====== SysmonEvents (Event ID 1 - Process Creation with Sensitive Data) ======
Time : 10/19/2023 2:15:43 PM
Process ID : 4832
Process GUID : {12345678-90AB-CDEF-1234-567890ABCDEF}
Process Name : C:\Windows\System32\net.exe
Command Line : net use \\fileserver\share /user:administrator P@ssw0rd123!
Parent PID : 2156
Parent GUID : {ABCDEF12-3456-7890-ABCD-EF1234567890}
Parent Process : C:\Windows\System32\cmd.exe
Parent CmdLine : cmd.exe
User : CORP\john.doe
LogonGuid : {98765432-10AB-CDEF-9876-543210FEDCBA}
Session : 1
Integrity : Medium
Hashes : MD5=A1B2C3D4E5F6...,SHA256=1234567890ABCDEF...,IMPHASH=FEDCBA9876543210...
Current Dir : C:\Users\john
Pattern Match : Password, Credential
====== SysmonEvents (Event ID 1 - Process Creation with Sensitive Data) ======
Time : 10/18/2023 9:30:21 AM
Process ID : 5124
Process GUID : {23456789-01BC-DEF0-2345-678901BCDEF0}
Process Name : C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Command Line : powershell.exe -enc <base64_encoded_command_with_apikey>
Parent PID : 892
Parent GUID : {BCDEF012-3456-7890-BCDE-F01234567890}
Parent Process : C:\Windows\explorer.exe
Parent CmdLine : C:\Windows\Explorer.EXE
User : CORP\administrator
LogonGuid : {87654321-09BA-FEDC-8765-432109FEDCBA}
Session : 2
Integrity : High
Hashes : MD5=B2C3D4E5F6A7...,SHA256=234567890ABCDEF1...,IMPHASH=EDCBA98765432101...
Current Dir : C:\Users\administrator
Pattern Match : API Key, Encoded Credential
====== SysmonEvents (Event ID 1 - Process Creation with Sensitive Data) ======
Time : 10/17/2023 3:45:18 PM
Process ID : 3344
Process GUID : {34567890-12CD-EF01-3456-789012CDEF01}
Process Name : C:\Program Files\Application\app.exe
Command Line : app.exe -dbconnection "Server=DB01;Database=Production;User Id=sa;Password=DBP@ss2023;"
Parent PID : 1024
Parent GUID : {CDEF0123-4567-8901-CDEF-012345678901}
Parent Process : C:\Windows\System32\services.exe
Parent CmdLine : C:\Windows\system32\services.exe
User : CORP\svc_admin
LogonGuid : {76543210-98BA-FEDC-7654-321098FEDCBA}
Session : 0
Integrity : System
Hashes : MD5=C3D4E5F6A7B8...,SHA256=34567890ABCDEF12...,IMPHASH=DCBA987654321012...
Current Dir : C:\Program Files\Application
Pattern Match : Connection String, Database Password