Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?
12/18/18 10:42:58 PM UTC , NULL ,
{
"@timestamp":"2018-12-18T22:42:58.788Z",
"@metadata":
{
"beat":"winlogbeat",
"type":"doc",
"version":"6.5.3",
"topic":"winlogbeat"
},
"computer_name":"DESKTOP-LFD11QP.RIVENDELL.local",
"event_id":3,
"source_name":"Microsoft-Windows-Sysmon",
"message":"Network connection detected:\x5CnRuleName: \x5CnUtcTime: 2018-12-18 22:42:57.990\x5CnProcessGuid: {1C9FDC81-7751-5C19-0000-0010F5F91E00}\x5CnProcessId: 7916\x5CnImage: C:\x5C\x5CProgram Files (x86)\x5C\x5CGoogle\x5C\x5CUpdate\x5C\x5CGoogleUpdate.exe\x5CnUser: NT AUTHORITY\x5C\x5CSYSTEM\x5CnProtocol: tcp\x5CnInitiated: true\x5CnSourceIsIpv6: false\x5CnSourceIp: 192.168.64.137\x5CnSourceHostname: DESKTOP-LFD11QP.RIVENDELL.local\x5CnSourcePort: 49737\x5CnSourcePortName: \x5CnDestinationIsIpv6: false\x5CnDestinationIp: 172.217.7.174\x5CnDestinationHostname: iad30s09-in-f14.1e100.net\x5CnDestinationPort: 443\x5CnDestinationPortName: https",
"opcode":"Info",
"thread_id":1972,
"level":"Information",
"task":"Network connection detected (rule: NetworkConnect)",
"host":
{
"name":"DESKTOP-LFD11QP"
},
"version":5,
"record_number":"3046076",
"user":
{
"identifier":"S-1-5-18",
"name":"SYSTEM",
"domain":"NT AUTHORITY",
"type":"User"
},
"event_data":
{
"DestinationPort":"443",
"Protocol":"tcp",
"ProcessGuid":"{1C9FDC81-7751-5C19-0000-0010F5F91E00}",
"ProcessId":"7916",
"DestinationIp":"172.217.7.174",
"SourcePort":"49737",
"DestinationPortName":"https",
"Image":"C:\x5C\x5CProgram Files (x86)\x5C\x5CGoogle\x5C\x5CUpdate\x5C\x5CGoogleUpdate.exe",
"User":"NT AUTHORITY\x5C\x5CSYSTEM",
"SourceHostname":"DESKTOP-LFD11QP.RIVENDELL.local",
"SourceIsIpv6":"false",
"DestinationIsIpv6":"false",
"SourceIp":"192.168.64.137",
"DestinationHostname":"iad30s09-in-f14.1e100.net",
"UtcTime":"2018-12-18 22:42:57.990",
"Initiated":"true"
},
"beat":
{
"version":"6.5.3",
"name":"DESKTOP-LFD11QP",
"hostname":"DESKTOP-LFD11QP"
},
"type":"wineventlog",
"process_id":2160,
"provider_guid":"{5770385F-C22A-43E0-BF4C-06F5698FFBD9}",
"log_name":"Microsoft-Windows-Sysmon/Operational"
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.