Harnessing Windows Sysmon Splunk: Unveiling the Secrets of Enhanced System Security

In the maze of cybersecurity, we frequently stumble upon tools and techniques, hoping to shield our assets from looming threats. But what if I told you that there’s a dynamic duo ready to fortify your organization’s defenses? Dive with me into the depths of Sysmon Splunk, and let’s explore the secrets they hide.
The Synergy Between Sysmon & Splunk
At the heart of Windows-based security analytics stands a sentinel – Sysmon. Lightweight but vigilant, it keeps an eagle’s eye on processes, connections, and more. Splunk, its partner in crime, devours data voraciously, making sense of Sysmon’s observations, including Event IDs, and presenting them in a digestible format.
When paired, they become your watchtowers:
Sysmon unveils intricate details, from network connections to process inception.
Splunk translates these log system activity findings into actionable insights, helping identify suspicious activity and vulnerabilities. Embarking on the Sysmon & Splunk Journey.
Getting started? Here's a detailed guide:
- Step 1: Download Sysmon and welcome it to your Windows environment, tailoring its sysmon configuration to your observation needs.
- Step 2: Introduce your Sysmon logs to either Splunk Enterprise or Splunk Cloud with the help of Splunk Add-On, creating a seamless integration using the Universal Forwarder.
- Step 3: Design custom Splunk dashboards. Let them be your threat radar, alerting at the hint of anomalous activity.
Decrypting Sysmon's Tales with Splunk
With your tools in place, it’s deciphering time.
a. Process Creation Events: Friend or Foe?
Sysmon’s stories about processes can be intriguing. These tales can reveal malware’s footprints or ransomware’s whispers. Your task? Spot the anomalies. Some narratives to be wary of:
- Processes with shady origins or unfamiliar ancestors.
- Known malevolent signatures making surprise appearances.
- The dark arts of PowerShell with concealed intentions, often detected by monitoring modification of files.
Splunk’s searching prowess can help unravel these mysteries. For instance, a search query focused on uncommon parent-child process relationships can shed light on malicious activity.
1. Unusual parent-child process relationships:
This query searches for process creation events (EventCode=1) with unusual parent-child relationships by excluding those that occur frequently.
sourcetype="sysmon" EventCode=1
| eval ParentImage=lower(ParentImage), Image=lower(Image)
| search NOT [search sourcetype="sysmon" EventCode=1
| stats count by ParentImage, Image
| where count > 10
| fields + ParentImage, Image]
2. Processes with known malicious hashes:
This query looks for processes that have hashes matching a list of known malicious hashes stored in a CSV file (known_malicious_hashes.csv). Replace “known_malicious_hashes.csv” with the appropriate file name containing your list of malicious hashes.
sourcetype="sysmon" EventCode=1
| lookup known_malicious_hashes.csv Hash as ImageLoaded
| search Malicious="True"
3. PowerShell scripts with obfuscated or encoded commands:
This query searches for process creation events where the command line contains PowerShell scripts with obfuscated or encoded commands, often used to hide malicious activity.
sourcetype="sysmon" EventCode=1 CommandLine="*powershell*"
| search CommandLine="* -e " OR CommandLine=" -enc *"
b. Network Communications: A Web of Deceit?
Ever heard of digital whispers hinting at secret pacts? Sysmon listens to them, capturing network connection events. Red flags include:
- Dialogues with infamous IP hosts.
- Odd traffic patterns hinting at secrets exchanged during unholy hours.
- Mystery connections dancing away from non-standard ports.
Splunk, with its analytical spells, can dissect these connections, spotting potential adversaries or data sneaks.
1. Connections to known malicious IP addresses:
This query looks for network connection events (EventCode=3) where the destination IP address matches a list of known malicious IP addresses stored in a CSV file (known_malicious_ips.csv). Replace “known_malicious_ips.csv” with the appropriate file name containing your list of malicious IP addresses.
sourcetype="sysmon" EventCode=3
| lookup known_malicious_ips.csv DestinationIp as DestinationIp
| search Malicious="True"
2. High volume data transfers:
This query searches for network connection events with high volume data transfers (over 100 MB) within an hour, which could indicate potential data exfiltration attempts.
sourcetype="sysmon" EventCode=3
| bin _time span=1h
| stats sum(BytesSent) as TotalBytesSent, sum(BytesReceived) as TotalBytesReceived by _time, SourceIp, DestinationIp
| where TotalBytesSent > 104857600 OR TotalBytesReceived > 104857600
3. Connections using non-standard ports:
This query looks for network connection events where the destination port is not one of the common web service ports (80, 443, or 8080). Unusual ports could indicate C2 communications or attempts to bypass security controls.
sourcetype="sysmon" EventCode=3 NOT (DestinationPort="80" OR DestinationPort="443" OR DestinationPort="8080")
c. Modifications: Signs of a Silent Invader?
In the chronicles of Sysmon, tales of file and registry modification events stand out. These can herald silent invaders aiming for persistence or hint at unauthorized tweaks. Some chapters to monitor:
- Modifications in the guarded realms of “System32” or “Program Files.”
- Stealthy changes to registry keys guarding the startup or security chambers.
- Signatures that match known evil entities.
As always, Splunk can be your guide, deciphering the clues and illuminating the shadows.
1.Creation or modification of files in sensitive system directories:
This query looks for file creation (EventCode=11) and modification (EventCode=2) events occurring in the “System32” and “Program Files” directories, which could indicate unauthorized changes or malware activity.
sourcetype="sysmon" (EventCode=11 OR EventCode=2)
| eval TargetFilename=lower(TargetFilename)
| search TargetFilename="*\\system32\\*" OR TargetFilename="*\\program files\\*"
2. Unauthorized changes to registry keys associated with startup or security settings:
This query searches for registry key modifications (EventCode=12, 13, and 14) in the “Run” and “Policies” sections, which could indicate attempts to establish persistence or modify security settings.
sourcetype="sysmon" (EventCode=12 OR EventCode=13 OR EventCode=14)
| eval TargetObject=lower(TargetObject)
| search TargetObject="*\\software\\microsoft\\windows\\currentversion\\run\\*" OR TargetObject="*\\software\\microsoft\\windows\\currentversion\\policies\\*"
3. Files or registry keys with known malicious hashes:
This query looks for file and registry modification events where the associated file hash matches a list of known malicious hashes stored in a CSV file (known_malicious_hashes.csv). Replace “known_malicious_hashes.csv” with the appropriate file name containing your list of malicious hashes.
sourcetype="sysmon" (EventCode=11 OR EventCode=12 OR EventCode=13 OR EventCode=14)
| lookup known_malicious_hashes.csv Hash as TargetImage
| search Malicious="True"
Leveling Up: Boosting Defenses with Sysmon & Splunk
Beyond surveillance, our duo offers more:
- Trigger real-time alerts in Splunk, backed by alert names. When the night is darkest, let these be your beacons.
- Use Splunk’s foresight (aka machine learning) to spot and forecast odd patterns, staying one step ahead in threat hunting. Integrate with your security arsenal.
- Whether it’s IDS, SIEM, or incident platforms, create a fortified stronghold, enhancing the powerful tool capability of both.
A Deep Dive into Splunk and Sysmon: Configuration, Event Logs, and Beyond
Navigating the labyrinthine world of cybersecurity, SOC analysts are always on the lookout for tools that can bolster their defenses. Amidst the myriad solutions available, one duo shines particularly bright. Enter Splunk and Sysmon, stalwarts of system security, awaiting to be deployed.
The Anatomy of a Configuration File
Before diving headlong into Sysmon, an analyst must be acquainted with the heart and soul of Sysmon – its Configuration File. This isn’t just any file. It’s the essence of how Sysmon will operate.
- The Default Configuration is decent, but you, the vigilant guardian, might want to tweak it according to the bespoke needs of your organization.
- Remember the File Creation Time? This might be pivotal in threat hunting, especially when you’re tracing back to when a potential compromise occurred.
- File Delete operations also tell their tales, signaling the steps an adversary took post-breach, perhaps to cover their tracks.
Musing over this, do you recall your Favorite Text Editor? Whether you’re a ‘vim’ aficionado or a ‘nano’ enthusiast, you’d need it. For what? Well, for Editing Lookup Files, Config File adjustments, or even dabbling with that CSV File Splunk might throw your way.
Beyond the Basics: Splunk Universal and Event Logging
Ah, Splunk Universal. Not just Splunk, but its omnipresent cousin. But to extract its true potential, one needs the Splunk App. Additionally, have you heard of the Splunk Search Macros? These can be game-changers, offering shortcuts to complex search queries.
Event logs are the chronicles of a system. They narrate tales of normalcy and chaos alike:
- Windows Event Forwarding ensures no tale goes unheard, channeling logs from across the domain.
- Event Content can sometimes get overwhelming. That’s where Event Log Collection steps in, providing a consolidated view.
- Metrics like Event Per Minute offer a quick pulse on system activity. An unusual spike might be indicative of Abnormal Activity or even APT Activity.
Sysmon's Modular Approach and Other Tools
Have you tinkered with the Modular Sysmon or gotten your hands on the Sysmon Framework? What about the File From SwiftOnSecurity? If you haven’t, maybe it’s time. These are not just tools; they’re enhancements. Speaking of tools, ADHunt Tool is a commendable mention, especially when coupled with Administrative Tools.
The Server, The Folder, and The Commands
Embarking on this journey, one might need to familiarize themselves with the Server Setup. Whether you’re adopting a Centralized Server approach or a Client Server Model, the choice can significantly influence data flow.
- Ever seen the Yellow Folder Icon in the Downloads Folder? A mere icon, yet it signifies the start of many installations.
- The Documents Folder? Not just for reports or presentations. It might be harboring logs, configs, or more.
- Remember the ports? Whether Common Web Service Ports or the Destination Port of that suspicious traffic, it’s essential to keep an eye out. Especially when you Configure Receiving Default Port in Splunk.
Command Prompt enthusiasts, a shout-out to you! The Breakdown Of Commands or using the Command Line Options might seem trivial but can significantly influence how you interact with tools. It’s not just about entering commands; it’s about understanding their essence.
Wrapping Up: A Message to SOC Analysts
Dedicated SOC analysts, especially the ‘Blue-Team’ Team Members, this is for you. The journey with Splunk and Sysmon, enriched with tools and configurations, is not just about defense. It’s a quest, a constant endeavor to learn, adapt, and protect.
Closing Thoughts
In the realm of cybersecurity, Sysmon and Splunk emerge as knights in shining armor. Their combined prowess aids in detecting shadows, countering threats, and safeguarding your digital treasures. So, gear up and embark on this quest, fortified with the knowledge from this blog post, to strengthen your digital kingdom.


