1+ {
2+ "Event" : {
3+ "#attributes" : {
4+ "xmlns" : " http://schemas.microsoft.com/win/2004/08/events/event"
5+ },
6+ "System" : {
7+ "Provider" : {
8+ "#attributes" : {
9+ "Name" : " Microsoft-Windows-Sysmon" ,
10+ "Guid" : " 5770385F-C22A-43E0-BF4C-06F5698FFBD9"
11+ }
12+ },
13+ "EventID" : 1 ,
14+ "Version" : 5 ,
15+ "Level" : 4 ,
16+ "Task" : 1 ,
17+ "Opcode" : 0 ,
18+ "Keywords" : " 0x8000000000000000" ,
19+ "TimeCreated" : {
20+ "#attributes" : {
21+ "SystemTime" : " 2026-08-12T18:18:19.1149079Z"
22+ }
23+ },
24+ "EventRecordID" : 488235 ,
25+ "Correlation" : null ,
26+ "Execution" : {
27+ "#attributes" : {
28+ "ProcessID" : 3288 ,
29+ "ThreadID" : 3372
30+ }
31+ },
32+ "Channel" : " Microsoft-Windows-Sysmon/Operational" ,
33+ "Computer" : " SigmaCatchVm" ,
34+ "Security" : {
35+ "#attributes" : {
36+ "UserID" : " S-1-5-18"
37+ }
38+ }
39+ },
40+ "EventData" : {
41+ "RuleName" : " technique_id=T1059.003,technique_name=Windows Command Shell" ,
42+ "UtcTime" : " 2026-08-12 18:18:19.112" ,
43+ "ProcessGuid" : " 570E49AA-B8EB-6A7C-B309-000000001400" ,
44+ "ProcessId" : 12236 ,
45+ "Image" : " C:\\ Windows\\ System32\\ cmd.exe" ,
46+ "FileVersion" : " 10.0.26100.8737 (WinBuild.160101.0800)" ,
47+ "Description" : " Windows Command Processor" ,
48+ "Product" : " Microsoft® Windows® Operating System" ,
49+ "Company" : " Microsoft Corporation" ,
50+ "OriginalFileName" : " Cmd.Exe" ,
51+ "CommandLine" : " \" cmd.exe\" /c wscript.exe C:\\ Windows\\ System32\\ gatherNetworkInfo.vbs" ,
52+ "CurrentDirectory" : " C:\\ Users\\ frack113\\ AppData\\ Local\\ Temp\\ " ,
53+ "User" : " SigmaCatchVm\\ frack113" ,
54+ "LogonGuid" : " 570E49AA-C366-6A76-1EDD-080000000000" ,
55+ "LogonId" : " 0x8dd1e" ,
56+ "TerminalSessionId" : 1 ,
57+ "IntegrityLevel" : " High" ,
58+ "Hashes" : " SHA1=6142A8457F497ABC4B102D75F549F76A9E3577C7,MD5=1F4D18374A699452622E80F6D5BB743E,SHA256=65EC268ADD3973B6DCA64222985DA47CAEAEE44A340B0EC1466782914FD743D9,IMPHASH=010B165E4C37F484601D3DBD700C9423" ,
59+ "ParentProcessGuid" : " 570E49AA-A962-6A7C-F601-000000001400" ,
60+ "ParentProcessId" : 8368 ,
61+ "ParentImage" : " C:\\ Windows\\ System32\\ WindowsPowerShell\\ v1.0\\ powershell.exe" ,
62+ "ParentCommandLine" : " \" C:\\ Windows\\ System32\\ WindowsPowerShell\\ v1.0\\ powershell.exe\" " ,
63+ "ParentUser" : " SigmaCatchVm\\ frack113"
64+ }
65+ }
66+ }
0 commit comments