Trace a Suspicious Process with Sysmon
Sysmon process-creation event ID 1 records the image, command line, user, hashes, process GUID, and parent-process context when those fields are available. Follow that evidence as a timeline: identify the parent, understand the command, then look for related file, network, or DNS events.
This guide assumes Sysmon is installed and the Microsoft-Windows-Sysmon/Operational channel is collected. Network, DNS, and file events depend on the active configuration. Do not change the deployed configuration during triage unless the owner approves it.

Process Create: Use the parent, command line, user, and process GUID to place an Event ID 1 record in context.
Step 1: Confirm the Host and Sysmon Event Channel
Check That the Expected Telemetry Is Available
TelemetryConfirm the alert’s host name and event time, then check that the Sysmon Operational channel is enabled and has records. If the channel is absent or empty, check the deployment and forwarding health before interpreting silence as normal activity.
Get-WinEvent -ListLog 'Microsoft-Windows-Sysmon/Operational' | Select-Object LogName, IsEnabled, RecordCount, MaximumSizeInBytes
$start = (Get-Date).AddHours(-2)$events = Get-WinEvent -FilterHashtable @{ LogName = 'Microsoft-Windows-Sysmon/Operational' Id = 1 StartTime = $start} -MaxEvents 500❯ View Expected Console Output
LogName : Microsoft-Windows-Sysmon/OperationalIsEnabled : TrueRecordCount : 28416Step 2: Build a Readable Process-Creation Timeline
Extract Process and Parent Fields
Process TreeEvent ID 1 stores named values in event XML. The script below extracts the common process and parent fields while retaining the original timestamp and record ID. Missing values can mean that the event version or configuration does not provide that field; inspect the original event before drawing a conclusion.
$rows = foreach ($event in $events) { [xml]$xml = $event.ToXml() $fields = @{}
foreach ($item in $xml.Event.EventData.Data) { $name = $item.GetAttribute('Name') if ($name) { $fields[$name] = $item.InnerText } }
[pscustomobject]@{ TimeUtc = $event.TimeCreated.ToUniversalTime().ToString('o') Computer = $event.MachineName RecordId = $event.RecordId ProcessGuid = $fields.ProcessGuid ProcessId = $fields.ProcessId User = $fields.User Image = $fields.Image CommandLine = $fields.CommandLine Hashes = $fields.Hashes ParentProcessGuid = $fields.ParentProcessGuid ParentImage = $fields.ParentImage ParentCommandLine = $fields.ParentCommandLine }}
$rows | Sort-Object TimeUtc | Format-List TimeUtc, Computer, RecordId, ProcessGuid, ProcessId, User, Image, CommandLine, Hashes, ParentProcessGuid, ParentImage, ParentCommandLine❯ View Expected Console Output
TimeUtc : 2026-10-05T09:22:18.0000000ZComputer : WS-042RecordId : 81022ProcessGuid : {example-process-guid}ProcessId : 6840User : CORP\jleeImage : C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCommandLine : powershell.exe -NoProfile -File C:\Users\jlee\Downloads\review.ps1Hashes : SHA256=[example hash]ParentProcessGuid : {example-parent-guid}ParentImage : C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEParentCommandLine : "C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE" ...Step 3: Reconstruct the Parent-Child Relationship
Read the Chain from Parent to Child
Behavior ReviewStart with the process that triggered the alert and follow its ParentProcessGuid to the parent event’s ProcessGuid. Review the parent image and command line, then inspect the child image, complete command line, user, integrity level, and hash. A familiar executable name alone is weak evidence; its path, signer, parent, arguments, account, and timing matter.
Trigger process: Image and full command line User and host ProcessGuid and hash
Parent process: ParentImage and ParentCommandLine ParentProcessGuid Expected application or management workflow?
Child and follow-on activity: New processes, files, network connections, or alerts❯ View Expected Console Output
The parent is an office application, but the user's workflow anddocument origin are not yet confirmed. Keep the finding unresolved.Step 4: Correlate Optional Network, DNS, and File Events
Use Related Events Only When the Configuration Collects Them
CorrelationSysmon event ID 3 records network connections, event ID 22 records DNS queries, and event ID 11 records file creation when those events are enabled. Review the events near the process start and correlate on ProcessGuid where present. Event ID 3 is disabled by default in Sysmon’s standard behavior and may also be excluded by the deployed rules.
$relatedEvents = Get-WinEvent -FilterHashtable @{ LogName = 'Microsoft-Windows-Sysmon/Operational' Id = @(3, 11, 22) StartTime = $start} -MaxEvents 1000
$relatedEvents | Select-Object TimeCreated, Id, RecordId, MachineName, Message | Format-List❯ View Expected Console Output
Event ID 3: network connection details, including process correlationEvent ID 22: DNS query detailsEvent ID 11: file creation details
No result can mean the event type is not configured or retained.Step 5: Verify File Context and Document the Decision
Check the On-Disk File Without Running It
Safe ValidationIf the file still exists and your evidence procedure permits live inspection, calculate its current hash and check its Authenticode signature. These checks describe the file as it exists now; they do not prove it was unchanged since the event. Do not launch a suspicious file to test it.
$path = 'C:\Path\To\ObservedProgram.exe'Get-FileHash -LiteralPath $path -Algorithm SHA256Get-AuthenticodeSignature -FilePath $path | Select-Object Status, StatusMessage, SignerCertificate❯ View Expected Console Output
Algorithm Hash Path--------- ---- ----SHA256 [record the resulting hash] C:\Path\To\ObservedProgram.exe
Status: Valid / NotSigned / UnknownError