0
General Details
Process Create:
RuleName:
UtcTime: 2020-06-30 09:42:07.507
ProcessGuid: {5c0220b3-08ef-5efb-0000-001000f90600}
[m^ger^j\Win^ow^S^rtem32\caTcT^eJ nie^ersion^!T95ro^ę5nwmęrieT5l>0123-1500)
Description: Windows Calculator Product: Microsoft® Windows® Operating System Company: Microsoft Corporation OriginalFileName: CALC.EXE CommandLine: cale
C u rrentD i rectory: C :\Wi n d ows\system 32\
User: UK\Administrator
LogonGuid: {5c0220b3-08ef-5efb-0000-002075f50600}
Logonld: 0x6F575 TerminalSessionld: 0 lntegrityLevel: High
Hashes: MD5= D82C445E3D484F31 CD2638A4338E5FD9,SHA256=
5543A258A819524B477DAC619EFA82B7F42822E3F446C9709FADC25FDFF94226,IMPHASH=045715AC29C84A0E47DAB339E337BC06 ParentProcessGuid: {5c0220b3-08ef-5efb-0000-00100bf60600}
3arentlmage: C:\Windows\System32\wbem\WmiPn/SE.exe
3arentCommandLine: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
Log Name:
Source:
EventID:
Level:
User
OpCode:
Morę Information:
Microsoft-Windows-Sysmon/Operational Sysmon Logged:
1 Task Category:
Information Keywords:
SYSTEM Computer:
6/30/202010:42:07 AM
Process Create (rule: ProcessCreate)
DC2.uk.mwr.com
Info
Event Log Online Help
Close