Windows Event Logs and Sysmon for Beginner SOC
Windows Event Logs record security-relevant activity (logons, process creation when enabled, account changes). Sysmon (Sysinternals) adds high-fidelity endpoint telemetry — process create, network connect, file create — that beginner SOC analysts use to rebuild “what happened” timelines. Defence only: install and read logs on systems you administer; no attack payloads.
Friends! In a SOC job "did you check the logs?" comes often. Windows Security log + Sysmon = a beginner's strongest free-ish visibility. Remember Event IDs – 4624 success logon, 4625 fail, Sysmon 1 process create. Today: read + triage — no exploit / remote-access payloads. Own lab only.
मित्रांनो! SOC job मध्ये "log बघितला का?" बरोबर येतो. Windows Security log + Sysmon = beginner ची strongest free-ish visibility. Event ID numbers लक्षात ठेवा – 4624 success logon, 4625 fail, Sysmon 1 process create. आज read + triage – exploit / remote-access payloads नाही. Own lab only.
मित्रों! SOC job में "log देखा क्या?" बार-बार आता है. Windows Security log + Sysmon = beginner की strongest free-ish visibility. Event ID numbers याद रखो – 4624 success logon, 4625 fail, Sysmon 1 process create. आज read + triage – exploit / remote-access payloads नहीं. Own lab only.
Quick answer
Windows logs + Sysmon for SOC beginners:
- Enable and forward critical Security events (logon, account logon, special privileges).
- Install Sysmon with a reputable community or org config (process, network, file, DNS if included).
- Ship both to a SIEM or central collector — local-only logs die when a host is wiped.
- Memorise a starter ID set: Security 4624/4625/4688 (if process auditing on), Sysmon 1/3/11.
- Triage with a story: user → host → parent/child process → network → time (IST labelled).
- Protect log integrity: restricted admin, central store, alert on audit policy tampering.
- Document every case like L1: decision, evidence EventRecordIDs, next action.
Tiny mental model:
Host events → (Sysmon enrich) → central SIEM → SOC triage notes
No forward = blind after wipe
IDs without context = noise
What do I need before this guide?
- Basic SOC / SIEM idea: What is SIEM?.
- Optional: EDR vs Antivirus.
- A Windows lab VM you own if you will install Sysmon.
What should a beginner SOC read first?
Windows Security and Sysmon events feed a SIEM so SOC analysts can triage process and network activity with notes.
Windows Security आणि Sysmon events SIEM ला feed करतात जेणेकरून SOC analysts process आणि network activity notes सह triage करू शकतील.
Windows Security और Sysmon events SIEM को feed करते हैं ताकि SOC analysts process और network activity notes के साथ triage कर सकें.
Core Windows Security events (starter)
- 4624 — successful logon (check Logon Type: 2 interactive, 3 network, 10 remote interactive — know the common ones).
- 4625 — failed logon (spray / password guess patterns).
- 4648 — logon with explicit credentials (interesting lateral clues at high level).
- 4720 / 4728-style account changes — new users / group membership (monitor tightly).
- Enable process creation auditing carefully if Sysmon is not yet present (noise management matters).
Sysmon events (starter)
- Event ID 1 — Process Create (Image, CommandLine, ParentImage — gold for investigation).
- Event ID 3 — Network connection (which process talked where).
- Event ID 11 — FileCreate (dropped tools / scripts — high-level detection).
- Event ID 13 / registry (if enabled) — persistence clues for later modules.
- Use a maintained config; default-everything can flood disks.
Educational warning: practise on your isolated lab or corporate lab with written approval. Do not enable aggressive auditing on production without change control.
Real incident: NotPetya (2017) — Windows estates and visibility gaps
Public reporting on NotPetya described destructive malware spreading across Windows environments at terrifying speed, with huge business outages. Defenders studying the aftermath emphasised endpoint logging, rapid isolation, and the cost of flat networks — themes that still shape SOC Windows monitoring today.
Takeaways (vertical):
- What happened — destructive wormable impact on Windows-heavy organisations.
- What went wrong (theme) — insufficient segmentation and slow understanding of process/network behaviour under stress.
- Care-take — process ancestry and rare network destinations must be queryable centrally.
- Care-take — backups and isolation playbooks beat perfect after-the-fact forensics alone.
- Care-take — “we have Event Viewer” ≠ “SOC can hunt last 30 days”.
- Bonus parallel — many ransomware IR reports start from missing or rotated-away endpoint logs.
Logon Type cheat sheet (memorise a few)
- 2 — interactive (keyboard on the console).
- 3 — network (SMB / similar access patterns).
- 10 — remote interactive (RDP-style).
- Unusual Type 10 from a rare country at 03:00 IST deserves a closer look with MFA / VPN context.
- Pair with Sysmon process evidence before calling “compromised” — admins work nights too.
Red Team vs Blue Team (awareness only)
Red Team — what attackers try
- Clear or stop local logging after access (high-level).
- Blend into normal admin tools and signed binaries (“living off the land”).
- Create noise with failed logons elsewhere to distract.
Blue Team — defend, detect, respond
- Centralise Security + Sysmon; alert if forwarding stops.
- Baseline admin process trees; alert odd parents (for example Office spawning scripting hosts — tune carefully).
- Correlate 4624 rare-source with Sysmon network events.
- Preserve timelines before reimaging.
How do I practise step by step?
Step 1 — Lab baseline
- Snapshot a Windows lab VM you own.
- Confirm you can open Event Viewer → Windows Logs → Security.
- Generate a controlled failed logon against that VM only; find 4625.
- Note time in IST with a label when you write notes.
Step 2 — Install Sysmon safely
- Download Sysmon only from the official Microsoft Sysinternals source.
- Apply a known-good config used by your org or a well-reviewed community baseline (read it first).
- Confirm Event Viewer → Applications and Services Logs → Microsoft → Windows → Sysmon → Operational.
- Start a Notepad process; confirm Sysmon ID 1 appears.
Step 3 — Build an L1 mini playbook
For each alert or lab exercise write:
- Host name and user.
- Event IDs and Record IDs cited.
- Parent → child process chain (from Sysmon 1).
- Any network (Sysmon 3) destinations — reputation check via approved tools.
- Decision: false positive / true positive / escalate.
- Containment idea: isolate host via EDR / network; reset credentials if identity suspicious.
Step 4 — Ship to SIEM
- Use Winlogbeat, Windows Event Forwarding, or your SIEM agent — product-specific docs.
- Prove a lab event arrives within minutes.
- Alert when the agent goes silent.
Step 5 — Tune before burnout
- Exclude known software update storms carefully (document exclusions).
- Keep high-signal rules: rare parent/child pairs, unexpected script hosts, sudden local account creation.
- Review exclusions quarterly so attackers do not hide in them.
Step 6 — Pair with identity
- Same user failing VPN then succeeding on the desktop?
- New mailbox rule after odd 4624 Logon Type 10?
- Windows endpoint truth + cloud identity truth together — see the SIEM guide.
Ravindra Bagale's Tip
💡 Students show Event Viewer screenshots as "analysis" in interviews — it falls short. In an L1 note write EventRecordID, parent/child, decision and next action. Sysmon CommandLine is gold, but it can hold privacy/secrets — never paste a password into a ticket. Got the discipline?
Ravindra Bagale's Tip – मराठी
💡 Students Event Viewer मध्ये screenshot घेऊन "analysis" म्हणून interview मध्ये दाखवतात – कमी पडतं. L1 note मध्ये EventRecordID, parent/child, decision आणि next action लिहा. Sysmon CommandLine field = gold, पण privacy / secrets पण असू शकतात – ticket मध्ये password paste नको. समजलं का discipline?
Ravindra Bagale's Tip – हिंदी
💡 Students Event Viewer में screenshot लेकर interview में "analysis" दिखाते हैं – कम पड़ता है. L1 note में EventRecordID, parent/child, decision और next action लिखो. Sysmon CommandLine field = gold, लेकिन privacy / secrets भी हो सकते हैं – ticket में password paste मत करो. समझ में आई discipline?
Care-take — logs that still help at 2 a.m.
- Central retention written down (hot / cold).
- Clock sync (NTP) so timelines merge.
- Alert on audit policy / Sysmon service stop.
- Admin workstations get extra telemetry, not less.
- Reimage only after volatile evidence plan — or you study a wiped disk.
- Legal hold paths for serious cases (company IR / counsel).
How do I fix common Windows logging mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Empty Security log | Audit policy off / overwritten | Enable needed categories; increase size; forward |
| Disk full in a day | Sysmon config too chatty | Start from reviewed baseline; exclude noisy paths carefully |
| “Sysmon installed” but SOC blind | Not forwarded | Agent / WEF to SIEM; test end-to-end |
| Alert fatigue on 4625 | Internet RDP exposed | Remove exposure; MFA; then tune |
| Timeline mismatch | Host clock drift | Enforce NTP |
| Lost evidence after reimage | No central copy | Forward first; IR preserve steps |
Try it at home
On your own Windows lab VM only:
- Find one 4624 and one 4625; write Logon Type and source IP fields you see.
- Install Sysmon from the official source; catch one Process Create for
notepad.exe. - Write a 6-line L1 note as if you were on SOC shift.
- List three Event IDs you will memorise this week.
- Never point lab “attack tools” at other people’s machines.
Learn it properly
Course lessons:
- Where logs live
- What a SIEM does
- Alert triage
- What digital forensics is
- Covering tracks vs log integrity
Related guides: SIEM for SOC · EDR vs AV · Phishing like a SOC analyst · IR first 24 hours
Got it? Security log + Sysmon = a SOC beginner's eyes. Memorise IDs, forward centrally, write L1 notes. Local-only logs are useless after a wipe. Lab / authorisation only. Next: MITRE ATT&CK + first Sigma rule (defence).
समजलं का? Security log + Sysmon = SOC beginner ची डोळे. IDs memorise करा, central forward करा, L1 notes लिहा. Local-only log wipe नंतर usefulness zero. Lab / authorisation only. आता MITRE ATT&CK + पहिला Sigma rule (defence) शिका.
समझ में आया? Security log + Sysmon = SOC beginner की आँखें. IDs memorise करो, central forward करो, L1 notes लिखो. Local-only log wipe के बाद usefulness zero. Lab / authorisation only. आगे MITRE ATT&CK + पहला Sigma rule (defence) सीखो.
Frequently asked questions
What is Sysmon?
A Microsoft Sysinternals service that writes high-fidelity Windows telemetry such as process create and network connect events.
Which Event IDs should beginners learn first?
Security 4624 and 4625 for logons; Sysmon 1, 3 and 11 for process, network and file create.
Why forward logs centrally?
Attackers or routine reimages destroy local evidence; SOC needs searchable history.
Can Sysmon fill the disk?
Yes if the config is too chatty — start from a reviewed baseline and tune exclusions carefully.
Is this an attack guide?
No. It is defensive logging and triage on lab or authorised systems only.
Where are deeper lessons?
SOC/SIEM chapters and log-integrity lessons in the Cyber course.