Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium

A SOC analyst is investigating a Windows endpoint where an Endpoint Detection and Response (EDR) solution has flagged a 'Suspicious Parent-Child Process Relationship' alert. The alert indicates that 'cmd.exe' was spawned by 'winword.exe', and subsequently 'powershell.exe' was spawned by 'cmd.exe'. The analyst needs to determine the full command-line arguments used for the 'powershell.exe' process. Which of the following Windows event logs and Event IDs should the analyst prioritize to find this specific information?

  1. AApplication Log, Event ID 1000 (Application Error)
  2. BSecurity Log, Event ID 4624 (An account was successfully logged on)
  3. CMicrosoft-Windows-Sysmon/Operational, Event ID 1 (Process Create)
  4. DSystem Log, Event ID 7036 (Service Control Manager)
Show answer & explanation

Correct answer: C. Microsoft-Windows-Sysmon/Operational, Event ID 1 (Process Create)

Sysmon (System Monitor) is a critical tool for detailed host-based logging, and its Event ID 1 specifically logs process creation events. Crucially, these logs include the full command-line arguments used when a process is launched, which is exactly what the analyst needs to investigate the suspicious PowerShell execution.

Why the other options are wrong

  • A. Event ID 1000 in the Application log indicates application crashes or errors, not process creation details or command-line arguments.
  • B. Event ID 4624 in the Security log indicates a successful logon and does not contain command-line information for subsequent process executions.
  • D. Event ID 7036 in the System log relates to service start/stop events, not detailed command-line arguments for general process creation.

Sysmon Process Create (Event ID 1)

Sysmon's Event ID 1 logs every process creation, providing extensive details including the executable path, parent process, user, and full command-line arguments.

  • Crucial for detecting suspicious process execution.
  • Captures full command-line arguments.
  • Requires Sysmon to be installed and configured.

Memory trick: Sysmon sees every single system process starting.

More Host-Based Analysis questions