name: Sysmon EventID 3 id: 01d84dff-4e26-422c-9389-6a579ee6e75b version: 4 creation_date: '2024-05-22' modification_date: '2026-05-13' author: Patrick Bareiss, Splunk description: Logs details of network connections initiated by processes, including source and destination IPs, ports, protocols, and the associated process metadata. mitre_components: - Network Connection Creation - Network Traffic Flow - Process Metadata - Application Log Content - OS API Execution source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog separator: EventID separator_value: '3' configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 version: 5.0.0 fields: - _time - Channel - Computer - DestinationHostname - DestinationIp - DestinationIsIpv6 - DestinationPort - DestinationPortName - EventChannel - EventCode - EventData_Xml - EventDescription - EventID - EventRecordID - Guid - Image - Initiated - Keywords - Level - Name - Opcode - ProcessGuid - ProcessID - ProcessId - Protocol - RecordID - RecordNumber - RuleName - SecurityID - SourceHostname - SourceIp - SourceIsIpv6 - SourcePort - SourcePortName - SystemTime - System_Props_Xml - Task - ThreadID - TimeCreated - User - UserID - UtcTime - Version - action - app - creation_time - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dest - dest_ip - dest_port - direction - dvc - dvc_ip - dvc_nt_host - event_id - eventtype - host - id - index - linecount - process_exec - process_guid - process_id - process_name - protocol - protocol_version - punct - signature - signature_id - source - sourcetype - splunk_server - src - src_host - src_ip - src_port - state - tag - tag::eventtype - timeendpos - timestartpos - transport - transport_dest_port - user - user_id - vendor_product output_fields: - action - app - dest - dest_ip - dest_port - direction - dvc - protocol - protocol_version - src - src_ip - src_port - transport - user - vendor_product example_log: 354300x8000000000000000156837Microsoft-Windows-Sysmon/Operationalwin-dc-ctus-attack-range-403.attackrange.local-2022-09-15 12:56:19.679{6820D070-1F1B-6323-E113-000000007402}5728C:\Temp\agent_tesla-deob.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-ctus-attack-range-403.attackrange.local61722-false41.77.117.236youssef5.genious.net21ftp