logo

Using Sysmon and ETW For So Much More

ID: ffdca301-2ea2-5014-bb5d-6c6d70ad4905

STIX ID: report--ffdca301-2ea2-5014-bb5d-6c6d70ad4905

Feed Name: Binary Defense Blog

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This post explains Sysmon v10's new DNS query logging (Event ID 22) and demonstrates how to combine Sysmon events (Process Create ID 1, Network Connect ID 3, and DNS ID 22) to detect LOLBAS abuse such as regsvr32.exe retrieving remote scriptlets; it includes example config snippets, detection recommendations, and guidance on filtering noise for enterprise threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.