Windows Event Logs go from mush to goldmine: process creation with full command lines, network connections, DNS queries, image loads. No serious SOC works without it.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Olaf Hartong / SwiftOnSecurity configs are the community standard.
Every process, who's its parent, full command line.
Encoded commands become visible artifacts.
Sysmon 3 + GeoIP = beacon hunting.
Shipped logs = detections everywhere; that's the job.
| Event 1 | process creation |
| Event 3 | network connections |
| Event 7 | image/DLL loads |
| Event 11 | file creation |
| Event 22 | DNS queries |
| config.xml | rules decide quality |
Config IS the product: start with SwiftOnSecurity, tune with lolbas research.
Test each event type by doing the attack in your lab, then find it.
Event 10 (process access to lsass.exe) is the mimikatz tripwire.
Pair with Sigma rules β convert to your SIEM's language.
Use Sysmon only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.