Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
A SOC analyst is investigating a Windows endpoint where an Endpoint Detection and Response (EDR) solution has flagged a 'Suspicious Parent-Child Process Relationship' alert. The alert indicates that 'cmd.exe' was spawned by 'winword.exe', and subsequently 'powershell.exe' was spawned by 'cmd.exe'. The analyst needs to determine the full command-line arguments used for the 'powershell.exe' process. Which of the following Windows event logs and Event IDs should the analyst prioritize to find this specific information?
- AApplication Log, Event ID 1000 (Application Error)
- BSecurity Log, Event ID 4624 (An account was successfully logged on)
- CMicrosoft-Windows-Sysmon/Operational, Event ID 1 (Process Create)
- DSystem Log, Event ID 7036 (Service Control Manager)
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft-Windows-Sysmon/Operational, Event ID 1 (Process Create)
Sysmon (System Monitor) is a critical tool for detailed host-based logging, and its Event ID 1 specifically logs process creation events. Crucially, these logs include the full command-line arguments used when a process is launched, which is exactly what the analyst needs to investigate the suspicious PowerShell execution.
Why the other options are wrong
- A. Event ID 1000 in the Application log indicates application crashes or errors, not process creation details or command-line arguments.
- B. Event ID 4624 in the Security log indicates a successful logon and does not contain command-line information for subsequent process executions.
- D. Event ID 7036 in the System log relates to service start/stop events, not detailed command-line arguments for general process creation.
Sysmon Process Create (Event ID 1)
Sysmon's Event ID 1 logs every process creation, providing extensive details including the executable path, parent process, user, and full command-line arguments.
- Crucial for detecting suspicious process execution.
- Captures full command-line arguments.
- Requires Sysmon to be installed and configured.
Memory trick: Sysmon sees every single system process starting.