| 1 | Microsoft-Windows-Sysmon/Operational | 1 | Process Create (rule: ProcessCreate) | Process Create. 
                      LogonGuid/LogonId: ID of the logon sessionParentProcessGuid/ParentProcessId: Process ID of the parent processParentImage: Executable file of the parent processCurrentDirectory: Work directoryCommandLine: Command line of the execution command ([Path to Tool] -u [User Name] -s [User SID] -d [Domain])IntegrityLevel: Privilege level (Medium)ParentCommandLine: Command line of the parent processUtcTime: Process execution date and time (UTC)ProcessGuid/ProcessId: Process IDUser: Execute as userHashes: Hash value of the executable fileImage: Path to the executable file (path to the tool) | 
                  
                    
                    | Security | 4688 | Process Create | A new process has been created. 
                      Process Information > Required Label: Necessity of privilege escalationSubject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolProcess Information > Source Process Name: Path to parent process that created the new processLog Date and Time: Process execution date and time (local time)Process Information > New Process Name: Path to the executable file (path to the tool)Process Information > Token Escalation Type: Presence of privilege escalation (1)Process Information > New Process ID: Process ID (hexadecimal)Process Information > Source Process ID: Process ID of the parent process that created the new process. "Creator Process ID" in Windows 7Subject > Logon ID: Session ID of the user who executed the process | 
                  
                    | 2 | Microsoft-Windows-Sysmon/Operational | 12 | Registry object added or deleted (rule: RegistryEvent) | Registry object added or deleted. 
                      EventType: Process type (CreateKey)Image: Path to the executable file (path to the tool)ProcessGuid/ProcessId: Process IDTargetObject: Created/deleted registry key/value (\REGISTRY\MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters) | 
                  
                    
                    | Microsoft-Windows-Sysmon/Operational | 3 | Network connection detected (rule: NetworkConnect) | Network connection detected. 
                      Protocol: Protocol (tcp)DestinationIp: Destination IP address (Domain Controller IP address)Image: Path to the executable file (executable file name of the tool)DestinationHostname: Destination host name (Domain Controller host name)ProcessGuid/ProcessId: Process ID (process ID of the tool)User: Execute as userDestinationPort: Destination port number (88)SourcePort: Source port number (high port)SourceHostname: Source host name (source host name)SourceIp: Source IP address (source host IP address) | 
                  
                    
                    | Security | 5158 | Filtering Platform Connection | The Windows Filtering Platform has permitted a bind to a local port. 
                      Network Information > Protocol: Protocol used (6=TCP)Network Information > Source Port: Bind local port (high port)Application Information > Process ID: Process IDApplication Information > Application Name: Execution process (path to the tool) | 
                  
                    
                    | Security | 5156 | Filtering Platform Connection | The Windows Filtering Platform has allowed a connection. 
                      Network Information > Destination Port: Destination port number (88)Network Information > Source Port: Source port number (high port)Network Information > Destination Address: Destination IP address (Domain Controller IP address)Network Information > Protocol: Protocol used (6=TCP)Application Information > Application Name: Execution process (path to the tool)Network Information > Direction: Communication direction (outbound)Network Information > Source Address: Source IP address (source host IP address)Application Information > Process ID: Process ID | 
                  
                    | 3 | Microsoft-Windows-Sysmon/Operational | 11 | File created (rule: FileCreate) | File created. 
                      Image: Path to the executable file (path to the tool)ProcessGuid/ProcessId: Process IDTargetFilename: Created file ([Work Directory]\TGT_[User Name]@[Domain].ccache)CreationUtcTime: File creation date and time (UTC) | 
                  
                    
                    | Security | 4656 | File System/Other Object Access Events | A handle to an object was requested. 
                      Process Information > Process ID: Process ID (hexadecimal)Access Request Information > Access/Reason for Access/Access Mask: Requested privilegeSubject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolObject > Object Name: Target file name ([Work Directory]\TGT_[User Name]@[Domain].ccache)Process Information > Process Name: Name of the process that closed the handle (path to the tool)Object > Object Type: Type of the file (File)Subject > Logon ID: Session ID of the user who executed the processObject > Handle ID: ID of the relevant handle | 
                  
                    
                    | Security | 4663 | File System | An attempt was made to access an object. 
                      Process Information > Process ID: Process ID (hexadecimal)Access Request Information > Access/Reason for Access/Access Mask: Requested privileges (including WriteData or AddFile, and AppendData)Subject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolObject > Object Name: Target file name ([Work Directory]\TGT_[User Name]@[Domain].ccache)Access Request Information > Access: Requested privilegeAudit Success: Success or failure (access successful)Process Information > Process Name: Name of the process that closed the handle (path to the tool)Object > Object Type: Category of the target (File)Subject > Logon ID: Session ID of the user who executed the processObject > Handle ID: ID of the relevant handle (handle obtained with Event ID 4656) | 
                  
                    
                    | Security | 4658 | File System | The handle to an object was closed. 
                      Process Information > Process ID: Process ID (hexadecimal)Process Information > Process Name: Name of the process that requested the object (path to the tool)Subject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolSubject > Logon ID: Session ID of the user who executed the processObject > Handle ID: ID of the relevant handle (handle obtained with Event ID 4656) | 
                  
                    | 4 | Microsoft-Windows-Sysmon/Operational | 5 | Process terminated (rule: ProcessTerminate) | Process terminated. 
                      UtcTime: Process terminated date and time (UTC)ProcessGuid/ProcessId: Process IDImage: Path to the executable file (path to the tool) | 
                  
                    
                    | Security | 4689 | Process Termination | A process has exited. 
                      Process Information > Process ID: Process ID (hexadecimal)Subject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolProcess Information > Exit Status: Process return value (0x0)Log Date and Time: Process terminated date and time (local time)Process Information > Process Name: Path to the executable file (path to the tool)Subject > Logon ID: Session ID of the user who executed the process | 
                  
                    | 5 | Microsoft-Windows-Sysmon/Operational | 1 | Process Create (rule: ProcessCreate) | Process Create. 
                      LogonGuid/LogonId: ID of the logon sessionParentProcessGuid/ParentProcessId: Process ID of the parent processParentImage: Executable file of the parent processCurrentDirectory: Work directoryCommandLine: Command line of the execution command ([Path to Tool "mimikatz"] "kerberos::ptc TGT_[User Name]@[Domain].ccache" exit)IntegrityLevel: Privilege level (Medium)ParentCommandLine: Command line of the parent processUtcTime: Process execution date and time (UTC)ProcessGuid/ProcessId: Process IDUser: Execute as userHashes: Hash value of the executable fileImage: Path to the executable file (path to tool "mimikatz") | 
                  
                    
                    | Security | 4688 | Process Create | A new process has been created. 
                      Process Information > Required Label: Necessity of privilege escalationSubject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolProcess Information > Source Process Name: Path to parent process that created the new processLog Date and Time: Process execution date and time (local time)Process Information > New Process Name: Path to the executable file (path to tool "mimikatz")Process Information > Token Escalation Type: Presence of privilege escalation (1)Process Information > New Process ID: Process ID (hexadecimal)Process Information > Source Process ID: Process ID of the parent process that created the new process. "Creator Process ID" in Windows 7Subject > Logon ID: Session ID of the user who executed the process | 
                  
                    | 6 | Security | 4673 | Sensitive Privilege Use | A privileged service was called. 
                      Subject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolProcess > Process ID: ID of the process that used the privilegeSubject > Logon ID: Session ID of the user who executed the processService Request Information > Privilege: Privileges used (SeTcbPrivilege)Process > Process Name: Process that used the privileges (path to the tool "mimikatz") | 
                  
                    | 7 | Microsoft-Windows-Sysmon/Operational | 5 | Process terminated (rule: ProcessTerminate) | Process terminated. 
                      UtcTime: Process terminated date and time (UTC)ProcessGuid/ProcessId: Process IDImage: Path to the executable file (path to tool "mimikatz") | 
                  
                    
                    | Security | 4689 | Process Termination | A process has exited. 
                      Process Information > Process ID: Process ID (hexadecimal)Subject > Security ID/Account Name/Account Domain: SID/Account name/Domain of the user who executed the toolProcess Information > Exit Status: Process return value (0x0)Log Date and Time: Process terminated date and time (local time)Process Information > Process Name: Path to the executable file (path to tool "mimikatz")Subject > Logon ID: Session ID of the user who executed the process | 
                  
                    | 8 | Microsoft-Windows-Sysmon/Operational | 3 | Network connection detected (rule: NetworkConnect) | Network connection detected. 
                      Protocol: Protocol (tcp)DestinationIp: Destination IP address (Domain Controller IP address)Image: Path to the executable file (System)DestinationHostname: Destination host name (Domain Controller host)ProcessGuid/ProcessId: Process IDUser: Execute as user (NT AUTHORITY\SYSTEM)DestinationPort: Destination port number (445)SourcePort: Source port number (high port)SourceHostname: Source host name (source host)SourceIp: Source IP address (source host IP address) | 
                  
                    
                    | Security | 5158 | Filtering Platform Connection | The Windows Filtering Platform has permitted a bind to a local port. 
                      Network Information > Protocol: Protocol used (6=TCP)Network Information > Source Port: Bind local port (high port)Application Information > Process ID: Process IDApplication Information > Application Name: Execution process (System) | 
                  
                    
                    | Security | 5156 | Filtering Platform Connection | The Windows Filtering Platform has allowed a connection. 
                      Network Information > Destination Port: Destination port number (445)Network Information > Source Port: Source port number (high port)Network Information > Destination Address: Destination IP address (Domain Controller IP address)Network Information > Protocol: Protocol used (6=TCP)Application Information > Application Name: Execution process (System)Network Information > Direction: Communication direction (outbound)Network Information > Source Address: Source IP address (source host IP address)Application Information > Process ID: Process ID | 
                  
                    | 9 | Microsoft-Windows-Sysmon/Operational | 3 | Network connection detected (rule: NetworkConnect) | Network connection detected. 
                      Protocol: Protocol (tcp)DestinationIp: Destination IP address (Domain Controller IP address)Image: Path to the executable file (System)DestinationHostname: Destination host name (Domain Controller host)ProcessGuid/ProcessId: Process IDUser: Execute as user (NT AUTHORITY\SYSTEM)DestinationPort: Destination port number (88)SourcePort: Source port number (high port)SourceHostname: Source host name (source host)SourceIp: Source IP address (source host IP address) | 
                  
                    
                    | Security | 5158 | Filtering Platform Connection | The Windows Filtering Platform has permitted a bind to a local port. 
                      Network Information > Protocol: Protocol used (6=TCP)Network Information > Source Port: Bind local port (high port)Application Information > Process ID: Process IDApplication Information > Application Name: Execution process (\device\harddiskvolume2\windows\system32\lsass.exe) | 
                  
                    
                    | Security | 5156 | Filtering Platform Connection | The Windows Filtering Platform has allowed a connection. 
                      Network Information > Destination Port: Destination port number (88)Network Information > Source Port: Source port number (high port)Network Information > Destination Address: Destination IP address (Domain Controller IP address)Network Information > Protocol: Protocol used (6=TCP)Application Information > Application Name: Execution process (\device\harddiskvolume2\windows\system32\lsass.exe)Network Information > Direction: Communication direction (outbound)Network Information > Source Address: Source IP address (source host IP address)Application Information > Process ID: Process ID |