malware](#the-event-ids-that-reveal-hidden-malware)
*   [The Nine Events That Carry a Hidden Attack](#the-nine-events-that-carry-a-hidden-attack)
*   [Query Sysmon Telemetry with Get-WinEvent](#query-sysmon-telemetry-with-get-winevent)
*   [Filter by Event ID and Time Window](#filter-by-event-id-and-time-window)
*   [Read the Command Line, Parent, and Hash](#read-the-command-line-parent-and-hash)
*   [Detect Process Injection and Process Tampering](#detect-process-injection-and-process-tampering)
*   [CreateRemoteThread and ProcessAccess](#createremotethread-and-processaccess)
*   [Detect Registry Persistence and Fileless Payloads](#detect-registry-persistence-and-fileless-payloads)
*   [Run Keys and Alternate Data Streams](#run-keys-and-alternate-data-streams)
*   [Detect C2 Beaconing with Network and DNS Events](#detect-c2-beaconing-with-network-and-dns-events)
*   [Network Connect Is Noisy by Default](#network-connect-is-noisy-by-default)
*   [DNS Query Is the Higher-Signal Event](#dns-query-is-the-higher-signal-event)
*   [Tune the Configuration to Cut False Positives](#tune-the-configuration-to-cut-false-positives)
*   [Find the High-Volume Offenders](#find-the-high-volume-offenders)
*   [Write Narrow Exclusions](#write-narrow-exclusions)
*   [Forward Sysmon to a SIEM and Write a Starter Detection](#forward-sysmon-to-a-siem-and-write-a-starter-detection)
*   [Write a Portable Rule](#write-a-portable-rule)
*   [Validate Detections with Atomic Red Team](#validate-detections-with-atomic-red-team)
*   [Run the Atomic and Read the Event](#run-the-atomic-and-read-the-event)
*   [Keep the Telemetry Flowing](#keep-the-telemetry-flowing)

Name the process that wrote a value under `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` on your endpoints in the last day. Now name the parent process that launched it, the full command line it carried, and the hash of the image on disk. If the honest answer is a shrug and a full-disk scan that comes back clean, you are carrying a detection gap that no signature update will close.

This tutorial closes that gap with Sysinternals Sysmon, which Microsoft describes as “a Windows system service and device driver.” You will deploy Sysmon with a tuned configuration, confirm which event IDs your build actually emits, and read the telemetry with `Get-WinEvent`.

Then you work three hidden-malware behaviors end to end: process injection, registry-based persistence, and command-and-control (C2) beaconing. From there you tune the configuration until the noise drops, forward events to a security information and event management (SIEM) with a starter detection, and prove each rule fires with a safe, repeatable test. Everything runs from an elevated PowerShell session against Windows 11 or later, or Windows Server 2019 and later, and you can rehearse the whole sequence on one lab host before you touch production. By the end, you will be able to answer the opening question on any endpoint you own.

## What Sysmon Sees That Windows Event 4688 Cannot

Windows already logs process creation as Event ID 4688, so the fair question is why you need a second tool. Microsoft’s [Sysmon overview](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/overview) answers it in one line: “Built-in System Monitor (Sysmon) is an optional Windows feature on Windows 11 and Windows Server 2025 that when enabled, remains resident across system reboots to monitor and log system activity to the Windows event log.” Because Sysmon stays resident across reboots, a restart does not open the gap back up. Native 4688 reveals the full story only when command-line auditing is switched on separately, and even then it hands you a process ID that Windows recycles.

### Windows Event 4688 Falls Short on Context

Put the two sources side by side and the gap becomes concrete.

| What you need to see | Native Event 4688 | Sysmon Event ID 1 |
| --- | --- | --- |
| Full command line | Only with command-line auditing enabled | Logged for the process and its parent |
| Parent process context | A process ID | Parent image, parent command line, ProcessGuid |
| Image hash | Not recorded | SHA1 (default), MD5, SHA256, or Import Hash (IMPHASH) |
| Correlation after PID reuse | Lost | Preserved by the ProcessGuid |

The gap in native process logging is not academic. Fileless malware and living-off-the-land binaries (LOLBins) such as `powershell.exe`, `certutil.exe`, and `rundll32.exe` never drop the file your scanner inspects, so the only evidence left behind is behavior: the command line, the parent chain, the network call, and the registry write. The [Sysinternals Sysmon page](https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon) states the design goal directly: “Logs process creation with full command line for both current and parent processes.”

One boundary matters before you deploy. Sysmon records behavior and leaves the verdict to you. Microsoft’s [enable and configure guide](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/how-to-enable-sysmon) is blunt that “Sysmon doesn’t analyze events or generate alerts.” The tool produces evidence; you supply the judgment.

## Prerequisites: Rights, Host, and a Configuration

If you want to follow along hands-on, you’ll need:

*   An elevated PowerShell session on Windows 11 or later, or Windows Server 2019 and later. The current Sysmon download page lists Client support as “Windows 11 and higher” and Server support as “Windows Server 2019 and higher”, so treat Windows 10 as a client Microsoft no longer documents as supported. Sysmon installs a service and a kernel driver, so anything less than administrator rights fails at install.
    
*   The [Sysinternals Sysmon package](https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon) (v15.22, the release this walkthrough targets, with its PowerShell blocks validated on PowerShell 7.6.1) or the built-in Sysmon optional feature on Windows 11 or Windows Server 2025. Pick one path, because Microsoft documents that built-in Sysmon “doesn’t support coexistence with standalone Sysmon.”
    
*   A tuned configuration file. Use [SwiftOnSecurity’s sysmon-config](https://github.com/SwiftOnSecurity/sysmon-config) for a single heavily commented baseline, or [Olaf Hartong’s sysmon-modular](https://github.com/olafhartong/sysmon-modular) when you want the rules split by event ID with MITRE ATT&CK tags.
    
*   One lab host you are willing to reboot and to fill with events. Deployment reverses cleanly with `sysmon64.exe -u`, but it changes what the endpoint records from the first minute.
    

## Deploy Sysmon and Apply a Tuned Configuration

Sysmon ships with almost nothing switched on, which surprises people who install it and then stare at an empty log. The [configuration files guide](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-configuration-files) frames the decision correctly: “Sysmon configuration files define what telemetry Sysmon records and what it ignores.” Install the binary with no configuration and you inherit defaults that leave network, image-load, and registry events turned off.

### Choose the Standalone Binary or the Built-In Feature

The standalone Sysinternals binary and the built-in Windows feature emit the same Sysmon event IDs with the same `EventData` fields, so choose based on your fleet. The standalone Sysinternals binary installs on Windows 11 and Windows Server 2019 and later and gives you version control over the deployment. The built-in optional feature exists on Windows 11 and Windows Server 2025 and removes the third-party executable, but it will not coexist with a standalone install.

### Install and Apply the Configuration

Work from an elevated prompt in the folder that holds `sysmon64.exe` and your config file. First confirm nothing is already installed:

```powershell
Get-Service sysmon*
```

An empty result means you are clear to proceed. Then install Sysmon and point it at the configuration in one command:

```powershell
sysmon64.exe -accepteula -i sysmonconfig-export.xml
```

The `-accepteula` flag suppresses the license dialog, and `-i` installs the driver and service. If Sysmon is already running and you only changed the rules, swap `-i` for `-c` to update the live configuration without a reinstall:

```powershell
sysmon64.exe -c sysmonconfig-export.xml
```

Microsoft confirms the update path is live: “Once applied, the configuration takes effect immediately. No restart is required.” To reverse everything on the lab host, run `sysmon64.exe -u`. The screenshot below shows the install completing and the service reporting as running.

![Sysmon install output](https://adamtheautomator.com/wp-content/uploads/publisher/6cfb947177c895896907f644d6b63e26d88d0be47f72cf48ac8e1d5a45f31a66.png)

On the built-in optional feature path, the same outcome comes from two commands:

```powershell
Enable-WindowsOptionalFeature -Online -FeatureName Sysmon
sysmon -i C:\Sysmon\sysmonconfig-export.xml
```

* * *

_**Warning: An untuned deployment can flood the endpoint. Microsoft’s enable guide notes that “a restrictive or unoptimized configuration may generate high event volume,” and every one of those events lands in a log you pay to store. Install on a lab host first, watch the event rate for a day, and only then roll the configuration to production.**_

* * *

## The Event IDs That Reveal Hidden Malware

Sysmon emits more than two dozen event types, and you do not need all of them to catch a fileless attack. The [Sysmon events reference](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-events) organizes them around behavior, which is the right mental model: “No single event indicates malicious activity by itself.” You catch hidden malware by correlating a small set of events into a chain.

### The Nine Events That Carry a Hidden Attack

| Event ID | Event name | Why a hidden attack cannot avoid it |
| --- | --- | --- |
| 1 | Process Create | Records the full command line, parent image, and hashes for every process, including LOLBins launched by `cmd.exe` or Office |
| 3 | Network Connect | Attributes an outbound connection to the exact process and user that made it |
| 8 | CreateRemoteThread | Flags one process starting a thread inside another, the signature of code injection |
| 10 | ProcessAccess | Catches a process opening another for memory access, the step before credential theft |
| 11 | FileCreate | Shows a dropper writing a payload to disk, including into user-writable folders |
| 13 | RegistryEvent (Value Set) | Records the value data written to persistence keys such as `Run` |
| 15 | FileCreateStreamHash | Hashes alternate data streams, including the Zone.Identifier stream on downloaded files |
| 22 | DNS Query | Logs name resolution whether or not the connection succeeds, exposing beaconing |
| 25 | ProcessTampering | Detects image manipulation such as process hollowing |

One expectation to set before you read that table: what appears depends on the configuration you applied. The SwiftOnSecurity baseline logs Event ID 3 through its own 70-rule include list, but its ProcessAccess section matches nothing and its ProcessTampering section carries no rules. FileCreateStreamHash is narrower still, limited to 19 filename patterns. Four of these rows therefore stay quiet until you add targets of your own.

Each matching rule carries a `RuleName`, and that field is what you read when you tune the configuration. Hartong’s sysmon-modular injects an ATT&CK technique label into each matching rule, so an Event ID 8 hit can arrive already tagged as [T1055 Process Injection](https://attack.mitre.org/techniques/T1055/).

## Query Sysmon Telemetry with Get-WinEvent

Events land in the operational channel `Microsoft-Windows-Sysmon/Operational`, and the fastest way to read them is PowerShell’s [Get-WinEvent cmdlet](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/get-winevent). A hash-table filter keeps the query structured instead of dumping the whole log.

### Filter by Event ID and Time Window

Start narrow. This pulls the last twenty process-creation events:

```powershell
Get-WinEvent -FilterHashtable @{
    LogName = 'Microsoft-Windows-Sysmon/Operational'
    Id      = 1
} -MaxEvents 20
```

The `LogName` key targets the Sysmon channel, `Id` selects the event type, and `-MaxEvents` caps the output so you are not scrolling a week of telemetry. Add `StartTime` to bound a hunt to the window around an alert.

### Read the Command Line, Parent, and Hash

The default `Get-WinEvent` view truncates the message body. Select the structured fields you actually need:

```powershell
Get-WinEvent -FilterHashtable @{
    LogName = 'Microsoft-Windows-Sysmon/Operational'
    Id      = 1
} -MaxEvents 50 | ForEach-Object {
    $x = [xml]$_.ToXml()
    [pscustomobject]@{
        Time        = $_.TimeCreated
        Image       = $x.Event.EventData.Data[4].'#text'
        CommandLine = $x.Event.EventData.Data[10].'#text'
        ParentImage = $x.Event.EventData.Data[20].'#text'
        Hashes      = $x.Event.EventData.Data[17].'#text'
    }
} | Format-Table -AutoSize
```

Sysmon writes each record as XML, and `ToXml()` exposes the named fields. The exact indexes shift with your Sysmon version and configuration, so print `$x.Event.EventData.Data` once to confirm the shape before you hard-code a report.

* * *

_**Pro Tip: Sort by field name, not by index, when you script this. Build a lookup from the _**`Name`**_ attribute so _**`Image`**_ and _**`CommandLine`**_ stay correct after a Sysmon upgrade adds or reorders fields.**_

* * *

## Detect Process Injection and Process Tampering

Injection is how fileless malware keeps running inside a trusted process. The Microsoft events reference calls out Event ID 8 as the direct tell: CreateRemoteThread “indicates that a process created a thread in another process,” a “classic code injection technique,” and the event is “low-volume and high-signal.”

### CreateRemoteThread and ProcessAccess

Query Event ID 8 on its own:

```powershell
Get-WinEvent -FilterHashtable @{
    LogName = 'Microsoft-Windows-Sysmon/Operational'
    Id      = 8
} -MaxEvents 50
```

Read the result with the image relations in mind. A remote thread from `C:\Windows\System32\svchost.exe` into another system process may be legitimate; the same event from a binary in a user profile into `explorer.exe` deserves an investigation. Event ID 10 covers the sibling behavior, one process opening a handle to another. The [Sysinternals Sysmon documentation](https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon) describes why it matters: “This enables detection of hacking tools that read the memory contents of processes like Local Security Authority (Lsass.exe) in order to steal credentials for use in Pass-the-Hash attacks.” Event ID 25 closes the loop by flagging image replacement, which Sysmon generates for “process image manipulation techniques such as process hollowing and Herpaderping.”

The trap here is volume. The same events reference notes that ProcessAccess “can be noisy, it’s typically used with targeted filtering,” so filter it to the paths and access masks you care about. The diagram below traces the chain these three events describe.

![Process injection chain](https://adamtheautomator.com/wp-content/uploads/publisher/2bd8d0dbcfe390c4c6ffbf9bf38cc81190f87866fa0e6483e38319f7feeb818d.png)

## Detect Registry Persistence and Fileless Payloads

A registry Run key is the cheapest persistence an attacker can buy. Sysmon records registry activity as Event IDs 12 through 14, and the events reference notes that Sysmon “uses abbreviated root key names (for example, HKLM, HKCU) to normalize data.” Unusual value data in a Run key matters more than the write itself.

### Run Keys and Alternate Data Streams

Pull the registry value-set events and filter to the Run key:

```powershell
Get-WinEvent -FilterHashtable @{
    LogName = 'Microsoft-Windows-Sysmon/Operational'
    Id      = 13
} -MaxEvents 100 | Where-Object { $_.Message -match 'CurrentVersion\\Run' }
```

Pair Event ID 13 with Event ID 11 to see the payload and the persistence on one timeline. Event ID 11 records a file created in a user-writable folder, which is where a dropper stages before it hides. Event ID 15 covers the alternate data stream case; the [Sysmon events reference](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-events) explains that it “records named alternate data streams, including Zone.Identifier streams,” so a file that arrived from the internet carries a marker you can trace back to the download.

* * *

_**Key Insight: Correlate the chain instead of the single hit. A registry write (Event ID 13) is benign on its own. A registry write in the same minute as a file drop (Event ID 11) by a browser process, followed by a network connection (Event ID 3) from the dropped image, is a behavior you can act on.**_

* * *

## Detect C2 Beaconing with Network and DNS Events

Every implanted attacker has to call home eventually, and that call is measurable even when the traffic is encrypted. Event ID 3 records outbound connections, but it is “disabled by default due to volume and should be enabled selectively,” so scope it to the processes that should never talk to the internet.

### Network Connect Is Noisy by Default

Event ID 3 fires for every outbound connection, so on a busy host its volume buries the signal. Add the trusted processes you never want to review to the exclusion list, and the log keeps only the connections worth a look.

Where the element sits matters as much as what it says. Every event element in a Sysmon configuration belongs inside the `<EventFiltering>` section, and the SwiftOnSecurity baseline already carries a `<NetworkConnect onmatch="exclude">` element there for Microsoft Defender’s platform binaries and Teams. Add the `<Image>` line to that element instead of starting a second one:

```xml
<Sysmon schemaversion="4.50">
  <EventFiltering>
    <!-- ... the baseline's existing rules ... -->
    <RuleGroup name="" groupRelation="or">
      <NetworkConnect onmatch="exclude">
        <Image condition="begin with">C:\ProgramData\Microsoft\Windows Defender\Platform\</Image>
        <Image condition="end with">AppData\Local\Microsoft\Teams\current\Teams.exe</Image>
        <Image condition="is">C:\Program Files\Google\Chrome\Application\chrome.exe</Image>
      </NetworkConnect>
    </RuleGroup>
  </EventFiltering>
</Sysmon>
```

Push the updated file with the same `-c` command you used in the install section. An element placed anywhere else makes `sysmon64.exe -c` exit with code `0xC0000409`, print nothing past the schema-version line, and leave the previous configuration running.

### DNS Query Is the Higher-Signal Event

Event ID 22 is the higher-signal event to hunt on. The [Sysmon events reference](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-events) notes that “DNS events often provide early indicators even when network traffic is encrypted,” because name resolution happens before the tunnel is built. Hunt for repeated queries to a rare domain from a process such as `powershell.exe` or `rundll32.exe`, and hold Microsoft’s counterweight in view: “Rare doesn’t mean malicious” and “Common doesn’t mean safe.” Baseline the DNS names and processes you expect on the host, then alert on new rare-domain queries.

## Tune the Configuration to Cut False Positives

Within a day of deployment your log fills with routine writes from software update agents and antivirus components. The [read and tune guide](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/read-tune-sysmon-events) names the discipline: “Sysmon configurations should be tuned over time to reduce noise while preserving useful signal.”

### Find the High-Volume Offenders

Summarize the log by Event ID over one to two weeks, then group the top offender by the field that explains it:

*   `Image` for a process that generates disproportionate events
    
*   `CommandLine` for a script-driven spike
    
*   `RegistryKey` for a component that writes thousands of values
    

With the offenders named, write the exclusion.

### Write Narrow Exclusions

Exclusions carry a cost that the [configuration files guide](https://learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/sysmon-configuration-files) states without softening: “Once telemetry is excluded, it cannot be recovered retroactively.” So exclude the narrowest thing that removes the noise. An update agent that writes thousands of registry values a day is a clean target:

```xml
<EventFiltering>
  <!-- ... the baseline's existing rules ... -->
  <RuleGroup name="" groupRelation="or">
    <RegistryEvent onmatch="exclude">
      <TargetObject condition="begin with">HKLM\COMPONENTS</TargetObject>
      <Image condition="end with">update-agent.exe</Image>
    </RegistryEvent>
  </RuleGroup>
</EventFiltering>
```

The `<RegistryEvent>` element belongs inside `<EventFiltering>` for the same reason the network block did, and the baseline already carries an exclude element there whose conditions you can extend. Placed outside that section, the same update aborts with exit code `0xC0000409`.

Resist the urge to switch off an entire category. Microsoft warns against disabling whole event categories or using broad string matches because that “can remove important investigative context,” and it recommends that you “start with broader logging and gradually add exclusions rather than aggressively filtering early.”

## Forward Sysmon to a SIEM and Write a Starter Detection

Local logs rotate, and evidence that rotated out of the event log is gone. Send Sysmon events off the host so an incident a month from now still has proof. [Windows Event Forwarding](https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/use-windows-event-forwarding-to-assist-in-intrusion-detection) collects the Sysmon channel to a central collector using the native subscription model, and the [Windows Forwarded Events connector for Microsoft Sentinel](https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/windows-forwarded-events) ingests it into Sentinel. On Splunk or Elastic, the [Splunk Add-on for Microsoft Sysmon](https://splunkbase.splunk.com/app/5709) or [Winlogbeat](https://www.elastic.co/docs/reference/beats/winlogbeat) parses the same XML.

### Write a Portable Rule

Write detection logic in a format that survives a SIEM migration. [Sigma](https://github.com/SigmaHQ/sigma) is the open rule language that pySigma converts into your platform’s query syntax:

```yaml
title: Suspicious Download Via Certutil.EXE
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: '\certutil.exe'
    - OriginalFileName: 'CertUtil.exe'
  selection_flags:
    CommandLine|contains:
      - 'urlcache '
      - 'verifyctl '
      - 'URL '
  selection_http:
    CommandLine|contains: 'http'
  condition: all of selection_*
level: medium
```

The rule fires when certutil starts, a download flag appears in the command line, and that line carries a URL, so it ports cleanly across platforms and documents intent for the next analyst who reads it. The block above is the current [SigmaHQ certutil download rule](https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_download.yml), reproduced as written.

## Validate Detections with Atomic Red Team

A detection you have never triggered is a guess. [Atomic Red Team](https://github.com/redcanaryco/atomic-red-team) supplies the test: it is “a library of tests mapped to the MITRE ATT&CK framework” that security teams use “to quickly, portably, and reproducibly test their environments.”

### Run the Atomic and Read the Event

One caveat before you pick. The rule above targets certutil’s download flags, and the matching atomic is T1105-7 `certutil download (urlcache)`. On a default Windows host, Microsoft Defender blocks that launch (threat ID `2147726914`, keyed on the `certutil -urlcache -split -f http...` command line), so no Event ID 1 reaches the channel and the missing event looks like a coverage hole that is not there.

You have two ways through it. Run the atomic on a dedicated lab host where the technique is allowed, or choose one that exercises the same download path without the block: T1105-10 “Windows - PowerShell Download” or T1105-18 “Curl Download File”. Certutil stays the example inside the rule; it is the atomic that changes.

Pick the atomic that matches your rule, run it on the lab host, and confirm the Sysmon event lands where you expect:

```powershell
Get-WinEvent -FilterHashtable @{
    LogName = 'Microsoft-Windows-Sysmon/Operational'
    Id      = 1
} -MaxEvents 5 | Where-Object { $_.Message -match 'certutil' }
```

Without `-Oldest`, the query reads backward from the newest record, which is where the atomic you just ran sits. To read the first events after you fire the atomic instead, bound the query with a `StartTime` value rather than adding `-Oldest`.

If the event appears and your Sigma rule fires on it, the detection is provable. If the event is missing, the fault sits in the configuration and you have found a coverage hole before an attacker did. Record which atomics you ran and the event IDs they produced so the next reviewer can reproduce the result.

## Keep the Telemetry Flowing

Treat Sysmon as a monitored service rather than a one-time install. Event ID 4 records the service starting and stopping, Event ID 16 records a configuration change, and Event ID 255 records internal errors. Alert on all three, because blinding the tool is an early move for an attacker who has landed. Microsoft’s events reference lists Event ID 4 as the sign that the service restarted, and it notes that “unexpected stops can indicate tampering attempts.”

The larger shift is in how you work. Signature scanning asks whether a file is known bad. Sysmon telemetry asks what a process did, against which target, at what time. That second question survives fileless execution, signed LOLBins, and registry-resident payloads, because behavior leaves traces a signature cannot erase. Deploy on one host, forward the events, write three rules, and validate them with atomics. The gap you started with closes with evidence, and the [Sysmon Community Guide](https://github.com/trustedsec/SysmonCommunityGuide) by Carlos Perez is the next stop when you want to go deeper on tampering and advanced configuration.

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Fsysmon-detect-hidden-malware%2F&text=Sysmon%3A%20Detect%20Hidden%20Malware%20in%20Windows%20Event%20Logs)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Fsysmon-detect-hidden-malware%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Fsysmon-detect-hidden-malware%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/publisher/3ec5d9c85b2b8198b651eec70c447ee1/bc27e65fd261774769a0da850c0fe0f594bb2c6ba5bfcf317eadea5471382804.jpg)

### [Find Expired Windows Certificates Instantly via PowerShell](/find-expired-certificates-powershell/)

Use PowerShell to scan every certificate store across a Windows fleet, report expired and expiring certificates, and alert before authentication breaks.

![](https://adamtheautomator.com/wp-content/uploads/publisher/2e05d9c85b2b81c080b8d45ec1cdfbb3/71dd588b2369d52e1695c95c1493383c6c0ed2adb4aac7eba04c1ab324f3a6a6.webp)

### [Stop Service Principal Sprawl in Entra ID with PowerShell](/stop-service-principal-sprawl-entra-id-powershell/)

Inventory every app registration and service principal, then automate ownership, rotation, and safe disablement with PowerShell and Microsoft Graph.

![](https://adamtheautomator.com/wp-content/uploads/2026/06/featured_image-13.png)

### [Taming AI Tool Sprawl: A PowerShell Guide to Auditing and Governing Unauthorized AI Applications](/taming-ai-tool-sprawl-powershell-guide-auditing/)

Detect and govern unauthorized AI tools with PowerShell, Microsoft Graph, Entra ID, and Defender for Cloud Apps.

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
