354300x8000000000000000670492Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:07.296{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51123-false10.0.1.12-8000-
23542300x8000000000000000670491Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:08.804{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5935DDAA571AE078D48A17893E35BE5F,SHA256=CEA4226FC40B694A86A810BBED9351BE74840813C2EAF969726D242A3A16FC9C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571909Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:08.672{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0FC490679F24FA49721A4517ABAA612F,SHA256=80435222DDD0CE9DCE4CCCD78AD1EAD07EC42D600DA72201E0F58AF969A2B105,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670493Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:09.818{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A41547B0309BDCE80D54F9EF5B7281FF,SHA256=78E1EB50F25255EA1A557D08D198217E23827723F2CDD6BC6D9EE91C2333A35B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571911Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:09.672{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9EE527490B3848550BF74CD410765567,SHA256=C47420DAB93F1CFB779CD5F2AC6374BBD2C811E389C86CDC4F66A5AB78341275,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571910Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:09.469{E1BD9FC2-D2BA-609A-1000-00000000BB01}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=65B75C2101C5AEC4EFF324132C52F46B,SHA256=E30E09626129BC2A8F0EA518E2B91BB50C449C9D9D99F5514FC22C2DE3C87345,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670504Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.819{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=29E18EF79E6EE1B6E53C2021678547C8,SHA256=3309FAC138993962E90DE119DEFCCB8B7EE3CE4EEC6E2CEB3BE3364E46B4381B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571914Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:10.672{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7E4DC128B463F65A80C2AEEA212BD971,SHA256=49ABF14D98E3461F273806D7CC8849FD8B4FEAF0C87DA8E3DC149CCBAE1E58D0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670503Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.120{7B03F3B2-4788-609D-774E-00000000BA01}1036ATTACKRANGE\AdministratorC:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exeC:\Users\Administrator\AppData\Local\Microsoft\Windows\PowerShell\ISE\S-1-5-5-0-27437121\PowerShellISEPipeName_1_ef81047d-3beb-438b-9a37-b80788d920bfMD5=A5EA0AD9260B1550A14CC58D2C39B03D,SHA256=F1B2F662800122BED0FF255693DF89C4487FBDCF453D3524A42D4EC20C3D9C04,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670502Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.104{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-4788-609D-774E-00000000BA01}1036C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1a375|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670501Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.089{7B03F3B2-31A0-609C-522D-00000000BA01}18764012C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-872D-00000000BA01}6892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+194dd|C:\Windows\System32\SHELL32.dll+61df0|C:\Windows\System32\SHELL32.dll+62e17|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd9f|C:\Windows\System32\windows.storage.dll+13ab2b|C:\Windows\System32\windows.storage.dll+13904f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670500Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.089{7B03F3B2-31A0-609C-522D-00000000BA01}18764012C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-872D-00000000BA01}6892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618a4|C:\Windows\System32\SHELL32.dll+62e17|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd9f|C:\Windows\System32\windows.storage.dll+13ab2b|C:\Windows\System32\windows.storage.dll+13904f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670499Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.089{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6164f|C:\Windows\System32\SHELL32.dll+628b0|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670498Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.089{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+47bd0|C:\Windows\System32\SHELL32.dll+6286c|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670497Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.089{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618a4|C:\Windows\System32\SHELL32.dll+62840|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670496Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.089{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d319|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670495Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.073{7B03F3B2-D0CA-609A-1400-00000000BA01}10764220C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\cryptsvc.dll+6124|c:\windows\system32\cryptsvc.dll+5e34|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670494Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:10.058{7B03F3B2-4788-609D-774E-00000000BA01}1036ATTACKRANGE\AdministratorC:\Windows\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exeC:\Users\Administrator\AppData\Local\Microsoft_Corporation\PowerShell_ISE.exe_StrongName_lw2v2vm3wmtzzpebq33gybmeoxukb04w\3.0.0.0\AutoSaveInformation\1036.xmlMD5=5714059E6175AA2BE2D911D4379F98E9,SHA256=264C6878029CE25FF6ED4F8B1DC23FC47E1DCE8FD2D3EE4B31E7066B69968955,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571913Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:10.407{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0B0C72036F7FF9F4112FA94297406878,SHA256=F808654766B7D0E94E6DD8CA7F9EC46D108DFD14F90AFAAA511B28BF510C9D8E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571912Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:10.407{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A3347526878DEE4ABBCF82DE10C6EEE0,SHA256=9D47E9830D6E34F17065D558B59F37B87529DFC67B8527DB8A0FE873D8900FF1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571916Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:11.688{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BE1068E4B0B80C245FD29C851B708D51,SHA256=508F91EF8EB6502627A54BD974DE3C6BFA4CA9BD49277A86A5FA8207AAFEC05A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670512Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.835{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0AD7FED15C307168CAB60C613C46A0D6,SHA256=19F0A82C58C861F9026E3CE416F54A67DDB97DBE87CD241B289D406271668858,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670511Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.457{7B03F3B2-31A0-609C-522D-00000000BA01}18764012C:\Windows\Explorer.EXE{7B03F3B2-3953-609D-A54C-00000000BA01}2120C:\Program Files\Git\git-cmd.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+194dd|C:\Windows\System32\SHELL32.dll+61df0|C:\Windows\System32\SHELL32.dll+62e17|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd9f|C:\Windows\System32\windows.storage.dll+13ab2b|C:\Windows\System32\windows.storage.dll+13904f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670510Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.457{7B03F3B2-31A0-609C-522D-00000000BA01}18764012C:\Windows\Explorer.EXE{7B03F3B2-3953-609D-A54C-00000000BA01}2120C:\Program Files\Git\git-cmd.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618a4|C:\Windows\System32\SHELL32.dll+62e17|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd9f|C:\Windows\System32\windows.storage.dll+13ab2b|C:\Windows\System32\windows.storage.dll+13904f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670509Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.457{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-3953-609D-A64C-00000000BA01}1904C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6164f|C:\Windows\System32\SHELL32.dll+628b0|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670508Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.457{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-3953-609D-A64C-00000000BA01}1904C:\Windows\system32\conhost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+47bd0|C:\Windows\System32\SHELL32.dll+6286c|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670507Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.457{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-3953-609D-A64C-00000000BA01}1904C:\Windows\system32\conhost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618a4|C:\Windows\System32\SHELL32.dll+62840|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670506Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.457{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-3953-609D-A64C-00000000BA01}1904C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d319|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670505Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:11.154{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=396329CB22319760E1E3F261D6A6C233,SHA256=85E512ADCEB0378F1DDA5FD08C56EC1811C5CB6C6F6F7835EF088F6B09D080B9,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000571915Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:08.851{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52742-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000670519Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.855{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BFC03B595B6C4246FCB2872D6362DD72,SHA256=4463C9BF3507AB799590240B3267DB1D5AF30098ECCCE650804CA337B5784B46,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571917Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:12.688{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=187AABD48957806C1A58880FCB491DA1,SHA256=06B2948A94348C8095ECE0F3CEB4DBBC832C0F49E37D824F57FADE1D724751AA,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670518Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.403{7B03F3B2-31A0-609C-522D-00000000BA01}18764012C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-872D-00000000BA01}6892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+194dd|C:\Windows\System32\SHELL32.dll+61df0|C:\Windows\System32\SHELL32.dll+62e17|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd9f|C:\Windows\System32\windows.storage.dll+13ab2b|C:\Windows\System32\windows.storage.dll+13904f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670517Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.403{7B03F3B2-31A0-609C-522D-00000000BA01}18764012C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-872D-00000000BA01}6892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618a4|C:\Windows\System32\SHELL32.dll+62e17|C:\Windows\Explorer.EXE+3c618|C:\Windows\Explorer.EXE+3c4a4|C:\Windows\Explorer.EXE+3c411|C:\Windows\System32\windows.storage.dll+13bd9f|C:\Windows\System32\windows.storage.dll+13ab2b|C:\Windows\System32\windows.storage.dll+13904f|C:\Windows\System32\SHCORE.dll+367a6|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670516Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.403{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+6164f|C:\Windows\System32\SHELL32.dll+628b0|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670515Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.403{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+47bd0|C:\Windows\System32\SHELL32.dll+6286c|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670514Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.403{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHELL32.dll+618a4|C:\Windows\System32\SHELL32.dll+62840|C:\Windows\System32\TwinUI.dll+12d4e1|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670513Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.403{7B03F3B2-31A0-609C-522D-00000000BA01}18763640C:\Windows\Explorer.EXE{7B03F3B2-326C-609C-882D-00000000BA01}6984C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\TwinUI.dll+12d319|C:\Windows\System32\TwinUI.dll+12dfcf|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670521Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:13.871{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=73E1BD8223C5D7691B46BB41FA2DA0C1,SHA256=9EC95ABAD55A025539BC2B9961F43D4CACB12D32D96E12357EBC437F37199D9C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571918Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:13.704{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=62F78098EA2E4F7BE9283BDCF34FD0DB,SHA256=E2C6B07F2489E95F79588EE916F5B2A3F1EA499316037862855C7FD6CAAB2EC0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670520Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:13.103{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B336164CF1B8EBFE19162B99CEA3FF35,SHA256=3274286E3A41E8E1FC19E5D1A784746784BE033BF60FA834260FC44C2DB1AC3F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670524Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:14.885{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=816559304BE057D4A3E1ECFB35A9C0BC,SHA256=C47F6DA8CB820BD0DB5C7DB70B0F90B0097CC095A5A9C670CCD80CD73FE7C579,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571919Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:14.719{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2DC8CC9FDE8F458EF8F60A1BB2986685,SHA256=C2E6AB84CBA9228BA0AE6BE662FDA680CC01051171F159D44893B4AF0F1CFD4B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670523Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:14.502{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-PowerShell_OperationalMD5=22FA6C2ECAB9C0330F57C46448C19474,SHA256=985C63C49E6C10CAD4E9BE13728D588BD8090B15B4D71DEB019FFAC26C7DFF63,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670522Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:12.334{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51124-false10.0.1.12-8000-
23542300x8000000000000000670525Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:15.888{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B6A143B1903E6CDC43D981ABA5C8932,SHA256=9FA26F7239DC218D93683463BCA8440D2B1E4A6ABA4A5F6ECFC52FA1A24D1AA2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571920Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:15.719{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A0F49CF2D7290EFF62124ACED1B3E9D1,SHA256=A67DB9580E0773B5CF201F2A3109AA684074D06CDAD9D448A399991F2E2BB749,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670526Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:16.903{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5FF6F4346C99ECF217059A3E1BA1B14E,SHA256=BB84B059CAD8DABFD9D5CA5346913D9FA2CD5DEAC4EEBA0AA89F5A207B14E5D3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571923Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:16.719{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE355CCEA08E0DA8190975FA4113D456,SHA256=07495B875F6AF97F52709FFAD02D8C1BFB6A6CA4833B47A6A4A3490292653CA6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571922Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:16.110{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4B441B24E6E724415E1C09888BDBD50B,SHA256=274D5DDC7D33A9FD6FFD6F45C636E8EDC1897A3BA521CB43B558BD298973CAB3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571921Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:16.110{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0B0C72036F7FF9F4112FA94297406878,SHA256=F808654766B7D0E94E6DD8CA7F9EC46D108DFD14F90AFAAA511B28BF510C9D8E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571925Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:17.735{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9F8FE9026D293D4773CFD096C134B876,SHA256=5992622225BDBF7C466317869F6BC490A6AAF25EC2191CE49709A8725ED60FAD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670527Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:17.934{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7FCDD9ED4A436F053FCA86E75F78341E,SHA256=9453D88FB64FDFD64B16F8A230EE69792FAFEAE30F1A0FAE27F8113E402920C8,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000571924Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:14.710{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52743-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000670530Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:18.935{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3DC32ECB8FD1DBD0041647EC574D599E,SHA256=386B2A84C53AEE0371DADF51ED299BB5615444D422513BE7A316C1AAC9B1FB8C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571926Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:18.735{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB81D55D8D8FC206CE3F7573D7AF4190,SHA256=34874DDD91D30BE6637ADF99110648E0B7020697FB9EE9DA4F5D41E688E150FF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670529Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:18.153{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=04D5B28FE07E24A6D6DB473216026BBF,SHA256=5C1FAA8DE9E546394D4CE5A8B1D6E813539E8ECE4129F59C871CAAB6F8F30F4D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670528Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:18.152{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8DBB5F76D63DECBE0CAE7589E1025FB0,SHA256=27C3B5570B6F0870B20E9D601026A929D1F1E0E1449CD9E5A3EAC5DE031704F4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670532Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:19.935{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A6E106CAF07C029BB6B7D1FB73BAA2DA,SHA256=299CB3F187168AF0878510F5C3503F7B8D76AF21E0ACF722DF7ADE3E147BBCA2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571927Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:19.750{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3BFB42572FA3A2589DC3C55D5E774F4A,SHA256=6D63FDD186FCA1217640047581B5ADF9ED528FF11C752EA4B0F824B1A91F9B42,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670531Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:17.349{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51125-false10.0.1.12-8000-
23542300x8000000000000000670533Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:20.952{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=337FC2F693A277FF1655BC913B64F19E,SHA256=607F4B67819AF5320BAFB195993BCB7241AAC8E5F273458A9C14A33A808BB867,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571928Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:20.750{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F3FAEAF477632C348950D7E837F151D,SHA256=B47C939D8F4F9375F79E7E96DBE4067AA6D8C75A29CF78BEE4729B70A02B1002,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670534Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:21.971{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AD57BC78E6C88693F1F89AC7952D5206,SHA256=95FC5FD4913B95D0ABC0FF8704D9157FFBD80CE1C7F9B062989AEC1E17303BA6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571931Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:21.766{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4331A03098958ECC58C3D8BB8C90567C,SHA256=8BDE4461C8EB3769DC0E605F5F82FBE38B65D52B4F56E94755B3357A652DFE16,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571930Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:21.329{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=64C64A5940F00F0CCA2C9D8D1FD4AF0C,SHA256=6500B185B30EA22F0D0484203A6DCA795CBF7BA8AFD024DCAB8570D52DABF5E2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571929Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:21.329{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4B441B24E6E724415E1C09888BDBD50B,SHA256=274D5DDC7D33A9FD6FFD6F45C636E8EDC1897A3BA521CB43B558BD298973CAB3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571933Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:22.766{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=814CDA3E940E0891D699ADD07A2E4FD9,SHA256=85EC819787111CDAC84D02D02AE623EEAE49462ADA5EF007CA417E104DD0B269,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670536Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:22.985{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=432F70D368F67FE0106E40D42374C228,SHA256=A6BE60BA13B0CBC23FDB2F6B80240950C91A08DB917294597DEFF9728DF31560,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670535Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:22.271{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=04D5B28FE07E24A6D6DB473216026BBF,SHA256=5C1FAA8DE9E546394D4CE5A8B1D6E813539E8ECE4129F59C871CAAB6F8F30F4D,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000571932Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:19.726{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52744-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000571934Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:23.797{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=79BE590E9C9E4BC1D5ECA771B7931D1E,SHA256=A2289BFD829FF1DBFCADCE9C9B1DCDD5992ECFB7556BE0719293E49B184264E4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571935Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:24.829{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4B1F349C8CE20C4D65CC9BA44444A0AD,SHA256=CB7828D2A367FC2DC3DFF31D28CACBC572F0B2B5B2EB7D031E6FB13117CEE697,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670538Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:22.379{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51126-false10.0.1.12-8000-
23542300x8000000000000000670537Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:24.000{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D35073299745CC8250A76F0125A87CE7,SHA256=58B14657C17D22F973AF6F224C0B454BA1FE6779F22E0EEECF7C6B1C828FFC93,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000571950Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.938{E1BD9FC2-7F05-609D-E150-00000000BB01}36403432C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000571949Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.875{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7EA8E5CBEE60DB078D77658FD626D999,SHA256=98AA1FC023C5FE3EE721C8223810B5BC4BD485F04501B85630CF9C3E02FB0654,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670541Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:25.200{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D65F22600ECCA0F426860C41C6BDC2B6,SHA256=E07B9E8593DA0C0950717AA448716B57D9CACB06BE9E4151C310A380A770F6CF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670540Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:25.152{7B03F3B2-5120-609D-3250-00000000BA01}1532NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670539Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:25.000{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C6D69EC2D4DC8E1F253600BB06123635,SHA256=5BDC2F0EA5279570C816426C5EECC18265E6EE2A01FC445590ABE539FF25535C,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000571948Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F05-609D-E150-00000000BB01}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571947Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571946Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571945Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571944Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571943Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571942Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571941Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571940Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571939Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571938Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D2B9-609A-0500-00000000BB01}412988C:\Windows\system32\csrss.exe{E1BD9FC2-7F05-609D-E150-00000000BB01}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000571937Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.813{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F05-609D-E150-00000000BB01}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000571936Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:25.814{E1BD9FC2-7F05-609D-E150-00000000BB01}3640C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000571979Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F06-609D-E350-00000000BB01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571978Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571977Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571976Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571975Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571974Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571973Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571972Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571971Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571970Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571969Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D2B9-609A-0500-00000000BB01}412528C:\Windows\system32\csrss.exe{E1BD9FC2-7F06-609D-E350-00000000BB01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000571968Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.939{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F06-609D-E350-00000000BB01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000571967Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.941{E1BD9FC2-7F06-609D-E350-00000000BB01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000571966Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.892{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=24FE622BE8DC917165181F9B1E2C6648,SHA256=915EB21386AFF886100F5275191972BFA92C422A658C3D6F12756C17F2E436AE,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670544Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:24.431{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51127-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
354300x8000000000000000670543Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:24.431{7B03F3B2-D0D7-609A-2700-00000000BA01}2888C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51127-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
23542300x8000000000000000670542Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:26.014{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B725A397D082E840F1938F747AEEB3C,SHA256=9D1EB87D30F5505304D7533EB87F4EA7D7C08C78A5B34D9850C3E6AF3D09D744,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000571965Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F06-609D-E250-00000000BB01}3308C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571964Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571963Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571962Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571961Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571960Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571959Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571958Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571957Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571956Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571955Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F06-609D-E250-00000000BB01}3308C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000571954Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.314{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F06-609D-E250-00000000BB01}3308C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000571953Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.315{E1BD9FC2-7F06-609D-E250-00000000BB01}3308C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
354300x8000000000000000571952Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:24.772{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52745-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000571951Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:26.203{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=64C64A5940F00F0CCA2C9D8D1FD4AF0C,SHA256=6500B185B30EA22F0D0484203A6DCA795CBF7BA8AFD024DCAB8570D52DABF5E2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571981Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:27.908{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=59951FAF0E4A4EC8971DBF1E7E09C1F0,SHA256=896F881A71FD0CFB6856B34EF6C84A9C7956E90735B261A088BA1F00620936B0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670555Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=DB650C50234CCBF23C732D3F9192B75E,SHA256=637205BE77DA2D84F69EB16018BAFCD822EEFB98667DD2FD8509B18F0CC275B6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670554Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=54083AAF667D5207BB677FC560800F19,SHA256=1E2C60BAEFA2AB8312FBF2BD938DE5668FBAF320B2B0780559C91AC567CEB68B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670553Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=9294C09034F3BD53B05D43D471BD1B1F,SHA256=04D7910538822B972C3AA4D1AC77750D3518A90A5FE30C76A311F6CADDA15B83,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670552Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=11F4D2C9B6987D57EE9E05AD6A31659A,SHA256=FCB12CA28F3FA0EB22F4C5F97F39C2A3DEA8A3AA168C6B2386906B423FB5D2C3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670551Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=A329AD5F3F4C6559C3E04A5E6C12F2F5,SHA256=91F9CF6ADD8269287B351E2DF789BC3CFB8C2DC42C3FF233D4157F27128A89CA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670550Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=BD4E2A69C0B8CC4C0D1634546CD0B47E,SHA256=6C418FAC75968B93C8CB91A820603F61E824ECC0A79BA50BF714F02B6D7C3438,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670549Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=23D7679051045F060FC81EC208C57D73,SHA256=657A4F9874FC08559235D96A5F02BA386B945735F6B76B11C8B1E2917F214781,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670548Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.667{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=76C6DB9A1F900F7B46409B43D2684FCC,SHA256=552C760F06C9C365899D3F8CBA7872C6133167B037C0A03027F9E51946492C6F,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670547Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:25.377{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51128-false10.0.1.12-8089-
23542300x8000000000000000670546Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.266{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=43C0F711038CCBCD8F8658B33DA3425F,SHA256=6DB3C8D7D089FAB93BBE7CCFAFD6AA8C64C69FD8231532428AB14518E82C7971,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670545Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:27.049{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E0D53EFCE4AEDB4CCC66E439ACB5CCE0,SHA256=8088D2F03CA0406EC2F6AE190C9E5445A61B56F8D68C7BFE602205BBC6E821DC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571980Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:27.361{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1126368DC18696075CE45AA82E5247C9,SHA256=3D904538775C65429CC60C98505F30AD04B13C5BB77E3227BE0A336D2BF8A1B2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571982Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:28.925{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB04BFD750D935FA194F0211D6A44018,SHA256=6FBBB862B39DFFEA52B201160B4BA0C150456FEE2D3DF218AF9D663FE3EC76D4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670556Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:28.082{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C20C29D7F0594B1B20F094049A867068,SHA256=1A4CC057D0746CA472029C6A838852ACB7BD9197DB23DFAF26A4C208ACE2CC01,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670559Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:28.412{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51129-false10.0.1.12-8000-
23542300x8000000000000000670558Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:29.181{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9C476B4508CB38B8F43250BF5C539ECA,SHA256=37C88568D69809DAD6BA2295511AEC94AE6AAED72D550F3EE4501920B13FAB4A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670557Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:29.096{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C71665BD062A84C5E45B054C23067358,SHA256=FC75B9486FA48C53D4E6F5A9A756B2E5BC99F03B5AE55B250F7760E96C89D0BB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571983Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:29.739{E1BD9FC2-D335-609A-9D00-00000000BB01}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670560Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:30.111{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F1A62A466B981957D3223F61DF0FD01,SHA256=CFB49E7DCCD2F319188A29D57A1C626694D66E0A865D4BAEF88CCF76F512C237,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571985Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:30.725{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8176AD386DE268A2B5AE80841733D956,SHA256=4E2AC6C9308C2D9E9F3A901CF9E4DC5F4CA102A1927539B01ADAB75AA099F0CF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571984Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:30.004{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B5BB6D2B2B93CC5977B812F5DFBA1DC4,SHA256=9AA3BC4E5A247175522E4A3087167528B4521F6B034FB433DB8E525180671E83,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670561Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:31.126{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E8DC7DEAE6597C241C5408B15EA8B0E9,SHA256=2D85FA1D87B8581A29E69BF71716EF088F291BD44ECF4D07C639D344B071BA4C,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000571987Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:29.354{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52746-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8089-
23542300x8000000000000000571986Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:31.037{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A1317E1EC6B51936D260E3EF16CCF2FE,SHA256=EE731889486E0F9C2A8D2D52E590AD9AB8B89570BC743F73C1CBB667BCD78F5C,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000571989Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:29.809{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52747-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000571988Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:32.053{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5E9787119CD817AB1209B5D3D29C08C0,SHA256=37DF61083A63A2E0BD64F247EBDE6B953AF31888AA119E97436C8D853EA8BA38,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670570Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=12849F636644AF16A7BBE28AC49A6D13,SHA256=96A54A57EF72DE8209AE628B613A71439EC59106907AC9513D558E233E13F1C9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670569Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=B24DE056D9BA1C8042D684ADF2AF57D8,SHA256=F05BC097BC7581C7AC0F875A7F93D32AFED90C9EE39465B5B2E3D39F5D3E12E1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670568Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=ECA9F6397D91CD8CF550F87429B568E3,SHA256=C55AB820AB3D161F7FEA0FBEE936810319356AFBE14367FFB93FB4F879D247DE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670567Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=9CCF2B283D6BE1FBE185F7C980C883F0,SHA256=A8C86C66F0AB705AA0D4A428AE0E4B116883103F70AE51806DE87A6A55ACBA2C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670566Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=B8AD46A693DD712EDB8E2F45CBADC882,SHA256=906DAFB87FB63C5E5C941A70009EA960C7FFB84867557C745E0CC4776ECF9BD5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670565Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=EA888EFD6E081F4014C4F98C4FFEBE1F,SHA256=9AF9897AC5DF7F18BEC855B203F5484222B5754B026728F3AC8481B84234960E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670564Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=56B9093ABFCF6CF68BFEF07D1CFC6208,SHA256=7493C58070C899444C156C8A7316521A74D476AB288351DB352D8EBA780BEAC6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670563Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.677{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=B4279EF28559D72A7A837DB5F5300189,SHA256=33E0B5B97BB66543813EC3A0A180F7C28156FDCD0880DDDA16C1A069C84781F2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670562Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:32.162{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=374482B2E7FEDA49CB8EE9D514D5A077,SHA256=8C5F0419BDC0C3FF8F717CF11D4220920ABB09EEBF3E97C8962B0FF87D78A481,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571990Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:33.068{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39B9E657F1E0808C7CB5231D29B54B36,SHA256=BBAA79C6FFF2A6EBAF2390F5E87AE15BACB157A1A5112482FBF9A4D85E0BF1E8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670571Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:33.176{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=639F53E8AB478E103C05FC2978A585B5,SHA256=75BF7C12F18FAB56345C418580081202E041C30CAB22923E20BA3D72AD647F58,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670574Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:34.242{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6DA92D20A987BF2941EA1EDDD27CCCA7,SHA256=DA92EEB617FFD4CAA1452304394B51966919B608031F136D4079ED6EE3BD6190,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670573Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:34.241{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1FF32EAC3A36E81B19D01A99E1363B28,SHA256=CAE209A3F8CFB56A3C485B768F4D2D6D09C2376DDE8B9E7131F9E539DA1E41E0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670572Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:34.190{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F8797C023C5F323A6EFF09FF0ED387F,SHA256=85D13FF80F93B3D1F4E8C30D4FE661AF8964ABEF932D66CD568EA94A47E61B68,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000571991Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:34.084{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7A2019F4D423CB9C3BE405C51F2E1D96,SHA256=87A39635CD74AE9C47EF531C371F8EBFBCFF256B65EA6D52D876457028E23EE1,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670576Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:33.485{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51130-false10.0.1.12-8000-
23542300x8000000000000000670575Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:35.221{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC5C95BEE663CC06D819594810FF49EB,SHA256=85FDB7F23D5B40BC61D1B86389063ECD59F25352926837F3E80B523C701D07F7,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572020Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.990{E1BD9FC2-7F0F-609D-E550-00000000BB01}25282552C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572019Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F0F-609D-E550-00000000BB01}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572018Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572017Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572016Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572015Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572014Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572013Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572012Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572011Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572010Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572009Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F0F-609D-E550-00000000BB01}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572008Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.865{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F0F-609D-E550-00000000BB01}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572007Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.866{E1BD9FC2-7F0F-609D-E550-00000000BB01}2528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000572006Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.334{E1BD9FC2-7F0F-609D-E450-00000000BB01}2162152C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572005Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F0F-609D-E450-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572004Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572003Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572002Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572001Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572000Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571999Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571998Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571997Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571996Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000571995Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F0F-609D-E450-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000571994Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.193{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F0F-609D-E450-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000571993Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.194{E1BD9FC2-7F0F-609D-E450-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000571992Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.115{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=071B3C135BCE47B2ABD85665A07F11C8,SHA256=AC55B069EE0844FF7EC627C904E5A96AA4FB0062D3E307A43F24B2D24D921E81,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670577Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:36.239{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA6E6FDB4EF38F36EE456E6634194E02,SHA256=4F107C41D17A74660EB35B083E77096857F73CF12EA08919F64D33119390A57D,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572036Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F10-609D-E650-00000000BB01}1192C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572035Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572034Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572033Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572032Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572031Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572030Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572029Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572028Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572027Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572026Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D2B9-609A-0500-00000000BB01}412988C:\Windows\system32\csrss.exe{E1BD9FC2-7F10-609D-E650-00000000BB01}1192C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572025Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.537{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F10-609D-E650-00000000BB01}1192C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572024Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.538{E1BD9FC2-7F10-609D-E650-00000000BB01}1192C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572023Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.334{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5E5CDEF255320B97DE632FE7CD506697,SHA256=BB81A5E0F05BB5604AD3B724DA13795F538DC8B92F10927B87B4E48663C33F03,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572022Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.334{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D683F1D9F3D6A2DC23858493D7B99717,SHA256=764B1C744D69888911BCD484E414B4A3A2F6853A8C5105D971FBCC92FC2FF716,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572021Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:36.334{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=80755D31A427CCBD28EE6FE9F5823198,SHA256=382E9EDB4E632A4E3F1334CB3A40659DF756613AD23997BB61C6D1214F2E49B3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572053Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.771{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5E5CDEF255320B97DE632FE7CD506697,SHA256=BB81A5E0F05BB5604AD3B724DA13795F538DC8B92F10927B87B4E48663C33F03,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572052Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:35.700{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52748-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572051Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.506{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E9671643C7AA19A7722F71A9C52E4FC1,SHA256=21F099AF90CD6D7988D52A07D916049C3374DFB723BE0BB8A493456A34B23F0C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670578Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:37.320{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FF185CB4E73809E7328BB658046BBF99,SHA256=92FD2F5E3569199950F6C1A90A110A6B7AC59F4121EE9A997ED745E8AC36E52E,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572050Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.334{E1BD9FC2-7F11-609D-E750-00000000BB01}19641168C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572049Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F11-609D-E750-00000000BB01}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572048Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572047Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572046Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572045Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572044Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572043Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572042Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572041Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572040Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572039Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F11-609D-E750-00000000BB01}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572038Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.209{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F11-609D-E750-00000000BB01}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572037Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:37.210{E1BD9FC2-7F11-609D-E750-00000000BB01}1964C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572054Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:38.521{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76534D804672C60629CB4A9EA69E8107,SHA256=7E2E63088E5A5696F3C496355B9DE3899C5E6D400E18AC8794C6F7A7FA5D0C76,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670579Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:38.337{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CCBFF0044C3A04F8A559F39C08FEADBD,SHA256=EA19693B5071FE4616E6CA694C98438AD94064697B0EEE36C79C428538A0F284,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572055Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:39.537{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=018E84AE3A34C1357616C0619192CE32,SHA256=0376B5B5EF6C34CFA18DB8D9260D6E503B69BF87670109A527ECBEF046BD282B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670580Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:39.355{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5723E9E6769BD4706E9ECD29122B59BA,SHA256=E27AC153D979DA6F7F1D7FFBFEE36B0114F6ED4A6FA7E07214444627DE56B9BC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572056Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:40.553{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0E3119297714CEC0895AFEA9D3A7A4D1,SHA256=E97A64CDA490E4C805F7CBE973006778257C4BE7F347084DA912B44B31E7226F,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670584Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:39.301{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51131-false10.0.1.12-8000-
23542300x8000000000000000670583Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:40.385{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=536DADF69FE5F31C4CE269FFDF990782,SHA256=6265EB323EA9F1C5C4B18411AF9DA4CE914929D83BD81B61841DFC4F7624C1F3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670582Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:40.085{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=85A9A2E773EC9C4EFE63925BA4A0FB42,SHA256=E87EFA792CD704A24DC70D32C9BFCE1F407E59DB26F58472A67A6C336A0645E7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670581Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:40.085{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6DA92D20A987BF2941EA1EDDD27CCCA7,SHA256=DA92EEB617FFD4CAA1452304394B51966919B608031F136D4079ED6EE3BD6190,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670585Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:41.399{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D89A5106A98A7E26814CF2944352DE2,SHA256=56320E19E08184EDEB9641CDA4AE8C58A3A186EE7B9B4EE67884856865B4C1D0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572057Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:41.553{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F3B46D37275B435ADAF60C696201F4EE,SHA256=DDF3E8FFF8D63009533C8819EB6930C6D9B35AAD83776A517C783C9BA78B55FF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670587Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:42.433{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C7EEF9CCB87CE00B8682A6D4840D1A1A,SHA256=BED9770A19E2DC90EBE34E44F4F35AC9E138D67CD6B7C4B8830242F68FF3D601,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572060Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:40.871{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52749-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572059Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:42.568{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A82C283407238130C2A045A1A9299B5D,SHA256=B4EEBF9757DA01C1D8A069F04099FD690063DA45F9F971D42150C33F21DA3DF3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670586Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:42.268{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=85A9A2E773EC9C4EFE63925BA4A0FB42,SHA256=E87EFA792CD704A24DC70D32C9BFCE1F407E59DB26F58472A67A6C336A0645E7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572058Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:42.271{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D4AFF2F1BE518F213F2CE03808D7AB16,SHA256=F9DD8A3DEE25E648309FBC4D709AF71A212930DADCEC70381501BEC75DC8DAF0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572061Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:43.584{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B00FFC99B7A157DB559E04B11F3F1B72,SHA256=0383F4610ADCFB567593227C82B3B3AF03FA04F3E1DD220855DF50B6704FAC69,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670588Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:43.451{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3C2961E7628FAC3BC728B47D98419E1F,SHA256=19ED94560AC00F0450EBC20D50EB56F498C00320B4F4A9A9849241936B0160A4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572062Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:44.631{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=457471183B18953B0B1A139469F723C9,SHA256=5CA736D3F6DD2708D835609E84D8947141CB59D9CFDE0190BEDC8644AE5F1BBD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670589Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:44.465{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7D1B9F8B2099CD8E24FED35FF4EF6B41,SHA256=B6DFC8883CC10B11FE4508045C3C4C16FD156D4F90EE849128A4933AF68328C9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572063Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:45.646{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0E3A5F69CC81236115BF750E34DCAC5B,SHA256=1D0F5A9595A52B71D382691A1C7C86CE8D40F01E7E367E36E7789E4F3E286252,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670608Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:44.412{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51132-false10.0.1.12-8000-
10341000x8000000000000000670607Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.634{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F19-609D-DE55-00000000BA01}5660C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670606Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.631{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670605Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.631{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670604Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.631{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670603Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.630{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670602Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.630{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F19-609D-DE55-00000000BA01}5660C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670601Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.630{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F19-609D-DE55-00000000BA01}5660C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670600Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.630{7B03F3B2-7F19-609D-DE55-00000000BA01}5660C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670599Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.466{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CED4DEFFCF60FFA1055EA56E92ED6832,SHA256=230A3446271027AEEE6EEEF6E48AB85A0FD43141777956F4D9BDBAFFE87BBF25,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670598Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.181{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=AB11D4F050CAF8E9B71E603D934FD8F0,SHA256=B7B5122B381A69FD70733A309946C441CC4C667F3E4C3644EB452716ECCE5B92,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670597Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.065{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F19-609D-DD55-00000000BA01}5604C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670596Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.065{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670595Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.065{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670594Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.065{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670593Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.065{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670592Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.065{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F19-609D-DD55-00000000BA01}5604C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670591Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.065{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F19-609D-DD55-00000000BA01}5604C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670590Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:45.066{7B03F3B2-7F19-609D-DD55-00000000BA01}5604C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572064Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:46.663{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CF8B2D61438A6E0CF94F38ABE664A815,SHA256=78B4DA75C960480D448FBFE9EDFFBA8A28765AF4B07489EFF4C3DC19A2981755,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670619Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.481{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3CB63A23E6BD31AF2B9E0C01255AE841,SHA256=CA8EDD1ED4017C9E24681211CD4700E72BEB48A6D76BB3198B1061A2EF71FFC2,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670618Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.465{7B03F3B2-7F1A-609D-DF55-00000000BA01}68084024C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670617Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.327{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BA22F76E379131E7CFAC0EDBEFA83FB4,SHA256=C4A74E65432DAB0536FE286D5F88EE35DF0B1877EEF5689C8E173B0A1ABBB899,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670616Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.307{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F1A-609D-DF55-00000000BA01}6808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670615Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.307{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670614Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.307{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670613Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.307{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670612Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.307{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670611Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.307{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F1A-609D-DF55-00000000BA01}6808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670610Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.307{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F1A-609D-DF55-00000000BA01}6808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670609Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:46.308{7B03F3B2-7F1A-609D-DF55-00000000BA01}6808C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572065Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:47.679{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=10C13A6346C790AC33061CC48F132C6F,SHA256=9C9A1A7AEB82964312F2643EE779225F3E58C49BE0B40863CBC5C7442BF94B35,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670638Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.882{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F1B-609D-E155-00000000BA01}6776C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670637Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.882{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670636Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.882{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670635Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.882{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7F1B-609D-E155-00000000BA01}6776C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670634Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.882{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670633Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.882{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670632Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.882{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F1B-609D-E155-00000000BA01}6776C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670631Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.883{7B03F3B2-7F1B-609D-E155-00000000BA01}6776C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670630Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.482{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5966D9C4DB7824CB9C2191D00F2B20BA,SHA256=89412B8C19FA38EBF117809EA629F9E0BC1138D10F0B441599E08E8D5F1C6ACA,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670629Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.398{7B03F3B2-7F1B-609D-E055-00000000BA01}72287868C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670628Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.336{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5F02E584BCA129B95DC64F63F8FAFE4B,SHA256=B0FE9CE8A5345CAF74FDB8DC8DEF7CA4058E5E98F4499267B78B956D4D78570E,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670627Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.198{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F1B-609D-E055-00000000BA01}7228C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670626Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.198{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670625Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.198{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670624Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.198{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670623Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.198{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670622Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.198{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7F1B-609D-E055-00000000BA01}7228C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670621Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.198{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F1B-609D-E055-00000000BA01}7228C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670620Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:47.199{7B03F3B2-7F1B-609D-E055-00000000BA01}7228C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
354300x8000000000000000572069Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:46.716{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52750-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572068Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:48.694{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C19F691BB28EC3CB432CB5F6053FD1E,SHA256=A1D57238C3E17B0D96F887DF4A05167720E94DEE598FDAE1DEEBDC3398EED15E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670649Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=CA1FD358CFDB9B6086556D4C199BDC11,SHA256=CDD671F28E06F222CCCA992EF5E93B81F70CB2D5B3D65B1DF3E627592279F9BD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670648Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=369EE1AC8CA4ACA3F6DFD850E3F661A8,SHA256=270AA68E59057D23007BC819D18DA4399CC6F16404CF71FF86080F988A5B1E11,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670647Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=12687E8A93A3A899992CB26BAF1CE4AD,SHA256=FC09C31043FFCAC48997426F63F823BC95A0AC8AC7DA00E62649E49C3E21E64F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670646Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=3C0B1779FFA9A9B8977D89391792930C,SHA256=60954CC76E519EC6CA4BECDE5B0BB728174B8108FB6DC7FDC3C042CBE13E9E75,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670645Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=B45BE1B57F89C0F7AA48AE4F7A5CD3DA,SHA256=B2DFC9699A6EEFFC71E4B790EED49A973AC05AAA0EBC417E4B20B09370E9377A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670644Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=766F5FD9A4E2CB4EE0915EEE8D13A21C,SHA256=80F84C4C6A76FE6AA98B74B6CA68B110AF6B4ED29A3C56DC2F72A7ECE0463684,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670643Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=656DA559066D156C6E8A867C1C837900,SHA256=6ED568B972FC5AECB3186F2BD84330EBC5FD4210319704BA200CA1B311ACB8C6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670642Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.662{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\glean\db\data.safe.binMD5=AA8059246A21FD59D466079752703F12,SHA256=D505237C2ED78194FF94D14CCCCDFB299E79BA208950B664A8CAAA47C06A7C24,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670641Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.493{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E0AE244381C4B69E0D55EE5586EBBA86,SHA256=B1F04E823E5572E269D0452308D081912DC59A88A3F6AAE27E4CE053A421D423,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572067Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:48.116{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BAD5B79FFEEAC5A5468C997A4A4CFF27,SHA256=63643942F80D9A2868061979957E99922D3D5C5E0A351F4346ED3309DD07A47E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572066Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:48.116{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=AC958DD0C3A4D88432EA44FDBAB0BB20,SHA256=EBA73D5F74AACD8FD2968A61E9AD0973F397988FC6AA160D78D96189A494B760,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670640Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.424{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=509327FB5CC9E8C901B53B48C20CC23F,SHA256=6935368CE54527592B15A6DDDBA504607938F5DD1B08E01561A892BB41F6C4A1,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670639Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:48.127{7B03F3B2-7F1B-609D-E155-00000000BA01}67764520C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572070Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:49.695{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A6646455F0F0B48ED1D03EEE06FD6E6D,SHA256=2EAC36BD8B3092289B272A2B19D65451040432FF8740BD6E92F03FD9831E91DA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670650Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:49.524{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3FB28D3E94D6924E3011896E04678785,SHA256=DED5BDB9620AAC355B16E13998B76289D7BE2B544468D0B2F7DA29E3A4126A15,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572071Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:50.758{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E439A96E5BAB1FAB59A64037385E18A,SHA256=8943B56BC8A699B54CE6125241A04858EA0291620B4F0D573D8CFAF367E03D15,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670659Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.822{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F1E-609D-E255-00000000BA01}7448C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670658Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.822{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670657Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.822{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670656Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.822{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670655Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.822{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670654Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.822{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F1E-609D-E255-00000000BA01}7448C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670653Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.822{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F1E-609D-E255-00000000BA01}7448C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670652Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.823{7B03F3B2-7F1E-609D-E255-00000000BA01}7448C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670651Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.540{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=03C1935E83E789665D4308EE33C52D47,SHA256=A944D2EBAB7DC0F074B00472030AC6D4831EA149F389A702E94F2D5B85F6E94B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572072Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:51.789{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EC9C5CA813E054FD267BFCC5B9ABDE86,SHA256=6A3890F3C4934080345DF9B77AF5C84406BC46C57550C1108189E1EC3BF8230F,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670671Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:50.406{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51133-false10.0.1.12-8000-
23542300x8000000000000000670670Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.546{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4AA18B1415A1517423AB2AD03BE234E1,SHA256=C874839E9AAFE98CB300FA8CB0C087C9114B960A8C81621FF70743909845712B,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670669Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.493{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F1F-609D-E355-00000000BA01}712C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670668Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.493{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670667Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.493{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670666Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.493{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670665Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.493{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670664Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.493{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7F1F-609D-E355-00000000BA01}712C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670663Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.493{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F1F-609D-E355-00000000BA01}712C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670662Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.494{7B03F3B2-7F1F-609D-E355-00000000BA01}712C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670661Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.192{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1EFBDB5771CC0BDC86D653A9FEA59E8D,SHA256=0021B8C4DFD67889D76BAFD8E3E727F1D1D697E00800626AB3EBA7B5F6F0833A,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670660Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:51.077{7B03F3B2-7F1E-609D-E255-00000000BA01}74487612C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572073Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:52.805{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C25E39B3027BE8E949D49EC76ADD4613,SHA256=00A207E5CB5E26D76C9718F1A20FA13096CE6E0D162793856E67D452EC22CA4E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670673Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:52.553{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7EA1E191CA40FFC7B2253F531C7BA308,SHA256=16D0BE83FECC79D8C3F9AC23FCB1B6A50FAFFA855E207D45260907FA648D7656,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670672Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:52.506{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=746035797CF18E101C515E07DD6C0A70,SHA256=1E375C03D1D43F0D1B8E963253ADC3A00B37AA5D639AA07445B0CAF192FF5A7A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572076Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:53.852{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08ADBD24FD740CB41AFF7AD32095D7B6,SHA256=FC19080777715C3058D9CE80787DE237ED3647BA12C2B92823493ACF0C09DF3C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670675Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:53.570{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6B30260AB22EA60BCAC7C6E812EFA622,SHA256=87CC02223FD31F74E53081666319349941B102A6ADC314C81D055EB98A0AE829,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572075Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:53.180{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=93B821FCF3BA4FCFF0DD22864BB5FA15,SHA256=3BC34318B1ECF02AAD97D469240088109F815E82DDC99484B34BF6859A1ADAF4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572074Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:53.180{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BAD5B79FFEEAC5A5468C997A4A4CFF27,SHA256=63643942F80D9A2868061979957E99922D3D5C5E0A351F4346ED3309DD07A47E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670674Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:53.536{7B03F3B2-D0CA-609A-1100-00000000BA01}620NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=6416BB0E03B1EFB3D10CC1907F823B7A,SHA256=26F95C66646A8A007C5D98864939014E5654FB5DA8424C9EC8EC4052BAD0A718,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572078Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:54.867{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E36BF55F0AE955CE053648D105A0DDA,SHA256=70551CFA25B760C963850CF5BD14CF98E13E94C4796CE8FD45AEAC4C647A0A98,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670676Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:54.588{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E9BE8A3F27DC325D1236590E70DFF3D,SHA256=CAD4036CA0284E5DED1A6462CC2BA8411E937AD559592CA6654449EFF5BE1CCC,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572077Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:51.764{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52751-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572079Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:55.961{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BF302D18498D8423FE08732E3518E88E,SHA256=5130DFA90F846569D5E1FBB7CFBB37118144370B923ACC722812D866F621C317,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670677Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:55.620{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0650AB87DBFABD84EA691736795D5433,SHA256=7BA5CF1B67B0AEAB436C1D04162CA192EC41DCA4D5C40F906DDAC1421FFDD89D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572080Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:56.977{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D60818B48D1ABA127C388BD178CDA3A5,SHA256=E6214B2ECA19B557C00D27225A9E595A2570E8E212078B224C3905EB6E7FCCFA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670679Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:56.634{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0B2520CEE837CEB243425CA610B80CDB,SHA256=C4DBD8380748B54B2F1956B746BBED6A5B06A4181CC4E217235F12E29FA08F66,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670678Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:56.188{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1BEEDC4508E833A83E3486CE2C7CC667,SHA256=8A7A9B596FF69A6FFFA900374C906A1CCF9447BDCDCB56167BD709D3F3A0E0EB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572081Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:57.992{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36B9D61079EAD1D0EAFBAE768771916E,SHA256=B49947EA7888F2AC6537EFD738B0291D0F040CF6D039E05FAEBAECA999675F19,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670680Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:57.635{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=595A3A2DD12483CDD8AA4AE4B49391E5,SHA256=8C186487EBBD946B99722F7AF7CB86E1223B06F69076A019BAED69D647162CA6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670682Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:58.637{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3C4BA93A40104249BE5E010A64AD1255,SHA256=76F72D1C1C207D4C67F18985FE510C5D929F1B29F8D7D9A563884F1CEE4C38EB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572083Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:58.180{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0D46B0E55EDD5D56FE9F4CC8B78F7396,SHA256=337EF914BA20A2F7C9955CCC13FD09E45342B3E39A4D7372C0BEE95D561F79F7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572082Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:58.180{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=93B821FCF3BA4FCFF0DD22864BB5FA15,SHA256=3BC34318B1ECF02AAD97D469240088109F815E82DDC99484B34BF6859A1ADAF4,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670681Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:55.412{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51134-false10.0.1.12-8000-
23542300x8000000000000000670683Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:33:59.652{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=475389A861BD1BB972FD3E3FEBCD2622,SHA256=3A6555C46EF795C80C9B2B85A5065CC50C52D22EF22B9DFD14159FC63557676A,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572085Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:56.796{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52752-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572084Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:33:59.008{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C0C8017490B1B295A84CC6E1144BAF0,SHA256=041C3C0A2954D862DF4D9F87017F56CA95A629B572298051BD663C9B40834A91,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670684Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:00.668{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=937656435F713EA3D46165A2D7F83A22,SHA256=94BD557B9EADA9E83A3115B41967EA2FD99AB5BC11650A06800D279B841F0634,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572086Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:00.055{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5F925F8AA1EA718CCC8926AB069AAD0B,SHA256=2E92FF57AB2E114699E4479384A782B3CB908B5AA18E1986FDB1887A5E877B2B,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670688Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:00.450{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51135-false10.0.1.12-8000-
23542300x8000000000000000670687Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:01.687{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F69762834149FFBD9A894437E10600E7,SHA256=5E3D78579FF5D9F1E07864AB13D4733FD3C0A026E684BFCFF9F72D708868ADFC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572087Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:01.086{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FAF4AF3CCFE8BA1619D9DD3CB749CC05,SHA256=11996E12824BAC954B97234E50CF45912A0E85F2B8257776BF5FE22A872C8689,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670686Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:01.234{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0D430D55689F33C4CAC1B54FBBF564CE,SHA256=38DE7FF70F14CF5D56DB629561553A39B3BC84345A8DB583AE7C348FBA2EDF0E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670685Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:01.234{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0FE1B89B1A417E20B32126667510F4FF,SHA256=BC8122A7B3A13C0FF000FDA2D6C190B120C24B06640856615E3F04BE16398638,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670690Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:02.703{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CCEBACFF6BF7D5AC3A20196ABCD76D21,SHA256=121E3D5F9219DCB9C3F33BE807B0B04846B079E2360197BE50E56E79800125D9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572088Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:02.133{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=054C6C9C332CCE9FD6E16B0EFB8ED965,SHA256=CBA35692079FF32174923C153F4C187124F45B6C247AD45CE2E4CD540AC6323D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670689Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:02.287{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0D430D55689F33C4CAC1B54FBBF564CE,SHA256=38DE7FF70F14CF5D56DB629561553A39B3BC84345A8DB583AE7C348FBA2EDF0E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670691Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:03.718{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7E3F3A5C21EDC6E7EA0268540114A46F,SHA256=A03B6EBF7DA3BF93BEB16221D82B3FA4DB4F6EDF3CC803F3424BB054FDAF3AED,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572091Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:03.227{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DB3B86A92C31C4218410CC123163E9F2,SHA256=C58EF291BB46F241678B9DFBDD0DE5447376CEC4B80FB4B01754EDF69410969B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572090Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:03.227{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0D46B0E55EDD5D56FE9F4CC8B78F7396,SHA256=337EF914BA20A2F7C9955CCC13FD09E45342B3E39A4D7372C0BEE95D561F79F7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572089Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:03.164{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=35428A933B269C630238ADF90ABB6B27,SHA256=9F1C65E68B4375FC3627710B0022378333305E3B4E6165D8C0939921A40C2072,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670692Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:04.732{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AF59C3B21753602D8F3D02A0E1365DED,SHA256=D9FDB8F690503275EB296210175D91C91091995B78F129CC8D9B12B562D53595,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572093Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:01.842{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52753-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572092Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:04.180{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DE6C02891CDB0BDBE681B1D9100196BE,SHA256=4333B2B0F16FE433D45EE8376CE890C75D0C6EFAAAC88C8F5D03006D29DA314A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670693Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:05.764{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6EC1969B3C900AA3C71A18A8DD19A6E5,SHA256=46F4E56080A3BA1FFC79A893380B42BA079C497B732D3DE0F4AAD3D74CB53C6F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572094Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:05.211{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9166DF88733DE54FABE3B64AFB6D7DB5,SHA256=AD1353480E48CD714BE8FD737DEB58DFCBEBC9B826697AD63E893B861FBC3634,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670695Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:06.784{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0C0BB979EE2E481672BB6F24E23879E2,SHA256=143A3E4E514738325DA45DA0C597D79509116ED1464D99608107564326A57B8D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572095Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:06.242{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=80E10336F80C3ADD52F60F65676517E6,SHA256=040476ACF089E6F207DEF3C0BEC9178B1F4440A7DEC2A2E7C6F2033FCBC38B91,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670694Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:06.264{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B067A9E18C018D32644BFDE1A86AB81F,SHA256=F4BA54D8BACF464D577ECC07E8C90385F55D100CD093AC04B491E397F75551A5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670698Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:07.785{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=508EFD8810D74EDB1A0E0D5B77E761BA,SHA256=339A2971398DE9091C0BECC9049E63508E6A2008A927BCF2EDC0ABC51D99ABC0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572096Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:07.271{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44F1D849479B0BEE81393E33F1A2F33E,SHA256=35AF58229C7074A6D0F2E3E820EE75DA206A78ADB45CEE6B983458118F4A9EC5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670697Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:07.286{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5BA60ADCF32C6CBEB344C8452AF7E381,SHA256=C81786EFE5D131A6083D60A5E1D27357D98EE8047C2EF235887070B06F898167,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670696Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:05.493{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51136-false10.0.1.12-8000-
23542300x8000000000000000670699Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:08.801{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=71F21D2227D43662DADFB7EE1FF1C364,SHA256=551657B3A589155328B17A9EDE090B2DB45592A70FD1851755CDB72CC33668B9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572097Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:08.334{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44119C1486C3F5BD9919F1E372EA2069,SHA256=B5D3EB1CCB7E537F7B756D7D066E1A835957917363A6C111AAB96B04D270DBD3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670700Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:09.815{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D210176198F33979A73343BFA0A52398,SHA256=F7ACCCD4832F32D19BB97855B1CC0714A897FB13C9413B51DD213B85438DD783,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572102Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:07.715{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52754-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572101Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:09.474{E1BD9FC2-D2BA-609A-1000-00000000BB01}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=21413888F705151D9C338924607AC714,SHA256=931A9A8B565FB6ECAC49F466A1F61469720C8B22F1B6D3AA0D81DFC6496408DF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572100Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:09.381{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=32C234E06F85C62842BC733451093EF8,SHA256=71C7AF9056E13FF3F600078D7477F02871C17BD07A7C42ADB0C718BB43191327,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572099Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:09.131{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6BA7010844630EC7AA7B651C3852D045,SHA256=8FF48511556DD6FBC2895EC722104B1CA01831A9D347812646FF0C3503C266DD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572098Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:09.131{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DB3B86A92C31C4218410CC123163E9F2,SHA256=C58EF291BB46F241678B9DFBDD0DE5447376CEC4B80FB4B01754EDF69410969B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670704Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:10.865{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A347488379C29FF7BB9FB00CC5771F3A,SHA256=7B795A1C050C5C939F4415CE82A4AFBDCA5E8594394635A9897275759F818223,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572103Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:10.381{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4D20B6E8FD23BCC29A6686EDF252B4A,SHA256=7248B20F22AB68C9D5933B640EA232BB6E89A4A349C346690AEC2E12593B608D,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670703Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:10.084{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670702Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:10.084{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670701Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:10.084{7B03F3B2-D0C8-609A-0B00-00000000BA01}6327824C:\Windows\system32\lsass.exe{7B03F3B2-D0C8-609A-0A00-00000000BA01}624C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670708Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:11.873{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=49A168776A4D713A2FE5AFC4C9502B6A,SHA256=0DD2AE5137E3869393B039534029BD022995F32DAC090474A5EAEE39B4868A8C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572104Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:11.396{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F40E441D8144A9F417BEBF8FD53F5B53,SHA256=39354B913524F1907F992693B013853C096300AAD13371E3C8C326AF19D713D2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670707Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:11.108{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=ADAD6E8CA6C517B59D955F82B5C8D605,SHA256=D2A049E50FF62015228DEB5A66BF03923BB89D00DBC608EC0DECF767E627EF46,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670706Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:11.093{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=C145C4D5E2C35FD12561ED0E19132289,SHA256=79D44ED3EB87BA76E1F3488B4ECD9D71D87F354B2066BC4F69B4F4C5EF377C31,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670705Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:11.093{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=099AA66755E3EFC7ED12B8D2D756543D,SHA256=0FACF2F5C750CAB0C859B857FF22C0EE2BE59BBF16940110F349DA12B92B3B22,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670712Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:12.890{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1D6A336A9C1BCFEA53ABEFB31213AA25,SHA256=AF4C1D3BE6856FF9800D52958F1434C58938DA22DC4D04703DB69427C429180F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572105Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:12.412{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CDD095AC2C4B4D9D682775FAC21C0157,SHA256=8A67E566872808B9E9B7B7D50C0069180D428E73C458CD4059654F2B8B56A6D6,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670711Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:10.350{7B03F3B2-D0CA-609A-1400-00000000BA01}1076C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcptruefalse10.0.1.14win-dc-18.attackrange.local51137-false8.240.38.126-80http
354300x8000000000000000670710Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:10.341{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local54980-
23542300x8000000000000000670709Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:12.191{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0AEE2CF00636F965E7A4E3F8C6052994,SHA256=BE533C17224589FA81C7656B9881B8348C88168013FD05A828B0B9ECEB06F1CE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670714Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:13.905{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B21564AB43CBDA726366886DA286003C,SHA256=A67159126E998432F8E9133FC06023A0CB97EC73139A4E691E385ADA9DB9589A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572106Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:13.443{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C81AB95BD768CD9C14D504F9D5C6AD0C,SHA256=4FC0C03E152B2428CB4C1855B3421A7E535A2B4B10FE19B409F59636CCE0AC34,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670713Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:11.416{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51138-false10.0.1.12-8000-
23542300x8000000000000000670717Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:14.920{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A552620B0770841A0B6682ED79E2C6F3,SHA256=D5536AF509D483178264B4A469E1731FDF306455CA14BBA2D144764621976984,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572109Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:14.443{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=965DC9E9C17CBA3C675D7D387A6C3A43,SHA256=877B1A7F0643C361DE0C486A9F95E80E6C2F9598C1DD51CA43FDA08A0C742F72,IMPHASH=00000000000000000000000000000000falsetrue
11241100x8000000000000000670716Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:14.220{7B03F3B2-37B7-609D-644C-00000000BA01}580C:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\SiteSecurityServiceState.txt2021-05-13 14:34:13.883
23542300x8000000000000000670715Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:14.220{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\SiteSecurityServiceState.txtMD5=5906967C1034B0D6EB40F53FCBFFA07F,SHA256=9C1BE92930D16E7E37F376A15B616970B55FA82800ED038AFCE5F9B80B640BBC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572108Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:14.209{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8D5498F67CDFAD47241AF2E65B936A0A,SHA256=296B38AE01353F87825439B300DEFC1853EB343C3A6860C7D0CADA4D9802B453,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572107Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:14.209{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6BA7010844630EC7AA7B651C3852D045,SHA256=8FF48511556DD6FBC2895EC722104B1CA01831A9D347812646FF0C3503C266DD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670718Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:15.949{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=62D7B07337A4B69674F1B01B2C0E7DF5,SHA256=C0806FA99B508F71942685A706380E66E6DAC2071E453003675350DEBE1E29EF,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572111Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:12.824{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52755-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572110Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:15.490{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE0413D62B6B7657A16C5F7FE8E775DB,SHA256=3A08CDEF80A1045F80188246788A6962AA66C382515093186CBD7C0AB621AEC1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670719Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:16.951{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D5BC1C2CBAEBB05969893FE5C65C395,SHA256=6412C6D2A88C237CE9194F85EF2D8E7671427DA8C974A2964D663C2320347343,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572112Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:16.615{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4588EE786C35784B46F9E7B8EEB643AE,SHA256=24F159827D195EABB258D3D153D18366612AB44DD3A8054018DD731D077F635B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670722Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:17.969{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=315F1202F1B4734F63CE28F2AF79E015,SHA256=24EE77B414064CB3A8C7071D9F2804A7CCE1B2B554425B45949D3973254A6F52,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572115Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:17.646{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2E9DD4655745B4853FC1B701EEE49D38,SHA256=0379AA230037F6E6802196B99A81858998D0851D96E846D609F46770CA9C8298,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670721Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:17.236{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BC7E804C76DFEC9DA97B92B1957D656B,SHA256=20F35AFE7EAD0EEF06203C548CC3D6A66ADF6421FC4A6D02B9A580ACCCE72A60,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670720Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:17.236{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3D64D0F7B92BD1170B5682510A5EF77A,SHA256=0307810FD2219E93A024AF1165117B70F4E1A7DB6CA3E39B258348295F64E2DA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572114Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:17.396{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=D4BF469587FAACEA227339B31C1BB287,SHA256=EB916CFCABE9BD0B6C9D825FEA2C10046BE299B7D7010DB78E759E41CAD63DB8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572113Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:17.396{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=E481D82249C8DC07AB59646C6802CF2F,SHA256=0C7A943254953900ABF5BF565299E0FC36A66FCA4FC88D8EE12E6F2F45330D63,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670723Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:18.988{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=43345008732D2772A31BDCB2BC61CB16,SHA256=447A5873C6C5C0F9A161A8929F3E15841F4ED1300E08D87F0209B75662454545,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572116Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:18.662{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D3777C5A7885C1BB1048D721CDB4DEE9,SHA256=4ED2E642D95470DE3AC93B6F1618D75093F9C4B8C53086B8D42EA181D73114C3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572119Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:19.662{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CC09DC22F5ECF44D5DC1C55E046E1F79,SHA256=292A9D66E15A9F14703BF91A4B288050B2B2B164E70012D82BF43DDA35387654,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670724Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:16.479{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51139-false10.0.1.12-8000-
23542300x8000000000000000572118Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:19.271{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B64076371FF0681BDDA2CFABB7684C5D,SHA256=9BC81DCE92F7425E226497B6D9F710EEF5B77260E2937EDD9586FF0BD5659421,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572117Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:19.271{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8D5498F67CDFAD47241AF2E65B936A0A,SHA256=296B38AE01353F87825439B300DEFC1853EB343C3A6860C7D0CADA4D9802B453,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572121Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:17.887{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52756-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572120Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:20.677{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3593A6E28C04F9754254887EBED948CA,SHA256=D5DF397441EB88D26B6FCA9BCABBEFEC05BF29EAC22375254211C337AA95E486,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670725Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:20.003{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7B4555840D090DB38839121473796446,SHA256=2CF04298E32D793FAF02C1413C6A361956255166665E2A2A2B29F43398E9FB19,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572122Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:21.678{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4484801A6D497DB8A72FEEF90696F2DF,SHA256=07364B7199262933F3D454E4B7A9ED988D651B9832C9E2338598B8F97F0D46E5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670726Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:21.017{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=912E34891568A526224F749FA0B30DD4,SHA256=116C9FF293DE1F55C7C9C4D0858A925303262E97C4F93599DEDA521D2087FE79,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572123Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:22.693{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=39B0F4833491F94414353E0CABDA5584,SHA256=E6FC0E8F1CBF5B4D4BD2B5E246809EDBB6A448ABF00C93FECBC3F6AE78719C42,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670729Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:22.300{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9A15E9A02312E07BD61301A0FF998702,SHA256=E9362C47115CAB61D2968E6DD6B577BBAB3AF8442B6FDB796BE0A7661B9C09DA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670728Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:22.300{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BC7E804C76DFEC9DA97B92B1957D656B,SHA256=20F35AFE7EAD0EEF06203C548CC3D6A66ADF6421FC4A6D02B9A580ACCCE72A60,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670727Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:22.066{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D81E16BFC90F43B5AC3919B81382BBB1,SHA256=E0FA6191DCFDCD8C53DF1976B8AEF8F7FDA3684FCC11FE6BF58109D008C501B3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572124Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:23.724{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A964D1D38D7C5AC11DAEE388EAE5FCC0,SHA256=316E8202F9576218E17A907B3C6690FFB70377996A30AF530BD6A55C80212115,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670730Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:23.084{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AC8744481F52C681781F38CC8B7C8738,SHA256=AC3D2C0C228112CE56B7F90173C7368062F5A0DCF3FD0A5D4523B9F4F2E20AB9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572125Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:24.756{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FB74EDA826D033352356BE763349B13F,SHA256=9E1F5E7F45115C0AC64BC89615BDDC04389A719F7EC4747B9E4423C2E6348644,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670732Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:22.309{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51140-false10.0.1.12-8000-
23542300x8000000000000000670731Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:24.130{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=245832A51B9A5D2BE3862F24A9573CEE,SHA256=A9E130317290588E25465DC21E0CA0BB78EF845D0C50CD18BBA388FED40FD7FA,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572141Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F41-609D-E850-00000000BB01}3260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572140Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572139Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572138Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572137Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572136Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572135Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572134Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572133Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572132Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572131Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F41-609D-E850-00000000BB01}3260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572130Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F41-609D-E850-00000000BB01}3260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572129Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.834{E1BD9FC2-7F41-609D-E850-00000000BB01}3260C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572128Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.818{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F35E329A46EAAE4DEC7A1235DF1BD64C,SHA256=974ADE5701D9259D29904213A50056C8061BD75FC93D97FD9EFE0F989B1727A6,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670737Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:24.445{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51141-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
354300x8000000000000000670736Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:24.445{7B03F3B2-D0D7-609A-2700-00000000BA01}2888C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51141-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
23542300x8000000000000000670735Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:25.213{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9A15E9A02312E07BD61301A0FF998702,SHA256=E9362C47115CAB61D2968E6DD6B577BBAB3AF8442B6FDB796BE0A7661B9C09DA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670734Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:25.182{7B03F3B2-5120-609D-3250-00000000BA01}1532NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670733Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:25.144{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02E8F4D2708984465B771684EC13B7A4,SHA256=D81AC845AD27921A8351EB0C38373305126707E3F798FD4C67F84644163BF474,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572127Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.006{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6C732CE2CC6DCA3FF033D5AB539A6AAC,SHA256=6696318B7D7EABB1313E773402CD6C411D62F151749676AAB55117C00FC8A293,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572126Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:25.006{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B64076371FF0681BDDA2CFABB7684C5D,SHA256=9BC81DCE92F7425E226497B6D9F710EEF5B77260E2937EDD9586FF0BD5659421,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670741Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:26.813{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmMD5=B7C14EC6110FA820CA6B65F5AEC85911,SHA256=FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670740Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:26.813{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmMD5=4CC08D40D007DCD6A104F5AB504C9B9F,SHA256=96236FD9E8F959F7DC929B70221C6328C113A96FC7071155E5436A22EFB8B0BB,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670739Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:25.406{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51142-false10.0.1.12-8089-
23542300x8000000000000000670738Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:26.166{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=06777BF29951812187CECEFBBE91D905,SHA256=ABFBB63077EF204A15CFE301BCC6613ACA03BE983A60A4AFE8C6C5FC389632D8,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572154Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F42-609D-E950-00000000BB01}3372C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572153Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572152Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572151Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572150Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572149Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572148Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572147Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572146Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572145Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572144Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F42-609D-E950-00000000BB01}3372C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572143Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.502{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F42-609D-E950-00000000BB01}3372C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572142Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:26.503{E1BD9FC2-7F42-609D-E950-00000000BB01}3372C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670743Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:27.313{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=45FD2077F2C56B0392ADDF686A151165,SHA256=C2AE10C9823C4DA7F6918DCD88BB5D6D5EFD05D52CF3199EDE1701596B4CB031,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670742Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:27.182{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F5332E7F092C3135105C8AAF25CB0F7,SHA256=DF92FA880248D2C923C1B2CA89AEDBCE569AFB219AE14EF2D1333D33ED8BF30F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572171Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.299{E1BD9FC2-7F43-609D-EA50-00000000BB01}3196896C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572170Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.299{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2139F97107DB6E7098E73A803D791557,SHA256=AD5FBA736D2E397CC61ECC7E4F6357D7D4530128AF3063EA6B1C9BCD1EC23C51,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572169Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.299{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6C732CE2CC6DCA3FF033D5AB539A6AAC,SHA256=6696318B7D7EABB1313E773402CD6C411D62F151749676AAB55117C00FC8A293,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572168Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F43-609D-EA50-00000000BB01}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572167Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572166Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572165Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572164Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572163Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572162Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572161Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572160Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572159Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572158Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D2B9-609A-0500-00000000BB01}412528C:\Windows\system32\csrss.exe{E1BD9FC2-7F43-609D-EA50-00000000BB01}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572157Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F43-609D-EA50-00000000BB01}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572156Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:27.174{E1BD9FC2-7F43-609D-EA50-00000000BB01}3196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
354300x8000000000000000572155Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:23.637{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52757-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572173Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:28.174{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=51557CB86FC373ABEAEF8E6AD00108C6,SHA256=5E03B32C46FED0C434A7815CD1FDEDE76FD220DB90FC8DCC5BF7974D83CB0F2E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572172Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:28.080{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ACAB0DB9A951AC6F20880B09A84F2A27,SHA256=0C588DC034144932D4156F5194E5D03C5616A9717FB9BDC1F8F92302F9B4F0AA,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670745Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:27.327{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51143-false10.0.1.12-8000-
23542300x8000000000000000670744Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:28.196{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0AAC756A221262DD99243F705C43BACD,SHA256=1A2B1469CF8DF91D17BA5470F18DD334B682F602BDC16F021E07F5B7E68D2DCC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670746Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:29.211{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=72410A362D2DC048CAD95A0585AE27F5,SHA256=2BF12A1EF9D193D73865E54548F224220751FB156629CBF70AB0DFC8AE5AF2B5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572175Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:29.768{E1BD9FC2-D335-609A-9D00-00000000BB01}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572174Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:29.096{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E028DB3FB183217B46ECD1CB693D6EDD,SHA256=02A1A68268E9CFADB1EDAA5B94CC3D4632EB49902649B5DA245612701F38CE45,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000670750Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:34:30.541{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Volumes\BD98497A-0000-0000-0000-100000000000\Volume Configuration File\\.\C:\System Volume Information\DFSR\Config\Volume_BD98497A-0000-0000-0000-100000000000.XML
13241300x8000000000000000670749Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:34:30.525{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\BB71F2B0-B2FD-473E-8F6A-A6267F6C421D\Config SourceDWORD (0x00000001)
13241300x8000000000000000670748Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:34:30.525{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\system32\DFSRs.exeHKLM\System\CurrentControlSet\Services\DFSR\Parameters\Replication Groups\BB71F2B0-B2FD-473E-8F6A-A6267F6C421D\Replica Set Configuration File\\?\C:\System Volume Information\DFSR\Config\Replica_BB71F2B0-B2FD-473E-8F6A-A6267F6C421D.XML
23542300x8000000000000000670747Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:30.241{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E88FA3D861CE2F12BB8F9C986FD83752,SHA256=5CC1B96D23A52C78371FE02FE3F5CA4E0BC2941DBE0C6E412D3146310A0AE306,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572179Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:29.383{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52759-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8089-
354300x8000000000000000572178Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:28.649{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52758-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572177Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:30.109{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9047A5ECE5CDBA96DFCAE894F041C97D,SHA256=E7CE09DFB1D4DC272679100F81ED80E5655724187304919A5E117E132605286D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572176Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:30.018{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3C72FE8ACF77DF2053E9EBA3CEB23D14,SHA256=14CAECBCD1535ECA6E2B5007D44CF9EBF867EC4B7C072A0E134E972D68AFE1C3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670752Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:31.640{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0F2B77DC934E1BC1E2FB9F1F125539C2,SHA256=FC40C9D4E1EDAEFBB63B9921A0094C2F3E363D55406F870685FC29105029C869,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670751Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:31.261{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=322761FB61893A1D5C8B3E4A4A351070,SHA256=3F92B1537686BD703E224763C3F54C718299B021DF3DB5B7419E2B636EC47E32,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572180Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:31.126{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ADA5E22790DD6968B1D4F9447084E5F8,SHA256=6AA361DE7B6E0F5C3D9217805B729CE1C8C5A353864141A691D0D2ADB6946560,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572181Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:32.188{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4428FAEE7A5B13D77E4ADB89B4BBCD29,SHA256=2A28489B469F23F68A77E8782D41676C10B0F33B67E7EBBB78EEAFEA4210DF13,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670759Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:30.796{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51146-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local389ldap
354300x8000000000000000670758Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:30.796{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51146-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local389ldap
354300x8000000000000000670757Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:30.789{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51145-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local389ldap
354300x8000000000000000670756Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:30.789{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51145-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local389ldap
354300x8000000000000000670755Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:30.773{7B03F3B2-D0CA-609A-0D00-00000000BA01}912C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51144-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local135epmap
354300x8000000000000000670754Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:30.772{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\System32\dfsrs.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51144-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local135epmap
23542300x8000000000000000670753Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:32.276{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FFDD55D7740754D1731A034A2454371D,SHA256=0728666BFDD32E042C5A70DF5718C4D47E7A9D14CD14307AC64C5717C59F7F21,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572182Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:33.251{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=15A5431F9A498613E652734F61A773F3,SHA256=560A0E35CA4B9335CD59D23B7107FEA56A244F2F9E9554BF27E20E9DAD2B6EBF,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670762Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:32.354{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51147-false10.0.1.12-8000-
23542300x8000000000000000670761Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:33.291{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC79ECED4C077C5DC28D73B597EEE67F,SHA256=379E6A49160D8C08C55C294632C21075F8296B511426ABABAD24C03C1CE02F00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670760Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:33.122{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=69C122082A006E2A00771DDA3E1771F4,SHA256=3DC1DE06C93DC35CCC1A547E36538E0C423A70CBB133E050D2F2DFFEE91EFBE3,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670769Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:33.426{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-18.attackrange.local57873-false10.0.1.14win-dc-18.attackrange.local53domain
354300x8000000000000000670768Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:33.426{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.14win-dc-18.attackrange.local53domainfalse10.0.1.14win-dc-18.attackrange.local57873-
354300x8000000000000000670767Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:33.426{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudptruetruea00:10e:0:0:c890:a4f4:8987:ffff-57873-truea00:10e:7419:488b:cfff:1521:8400:89-53domain
354300x8000000000000000670766Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:33.425{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local57100-
354300x8000000000000000670765Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:33.424{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudptruetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local64203-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domain
23542300x8000000000000000670764Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:34.305{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E785DC328394686EA9C3A256BBF9F02,SHA256=F5BB4E83D3EEC4F5128C9CCF1FB76D2C1BF908856522D416D037E090921CDBAB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572183Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:34.266{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE6DEFF04535507F09968D2E6867EDF4,SHA256=DB94A9D5AF0E1F3BB12B0D8B8ABD99D8BFEB3B956BFC39B7341CD03039F8CF75,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670763Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:34.205{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=34D1925581A3949800A9CC8E5154B5B8,SHA256=38EA58E41AA0AFCCC2D3FFF812CDF526D357AD82A85FE78EE0C24F880B3E5E37,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670770Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:35.320{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9956581E8BA0F5BA7F5D1C9F7F790795,SHA256=9FB4A88AFF196A615F2DFB85BAC7D701A877127E7EADDF97555AB6F55E03E8B1,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572211Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F4B-609D-EC50-00000000BB01}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572210Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572209Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572208Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572207Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572206Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572205Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572204Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572203Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572202Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572201Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F4B-609D-EC50-00000000BB01}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572200Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.876{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F4B-609D-EC50-00000000BB01}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572199Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.877{E1BD9FC2-7F4B-609D-EC50-00000000BB01}3956C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000572198Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.329{E1BD9FC2-7F4B-609D-EB50-00000000BB01}32564024C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572197Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.298{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=838EAE69999C931EB5AF60824C96FE2F,SHA256=57CD9988DEF69E46A7724051574184BE9DF9274A32BFDE14CC9278D4A0B683D5,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572196Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F4B-609D-EB50-00000000BB01}3256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572195Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572194Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572193Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572192Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572191Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572190Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572189Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572188Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572187Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572186Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F4B-609D-EB50-00000000BB01}3256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572185Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.204{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F4B-609D-EB50-00000000BB01}3256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572184Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:35.205{E1BD9FC2-7F4B-609D-EB50-00000000BB01}3256C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670771Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:36.334{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E8FF3054B9447E3BDF840C2EAE5E8EA0,SHA256=A525B79E031B1A75C3F7650F5720F58C33675C9FD425ED7F2A97F8AB43679E56,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572229Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.641{E1BD9FC2-7F4C-609D-ED50-00000000BB01}3044184C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572228Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F4C-609D-ED50-00000000BB01}3044C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572227Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572226Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572225Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572224Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572223Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572222Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572221Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572220Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572219Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572218Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F4C-609D-ED50-00000000BB01}3044C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572217Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.516{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F4C-609D-ED50-00000000BB01}3044C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572216Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.518{E1BD9FC2-7F4C-609D-ED50-00000000BB01}3044C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572215Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.298{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B71A51336AF55A6A4AF38EE5E2B8EFA4,SHA256=E904C40A35E51FCFC9173FD022EC79628BBB3C274F95EC2E890E9FBF12412992,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572214Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.141{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=300DEE8736BC50F7F27B82DF9BB5400A,SHA256=4BECC94E1D0B6D7E43AC425E11971352E4E06A1BFC2ED30F961B5AF2BE8D24A2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572213Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.141{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=625CAD1AC0310454DF2E1931586FF772,SHA256=058543D3DA6530E5C33BA6E0C18E7FA2D366EE9B2635E9049C42508829D2C865,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572212Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:36.001{E1BD9FC2-7F4B-609D-EC50-00000000BB01}39562828C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572245Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.751{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=300DEE8736BC50F7F27B82DF9BB5400A,SHA256=4BECC94E1D0B6D7E43AC425E11971352E4E06A1BFC2ED30F961B5AF2BE8D24A2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572244Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.657{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=67357005E564189B1DBB766632511D8E,SHA256=78DF9EE2172BA90CC6D2135DDDCAA08B2DF2036EFFFFD51DDA50610A876E7529,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670772Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:37.354{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1CD6F9A10F275B0E2DD549E467D40B91,SHA256=6B2B1CEB2060B824353FF9BCADA3D1DE810F0BDDEFE6898A4FFA8BBBB45E5316,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572243Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F4D-609D-EE50-00000000BB01}4012C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572242Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572241Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572240Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572239Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572238Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572237Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572236Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572235Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572234Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572233Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D2B9-609A-0500-00000000BB01}412988C:\Windows\system32\csrss.exe{E1BD9FC2-7F4D-609D-EE50-00000000BB01}4012C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572232Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.188{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F4D-609D-EE50-00000000BB01}4012C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572231Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:37.189{E1BD9FC2-7F4D-609D-EE50-00000000BB01}4012C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
354300x8000000000000000572230Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:34.679{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52760-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572246Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:38.673{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8F3564429F87D93C7878D38C038A1C54,SHA256=AEBB5DAD73390D979EF7D5458A50FF7E7FC8B0CE13BCFF6D5E4EA92A08E98F50,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670774Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:38.374{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4654C113208EF451BA89D608E785567E,SHA256=05BA869D77A94E4662A43A8DF2484797F9B6C6686D2921F6824D812FC20E15BA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670773Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:38.151{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=94D7CFD8C6C6556DED3B2E4CE707CF62,SHA256=959F6898417D62CE7CF16D7C29869DE709577DE216DDE22C4AD65E91F21421E3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572247Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:39.688{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=747F6FE9987CE194DBBAF30FD4AABBC1,SHA256=C0732537F56B6BF4F652C81AE4CACE245E76D47942F9851271F54C82A47CED6C,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670779Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:39.904{7B03F3B2-31A0-609C-522D-00000000BA01}18764336C:\Windows\Explorer.EXE{7B03F3B2-37B7-609D-644C-00000000BA01}580C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+6497|C:\Windows\System32\SHCORE.dll+6387|C:\Windows\System32\SHCORE.dll+62fd|C:\Windows\System32\SHCORE.dll+620a|C:\Windows\System32\SHELL32.dll+55a30|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF802640DD8C8)|UNKNOWN(FFFFF956C4EB4A38)|UNKNOWN(FFFFF956C4EB4BB7)|UNKNOWN(FFFFF956C4EAF241)|UNKNOWN(FFFFF956C4EB0C0A)|UNKNOWN(FFFFF956C4EAEEC6)|UNKNOWN(FFFFF80263DF4E03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+5929b|C:\Windows\System32\SHELL32.dll+dac5a|C:\Windows\System32\SHCORE.dll+33fad
10341000x8000000000000000670778Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:39.904{7B03F3B2-31A0-609C-522D-00000000BA01}18764336C:\Windows\Explorer.EXE{7B03F3B2-37B7-609D-644C-00000000BA01}580C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+1c0e5|C:\Windows\System32\SHELL32.dll+55511|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF802640DD8C8)|UNKNOWN(FFFFF956C4EB4A38)|UNKNOWN(FFFFF956C4EB4BB7)|UNKNOWN(FFFFF956C4EAF241)|UNKNOWN(FFFFF956C4EB0C0A)|UNKNOWN(FFFFF956C4EAEEC6)|UNKNOWN(FFFFF80263DF4E03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+5929b|C:\Windows\System32\SHELL32.dll+dac5a|C:\Windows\System32\SHCORE.dll+33fad|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670777Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:39.904{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms~RFa79d253.TMPMD5=36DBBADA813EDB200C2B5A8128054E48,SHA256=F4E0DB2CD90C5DD2683AE772A460616D1F0DB8B7E1C978F725E37B250DA33754,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670776Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:37.379{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51148-false10.0.1.12-8000-
23542300x8000000000000000670775Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:39.389{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5ACD9CCFB2FF1FD15ADC90C011574839,SHA256=A296A2EE17B4F439E10149EE3D185478009EAD39D0066EE35CBA1BD47F0EA24A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572248Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:40.688{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=51BA0768BE88443021E0E8C93C12DDC1,SHA256=6D3456B8B7791F9030DBD25A58A9EF753F0E07048A31EBED253E81EBFDABCF43,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670783Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:40.877{7B03F3B2-D0CA-609A-0D00-00000000BA01}9126412C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2B00-00000000BA01}3028C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+b157|c:\windows\system32\rpcss.dll+7897|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670782Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:40.877{7B03F3B2-D0CA-609A-0D00-00000000BA01}9126412C:\Windows\system32\svchost.exe{7B03F3B2-37B7-609D-644C-00000000BA01}580C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+b157|c:\windows\system32\rpcss.dll+7897|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670781Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:40.877{7B03F3B2-D0CA-609A-0D00-00000000BA01}9126412C:\Windows\system32\svchost.exe{7B03F3B2-37B7-609D-644C-00000000BA01}580C:\Program Files\Mozilla Firefox\firefox.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+b157|c:\windows\system32\rpcss.dll+7897|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670780Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:40.393{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4993473BC662E0352A259C4693A1277A,SHA256=4EE68EA820F552B81D96FC7D5C9841769A2B6A46AC11F0B63D8729AE813999CA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572250Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:41.688{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7FDE77099F64E78A7A1B51FF1E30AEE3,SHA256=30C1D294A6C69E177580FCAACCC09D86C3591FC1F95ACCD1DAA2F6A793A42A23,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670784Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:41.408{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6CBFC13944D986CD0FE81B45FA8E72B6,SHA256=3753C0DE5B9EA0F5BF65ADC48A3D4F9CC333DDE2BC8FB596958795D1A51EBA15,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572249Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:41.173{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D8B74273E729F8894A82E4777F01F1B9,SHA256=98468127434EE1438C670F23DFD83ADD9A2AFF66688FE022E4D2AEDE09E962E0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572252Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:42.688{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ACC747D05FCECBF6A797B29DBD113E1B,SHA256=A1CBB3F4DB92E9E11B7513339007E22F8E5572A0B2E0D675A767A48A5FD3C6C0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670786Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:42.422{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=563886760B3F92D7A6417C52914B147A,SHA256=11FBB17FCE9EA634EFF0F2F91684E734F4927363118B204EF277A10356F10F8D,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572251Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:39.773{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52761-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000670785Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:42.322{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4A495B98FAD0469174E6DCA79DDCE90A,SHA256=B7FAEB7CE7EA017D05449E5E5886FF0015E01A5169FA1D38D8E77FD3CB8DF82F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572253Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:43.735{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F632C6A38C57894F0A86012DB95EE97D,SHA256=19BDE7356933FAF2792ED3AA5F071A05B045C5393A7822B1D274BE6BA7E1D73A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670787Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:43.437{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D6D3C42B1B2443E05E61B24FBD3B46B2,SHA256=21E34CAE73DFB8A2C83F2060C3230B75088D65AB9043C8AAF80A826B4F9E490C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572254Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:44.735{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3EF869841CD8D6EFE16E8E51DFE4F663,SHA256=B81ED30C6526EC59579EB5BC9A727A8B147B282CDDA8B3FFF046BD73A33F2D19,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670790Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:43.383{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51149-false10.0.1.12-8000-
23542300x8000000000000000670789Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:44.454{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A90C786D195D490587C75736381E08BC,SHA256=A2E7BDB237EEB42F95587D23F3BAB9CCD077ACA65A5B9013260B8180431E33CD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670788Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:44.174{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=86D4EB1E15B2273BDA62F93D6DC89BD6,SHA256=D18BD34DC9738E9F505D187B84CB0BA306B05E9AC37EB013257659BB88BBC127,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572255Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:45.735{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4C1178B4C9A6091BF6B9BBC09653EC0E,SHA256=82E08C69F19764EDA8DF99922EEB6DD7CF02894AF940ABFB1767B6FDC3DB8B7F,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670809Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:44.322{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local55209-
10341000x8000000000000000670808Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.755{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F55-609D-E555-00000000BA01}7620C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670807Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.754{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670806Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.753{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670805Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.753{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670804Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.753{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670803Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.753{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F55-609D-E555-00000000BA01}7620C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670802Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.752{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F55-609D-E555-00000000BA01}7620C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670801Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.752{7B03F3B2-7F55-609D-E555-00000000BA01}7620C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670800Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.505{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=70CC36F2AAE4EE912C4E4D219A264B39,SHA256=C09BDA262738D710A1C9993FFF72189C7368E54325F932D9F3AD2E365EE9846B,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670799Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.257{7B03F3B2-7F55-609D-E455-00000000BA01}24164728C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670798Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.074{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F55-609D-E455-00000000BA01}2416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670797Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.074{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670796Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.074{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670795Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.074{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670794Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.074{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670793Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.074{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7F55-609D-E455-00000000BA01}2416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670792Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.074{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F55-609D-E455-00000000BA01}2416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670791Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:45.075{7B03F3B2-7F55-609D-E455-00000000BA01}2416C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572258Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:46.739{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB2D1E7C51F179496D5B440F6F1DF687,SHA256=FA043F89E6017971F31B6BD200AC43E99628E06DD9630270B734368BC7BEE980,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670819Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.520{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F9891F0E3A353588D574736B6D25D3FB,SHA256=09BA76F40702A1C02F3F8BE73F40C85CF9CD02A2C62866A156DA45EE0A78B2B9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572257Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:46.282{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=20BD305815CA0CA3BD0BD32EFBC477F9,SHA256=CC839DE6240E22E77A77BA9D0CA81BC95B45F5112CE09070521936312B4D3E43,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572256Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:46.282{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9009432DCE40398EB0271DD3854BDCF9,SHA256=A67662A44A4E6B58A31CD88335B279E0649C51EEE2F98E890E137E77C6FAB743,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670818Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.419{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F56-609D-E655-00000000BA01}6216C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670817Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.419{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670816Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.419{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670815Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.419{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670814Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.419{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670813Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.419{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7F56-609D-E655-00000000BA01}6216C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670812Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.419{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F56-609D-E655-00000000BA01}6216C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670811Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.420{7B03F3B2-7F56-609D-E655-00000000BA01}6216C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670810Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:46.088{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1FDEFAF7D96FBD983C64BCB54F0A02FB,SHA256=A2C1389CFE16C3ADDC36C1FF75BEF305B60B7B0797FFCB1E71DA5CBD664D4A9C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572260Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:47.739{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6655218FE94932049D2D63803FB59787,SHA256=84600578FB009FD6FD06C3291C997DC7B2F288D2FC788509E5423BA6D5E97B8F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670838Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.873{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F57-609D-E855-00000000BA01}5888C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670837Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.871{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670836Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.871{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670835Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.871{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670834Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.871{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670833Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.871{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7F57-609D-E855-00000000BA01}5888C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670832Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.870{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F57-609D-E855-00000000BA01}5888C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670831Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.870{7B03F3B2-7F57-609D-E855-00000000BA01}5888C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670830Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.523{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A592889646F5DE532136CCACB872DBF2,SHA256=3CEFADF36D8EACE9BB37A8A54B7672093FF2D1292B38C830282116CA58EF3EB3,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572259Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:44.882{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52762-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
10341000x8000000000000000670829Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.407{7B03F3B2-7F57-609D-E755-00000000BA01}64163380C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670828Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.307{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BD1781B66D82AE40EE53DE0A0F8E64FB,SHA256=D8A57292CD285003DF7BE234958327B1C9D5B9610950DB0F44361BAD88A813A0,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670827Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F57-609D-E755-00000000BA01}6416C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670826Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670825Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670824Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670823Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670822Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F57-609D-E755-00000000BA01}6416C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670821Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F57-609D-E755-00000000BA01}6416C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670820Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:47.208{7B03F3B2-7F57-609D-E755-00000000BA01}6416C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572261Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:48.739{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85D0264CF04FD6DD99E6871AFA39FDC7,SHA256=555DB5EBB0D8546239F2AD32A52648655B647B76F21CF3706807120A00F72953,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670841Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:48.524{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E6C7828283178BE8A1DC80BD6E970FD2,SHA256=5B4BF3D1961BC6D9BC610B36FDC625C723DF36F953F346961ADA1766F041EBC5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670840Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:48.424{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2B6A7DEC27D3A4FE399B3703A265DCD1,SHA256=4C4E697EB5720CB2E119B68AA0CD4E0FAAC8AE12F0406B231B018673DCF4D90F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670839Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:48.076{7B03F3B2-7F57-609D-E855-00000000BA01}58883848C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572262Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:49.770{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B524D0E3D8C1FF7347AF0F1DE869F6D,SHA256=EBF80020DCCE95B1EEF9B8DA45157EDCAA663D0068A83C16CDE252F6DC23EB71,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670842Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:49.539{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E35453F663A14D1C06D875D74238690A,SHA256=34011CA256EE365CDE105E54619EF620C7CBB38798FC3727303FCFD369DC116F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572263Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:50.802{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9B070552FA7294D23D76F9919C143A1F,SHA256=4493CB3A8A21986E3F5B16EDB5E3EBBD1CACAC5BE2D522C10532375C75366892,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670852Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.838{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F5A-609D-E955-00000000BA01}7952C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670851Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.838{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670850Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.838{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670849Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.838{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670848Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.838{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670847Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.838{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F5A-609D-E955-00000000BA01}7952C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670846Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.838{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F5A-609D-E955-00000000BA01}7952C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670845Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.839{7B03F3B2-7F5A-609D-E955-00000000BA01}7952C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670844Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:50.553{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D824D552DD9E7C0DEA5F97DD0CC2802A,SHA256=2C8FA36144CFD2EB0319C704E69726743DCE27644742639FB71C22CD2AC32CAD,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670843Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:48.399{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51150-false10.0.1.12-8000-
23542300x8000000000000000572264Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:51.848{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C21CEAEFBA4EE9F8CE88E98197EFC0C6,SHA256=5E73FA2508EEB090861422C5CCD883AC0C77CC498B3F4522A72300AA5EE024BD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670863Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.853{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D9E9CA1052864A5CB027B4F1D2A2C4D0,SHA256=3171C3E616D4F10F2E4B81A55180FDC59A7EA3A4F812DE77B7605116FB97746A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670862Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.575{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=34ACBFE99E78C7EE2590200BDFF4C3A9,SHA256=4E46FAFFF0657736E3B8FE632FCF5968C1EE131891AC68A1A6932FD2824FCB6F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670861Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.522{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F5B-609D-EA55-00000000BA01}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670860Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.522{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670859Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.522{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670858Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.522{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670857Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.522{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670856Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.522{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7F5B-609D-EA55-00000000BA01}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670855Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.522{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F5B-609D-EA55-00000000BA01}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670854Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.523{7B03F3B2-7F5B-609D-EA55-00000000BA01}3632C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000670853Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:51.022{7B03F3B2-7F5A-609D-E955-00000000BA01}79527416C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572268Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:52.880{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F2BE9A99E48B01F3C96734465DBE617F,SHA256=5BE03179DFCAC63C1C5B91596220A0B47B20F28DC5B079C9897801E4F570A458,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670864Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:52.589{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DCE5F8C3C3FC8D10637CD37B72F794B9,SHA256=54B070BC863779129F7BA9AC92345CE7F513D7DD45E4D3EA18E796558AD894F5,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572267Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:50.730{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52763-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572266Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:52.145{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6EC9AE3848D2D98E6FC60D355F5558EC,SHA256=F1339EEAF8555F93BAF3D0348E778250564030C950F077CF7E02FF3B90A9F02F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572265Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:52.145{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=20BD305815CA0CA3BD0BD32EFBC477F9,SHA256=CC839DE6240E22E77A77BA9D0CA81BC95B45F5112CE09070521936312B4D3E43,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572269Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:53.895{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=05A3534B906CD174647DEC4FC1E9C3B3,SHA256=9003B25C4B7FBFA2E4BC67A684B3B9E9CDCB8A823B843725CB35AD5D2F6E3F1E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670866Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:53.603{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EEA8A877C58840378882E4250C114A95,SHA256=9E24F35F1443D5D201D501DB03856ACCBA8D8FF1C81A81E0B01E8DB3B707DD11,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670865Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:53.550{7B03F3B2-D0CA-609A-1100-00000000BA01}620NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=C3C675813231834794C1C8FD76200181,SHA256=96C58D6919B4E07221E75C597E7DF6B1D8AB508A1934E9875475DB18F0115B34,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572270Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:54.895{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5A774B1B43AD5E5AF0CE5AB787EC9A35,SHA256=534DBC29CC26C6482263503E9275D5CB63C918343B269829B2D557F54FDCD452,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670868Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:54.617{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=871531F037750DA7C1171A1545D15506,SHA256=1D9883F8C1821EC9A1DA4301C817DBB6B6212A011A284637F715BB47703A4984,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670867Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:54.234{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=37A4B45DC461905D43642021C0A077DE,SHA256=A4338AB6409DF649C22758E77EC0C490FBF73FCEFB6D979C1F1FB5B4E1305ACC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572271Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:55.942{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=80BCE09B63E47D99DB8007310D8285E3,SHA256=8EACE5102841D25609A6A7BADEC1A37BC6DBED1388575DB88FF14E1381AF2DD0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670869Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:55.632{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ABF4AC2C6973D6F277B69DF7406F9907,SHA256=D72321991F0CBBEE5B1AD163D245FFC945C518A89B06D7AC88D852A9955E1F6A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670871Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:56.646{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EE582DF0CF7EF7CC62944EAB3ABBF6CC,SHA256=2E42D6A3F8E17E72233B93BA64499D74FF34B35D50B2E75C18D14E1D86BB7483,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572272Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:56.942{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=815A73C660A6D668D0B3A85B27D43FFF,SHA256=12FE8406376D6FB9AD78D3A6C6D3A4212ED8A99E19A44AFE7FA363ACB822D0FA,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670870Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:53.450{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51151-false10.0.1.12-8000-
23542300x8000000000000000670872Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:57.662{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FD924A18A1AA980D9DB77649322A5779,SHA256=C9095BE0D0F3F1224E93153D6D5040BEF63EDFE4A66D5567AD9AFECF0CB19443,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572276Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:57.958{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ADC77DEFEDE9829CE9697ECC58363BAA,SHA256=3FC68778421C75928F2254D55A0B8FE5123CE07AF2FDC4E81EAD34EBE1468554,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572275Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:55.839{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52764-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572274Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:57.223{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6E6E45125F89E5F093DA0B41915B6505,SHA256=318FB313F855A77EF7766053F3B1F89E3F9FB4F4DC57CDCD36806E1328F6A9E8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572273Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:57.223{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6EC9AE3848D2D98E6FC60D355F5558EC,SHA256=F1339EEAF8555F93BAF3D0348E778250564030C950F077CF7E02FF3B90A9F02F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572277Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:58.973{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D0D054FDFD5A2F36850AC083BBA4892,SHA256=5C27C965DA48455D79F61D2D25D5C44C0650653BBACDC054CE9882B80109A4D7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670873Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:58.696{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0FE9506B4EC1E5CEED67805212098FA7,SHA256=9763DD26BE5BC0B0C5C3DE9BB9B5DDC17202C7C863BC10752492688DB213424E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572278Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:34:59.973{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16247772B82682AC5EA65F20B8371543,SHA256=B60224457D2ED36E31220031CD0626CC508B909520799809C388749662EA1FFC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670874Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:59.711{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1F9FAC843E1D7029ECFD792ABBCB925D,SHA256=477B5CD842DDA237E1072283C26E063D4731C16096F4FF8DC13ACE2352E4AAAB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670877Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:00.725{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6157FB65E04621949EC4209B0E48E898,SHA256=4774A60DBCF5221D084F5C040737DC5A41D3C4A02EE3225BC577A243CF0557F4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670876Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:00.126{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FF7D4A29B0595CB2AE630DF094A37996,SHA256=CEB42CF59076FDD45366D7E4E8209E0C36BF629925432AC624F0516C812D90AE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670875Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:00.126{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=25420D66FAD724FD72AA516A1C78A1B7,SHA256=D95CFFC5206E3FED3E7C536FF9F9DB9E998E362889CD1EC3B5103060286F951E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670879Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:01.758{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2A1EAD58702137CBB6A555785772DDA,SHA256=E3E0FE67003B36AF759EA72FFDE14CE3D02FA334A03AD2695D51DA8C547D57BA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572279Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:01.067{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=46D57191E48A317698C95DABDF3FC42C,SHA256=6085701B4F274F97B59C5A020A12470953FE0566E4FB3857A04B47CB4F148AF4,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670878Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:34:59.357{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51152-false10.0.1.12-8000-
23542300x8000000000000000670881Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:02.792{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=726A18C44CCD28552F5F041057BF5A0A,SHA256=3BCB84CD8D881130DBCA60DE2EEF4050FCFDDE943F5CB69C7E40954014F649C7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572280Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:02.083{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=76856FF43114CD3BDFB3B4D113756823,SHA256=6313964ADC1C0B90141859AD1484046E102845CFBDCB90EF8999513438F0F030,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670880Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:02.324{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FF7D4A29B0595CB2AE630DF094A37996,SHA256=CEB42CF59076FDD45366D7E4E8209E0C36BF629925432AC624F0516C812D90AE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670882Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:03.806{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F06E53169A87DF474D21A11D8EF7077E,SHA256=5C0836FFF05B7B2A73CD5DC73A52EF7516617516B7616EE113A24C0FAEC4856A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572283Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:03.098{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=02C9BE628751E77ADB3B67EA7C9D1DC2,SHA256=63BB71037AD6DF805D225F08459732C125A53C224BCF753ABF649B6E5F06E9F7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572282Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:03.083{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0D501DD1FC0BE9FAB7E879E757CAB4C8,SHA256=ED3C6C9A11A7B1406378C2F62CFEF72A273B74755280C823F74A45E61911F64A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572281Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:03.083{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6E6E45125F89E5F093DA0B41915B6505,SHA256=318FB313F855A77EF7766053F3B1F89E3F9FB4F4DC57CDCD36806E1328F6A9E8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670883Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:04.854{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=425348FDF0527F586EC6C07F1B5DE75D,SHA256=64BBB09BD8A65EE48C6C8DC1918840F2E391B19A9764A58B01797D1B6DD14BE6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572285Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:04.114{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=51065B920D65AA68F741DBB1FF5FBCA0,SHA256=88E1E0F5F25F5F6FDDF1E25DBC9974627FD10CD30EA085B1594DBC03EDA2FD26,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572284Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:01.652{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52765-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000670885Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:05.874{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5783F30626C3D6C8CA91589F50B3553D,SHA256=2B5B59D2CD054FE1D21E906136712E684AD5B264E099ECEB0293E97F50BC3485,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572286Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:05.145{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=75297EC051D7711BE13947228576B28A,SHA256=742164D8CBE639ED94AA8FE1693BFFBCF432F9EB6D89DF884F6F6468EE694A7E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670884Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:05.221{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DCCDD129D935F9605F4A67633568052C,SHA256=E9AA6EA5D3AC0DEF1665923F2A3B172128DBEEB4E5D8FBA462D7F4AD2ABB63F1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670887Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:06.874{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E3A161D059268DC5055132C4378F4547,SHA256=14003F0C53B968BEDFC96D9ECC4090E173DD79035649412B2A107D08205C9141,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572287Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:06.255{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BA4C74C70DEDC4342AF0A1C3BFF5ECA3,SHA256=24991D829412069646B5FF398C0D9C1FA1023334FD542726386CBD78F8BCD211,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670886Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:04.436{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51153-false10.0.1.12-8000-
23542300x8000000000000000670889Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:07.888{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=297019FF6AF02ED0822B2D33838CA5C4,SHA256=DF8C2065A117EBB9FDA0404FF0B906DEEA4AD3E78547814FBEE7F876A7733152,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572288Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:07.306{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D12DCF20E0AD52948CC3BDF513F9B962,SHA256=C9921E6ACCDED7A3E000D3A92703A0B857DEC75B51F85E6B86925B6A62D8DE7B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670888Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:07.355{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9CDDF934971CDCEE4E1CE6DD43B6A2D9,SHA256=404FE57CB6E61F91803FBAC161E44330DB22605393BF0864F9901C287AEBF6A7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670890Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:08.904{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CED818E5B313AFC3DA962B2CD2540725,SHA256=20DBDE214B0BAF63B756117481B865D20CC4CBC8D061520074A39B7C8D5F70A6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572291Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:08.321{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3FF3111CCF2452EBC6D3D02783A63ED3,SHA256=1B3E139C58D71629731276A246FB669BBD53D427ED67367F8DE180651EF85FED,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572290Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:08.321{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0D501DD1FC0BE9FAB7E879E757CAB4C8,SHA256=ED3C6C9A11A7B1406378C2F62CFEF72A273B74755280C823F74A45E61911F64A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572289Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:08.321{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCC4BA34A5772F5EADF589852B46CD7A,SHA256=0068AFF4C0FAA912A1C55F2788E01B35AEFB017CE7A525752E4C6061281FEFDC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670891Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:09.918{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F6623ABE13025C111E07164A19D24B90,SHA256=41270421FFB1C27B2C2F7558000D849A3D19267D6D56C0B1F7427D9E7CEF5A75,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572294Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:09.478{E1BD9FC2-D2BA-609A-1000-00000000BB01}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=9D9D7D077C75EEE48C2E0406ED7326D5,SHA256=0994ACCB04BB4B520B07959C724FF29370D80613171E6329A01EBC2DB641420A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572293Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:09.337{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BE32839E7CB8017A8FFA8AA06882951E,SHA256=C021FEF0F0AB282265F76D124716B8080429F08B1DF599938496C377DBD77BEC,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572292Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:06.703{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52766-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000670892Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:10.934{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=091E50485BCFA40A75A762AB2BC85767,SHA256=49390DF9864AA341CC8E268962A61B6B6197BABA15DDC6A0D0B020C47FCB0E21,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572295Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:10.415{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5190AA2F443F9A108A57A89625D177B1,SHA256=88473926919239232C50F9821E87512EE8C1241A41FC846D75B5B908D3D0D4D7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670895Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:11.970{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=27E05BA75DF55AB6B1744218F5A7FD7E,SHA256=3EE9E0C4B1EEF9FEDAFB29C7226A43576BD1C87D9A3EB67CE36503459BA4E037,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572296Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:11.478{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C641A269AFA7BC6AC6C78DB348D29F5A,SHA256=7AF5C213EB3545A2A2AEF263673AF0E4370FC025CAED76E2E1654731CEAB50FB,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670894Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:10.299{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51154-false10.0.1.12-8000-
23542300x8000000000000000670893Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:11.102{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=297DE8F891BAD7A577CA272ED31482BF,SHA256=421FFFA1E299BC9DF6B7D2E28C84A3C790A635BC911E418B4B5A3F117B2A0AAD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572297Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:12.509{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A84CDC5B03A9CD7AEA1B31D24E8305A4,SHA256=A0ECEF066CF12D92F3F75D8464CEFF211B152B39B6EE41C2D9D0532D3DD12CBD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572299Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:13.540{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF01C22116EDD132D0B2CFE26ECC3EC6,SHA256=D3717861DE218B6DCF1435A5C44A6695464C3F1640BD951645A1851E60F6570C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670896Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:13.031{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B7BA81A5E2C6CD60E236BBAB31A55A9A,SHA256=AF3B771C9487517F31E47109887631FD1EDFCDDE52831D8DE22AFA3A5E2ABA8E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572298Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:13.181{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3FF3111CCF2452EBC6D3D02783A63ED3,SHA256=1B3E139C58D71629731276A246FB669BBD53D427ED67367F8DE180651EF85FED,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572301Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:14.556{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DC8A4B79B038F4ECA58591E4AF8F1961,SHA256=22EB7BD8BEC1BE9268E118D2E80B46EF23206A6CA56CCC535C021AA89B507299,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670897Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:14.048{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C27A08476BAC9A2FE0C6D1BF73EC40A,SHA256=348088D818AECBD4F057982CFC6AB45F370B5DA28482E79F7139ADEB8AF8A1A0,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572300Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:11.781{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52767-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572302Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:15.571{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=78A959A2AA96CF8D20CFEAEB1B76A2B9,SHA256=A26DFF11923B39958ED1405954FE8D2A8C2B800B478D4F9D237D822878B3D98F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670898Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:15.066{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F7A2C8A5A2B78D832307C90CADA65F50,SHA256=B48845C9BC587630688801E2F91ABBAE50E19AD57BBD65D8B4CAEEB9B4B7EF46,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572303Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:16.618{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2605F15D6952970A1BC64D25DD4116AB,SHA256=875B870A97CAA35EB4B0400596EF678C0A8BDEC6B963C031A2309824ABC29BB8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670899Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:16.096{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E1384170C2DAD8279634D1FB9E9A4C65,SHA256=DD86D77A8CDBC97F74C289619300A012475B8627E62A8BEA5318E917EE303D10,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572304Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:17.618{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BBE531E6BF35721C082A3B0E56BAA2A5,SHA256=41CF2E4A0908A574BB15F4481516E75C9EC0EFB0B4A0A1F9E2D9862A88B085B1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670902Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:17.111{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BB7D81D35FA5064BE909A12D4C4013E0,SHA256=8E2E9D38EC385AF448989112E830795DAC15BD44CA9033BA8F3C04D8EAF7F278,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670901Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:17.095{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B05B02E1A3753A59A56610E5C5125177,SHA256=FE1C4606BDA228AEC2765F08C59EED3E21C3D3438A84137C211B263850824914,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670900Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:17.095{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B4EAF4C6E6F895BAD066D788B2C5251D,SHA256=21A80B509DC1955FDBB7D3BF70B3E3C38A31F0CB5902C2F45804C016BCB5080B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572305Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:18.665{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=19A84EA126DD33A71EF4EF770BAD59DF,SHA256=29C08FBD77276C296035C7EE16CA93BD854CD4D14A5EDA85E71E58B56F8E6970,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670904Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:16.327{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51155-false10.0.1.12-8000-
23542300x8000000000000000670903Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:18.125{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B66FB61AA56D3DCFA7138537F3C22F8F,SHA256=F19C667C93CE2154244521414C2FD2DEAAFAFE88BE439E9F1944421A37873EC0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572309Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:19.665{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=743DFA2AC69BA5BFE71D782B4B570728,SHA256=D89513359E9341169242523524EE98F13AFDAB257CEEC0E78D18A5C293E29933,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670905Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:19.143{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=852BE6B35F595E640FEF3E6DF703D6C0,SHA256=2D07F39EEE3031DB308C76800EEB9EB134FA697D0C864B6338BD764899183FC6,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572308Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:17.703{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52768-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572307Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:19.103{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0F72581CADB616F124A3F8FB98F6DDDE,SHA256=0735D4881A4C7111ABAA7150DB6DF55F5DCF2167891ABC858CA336485312821F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572306Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:19.103{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6FF035999E09BDFEB72A594D0426BD2C,SHA256=E0C54F21084EDC35CC97F1D4F4941FC26B4DE92FEF2F6184403A8E3ED7A5DC71,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572310Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:20.665{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC5B9C669F955048F4741CDE53102FFC,SHA256=0F4FC6851778D1395DB3E4A3A67FA0E86197DEFB6238FCC0D9B515EAEB655AF9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670906Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:20.162{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3FE9EEC939D03CC0374D346A95450823,SHA256=12EA164F49E5C612CFE85BA900AE033BBE6FB8C3DE23F32E0F4AFEE2CD0F93E9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572311Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:21.681{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CB205542FE3062BBBE170A947005D963,SHA256=2FBA5498739F305ACD371C25CB2F0A466607EE62982E739E159A4C1682766ACF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670907Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:21.176{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=62A8CA3BBDD6E0EFE44312A5966BE836,SHA256=A860A005D1158D48F60F18D1324DEDC04DD32975BA344592C70EF39827E11709,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572312Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:22.681{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=30619ADA01C48A2A1183FD5D1CC2AAB4,SHA256=C81BA98641621916435C529127813BB0C91860E07D7F98FF66A7022D9EBEAF38,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670911Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:21.388{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51156-false10.0.1.12-8000-
23542300x8000000000000000670910Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:22.191{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=938A56F48A86D647BF76C9D255CDC743,SHA256=A7D1AF4145B428A89DF185D224F978E3AB1E1BAC3FCAE3376F8C5293F987F9FE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670909Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:22.160{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9B6B745FC954552414BC59CA2E055AEE,SHA256=23E21AA73E5DD3D62605E462C8AD81F4C54256ED8CCBCFCBAB3CEF2F59ACC5E8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670908Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:22.160{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B05B02E1A3753A59A56610E5C5125177,SHA256=FE1C4606BDA228AEC2765F08C59EED3E21C3D3438A84137C211B263850824914,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572313Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:23.743{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=141EEAAB49B2A3B47E9F4FCFB2C1D7D0,SHA256=D2465414A767E915B657E591F22CEF8255596F9689DEB15BA973E0797A858304,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670912Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:23.222{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A54E0F38A2284705FEFB57A20A29074,SHA256=F4F59424294C2D73D46301D714615A21D4D4BC1205A4733B420E62E936AC3958,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572317Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:24.759{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F0041337ED63CE358C4799BEEF73B6F2,SHA256=7D7A242F578C725149AC484CCE995F77FE623C6A844423052933DB0660C6EC57,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670913Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:24.239{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A5353F9CB27C1AAD663970FD2CDE5F73,SHA256=5CD823029C126E18282E47635454BF932FF6B11788314AC17F94497AF5DA558E,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572316Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:22.796{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52769-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572315Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:24.165{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E1B68C1E1F94C05F048509438A610E55,SHA256=5C541CB9023D040AADA64A91174A8215EAB33510062D3E21749850C39FCDA16A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572314Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:24.165{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0F72581CADB616F124A3F8FB98F6DDDE,SHA256=0735D4881A4C7111ABAA7150DB6DF55F5DCF2167891ABC858CA336485312821F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572331Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F7D-609D-EF50-00000000BB01}1068C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572330Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572329Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572328Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572327Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572326Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572325Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572324Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572323Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572322Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572321Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D2B9-609A-0500-00000000BB01}412528C:\Windows\system32\csrss.exe{E1BD9FC2-7F7D-609D-EF50-00000000BB01}1068C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572320Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.837{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F7D-609D-EF50-00000000BB01}1068C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572319Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.838{E1BD9FC2-7F7D-609D-EF50-00000000BB01}1068C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572318Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:25.775{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C095179AAE0675CF4B637057C3177BDE,SHA256=D9544B7FAD96D0F22BCBCA8FC98799098A2E6655652B1BC47EA2650099A870FC,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670918Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:24.451{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51157-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
354300x8000000000000000670917Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:24.451{7B03F3B2-D0D7-609A-2700-00000000BA01}2888C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51157-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
23542300x8000000000000000670916Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:25.275{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CFB50B67B99002FF36144688647AB51C,SHA256=B791A83A576E2EB2A1A052C383F18AC67E098C24C94E15C0852255150F509051,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670915Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:25.206{7B03F3B2-5120-609D-3250-00000000BA01}1532NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670914Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:25.206{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9B6B745FC954552414BC59CA2E055AEE,SHA256=23E21AA73E5DD3D62605E462C8AD81F4C54256ED8CCBCFCBAB3CEF2F59ACC5E8,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670920Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:25.436{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51158-false10.0.1.12-8089-
23542300x8000000000000000670919Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:26.306{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=769D39BC59F879B95EF30C52575B6F5A,SHA256=397438AF9A5716B0D200B00ABAC4599F6658C8BDCF80AFDA9FB70381556886AD,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572345Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.630{E1BD9FC2-7F7E-609D-F050-00000000BB01}24683364C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572344Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F7E-609D-F050-00000000BB01}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572343Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572342Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572341Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572340Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572339Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572338Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572337Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572336Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572335Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572334Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F7E-609D-F050-00000000BB01}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572333Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.505{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F7E-609D-F050-00000000BB01}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572332Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:26.506{E1BD9FC2-7F7E-609D-F050-00000000BB01}2468C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
354300x8000000000000000670923Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:26.436{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51159-false10.0.1.12-8000-
23542300x8000000000000000670922Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:27.321{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=662C3F4D6F1BE2B1789C7D73203B0C30,SHA256=553D237B15B3E28A6D134F66BF88EAD30AB4890BDFBFF9537271824EA01F319E,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572360Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F7F-609D-F150-00000000BB01}1220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572359Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572358Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572357Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572356Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572355Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572354Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572353Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572352Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572351Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572350Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F7F-609D-F150-00000000BB01}1220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572349Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F7F-609D-F150-00000000BB01}1220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572348Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.070{E1BD9FC2-7F7F-609D-F150-00000000BB01}1220C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572347Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E1B68C1E1F94C05F048509438A610E55,SHA256=5C541CB9023D040AADA64A91174A8215EAB33510062D3E21749850C39FCDA16A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572346Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:27.068{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=954FFF694851443DBA52FDA3F5D10BB4,SHA256=8FFD1BD8BE1BC654EAC62DF6B009EF70FC46ACD3B920401E4716BA198436541F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670921Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:27.241{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=110D96830AA73B607A6469CA69D65571,SHA256=53F8910C10BAAF500D457169843C68ACE1066B91AA3F0B4A4A056BAD916192A3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670924Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:28.338{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ACB951BB3584FDEDA2866A99F22EA56C,SHA256=DCC3D03D590E0D3849EA9B60BB3115A3B830BDF114EB2FEF7FD8C4BCF61B2373,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572362Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:28.083{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9BB9A84B472DE2745D13F9B82D6D69A8,SHA256=1B9FDABB592A0DDD85DC625749F241F5979EA8C45C0B962E5688DDF1BCE32379,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572361Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:28.083{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=6ADADF3A42B4825C78905BFEAD380320,SHA256=EF2C0227644E08FD0CB14DC1F0FF3314F686F3EE6801D7704477FC5B4D97F514,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670925Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:29.356{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4D476C9E9612B34FBF98F180DFE52633,SHA256=3B0D973ED9B555AD5750C6EBD77CAACA6B92B4077F3E328E3B1C58B2A098E6A2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572364Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:29.786{E1BD9FC2-D335-609A-9D00-00000000BB01}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572363Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:29.099{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2269607D26A42C7F1161D2B73367493,SHA256=22F5E9EABCF3429CC54685A1A8BD8DC6ED055B895106E09FB9C8BF19299A4517,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572367Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:28.746{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52770-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572366Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:30.116{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B9CE0C8200B36FDD6175F896BB1D2B22,SHA256=DC191B11872651EF8567571D2F5111C3AE76D82666D0D51DE8F0592EA964CFD9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572365Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:30.116{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4F3537C09B73E5345380C5C71B42760A,SHA256=4CE7FC18E9812B97C21370E8F757B4B7B7E221CB6BE341897C394534EF110211,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670929Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:30.956{7B03F3B2-D0C8-609A-0B00-00000000BA01}6327824C:\Windows\system32\lsass.exe{7B03F3B2-D0C5-609A-0100-00000000BA01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e
10341000x8000000000000000670928Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:30.818{7B03F3B2-D0CA-609A-1600-00000000BA01}13046684C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2a2f2|C:\Windows\system32\wbem\wmiprvsd.dll+29e26|C:\Windows\system32\wbem\wmiprvsd.dll+28432|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670927Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:30.818{7B03F3B2-D0CA-609A-1600-00000000BA01}13046684C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2F00-00000000BA01}1168C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2597b|C:\Windows\system32\wbem\wmiprvsd.dll+283dc|C:\Windows\system32\wbem\wmiprvsd.dll+57817|C:\Windows\system32\wbem\wmiprvsd.dll+8a475|C:\Windows\system32\wbem\wbemcore.dll+bcb3|C:\Windows\system32\wbem\wbemcore.dll+3393|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+2c9be|C:\Windows\system32\wbem\wbemcore.dll+202d8|C:\Windows\system32\wbem\wbemcore.dll+390e|C:\Windows\system32\wbem\wbemcore.dll+22bba|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670926Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:30.372{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=36AAD9323EA34FD89BDF8C8F1DDA2515,SHA256=A87E759AE83923B4839668071C073AB1FC7D3D427761BAAD65E5D8965A4B3528,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670931Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:31.402{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E2B123F1BF0C95E62CBF6C514132742D,SHA256=046FDA4637663F99C28E183A1E74A14A4D410F51B953554EADADA34395DB1304,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572369Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:29.402{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52771-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8089-
23542300x8000000000000000572368Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:31.152{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3188FD7A9079AD6830DD2AE444BAF303,SHA256=C6588EAEFB61D2E3A7C7F30FD276AC43946F602E33766452FAB28EB3F7C828FF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670930Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:31.171{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C38C021413D5AAE07E330711C16FD2CF,SHA256=8BB571FF71B9A051A4642CAD08733070BADB21A94678C3E4444536A6615A24EE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670934Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:32.434{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6827F50BFC6CF7663A9D2DE057CD1885,SHA256=620B167B0F9A1ACAC80F92CE9E82766DDC628E03CB238A2915AD6EE074AF0688,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572370Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:32.154{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=28BC6037B66A227076D9A3C32F6E5E86,SHA256=F59B2BC66C83380AE03515AE14B50228E68A49CF0457081A567B5F4A1D8361E4,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670933Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:31.202{7B03F3B2-D0C5-609A-0100-00000000BA01}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51160-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local445microsoft-ds
354300x8000000000000000670932Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:30.382{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local57775-
23542300x8000000000000000670937Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:33.484{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E0D3AA62EF0CB162EB3CAB53784539A9,SHA256=7D6294C0BBD050831531579C944925E0831D194EB26241BFDBEFD43BCD2EC5B5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572371Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:33.185{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=92A46FB84DD58420C7E813B23E6E772A,SHA256=DCA9690AA319F9310612AD8B0062FD62EF2F2D4EFAABEFB70AFF9B55970C4FA8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670936Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:33.236{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0CB0C375528583F480651A55E8A3C5DA,SHA256=C08703CC3F5B081F3C31841C8C710FB4582738A6A04737A877273CCBC889A840,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670935Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:31.202{7B03F3B2-D0C5-609A-0100-00000000BA01}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51160-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local445microsoft-ds
23542300x8000000000000000670939Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:34.498{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4D55532876FB1C84188F9C0E91BA042,SHA256=9D26346590C2A763C793FA1D64BDCAC2F24B95990A4318FA12B958A46FCB819D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572372Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:34.201{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1203869056F49A377927DD88E4612BB5,SHA256=549CBDD2BD4D80046CCA974B245C086D58646E6A861CA9B29C3232CF13F9558F,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670938Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:32.431{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51161-false10.0.1.12-8000-
23542300x8000000000000000670940Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:35.513{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CAD5CDBB807E6EC68BEA4EFE4A626DFA,SHA256=DFB0E48E2717AAF3B1AA13F94A5D00114ACB30B29BA4602ABDB948D77F3F171B,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572400Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F87-609D-F350-00000000BB01}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572399Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572398Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572397Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572396Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572395Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572394Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572393Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572392Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572391Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572390Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F87-609D-F350-00000000BB01}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572389Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.872{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F87-609D-F350-00000000BB01}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572388Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.873{E1BD9FC2-7F87-609D-F350-00000000BB01}3840C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000572387Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.325{E1BD9FC2-7F87-609D-F250-00000000BB01}1588352C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572386Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.294{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=06F21DBCF038F636A20F6B799C8E71E4,SHA256=1407EED8B8AC17AD1A5C0A8696ECD3D7BDCA8E50290EFB1CD44200BBB2CEE1BC,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572385Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F87-609D-F250-00000000BB01}1588C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572384Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572383Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572382Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572381Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572380Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572379Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572378Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572377Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572376Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572375Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D2B9-609A-0500-00000000BB01}412528C:\Windows\system32\csrss.exe{E1BD9FC2-7F87-609D-F250-00000000BB01}1588C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572374Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.200{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F87-609D-F250-00000000BB01}1588C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572373Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.201{E1BD9FC2-7F87-609D-F250-00000000BB01}1588C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670941Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:36.564{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=72E54DCC55AE21F187DB0B464E7203E8,SHA256=3E9017F9A80F5C63BA29F67C4BA302DC1CE58C89A16DC8EF529B8A038F32EC85,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572418Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:34.676{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52772-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
10341000x8000000000000000572417Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F88-609D-F450-00000000BB01}2884C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572416Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572415Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572414Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572413Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572412Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572411Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572410Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572409Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572408Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572407Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F88-609D-F450-00000000BB01}2884C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572406Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.544{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F88-609D-F450-00000000BB01}2884C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572405Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.545{E1BD9FC2-7F88-609D-F450-00000000BB01}2884C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572404Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.310{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=23A0100ED127BD5D2CA26FD9F53FE2CE,SHA256=6594B05C774471239E2C2E5C6E6707EDD759EB24220E64F945266B6B246DB8A9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572403Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.060{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2B2B11E7576E9D3EED0C0E1D50E37E27,SHA256=8D6A1C67611F1D1674D289B98061157FE5EFE067D247AD3808D61720308193ED,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572402Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:36.060{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0AD7EC1A424F2BEBEC9D8600D3F74461,SHA256=D06F037DF4FDEF3C69B6575C42AFFA5D0336725CAB3EA68144881653585B536E,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572401Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:35.997{E1BD9FC2-7F87-609D-F350-00000000BB01}38401200C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572434Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.575{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2B2B11E7576E9D3EED0C0E1D50E37E27,SHA256=8D6A1C67611F1D1674D289B98061157FE5EFE067D247AD3808D61720308193ED,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572433Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.466{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5C22367659F72750206992C764D51BF8,SHA256=51DF487E598F8CA4CADF33075BE13F8D62E6830582A9F97FAD7D15766EC734C4,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572432Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.341{E1BD9FC2-7F89-609D-F550-00000000BB01}9003580C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000670942Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:37.566{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E1371A8B58E7497AA50F92A88ED725C2,SHA256=455C7A49F5FC9A171F97256B8AB3E9BE0FC6D225B4D471AE7D2403B1E6AA8B0F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572431Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7F89-609D-F550-00000000BB01}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572430Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572429Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572428Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572427Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572426Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572425Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572424Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572423Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572422Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572421Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7F89-609D-F550-00000000BB01}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572420Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.216{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7F89-609D-F550-00000000BB01}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572419Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:37.217{E1BD9FC2-7F89-609D-F550-00000000BB01}900C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572435Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:38.357{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D28DB3CCB285F577A49DA819FF61D2E2,SHA256=CD8BBBFE33864B9EE294B579F146D655EB4D599AE9F7DF11D7888CD1C8584072,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670945Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:38.580{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DA3EC179D7C79D43B71A1AA6324B31C0,SHA256=F7B469E161A4FBBECDDF84E9311FDF1DAA98C5CE4BCD45DD9595783EB0DEFA95,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670944Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:38.231{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3AFD01AEA046889A197D6FF78A00A153,SHA256=7A9FE6942740FBCC44879A9DA0DDADE85E9E8B7BA523A7D78F3C6E5E74AACDA7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670943Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:38.230{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B46CB7AE2C6AAF0138C9B4E07DBA79C9,SHA256=40657D2F9003AB0F5641E9ED4C10959413970A33A2713832B67BEA8672EBEAFB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670947Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:39.594{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3829BFD69B0A72313F860466F7450B96,SHA256=880F262D4D7423BF412830D271BA0101EDA2170475222D39B590254569A43F3B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572436Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:39.372{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D0C7BE649C873841844C3F45D3982829,SHA256=A98BF869C6DCEBD4A9E7BB13828762EBC902E555884E4D15022A3B5BADA439DC,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670946Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:37.472{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51162-false10.0.1.12-8000-
23542300x8000000000000000670948Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:40.610{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=933FE0EA97FF1919ED95F97EA9849CB0,SHA256=331A8034B4AD95F1D0CE322CCAD9FB2556CD56DD0CC9DD72AFA5F1BC76C4B969,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572437Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:40.388{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7C679F85C2F9ACBA000AB1B59CAB40E5,SHA256=99C5FAFFA51E15D21D06E03500BACFA20825B8F2CC82FC2418F9EB9DEAFA8B65,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670949Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:41.628{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98EED972D76B5635B7F9090127736E3B,SHA256=185D15501A9BD2BB3E0F7AE0A88DDC53BA88A487BD964F89EE38CC95D439A2AF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572439Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:41.388{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FFEBEF980CA2310021D2B8DF000DAEB0,SHA256=F33E3B7D103A37FD3FD675267C6E35E434193BC8F4EC2E81BC4797467EC1645B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572438Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:41.107{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A7C44A97A06B361256B72396DD1A4A43,SHA256=EF9E279DB60A5EF9411EAAACB20870F4D49A0F4C2F24A4C86F747BA507CB4890,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670951Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:42.645{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D2128E875F6D5FDDEF70A2E926E23958,SHA256=A248230D66F1E009966447D984D7DBBC8B6836FEEDA2F1D17C22C216E2F218EC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572441Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:42.404{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=639F2FFAE496AE2E5640C5EBD41DC96A,SHA256=AB05D2D2149A6A3089F93FDC7072241BE7153FBBCC47B8955302539C3CF8F077,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670950Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:42.345{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3AFD01AEA046889A197D6FF78A00A153,SHA256=7A9FE6942740FBCC44879A9DA0DDADE85E9E8B7BA523A7D78F3C6E5E74AACDA7,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572440Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:39.691{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52773-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000670952Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:43.675{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D1A34A63A3963F8CCE10C40A9E7B0DB5,SHA256=B9A4567B3FFCBDEF40880DADF674BB78F695786CBFB4DD6925E9A11CB94DF9EB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572442Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:43.404{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=412BD090415497CC4833056003D52286,SHA256=B45CBAE75249B1D2CB320600580DCF899C5FC9A67AAAFCC8C5574CD58AA4C9F6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670955Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:44.705{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=088F51AA9D6F351F04FABCAAD795B01D,SHA256=A73E25FDC0433347BC8A782DBB7DD42B06AD6349D8E1611AFEEFDA7B64B651FA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572443Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:44.404{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=531CF1661B0D67AE3D3DA1DBE18EAE70,SHA256=E303C60C083236BA413681CB8AAF727471C08BE97A9BFB377F8A734BAE462179,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000670954Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:43.253{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51163-false10.0.1.12-8000-
23542300x8000000000000000670953Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:44.026{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=D83C7FEDFAB91313C71ED7E3AB80917E,SHA256=6DC07909B380556C9C5A102A5E419B5E6CDAD1EC381577B2EE57BF14854FC643,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670973Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.904{7B03F3B2-7F91-609D-EC55-00000000BA01}71965340C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670972Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.757{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F91-609D-EC55-00000000BA01}7196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670971Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.757{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670970Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.757{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670969Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.757{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670968Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.757{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670967Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.757{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F91-609D-EC55-00000000BA01}7196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670966Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.757{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F91-609D-EC55-00000000BA01}7196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670965Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.758{7B03F3B2-7F91-609D-EC55-00000000BA01}7196C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670964Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.723{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3AF6135B3F8AD325BDC81DEC10A95A0B,SHA256=BB3719051BFFFDE15638A5D496C1049745F68AC7673D7E0C97CC44EF3C989F68,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572444Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:45.435{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1E05B64222A1B222D919636A453483EC,SHA256=D19639EE5835610E3313ECEF682CA9666876AC1315C3658D18A5725182BE2F3E,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670963Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.075{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F91-609D-EB55-00000000BA01}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670962Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.075{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670961Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.075{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670960Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.075{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670959Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.075{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670958Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.075{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7F91-609D-EB55-00000000BA01}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670957Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.075{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F91-609D-EB55-00000000BA01}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670956Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:45.076{7B03F3B2-7F91-609D-EB55-00000000BA01}3888C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670983Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.742{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D3EC5CDA822980885AD06E6826D4F124,SHA256=0317DB5894581114F358BE07B1DA975B5E9BE093C1C3F9B55486B6CDD3C30401,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572447Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:46.473{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=47BECBE00BB914615CFA1E059121B5C0,SHA256=CE6E53E5725C8205BB1B30214C636865FE25B491BB3D34BD379B2AA01BF7CFFA,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670982Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.420{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F92-609D-ED55-00000000BA01}6036C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670981Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670980Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670979Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670978Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670977Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.417{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7F92-609D-ED55-00000000BA01}6036C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670976Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.416{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F92-609D-ED55-00000000BA01}6036C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670975Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.416{7B03F3B2-7F92-609D-ED55-00000000BA01}6036C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670974Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:46.108{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1352E10E326B06502F7B3D6E0F101B6D,SHA256=0F44348170C3E22D755C92092F7B4F8C68C59CAC067DCC7B2D378903754A8FD7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572446Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:46.154{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1CCC15951A2BBE350C30A31489FE0DF6,SHA256=CED4739AFC53E28612D3732D32E640423449EDFE8A3F9378BD0AA5E0E05A5222,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572445Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:46.154{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9F3E175E9FE6319DA506D0C418536B74,SHA256=F3BDA3EB6E1DDD442EBC5F28C820252C4CCFD8AABE0060AE9B76ED2E367EA7D1,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671002Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.856{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F93-609D-EF55-00000000BA01}7016C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671001Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.856{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671000Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.856{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670999Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.856{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670998Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.856{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670997Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.856{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7F93-609D-EF55-00000000BA01}7016C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670996Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.856{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F93-609D-EF55-00000000BA01}7016C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670995Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.858{7B03F3B2-7F93-609D-EF55-00000000BA01}7016C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000670994Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.756{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1B1470F5BAE3CD5AC2E9CAA80BC9B3B0,SHA256=6BD913E0DB637CEC9EFC494AE120F3B21488958E8A8573682B2B5ACA4B7853B9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572449Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:47.505{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AB3FFA17FE63CD268D86001F8B6D8ABD,SHA256=05800FA99D674B402726C3C7DC76C831DAC92EF375BB4753D138D84584EF5416,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000670993Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.425{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=505540B5A9F274103475E7DB42334EBE,SHA256=9208A780A8897453C3F9A7A9F778AF5DA2F14C98FB17829CF98A4455631FC88C,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000670992Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.357{7B03F3B2-7F93-609D-EE55-00000000BA01}19006568C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670991Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.204{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F93-609D-EE55-00000000BA01}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670990Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.204{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670989Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.204{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670988Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.204{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670987Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.204{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000670986Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.204{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7F93-609D-EE55-00000000BA01}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000670985Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.204{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F93-609D-EE55-00000000BA01}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000670984Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.205{7B03F3B2-7F93-609D-EE55-00000000BA01}1900C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
354300x8000000000000000572448Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:44.738{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52774-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000671006Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:48.861{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9C7AACD127C421C4CCCF4527D652210A,SHA256=967A7AC49107F94EAFC89740985978773638ADA72A20B23D10BDA1E49DD73213,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671005Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:48.777{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6F29F2E7948C09A4D277F3BA9C4E01B7,SHA256=883ABF1BD6E2CBD15798A5CF07354E51F6CEDBFAD3ED7FB1ACA0493C03F51622,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572450Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:48.520{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5C899EA226A0DC4A4A4854A3815FD54,SHA256=1028A89245F343D7F0E864C8A420F6590B1CBB9E109E40D3057B5747E275CA31,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671004Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:47.152{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53410-
10341000x8000000000000000671003Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:48.183{7B03F3B2-7F93-609D-EF55-00000000BA01}70164364C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671007Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:49.777{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=93CEB9C874FBED5056E97D7758B646F0,SHA256=0A14C69E2E539DB696820B3950BF1563F39A6412F39A07BF7A9C178881742CF9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572451Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:49.552{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B743BF260039945CDD8E229EA78B1903,SHA256=3B8AAB50526FF41A3AB58F5884441F8D9A6AD00A392A89A64FC0CAB30477D79C,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671017Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.859{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F96-609D-F055-00000000BA01}7452C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671016Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.859{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671015Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.859{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671014Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.859{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671013Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.859{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671012Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.859{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7F96-609D-F055-00000000BA01}7452C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671011Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.859{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F96-609D-F055-00000000BA01}7452C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671010Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.860{7B03F3B2-7F96-609D-F055-00000000BA01}7452C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671009Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:50.793{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=085198479A9327A9B580ADDCACCB09DC,SHA256=75ED373BE487D12AC132972A44DFA3E852ABC4E8FD4B04F892F671D071A1D95E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572452Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:50.567{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9E2688910D1C9CD5BD77D50D7A4865D,SHA256=5E8A50AAF22D0DBCDDD538AAE1D5D148921597865A214A4A6155E49210080522,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671008Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:48.324{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51164-false10.0.1.12-8000-
23542300x8000000000000000671028Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.895{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BCB9887CD3B2CE31D274A36F5E220B0C,SHA256=4E45867817D6CA667AA6003CCEA797545386A574A4B0C5C49F9996F0D4C7069D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671027Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.813{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FEE1A6DF13748F51EFE8D365E7BAE2DA,SHA256=75A458F495F6BA0C035B2AD8F964EBC1E9EDBDDAEF835B1AF01A3DF58EFC6C22,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572455Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:51.567{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=083009BD2BAB42A32DB741A6CC5AA4C7,SHA256=74864CBFC405AEF70C070F68A6FA7D624AADCF7D6DFFD55CAD4C5998EB2978DE,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671026Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.529{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7F97-609D-F155-00000000BA01}7688C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671025Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.529{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671024Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.529{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671023Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.529{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671022Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.529{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671021Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.529{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7F97-609D-F155-00000000BA01}7688C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671020Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.529{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7F97-609D-F155-00000000BA01}7688C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671019Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.530{7B03F3B2-7F97-609D-F155-00000000BA01}7688C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000671018Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:51.044{7B03F3B2-7F96-609D-F055-00000000BA01}74522108C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572454Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:51.176{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F2E78C7F22244776B15711F8FBD93632,SHA256=7B085AA60D66A04B7C9495247FCCC40786C0394B199D095A8C02AB87F93DABFC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572453Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:51.176{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1CCC15951A2BBE350C30A31489FE0DF6,SHA256=CED4739AFC53E28612D3732D32E640423449EDFE8A3F9378BD0AA5E0E05A5222,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671029Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:52.828{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1140E65EE3C407609A80BE9751CBA0F5,SHA256=623AA1AA911719931CA93F4B25B87589CA15038B14C64B38D7C01FA461C6BB7E,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000572467Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006)
13241300x8000000000000000572466Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a7353d9)
13241300x8000000000000000572465Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d74826-0xcd99f4b1)
13241300x8000000000000000572464Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7482f-0x2f5e5cb1)
13241300x8000000000000000572463Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d74837-0x9122c4b1)
13241300x8000000000000000572462Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000006)
13241300x8000000000000000572461Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a7353d9)
13241300x8000000000000000572460Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d74826-0xcd544982)
13241300x8000000000000000572459Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7482f-0x2f18b182)
13241300x8000000000000000572458Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-SetValue2021-05-13 19:35:52.927{E1BD9FC2-D2B9-609A-0B00-00000000BB01}628C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d74837-0x90dd1982)
23542300x8000000000000000572457Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:52.598{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=978D6AC104FBA836F60D0B7C4D07F3B5,SHA256=D6AD15A408646D498E6CCDB5B59C853870F8C8CE0CEBC1AE9DADDC1F4C664A2E,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572456Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:49.792{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52775-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000671031Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:53.859{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=636F675BF9D3CA9DAF9BB712E3E5B842,SHA256=76BED5250A6541B28A0DBA19D25D54F29A38223DA51749CD43ED2D8F46C24F9B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572468Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:53.645{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=23045E47DC1A90BB034C1EAE502B7B91,SHA256=51A8B4235E7DA2FF8C75D71A3BF33FCEB67CFB6B1239C1613FA26CA69607A6EC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671030Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:53.559{7B03F3B2-D0CA-609A-1100-00000000BA01}620NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=988C337339DA18CA17A5B76D9A520097,SHA256=1F039F6B8B4A66192A888960549E9B5798EA87366A17682839AC0DF299D34854,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572472Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:54.677{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=11CEF009EE2382972F0C2CC8BAB6BF65,SHA256=6D10C199A39EFD309B5CE9BE5AB49DB839F7AC50D2F56C824003C8948D7A469B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671034Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:54.874{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FFF3FFDEC8CA1023BB74B6093F9D64BD,SHA256=77C5885D82CBD0E78EFBECD9FEBCF7BE5BA402518B5C9D848D3834B453FA850B,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671033Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:53.336{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51165-false10.0.1.12-8000-
23542300x8000000000000000671032Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:54.159{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F76125B07AB4F59B255440E580A99E0C,SHA256=553D312A4D2147E063BECDFD0705593C797114D7D975764E7B164F201F4430E9,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572471Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:54.567{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1500-00000000BB01}1176C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572470Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:54.567{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1500-00000000BB01}1176C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572469Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:54.567{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1500-00000000BB01}1176C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572473Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:55.723{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=770DA78DEF1D1AB5AE0946A4B4CCB19F,SHA256=B4A7F1E009AB6F9E7508B8E7A04A36576239C604738AF26C7D5D85729058C2B9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671035Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:55.895{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A797B6E470E96DAAD5277BC7AAD712AD,SHA256=AA84F7C171C2F079F29C29449BD163930ABE650F7FD713D0375A76C939FA7792,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671036Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:56.925{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=57BB68F4F3139280370B9AC942F7459A,SHA256=EF773878A3F90079E699511F6F20CBDD88800732B9385A88668F7C086A61890B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572474Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:56.770{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=21EFAD848CB7CED1A7B4C06C8277F081,SHA256=1A6E0A4FF4C743E38D6E5AC39EFF3A22B8687E35D1399549930E60E373BB8A97,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671037Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:57.940{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C1645255CC79DC096F18CD667BF4BD0E,SHA256=58BE3593316E9A1EE717C76912D2BCCEFF3DCC6AAE8685B519496948B929AF71,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572480Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:57.770{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A31B94D628E4340DE985803B28369F77,SHA256=9D2658322276DBC62C85DA6AAFDDECF6B5A04FCF134B2505969BC1FFC6A63481,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572479Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:55.683{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52776-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
354300x8000000000000000572478Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:55.655{E1BD9FC2-D2B7-609A-0100-00000000BB01}4SystemNT AUTHORITY\SYSTEMudpfalsefalse10.0.1.255ip-10-0-1-255.us-west-2.compute.internal138netbios-dgmfalse10.0.1.15win-host-681.attackrange.local138netbios-dgm
354300x8000000000000000572477Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:55.655{E1BD9FC2-D2B7-609A-0100-00000000BB01}4SystemNT AUTHORITY\SYSTEMudptruefalse10.0.1.15win-host-681.attackrange.local138netbios-dgmfalse10.0.1.255ip-10-0-1-255.us-west-2.compute.internal138netbios-dgm
23542300x8000000000000000572476Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:57.052{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=04AC717454D9D96762EADC64E38E25C0,SHA256=9A0E5B15D022A741EE9C6B994DB3C32F810D60FE07A490A7EA3BA124B3614C44,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572475Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:57.052{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F2E78C7F22244776B15711F8FBD93632,SHA256=7B085AA60D66A04B7C9495247FCCC40786C0394B199D095A8C02AB87F93DABFC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671038Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:58.971{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=140D51422B094800D5ECBC313E94FD9B,SHA256=47B9D96ACA17FCC2FC831D4D4C8A402113BCBAEA910C8AF281C84DA17BB4A861,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572481Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:58.817{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0A56D7BF90F3FFA448729F06E21C1502,SHA256=D649E34A58B838112DF35BFDF1C447531E9E8F41104C58F2C13D90E4E714DFD1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671052Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:59.992{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F83E69FBB3B11AC5F29145DEA4F120D,SHA256=CE03EE6A135A51CD6A9AAD740A74EF90DE4CCA4FD4F09735888BF6F9DAE7A1F6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572482Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:35:59.864{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=89732D2C2130E3B915CA75F66018E8A2,SHA256=62FFE52999C4EAE89FBB82175B9EB1DF4CF0602E9664719C1487391BAF2EA0BE,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671051Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:58.417{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51166-false10.0.1.12-8000-
13241300x8000000000000000671050Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008)
13241300x8000000000000000671049Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a7b08c0)
13241300x8000000000000000671048Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d74826-0xd137c301)
13241300x8000000000000000671047Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7482f-0x32fc2b01)
13241300x8000000000000000671046Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d74837-0x94c09301)
13241300x8000000000000000671045Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeConfidenceDWORD (0x00000008)
13241300x8000000000000000671044Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\RunTime\SecureTimeTickCountQWORD (0x00000000-0x0a7b08c0)
13241300x8000000000000000671043Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeLowQWORD (0x01d74826-0xd137c301)
13241300x8000000000000000671042Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeEstimatedQWORD (0x01d7482f-0x32fc2b01)
13241300x8000000000000000671041Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:35:59.371{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exeHKLM\System\CurrentControlSet\Services\W32Time\SecureTimeLimits\SecureTimeHighQWORD (0x01d74837-0x94c09301)
23542300x8000000000000000671040Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:59.171{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=37929E03F80776B62D694275DC150139,SHA256=DFE4C0513EFB5A674AC01500EDDC9FC65784F192409FD2439864D50FF7DD708F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671039Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:35:59.171{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1F66D5A892948DAEFA9DF07C4D310EE7,SHA256=5C2899A83F2A563DF9136A4E799475607B7DC461C97F9D2B4F2B1E510450156E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572483Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:00.880{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=840F55909BB8A4E2369CFDCFE9ACC196,SHA256=05B7644BD7FC374004F0B3E1306B29C6D4F796725C20B91907E135DD3C02074A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572484Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:01.958{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A78C845935B29506DC0C39D24FACAF14,SHA256=F1E199C11C49ED66E8DAB793916E8309D5EFCB27142F9F47766F04D9E52F6652,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671053Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:01.022{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6EDB811828C87834924164DBA7AF3EE6,SHA256=8450ECEA4073499BA004BEDFD232A0A5C7C35EE972ADA457672C8F905993A863,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671055Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:02.368{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=37929E03F80776B62D694275DC150139,SHA256=DFE4C0513EFB5A674AC01500EDDC9FC65784F192409FD2439864D50FF7DD708F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671054Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:02.068{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8A41C1BC3540033C144D320B55376A70,SHA256=C4E6245F862A31F7DB77C1D00D81248101E8674ECCA182230BF0F115A7A496C6,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572487Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:00.777{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52777-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572486Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:02.161{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5D7FC5465D0C48FC009F5FC3615E05E5,SHA256=7F2C98FEA15A93DB5B5B6BAF182AB69C29D6274118973C744C589141099DEBD2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572485Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:02.161{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=04AC717454D9D96762EADC64E38E25C0,SHA256=9A0E5B15D022A741EE9C6B994DB3C32F810D60FE07A490A7EA3BA124B3614C44,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572488Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:03.005{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=132F195E00C8454E56AE1D1C1F555A57,SHA256=A2CD8AA015DE4F30ADD858C1E7E53CB3FB2DFBB31E34C448E4E4DAFFAF5368C8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671056Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:03.086{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C2F6CE8214097481C62F3FE1D7CE0377,SHA256=2F664D3FDF304EE688093A5FC5F3204B072E8828F4A2DDB6552BC4D630D06B51,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572489Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:04.020{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9789AC1328694531C20C7F345451F71D,SHA256=912D2AE97ACE6031E4407D056B7C18C6993656EC23AF5D0E6D0DC8080EDD5CA2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671057Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:04.104{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0356BABDDD184E5F79CF3E9E146CE332,SHA256=5B875D4A4BF94318AEA0E38CA310DA0510DF418058F6595D61A237E9720E4882,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572490Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:05.020{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=560AABADD5E0BB75FC91BB706318D656,SHA256=3C2E584F7A97F75C31AE360AE4C36600C6B7C0C4C03C4115B08F3B6A254588E2,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671060Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:04.296{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51167-false10.0.1.12-8000-
23542300x8000000000000000671059Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:05.118{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E011B305F270E567569606F6B88596DA,SHA256=2949C3B10302761E9496AA178B39E9846F044EE0803A472B97EE036EECE51CF3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671058Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:05.065{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9605C28E6284ABD6E05DC52CF3A53F96,SHA256=230B28C523090FCFC226455076E76F9FAF53A86FA48CA22EE6FAF7D67D045409,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671061Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:06.133{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E7054959B1221695ECE889F692EA842F,SHA256=F45C8A74657A926819B6F88D763B4704F021C5CAB0288B2FC7925BAD5C097075,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572491Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:06.036{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B30526690C19EA03893D6D1B5B870C54,SHA256=28D59FB6B988A6CAB7083D0B2698ADFAB9EF0DED9E30D78E59E24CAA7D446BEF,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671066Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:07.501{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1500-00000000BA01}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671065Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:07.501{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1500-00000000BA01}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671064Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:07.501{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1500-00000000BA01}1260C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671063Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:07.364{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2A28B19716D2DE0CA24FDD7675B0FCAD,SHA256=91FF410F0991C92DE2A5A8DEB240892731C61F1B95EA8028E1D86F80D497A187,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671062Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:07.148{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=820BF19EB2E5A9D5AB326D2C3905FA0A,SHA256=CFCD6B936CE8D51CEFB020A283725D237FD60937AD908F4A1DD9E2F494BA5F20,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572495Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:05.808{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52778-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572494Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:07.193{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A28F2C80C2063B1E9CC80FC9EF764F40,SHA256=A7378DF3723CCDA8169EC0A245CE045D25DBD479D4EC7C8BD75B4CDFF5EEF7C1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572493Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:07.193{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5D7FC5465D0C48FC009F5FC3615E05E5,SHA256=7F2C98FEA15A93DB5B5B6BAF182AB69C29D6274118973C744C589141099DEBD2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572492Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:07.037{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D4457167313D7766213680258B75F94,SHA256=9A5F2E359410272AE4310CB9BD6DF7C53817C0CC65BBFDF35BE4BC67923B51FE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572496Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:08.115{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A28576884544C482F6D6E5E154D3AD50,SHA256=6595A7225819DFAAF8E059E288914FCE9872B56B369481A13E1E8C1FFDC180D9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671067Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:08.163{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D2004BB1CB425BA58A91A6AF1E424C22,SHA256=6D0245558DB9730C9E5AB19F9AFBF6C1FA8B8FFFF2491ECCADA8F980FB774D9F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572498Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:09.490{E1BD9FC2-D2BA-609A-1000-00000000BB01}972NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.datMD5=C795A027A46728615850ED9FCC6AEB77,SHA256=80C33EFC48285D0603388DFB2F9268A595829B5961F8ED2893ACEF831229D3AD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572497Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:09.131{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=41084818F46AE3ECE534FF257843F89B,SHA256=3A660BE460A2CD59765CD6522E44C46E3ABFD0421D9B42ED3D58088A23E0E173,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671068Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:09.215{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1259E1FF106EA70E09F5C82B17F747D9,SHA256=02699030A853A53EED0F5A0EAE11B95603E89D9563FCE15126FB367F03EDC1FC,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671071Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:09.324{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51168-false10.0.1.12-8000-
23542300x8000000000000000671070Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:10.231{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=144BEF064992BF5ED005A41551C6603F,SHA256=8F43F12B7D33FA16264789A67D7D807C5814CDCF40FC2D3811027EE7A04A0283,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572499Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:10.146{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D4DB8444A9411518206412B5B384B1F8,SHA256=C185A66AE675BB4ED32BFC0AAE302471F88E173815A5C19C0C6436E872F5BF75,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671069Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:10.082{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=78E8762D22386C1EAB4E36301B4C841E,SHA256=D14EA35A05E7159353946C9A10A456C84B3219F984D1735BA37B07D6B7E140DC,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671072Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:11.262{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=08C2005D00B2C1564C001DAB05E6934C,SHA256=DE60950941D2ADEF48365E25F4D05043196D7392938695D507168BAF8C7F2277,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572500Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:11.146{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=5B36122360051C5259BD3125CE98DDDD,SHA256=D357C5BAD3CAE9556717608BBCDEBB6C10760066B1B033BD8AB9EC9B5E5D20BF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671073Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:12.265{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=42D8D02229E3F6BD68B1F3D9E5FD9DFE,SHA256=DDA6EE3E3A44E4BF991EF56552493654083D51545E26DDCDA7DA735B73C42BA7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572503Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:12.224{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B4279ABF01EE9E4DC6BDE7AE9B06B971,SHA256=F78E3350BC5B60B51E375873F75A1E97E77A4AFF9319902F67006A5ECAFB1FDB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572502Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:12.224{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A28F2C80C2063B1E9CC80FC9EF764F40,SHA256=A7378DF3723CCDA8169EC0A245CE045D25DBD479D4EC7C8BD75B4CDFF5EEF7C1,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572501Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:12.162{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=00F396909FE7E2617CB6F6430C6C196B,SHA256=0295CF87EE39E058F346CC57CFB251A8EA2BE7B71F3D6148A2B2DCAC37387B4E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572505Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:13.177{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=8DC5D2A3A24247B5B9574C9923C14E39,SHA256=3F5E76A63E72FE604394679573BC0F0C2BDC61B2CAAD96F72067445E5E29EC7B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671074Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:13.282{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6AFD7D8D1F0D5DEBC54E83C0025E733C,SHA256=2EC51B09BB29C41BC265CF113939A12CF2841DB37250BB681E89BCF2D6E29ACC,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572504Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:10.824{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52779-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000671075Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:14.300{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF9C7A510F93020D5ECE9C0E087DBAF4,SHA256=721FD410251C6CE9182949491632611DCE90E21C74713BF6A249E86CB6E56D1D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572506Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:14.256{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DCE58B452BD1C621CD74219F36D83B29,SHA256=D46DF10F43EADA9A6305E54A2ED8409F2AC0A69151F55811193ED27FD15DF6DE,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671079Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:14.362{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51169-false10.0.1.12-8000-
23542300x8000000000000000671078Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:15.346{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FB63A6ABFDBA5AAC9A98A8EB35316535,SHA256=8E885CE79E06DCD12A2DFBD119D4793A5086758286F525B4735B408338831718,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572507Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:15.271{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C591B56C01FA94C25D99C46D18AF8388,SHA256=1853B000F1F20B21E0FAD862BD1E78B99E084D1B8987AA84284D47C0AC177518,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671077Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:15.146{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E8A42C28B382D26CF10ADFECBAA4CBE7,SHA256=4698CE4A1A97CBB116223193F5F1409536B9E86B9F9E952F5654E03FC6C78252,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671076Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:15.146{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A69C3A1277A15CB6D4E2AFDB6D4AFE6E,SHA256=E529F69060F9EAF2E70C9DE3220FA79387D1FD6AD740C79921D8B6B0D8739FC0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671080Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:16.360{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BB099F763D434071A46140D581BE2E66,SHA256=D2D48B360C14EA1BE57A83CC781B75EF30616F8767A526DE6ADBBD8C9D1F6873,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572508Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:16.271{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DF2257F069E3768D47F6E992B5C83C44,SHA256=7D56BAEF4A97B3D1624935682434D6F92A3551B8CDF283013D0ECA0F0463E131,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671081Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:17.397{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D1B12EC4C4EBE04C7F9626198AB3DB8,SHA256=9CD48249AC6F78BBBEB040A60C1CDF4D99EF6F1A85F24002C2F6EFF0094B5812,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572509Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:17.287{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FACAE7632AA9100ABCA86739CB412BD7,SHA256=FE751A15A9A0B3D2E94109E9A74DB1546180D201F196F8D35E839B7B061867C8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671082Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:18.411{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9FF47D468BA8ADABC47457713E2CCEEA,SHA256=57FE2DCEFCB4E6C73EB688AE044A52DA086C7754D3A1468473C2297A90DEE1FF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572512Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:18.287{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2A902DECCCA29BF369D07D685D6C0E72,SHA256=8880EBF68B116E3662D37DD3349A14DC78C9EA9BE79A2C02B9850C17913D55FE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572511Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:18.131{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8F84BEEB5FF7CCF400E63CC4EE641EC5,SHA256=D6E09A8D1D4A65A02C1A496F5A9AC47E7BDAB001B67675B2088DA3462D4EBEC6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572510Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:18.131{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=B4279ABF01EE9E4DC6BDE7AE9B06B971,SHA256=F78E3350BC5B60B51E375873F75A1E97E77A4AFF9319902F67006A5ECAFB1FDB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671083Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:19.426{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=584BCABAD525244AE219CC1B246A2881,SHA256=FDFA09E025BB3C5F817F4918C3715272A075378359D9155F1E8B94CE715D2987,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572514Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:19.302{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EAD1A90E70E4D93ED8DEB9FC1BE03FDF,SHA256=344FB77D7482AEDA6ED4FDEF700015315D55A3D0413763F442CCAFB40FBB9B91,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572513Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:16.684{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52780-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572515Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:20.302{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CBEFA0F6568E2D76F19A681D295922A5,SHA256=FBF5CF2BA760621D85E9FF1C15D89EE36E8C0EC8164F08DFDDB62B299CEEC790,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671084Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:20.426{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E830A1587DAFB9899FC431B1E2D33C0F,SHA256=326722F11F63BE0887DAE8C6092AC144728A1ED4AC3A6AA8447570DA6615EE61,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671087Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:21.440{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A851CB1CD35C049043551DBCE707A30C,SHA256=49544537A8DE5099E04B74C2125817708C55E5829CA8259F1DBF32F57110216E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572516Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:21.318{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D40911D0F4D381565FACD003CE5D66F9,SHA256=8371B4132F5358F073ACB15E231645BF28CCA3C593F3D0BD799BF36CA185833A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671086Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:21.076{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E0A31A190E9809F6AA8EC9203376DE33,SHA256=CDCD15D9107BE875B43ACD558F7E818606F3BDCFF57C72E041470CB974499B09,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671085Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:21.075{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E8A42C28B382D26CF10ADFECBAA4CBE7,SHA256=4698CE4A1A97CBB116223193F5F1409536B9E86B9F9E952F5654E03FC6C78252,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671090Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:22.540{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B8DD8D31A7E79703638A6E82D378AEF0,SHA256=F3B5DCD82F0B6BBE8E1A1F674599B571B4D36E6EA7D0E79AE37DD30D4BE01A4C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572517Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:22.318{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2B4C4E138925119EDB02F138B72EBFAF,SHA256=315CB1610355A44068F465E86D823AA18157D9B79363648EEF0FFA8517BF92F5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671089Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:22.356{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=E0A31A190E9809F6AA8EC9203376DE33,SHA256=CDCD15D9107BE875B43ACD558F7E818606F3BDCFF57C72E041470CB974499B09,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671088Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:20.303{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51170-false10.0.1.12-8000-
23542300x8000000000000000671091Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:23.554{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6D8169ACCD85B54229FA8E8909F45758,SHA256=83A5470EEECFCA7007006DD06EA6FA77C1B6F99364F4268F3760693857A1E618,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572518Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:23.334{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=679C782B2E14229E0E51F2379CD5AA52,SHA256=E76A88C6866B2063D0935AFFBACD3D41A9FB2FA297AFB23F49FBA98AA1DF56A9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572521Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:24.349{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=06EDB1E4D6A7FA5770A42E3CC6AF79B8,SHA256=25481C69869D85AEEFA230DA5FDE461B3D826886D2E0D262BA48B37341E453B6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671092Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:24.574{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C9F1797CCF6944A570DAAB23F8BD08D0,SHA256=7C15F8AF6D819C142D3B114AEAE0AE04DA8F260E54A76F75598109CFB4CF0F51,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572520Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:24.302{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=01FBA9DCF60FB2AFA8EBBF6D57B954E3,SHA256=F8C6040BD640F269837FF74158BEEDF2F2C5B91FDA2D4C9819993963C5F9FAE3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572519Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:24.302{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=8F84BEEB5FF7CCF400E63CC4EE641EC5,SHA256=D6E09A8D1D4A65A02C1A496F5A9AC47E7BDAB001B67675B2088DA3462D4EBEC6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671095Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:25.589{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=362F5BF7B4F7415BE1FD2C4A79FEC0AF,SHA256=4273DB2D62D4AD8EECF305D050EF40D66488A9E7563DACE708C1EE2063CDB905,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572537Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.896{E1BD9FC2-7FB9-609D-F650-00000000BB01}3432700C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572536Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7FB9-609D-F650-00000000BB01}3432C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572535Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572534Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572533Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572532Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572531Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572530Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572529Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572528Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572527Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572526Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D2B9-609A-0500-00000000BB01}412988C:\Windows\system32\csrss.exe{E1BD9FC2-7FB9-609D-F650-00000000BB01}3432C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572525Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.771{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7FB9-609D-F650-00000000BB01}3432C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572524Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.772{E1BD9FC2-7FB9-609D-F650-00000000BB01}3432C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572523Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:25.365{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E6AE81FCB1DE05D08C3432AEC9526CB6,SHA256=490233F680CE93C9ACB40D00902928073FBB65DC2E440351CB6CFEED59EAD8C5,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572522Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:22.699{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52781-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000671094Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:25.236{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=1A3F27FF1113F49FA774B583E747B0B1,SHA256=9C5F18CBA76A934548532A8B67376EBF45D822035226F9907DC5CB92509A14D6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671093Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:25.236{7B03F3B2-5120-609D-3250-00000000BA01}1532NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671098Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:26.620{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9E594D62905BA4EE6209988A27B39487,SHA256=49EE8F3BCD1D2B26AE741F4B4BAFD7E84E1306C5199944D749490A6B9500E47C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572552Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.814{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=01FBA9DCF60FB2AFA8EBBF6D57B954E3,SHA256=F8C6040BD640F269837FF74158BEEDF2F2C5B91FDA2D4C9819993963C5F9FAE3,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572551Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7FBA-609D-F750-00000000BB01}2868C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572550Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572549Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572548Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572547Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572546Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572545Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572544Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572543Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572542Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572541Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7FBA-609D-F750-00000000BB01}2868C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572540Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.393{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7FBA-609D-F750-00000000BB01}2868C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572539Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.394{E1BD9FC2-7FBA-609D-F750-00000000BB01}2868C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572538Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:26.377{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7AB2890C0D31050F48B9E372CD41F239,SHA256=E9AFE015C8AD2483FEE5DEECC9DC2BCB342F5E536D257008E6D473F776084525,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671097Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:24.468{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51171-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
354300x8000000000000000671096Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:24.468{7B03F3B2-D0D7-609A-2700-00000000BA01}2888C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeNT AUTHORITY\SYSTEMtcptruetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51171-true0:0:0:0:0:0:0:1win-dc-18.attackrange.local389ldap
13241300x8000000000000000671103Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:36:27.837{7B03F3B2-D0CA-609A-1200-00000000BA01}388C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7482f-0x445dcb86)
23542300x8000000000000000671102Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:27.653{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=93C45F8D56D6095C3E6D3CF8BBB81ACF,SHA256=329EFB053E001AF917AA0FE09EAA7D46BFFEACA711A1935DD97C4C0AB6CD63C3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572566Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.642{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B0BEBB4CD7D34E8BA2A9C78E9B3BE20E,SHA256=C5E5805CFB625A34C565120247ADEBAA8C902D3E24320F93106E5043BCDCA2E5,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671101Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:27.338{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=EF5F6A4B72A4027C6D1A64097A165B41,SHA256=DD647B5D615CF7EF3473AD2A348E3EB019BC7751C778D7E9807B0D76C7D170C6,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671100Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:25.466{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51173-false10.0.1.12-8089-
354300x8000000000000000671099Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:25.335{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51172-false10.0.1.12-8000-
10341000x8000000000000000572565Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7FBB-609D-F850-00000000BB01}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572564Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572563Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572562Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572561Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572560Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572559Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572558Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572557Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572556Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572555Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D2B9-609A-0500-00000000BB01}412988C:\Windows\system32\csrss.exe{E1BD9FC2-7FBB-609D-F850-00000000BB01}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572554Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.018{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7FBB-609D-F850-00000000BB01}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572553Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.019{E1BD9FC2-7FBB-609D-F850-00000000BB01}2864C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671104Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:28.672{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=057532005C3E4BFF91C325C85CB14663,SHA256=4B72CFD84BD8D7B32675437FE3CDA17EE0B0C1B71099823F7CCB66B5A9D359EF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572568Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:28.658{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=7D7A9F6845F25E9A042F2715BFA5AC4B,SHA256=85827F3A835E44CA7D59B1704057EA6302B859AECCFCF9C5B2464BB01FF855B4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572567Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:28.033{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=24B8FE412F9759A8E1A1AB24E9DD83FA,SHA256=6F5124CF035F4FAA6A543186E17091C08FC081B5F53687BCCF0EBAFEEE533B68,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572571Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:29.814{E1BD9FC2-D335-609A-9D00-00000000BB01}3264NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeC:\Program Files\SplunkUniversalForwarder\var\run\serverclass.xmlMD5=A2082595039927B052D0A852CA90372E,SHA256=080CB1C21D6F7727A34C0B5DE8F2E2C25D197CB9222B4B86A86EAB5C70676C00,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572570Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:29.705{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=81845F17F4DC879398DDB995FB0D45A9,SHA256=CDFFB95A323362C7002B1E8729F7D239E5AA6859C81A0EB87BC2E4E999A780C4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671105Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:29.689{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0DFE711B62A647659291D924570C6042,SHA256=455F28491D29937090469A5C6DC30B5D42B1BC0A10882C85D4E5DFBCC09AC4D8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572569Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:29.143{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=EF02FADB29559DA9AC76E54794720D74,SHA256=A10DA0877E0D371610637686C92CCAA876CEEFEC8F34C99172E57A10657903A0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572574Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:30.830{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=31F228D8C27730F53BBB099DB24C922F,SHA256=294095A54770A40277FC0CB6A256C8D0FA6E3434FBC5B94A29293B755FE4E889,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572573Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:30.721{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=297D8AE1B5510F388FDA7A31CD4D0FF6,SHA256=5D702A25298F15B86AC0ED0E4C5135CCACB85FCF86BB14859150757482F3E54D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671106Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:30.720{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=324B4BD1C771C405CA9BEF055F4DBC08,SHA256=E8A51EDC0BDCE54D4E2A43AEE0193D1A7F1FBB1FA2598A95EB60963F430F16BF,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572572Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:27.742{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52782-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572576Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:31.754{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=960DB46C490272ABEBF8D2D76DF7C472,SHA256=FC69F04807162D50D47812A22081ED507C471E04C95AF36B0BAB47C3F791F798,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671107Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:31.736{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=207317FEF964D04305E8A7DD0129DB3B,SHA256=C0FA1EEDA8C18A96964DAB107E4ACB2DF4DD7C577FF5C42857D5DF90D3A19352,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572575Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:29.430{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52783-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8089-
23542300x8000000000000000572577Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:32.846{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B2EC012726A3325B92DCFB0D3A5485EB,SHA256=59B76DB109B34A8B28A49047F267528B16D903E5010C6E67AE56F1517C22285C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671109Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:32.750{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E5CF415A15E8BE384A6B3F0D97F546D3,SHA256=B200C24E7C85C4F58CB52FCE933DEB941C2C7939A5C1E2AC4C7357E196B06C1B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671108Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:32.151{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=F7C99C52591A35DE4D92279C318AA6A0,SHA256=048535B8ED54E22B6D8E8BCCE7EFA3AD88BA5ABDF0C7E06A378DE64AEEDE434D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671111Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:33.771{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=09E782E31A22E6867729033E5C6AD0FC,SHA256=362D75285C29B951E15016D3D9D58D833EAFFD1B05F0290C8293D06503D9E484,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572578Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:33.894{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98D09B463B213E221AF1B159BBA7F0D9,SHA256=52ECB9EEF8B56763B10F92A23871F1A27AA58861CFF98CA8DCEE2C75282491F4,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671110Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:31.366{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51174-false10.0.1.12-8000-
23542300x8000000000000000572581Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:34.925{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3FE7DDA93FCA04C20525CA1B18ECC734,SHA256=F034994743C251BE06CEA97BFA92795E4980BAD6A3AF7353AEACE649A67A69C2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671112Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:34.785{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCB6904390AF10F0439E2DA3D807C2B7,SHA256=A95826985C01958F98572C3E340FBCDF2CBC12980FDD9B08E477AFA6B2651C2D,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572580Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:32.837{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52784-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572579Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:34.253{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=33D62AE708F2A6214E0F686D18FFDDB9,SHA256=176F5780D18BDF28E0CFA19239BDBB5E078B01569DB2C3F210DE1586C1E5C1BB,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671114Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.816{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D38F9CAB3DD48A60C8E821A2C03F4BF2,SHA256=70EEECC142FA3760F67FA4E37EEA0031105D2B7D6EC6114E8BAD4FA1AF7E354A,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572608Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7FC3-609D-FA50-00000000BB01}2552C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572607Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572606Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572605Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572604Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572603Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572602Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572601Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572600Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572599Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572598Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D2B9-609A-0500-00000000BB01}412528C:\Windows\system32\csrss.exe{E1BD9FC2-7FC3-609D-FA50-00000000BB01}2552C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572597Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.878{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7FC3-609D-FA50-00000000BB01}2552C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572596Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.879{E1BD9FC2-7FC3-609D-FA50-00000000BB01}2552C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000572595Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.331{E1BD9FC2-7FC3-609D-F950-00000000BB01}2163616C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572594Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7FC3-609D-F950-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572593Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572592Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572591Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572590Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572589Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572588Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572587Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572586Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572585Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572584Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D2B9-609A-0500-00000000BB01}412528C:\Windows\system32\csrss.exe{E1BD9FC2-7FC3-609D-F950-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572583Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.206{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7FC3-609D-F950-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572582Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:35.207{E1BD9FC2-7FC3-609D-F950-00000000BB01}216C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
10341000x8000000000000000671113Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.517{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-D0C5-609A-0100-00000000BA01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+2b3f4|C:\Windows\system32\lsasrv.dll+30949|C:\Windows\system32\lsasrv.dll+2e2a7|C:\Windows\system32\lsasrv.dll+2d231|C:\Windows\system32\lsasrv.dll+15e0d|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e
23542300x8000000000000000671116Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:36.847{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0EFB29CEAA98A808466D4BAC8C14FD36,SHA256=5E7E02AFFB170F3117C3A2838443800CF04DD9D709D765B40B821D60AC7F17AE,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572625Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.612{E1BD9FC2-7FC4-609D-FB50-00000000BB01}29443280C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572624Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7FC4-609D-FB50-00000000BB01}2944C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572623Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572622Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572621Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572620Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572619Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572618Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572617Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572616Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572615Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572614Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D2B9-609A-0500-00000000BB01}412428C:\Windows\system32\csrss.exe{E1BD9FC2-7FC4-609D-FB50-00000000BB01}2944C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572613Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.487{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7FC4-609D-FB50-00000000BB01}2944C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572612Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.488{E1BD9FC2-7FC4-609D-FB50-00000000BB01}2944C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572611Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.222{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=23B8DEE7C48B58A4CF362115F3B30014,SHA256=EC2CAE206EDD3BB692228611E2171199F795A30F654C899DECF0383E0BBF26E9,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572610Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.159{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FBB869184368D9F0A99A62064015E050,SHA256=624143E7A70CC264364680F31062ABD3836A9BD1567543354DB0924038812782,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572609Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:36.050{E1BD9FC2-7FC3-609D-FA50-00000000BB01}25522528C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671115Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:36.465{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FA497CE1847D111E53E31ACD8B9E46D9,SHA256=EFC8A7578FFB498F93657D9EA54D3FE028CCDC86536BF173CAB59B2C946BC32B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671139Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.883{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A034FB689C77FB3FEECC854332BB9B35,SHA256=4CA2AEDABB647AA51C8ED65CAB350DD4F5FE054C5587715C8E0EC355DFA69974,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572640Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.487{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=650FCC08E44698EE9DB07B6DD0D79D95,SHA256=ECFE9D8433312DDC4593585DE9612BA53E12E0A1F96C3C81215BAEE54CBF3D8B,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000572639Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D336-609A-A100-00000000BB01}39243288C:\Windows\system32\conhost.exe{E1BD9FC2-7FC5-609D-FC50-00000000BB01}788C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572638Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572637Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572636Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572635Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572634Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572633Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572632Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572631Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572630Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0C00-00000000BB01}7283728C:\Windows\system32\svchost.exe{E1BD9FC2-D2BA-609A-1E00-00000000BB01}1544C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000572629Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D2B9-609A-0500-00000000BB01}412988C:\Windows\system32\csrss.exe{E1BD9FC2-7FC5-609D-FC50-00000000BB01}788C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000572628Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.159{E1BD9FC2-D335-609A-9D00-00000000BB01}32643944C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{E1BD9FC2-7FC5-609D-FC50-00000000BB01}788C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000572627Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.160{E1BD9FC2-7FC5-609D-FC50-00000000BB01}788C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{E1BD9FC2-D2B9-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{E1BD9FC2-D335-609A-9D00-00000000BB01}3264C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572626Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.050{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FE1FD96B19CDF5B3F63505D3A8C27326,SHA256=B31A67A8E3F4A9B63C9AB7A623281C3ECAE6C6EE8DD243E71128A6CE35EF1048,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671138Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.467{7B03F3B2-7FC5-609D-F355-00000000BA01}6927248C:\Windows\system32\conhost.exe{7B03F3B2-7FC5-609D-F255-00000000BA01}7084C:\Windows\System32\XblGameSaveTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671137Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.446{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FC5-609D-F355-00000000BA01}692C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671136Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.430{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671135Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.430{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671134Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.430{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671133Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.430{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC5-609D-F255-00000000BA01}7084C:\Windows\System32\XblGameSaveTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671132Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.430{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671131Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.430{7B03F3B2-D0CA-609A-1600-00000000BA01}13044540C:\Windows\system32\svchost.exe{7B03F3B2-7FC5-609D-F255-00000000BA01}7084C:\Windows\System32\XblGameSaveTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a7a1|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+d395|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+e9dd|c:\windows\system32\UBPM.dll+e1ba|c:\windows\system32\UBPM.dll+de12|c:\windows\system32\EventAggregation.dll+3e22|c:\windows\system32\EventAggregation.dll+36c9|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+65b55|C:\Windows\SYSTEM32\ntdll.dll+6585d|C:\Windows\SYSTEM32\ntdll.dll+656c0|C:\Windows\SYSTEM32\ntdll.dll+3a7f0|C:\Windows\SYSTEM32\ntdll.dll+1ed03|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671130Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.415{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671129Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.415{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671128Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:37.415{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
354300x8000000000000000671127Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:36.408{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51180-false10.0.1.12-8000-
354300x8000000000000000671126Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.770{7B03F3B2-D0C5-609A-0100-00000000BA01}4SystemNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51179-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local445microsoft-ds
354300x8000000000000000671125Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.770{7B03F3B2-D0C5-609A-0100-00000000BA01}4SystemNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51179-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local445microsoft-ds
354300x8000000000000000671124Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.767{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51178-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local49666-
354300x8000000000000000671123Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.767{7B03F3B2-D0CA-609A-1400-00000000BA01}1076C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51178-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local49666-
354300x8000000000000000671122Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.766{7B03F3B2-D0CA-609A-0D00-00000000BA01}912C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51177-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local135epmap
354300x8000000000000000671121Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.766{7B03F3B2-D0CA-609A-1400-00000000BA01}1076C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51177-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local135epmap
354300x8000000000000000671120Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.658{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsefalse10.0.1.14win-dc-18.attackrange.local51176-false10.0.1.14win-dc-18.attackrange.local389ldap
354300x8000000000000000671119Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.658{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51176-false10.0.1.14win-dc-18.attackrange.local389ldap
354300x8000000000000000671118Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.650{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\System32\lsass.exeNT AUTHORITY\SYSTEMtcpfalsetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51175-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local389ldap
354300x8000000000000000671117Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:35.650{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruetruefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local51175-truefe80:0:0:0:b173:2d3f:cb87:36edwin-dc-18.attackrange.local389ldap
23542300x8000000000000000671249Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.978{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E74FC1AC5A8A9C63DF979B2651A33886,SHA256=DD1A9AD31D8413740BD68CD655205332795859186C1F7112E5408B45F22EFA2F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671248Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.955{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=18110F7C147E1ED537153D2943468272,SHA256=F5E6D632AEB77E6A4CD068725A9B0D5ADA0A00E74E9A24FE05B4A47E95D307A4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671247Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.954{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=558249E6BB0A1E35AACE7CE76AD9575F,SHA256=987FC55A468DB35B471542AE4A33B7575C35114E8AABD6CFB74C6B4678BEA174,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671246Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.894{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=14D8A66E4ED06314E898913FEFCED77E,SHA256=5FE24B65F27E89135E4BA2B2D4A31549F9EB5E7EAFF4CE67E9F4515CF6476A75,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671245Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.872{7B03F3B2-D0CA-609A-1600-00000000BA01}1304NT AUTHORITY\SYSTEMC:\Windows\system32\svchost.exeC:\Windows\WindowsUpdate.logMD5=038356387332650843BCB352BB89A101,SHA256=492C9B102256321FB5598FF87ED5BCCAB8159F36DD8416CE4011FFBF5E96048D,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671244Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.868{7B03F3B2-D0CA-609A-1300-00000000BA01}92NT AUTHORITY\SYSTEMC:\Windows\System32\svchost.exeC:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSStmp.logMD5=FCD6BCB56C1689FCEF28B57C22475BAD,SHA256=DE2F256064A0AF797747C2B97505DC0B9F3DF0DE4F489EAC731C23AE9CA9CC31,IMPHASH=00000000000000000000000000000000falsefalse - shredded file with pattern 0x00
23542300x8000000000000000572641Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:38.066{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AAB1756558121B10D5F605B57E22E204,SHA256=43AEEB2FF9CFAB7FCF994CDBD1150E8F7CB37F43597C49FAC84B1F35568D8E32,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671243Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.831{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=14D8A66E4ED06314E898913FEFCED77E,SHA256=5FE24B65F27E89135E4BA2B2D4A31549F9EB5E7EAFF4CE67E9F4515CF6476A75,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671242Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.815{7B03F3B2-7FC6-609D-FF55-00000000BA01}81043272C:\Windows\System32\svchost.exe{7B03F3B2-D0CA-609A-1300-00000000BA01}92C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\appxdeploymentserver.dll+6468b|c:\windows\system32\appxdeploymentserver.dll+7b27|c:\windows\system32\appxdeploymentserver.dll+2db00|c:\windows\system32\appxdeploymentserver.dll+2d19d|c:\windows\system32\appxdeploymentserver.dll+114e56|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671241Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.802{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671240Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.802{7B03F3B2-7FC6-609D-F855-00000000BA01}80285724C:\Windows\system32\compattelrunner.exe{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\compattelrunner.exe+53b1|C:\Windows\system32\compattelrunner.exe+3ef9|C:\Windows\system32\compattelrunner.exe+2b7f|C:\Windows\system32\compattelrunner.exe+1522d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671239Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.772{7B03F3B2-7FC6-609D-FF55-00000000BA01}81043272C:\Windows\System32\svchost.exe{7B03F3B2-D0CA-609A-1300-00000000BA01}92C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\appxdeploymentserver.dll+6468b|c:\windows\system32\appxdeploymentserver.dll+2d35e|c:\windows\system32\appxdeploymentserver.dll+2d19d|c:\windows\system32\appxdeploymentserver.dll+114e56|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671238Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.771{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671237Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.770{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671236Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.770{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671235Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.770{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671234Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.717{7B03F3B2-D0CA-609A-1300-00000000BA01}92NT AUTHORITY\SYSTEMC:\Windows\System32\svchost.exeC:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSStmp.logMD5=FCD6BCB56C1689FCEF28B57C22475BAD,SHA256=DE2F256064A0AF797747C2B97505DC0B9F3DF0DE4F489EAC731C23AE9CA9CC31,IMPHASH=00000000000000000000000000000000falsefalse - shredded file with pattern 0x00
10341000x8000000000000000671233Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.701{7B03F3B2-D0C8-609A-0B00-00000000BA01}6325688C:\Windows\system32\lsass.exe{7B03F3B2-D0CA-609A-1300-00000000BA01}92C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671232Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.701{7B03F3B2-D0C8-609A-0B00-00000000BA01}6325688C:\Windows\system32\lsass.exe{7B03F3B2-D0CA-609A-1300-00000000BA01}92C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671231Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.685{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\ApplicationMD5=F59B207B2604A8788D50F1191837C76E,SHA256=F6D049D65F72F79CBA2AF77E3806F485BB13A7B4DAD40D16B8EDE23B93631312,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671230Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.685{7B03F3B2-7FC6-609D-0156-00000000BA01}22404732C:\Windows\system32\conhost.exe{7B03F3B2-7FC6-609D-FE55-00000000BA01}844C:\Windows\system32\disksnapshot.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671229Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.685{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671228Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.670{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671227Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.670{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671226Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.670{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671225Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.670{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A89855F03305833E87AB3A89564D1674,SHA256=8D9EDB6C66EB84F87B4206EEC060BE84AA137B02338B6C7F70767013E825B9B4,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671224Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.617{7B03F3B2-D0CA-609A-1600-00000000BA01}13046208C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671223Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.617{7B03F3B2-D0CA-609A-1600-00000000BA01}13041344C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671222Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.617{7B03F3B2-D0C8-609A-0A00-00000000BA01}6248140C:\Windows\system32\services.exe{7B03F3B2-7FC6-609D-FF55-00000000BA01}8104C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\services.exe+1713f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671221Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.617{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-FF55-00000000BA01}8104C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671220Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.617{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-0156-00000000BA01}2240C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671219Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-FF55-00000000BA01}8104C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671218Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0C8-609A-0A00-00000000BA01}6247176C:\Windows\system32\services.exe{7B03F3B2-7FC6-609D-FF55-00000000BA01}8104C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+307d|C:\Windows\system32\services.exe+6334|C:\Windows\system32\services.exe+dc24|C:\Windows\system32\services.exe+d248|C:\Windows\system32\services.exe+4d0c|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671217Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671216Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671215Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671214Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671213Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671212Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671211Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671210Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671209Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.586{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-FE55-00000000BA01}844C:\Windows\system32\disksnapshot.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671208Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.570{7B03F3B2-D0CA-609A-1600-00000000BA01}13044380C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-FE55-00000000BA01}844C:\Windows\system32\disksnapshot.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a7a1|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+d395|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+2039|c:\windows\system32\UBPM.dll+2be0|c:\windows\system32\UBPM.dll+16d25|c:\windows\system32\UBPM.dll+4552|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671207Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.570{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671206Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.570{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671205Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.570{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671204Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.570{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671203Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.567{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-D0C8-609A-0A00-00000000BA01}624C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+10d9e|C:\Windows\system32\lsasrv.dll+1d1e8|C:\Windows\system32\lsasrv.dll+1c411|C:\Windows\system32\lsasrv.dll+1ac30|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671202Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.567{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671201Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.566{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671200Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.566{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-D0C8-609A-0A00-00000000BA01}624C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671199Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-319D-609C-402D-00000000BA01}22881868C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671198Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671197Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671196Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671195Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-FD55-00000000BA01}4692C:\Windows\system32\CompatTelRunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671194Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-7FC6-609D-F855-00000000BA01}80285724C:\Windows\system32\compattelrunner.exe{7B03F3B2-7FC6-609D-FD55-00000000BA01}4692C:\Windows\system32\CompatTelRunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\compattelrunner.exe+53b1|C:\Windows\system32\compattelrunner.exe+3ef9|C:\Windows\system32\compattelrunner.exe+2b7f|C:\Windows\system32\compattelrunner.exe+1522d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671193Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671192Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.548{7B03F3B2-D0CA-609A-1600-00000000BA01}13044380C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\UBPM.dll+acf0|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+108c6|c:\windows\system32\UBPM.dll+d439|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+2039|c:\windows\system32\UBPM.dll+2be0|c:\windows\system32\UBPM.dll+16d25|c:\windows\system32\UBPM.dll+4552|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671191Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.532{7B03F3B2-7FC6-609D-FB55-00000000BA01}53966308C:\Windows\system32\conhost.exe{7B03F3B2-7FC6-609D-F955-00000000BA01}6724C:\Windows\system32\dstokenclean.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671190Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.517{7B03F3B2-7FC6-609D-FA55-00000000BA01}7726788C:\Windows\system32\conhost.exe{7B03F3B2-7FC6-609D-F855-00000000BA01}8028C:\Windows\system32\compattelrunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671189Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.517{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671188Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.517{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671187Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.517{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671186Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.517{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671185Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.517{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-FB55-00000000BA01}5396C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671184Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.517{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671183Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.501{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671182Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.501{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-F955-00000000BA01}6724C:\Windows\system32\dstokenclean.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671181Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.501{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-FA55-00000000BA01}772C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671180Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.501{7B03F3B2-D0CA-609A-1600-00000000BA01}13044380C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-F955-00000000BA01}6724C:\Windows\system32\dstokenclean.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a7a1|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+d395|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+2039|c:\windows\system32\UBPM.dll+2be0|c:\windows\system32\UBPM.dll+16d25|c:\windows\system32\UBPM.dll+4552|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671179Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.485{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671178Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.485{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671177Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.485{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-D0C8-609A-0A00-00000000BA01}624C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671176Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.470{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671175Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.470{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671174Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.470{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-F855-00000000BA01}8028C:\Windows\system32\compattelrunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671173Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.470{7B03F3B2-D0CA-609A-1600-00000000BA01}13044380C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-F855-00000000BA01}8028C:\Windows\system32\compattelrunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a7a1|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+d395|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+2039|c:\windows\system32\UBPM.dll+2be0|c:\windows\system32\UBPM.dll+16d25|c:\windows\system32\UBPM.dll+4552|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671172Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.448{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671171Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.448{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671170Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.448{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671169Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.448{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671168Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.448{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671167Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.448{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671166Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-1600-00000000BA01}13044540C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-F555-00000000BA01}7784C:\Windows\system32\rundll32.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+235b|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+39cf9|C:\Windows\SYSTEM32\ntdll.dll+1e88a|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671165Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-1600-00000000BA01}13041344C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-F555-00000000BA01}7784C:\Windows\system32\rundll32.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671164Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671163Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671162Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671161Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671160Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671159Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671158Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.432{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671157Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=39243EF234C54A4DAE444795BABDE951,SHA256=ABE422CC48A9D316EDBD59E0458E907E08CD54C8D2FAE2B2FAB7A9E2B6C9DC25,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671156Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-319D-609C-402D-00000000BA01}2288452C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-F555-00000000BA01}7784C:\Windows\system32\rundll32.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671155Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671154Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671153Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671152Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671151Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671150Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC6-609D-F555-00000000BA01}7784C:\Windows\system32\rundll32.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671149Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.417{7B03F3B2-D0CA-609A-1600-00000000BA01}13044380C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-F555-00000000BA01}7784C:\Windows\system32\rundll32.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\UBPM.dll+acf0|c:\windows\system32\UBPM.dll+fa34|c:\windows\system32\UBPM.dll+cdcc|c:\windows\system32\UBPM.dll+108c6|c:\windows\system32\UBPM.dll+d439|c:\windows\system32\UBPM.dll+dc95|c:\windows\system32\UBPM.dll+2039|c:\windows\system32\UBPM.dll+2be0|c:\windows\system32\UBPM.dll+16d25|c:\windows\system32\UBPM.dll+4552|C:\Windows\SYSTEM32\ntdll.dll+2063e|C:\Windows\SYSTEM32\ntdll.dll+1e854|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671148Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671147Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671146Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671145Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671144Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671143Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671142Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671141Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671140Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:38.385{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671436Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.998{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-7FC7-609D-0456-00000000BA01}7812C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671435Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.945{7B03F3B2-31A0-609C-522D-00000000BA01}18764336C:\Windows\Explorer.EXE{7B03F3B2-37B7-609D-644C-00000000BA01}580C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+6497|C:\Windows\System32\SHCORE.dll+6387|C:\Windows\System32\SHCORE.dll+62fd|C:\Windows\System32\SHCORE.dll+620a|C:\Windows\System32\SHELL32.dll+55a30|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF802640DD8C8)|UNKNOWN(FFFFF956C4EB4A38)|UNKNOWN(FFFFF956C4EB4BB7)|UNKNOWN(FFFFF956C4EAF241)|UNKNOWN(FFFFF956C4EB0C0A)|UNKNOWN(FFFFF956C4EAEEC6)|UNKNOWN(FFFFF80263DF4E03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+5929b|C:\Windows\System32\SHELL32.dll+dac5a|C:\Windows\System32\SHCORE.dll+33fad
10341000x8000000000000000671434Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.945{7B03F3B2-31A0-609C-522D-00000000BA01}18764336C:\Windows\Explorer.EXE{7B03F3B2-37B7-609D-644C-00000000BA01}580C:\Program Files\Mozilla Firefox\firefox.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\SHCORE.dll+64c8|C:\Windows\System32\SHCORE.dll+1c0e5|C:\Windows\System32\SHELL32.dll+55511|C:\Windows\System32\USER32.dll+121e4|C:\Windows\System32\USER32.dll+11ed7|C:\Windows\System32\USER32.dll+22a53|C:\Windows\SYSTEM32\ntdll.dll+a9814|UNKNOWN(FFFFF802640DD8C8)|UNKNOWN(FFFFF956C4EB4A38)|UNKNOWN(FFFFF956C4EB4BB7)|UNKNOWN(FFFFF956C4EAF241)|UNKNOWN(FFFFF956C4EB0C0A)|UNKNOWN(FFFFF956C4EAEEC6)|UNKNOWN(FFFFF80263DF4E03)|C:\Windows\System32\win32u.dll+10c4|C:\Windows\System32\USER32.dll+1ea2e|C:\Windows\System32\SHELL32.dll+5929b|C:\Windows\System32\SHELL32.dll+dac5a|C:\Windows\System32\SHCORE.dll+33fad|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671433Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.929{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms~RFa7ba732.TMPMD5=36DBBADA813EDB200C2B5A8128054E48,SHA256=F4E0DB2CD90C5DD2683AE772A460616D1F0DB8B7E1C978F725E37B250DA33754,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671432Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.929{7B03F3B2-37B7-609D-644C-00000000BA01}580ATTACKRANGE\AdministratorC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9n7q2hqo.default-release\datareporting\aborted-session-pingMD5=554258D49A4F738F578C9895A715E155,SHA256=9B36E38138F87CB949CF3CE4F8C352EC0D28AFCE12E3FCF4718CB2E4D7A9EC23,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671431Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.929{7B03F3B2-7FC7-609D-0656-00000000BA01}10402780C:\Windows\system32\conhost.exe{7B03F3B2-7FC7-609D-0B56-00000000BA01}5280C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671430Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.914{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0B56-00000000BA01}5280C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671429Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.914{7B03F3B2-7FC7-609D-0456-00000000BA01}78127352C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe{7B03F3B2-7FC7-609D-0B56-00000000BA01}5280C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\wow64.dll+10c0b|C:\Windows\System32\wow64.dll+10499|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e47|C:\Windows\SYSTEM32\ntdll.dll+78135|C:\Windows\SYSTEM32\ntdll.dll+77f9e|C:\Windows\SYSTEM32\ntdll.dll+6f66c(wow64)|C:\Windows\System32\KERNELBASE.dll+d9148(wow64)|C:\Windows\System32\KERNELBASE.dll+d7e2c(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvc.DLL+3d7ae(wow64)|UNKNOWN(00000000011F4853)|UNKNOWN(00000000011F4504)|UNKNOWN(00000000011F5A9B)|UNKNOWN(00000000011F28F8)|UNKNOWN(00000000011F0F66)|UNKNOWN(00000000011F0950)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+f036(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+122da(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+1859b(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+1992d7(wow64)
23542300x8000000000000000671428Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.898{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98F000DFD38478093688740577D15C86,SHA256=155D2662E3BAEDB0DF21234950E7A3929E725E17B107011261B0221C44AB4B8D,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671427Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.898{7B03F3B2-D0C8-609A-0B00-00000000BA01}6325688C:\Windows\system32\lsass.exe{7B03F3B2-7FC7-609D-0A56-00000000BA01}5272C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671426Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.898{7B03F3B2-D0C8-609A-0B00-00000000BA01}6325688C:\Windows\system32\lsass.exe{7B03F3B2-7FC7-609D-0A56-00000000BA01}5272C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671425Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.861{7B03F3B2-7FC7-609D-0656-00000000BA01}10402780C:\Windows\system32\conhost.exe{7B03F3B2-7FC7-609D-0A56-00000000BA01}5272C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671424Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.830{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0A56-00000000BA01}5272C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671423Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.830{7B03F3B2-7FC7-609D-0456-00000000BA01}78127352C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe{7B03F3B2-7FC7-609D-0A56-00000000BA01}5272C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\wow64.dll+10c0b|C:\Windows\System32\wow64.dll+10499|C:\Windows\System32\wow64.dll+6e75|C:\Windows\System32\wow64cpu.dll+1d07|C:\Windows\System32\wow64.dll+1bf87|C:\Windows\System32\wow64.dll+cba0|C:\Windows\SYSTEM32\ntdll.dll+92e47|C:\Windows\SYSTEM32\ntdll.dll+78135|C:\Windows\SYSTEM32\ntdll.dll+77f9e|C:\Windows\SYSTEM32\ntdll.dll+6f66c(wow64)|C:\Windows\System32\KERNELBASE.dll+d9148(wow64)|C:\Windows\System32\KERNELBASE.dll+d7e2c(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvc.DLL+3d7ae(wow64)|UNKNOWN(00000000011F4853)|UNKNOWN(00000000011F4504)|UNKNOWN(00000000011F2103)|UNKNOWN(00000000011F0F66)|UNKNOWN(00000000011F0950)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+f036(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+122da(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+1859b(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+1992d7(wow64)|C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll+1bb7fa(wow64)
10341000x8000000000000000671422Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.814{7B03F3B2-31A0-609C-482D-00000000BA01}46087328C:\Windows\System32\RuntimeBroker.exe{7B03F3B2-D0CA-609A-1200-00000000BA01}388C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\System32\TokenBroker.dll+1158a|C:\Windows\System32\TokenBroker.dll+d335|C:\Windows\System32\TokenBroker.dll+d669|C:\Windows\System32\TokenBroker.dll+1ff53|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+618c3|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+3cdcb|C:\Windows\System32\combase.dll+3e2d2|C:\Windows\System32\combase.dll+636f3|C:\Windows\System32\combase.dll+3e4dd|C:\Windows\System32\combase.dll+61acc|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde
10341000x8000000000000000671421Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.814{7B03F3B2-31A0-609C-482D-00000000BA01}46087328C:\Windows\System32\RuntimeBroker.exe{7B03F3B2-D0CA-609A-1200-00000000BA01}388C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\System32\combase.dll+61c8b|C:\Windows\System32\TokenBroker.dll+22ee6|C:\Windows\System32\TokenBroker.dll+114b3|C:\Windows\System32\TokenBroker.dll+d335|C:\Windows\System32\TokenBroker.dll+d669|C:\Windows\System32\TokenBroker.dll+1ff53|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+618c3|C:\Windows\System32\combase.dll+27cf|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+3cdcb|C:\Windows\System32\combase.dll+3e2d2|C:\Windows\System32\combase.dll+636f3|C:\Windows\System32\combase.dll+3e4dd|C:\Windows\System32\combase.dll+61acc|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d
23542300x8000000000000000671420Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.699{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F2B467E3279F3DE48AB0C55DCC3F56EF,SHA256=1D45409971A631D809F0B7F7EEB0378955DC51051F00A4944BAF5060783218D4,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671419Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.661{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-7FC7-609D-0956-00000000BA01}5176C:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\dismhost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671418Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.661{7B03F3B2-319D-609C-402D-00000000BA01}2288452C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0956-00000000BA01}5176C:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\dismhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671417Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.661{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671416Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.661{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671415Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.661{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671414Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.661{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671413Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.661{7B03F3B2-7FC6-609D-FC55-00000000BA01}49884584C:\Windows\system32\cleanmgr.exe{7B03F3B2-7FC7-609D-0956-00000000BA01}5176C:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\dismhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\system32\Dism\DismCore.dll+273f6|C:\Windows\system32\Dism\DismCore.dll+8eaa|C:\Windows\system32\Dism\DismCore.dll+58d4|C:\Windows\system32\DismApi.DLL+55381|C:\Windows\system32\DismApi.DLL+2c46a|C:\Windows\system32\DismApi.DLL+25f06|C:\Windows\system32\DismApi.DLL+24ceb|C:\Windows\system32\DismApi.DLL+2466f|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671412Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.663{7B03F3B2-7FC7-609D-0956-00000000BA01}5176C:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\DismHost.exe10.0.14393.4169 (rs1_release.210107-1130)Dism Host Servicing ProcessMicrosoft® Windows® Operating SystemMicrosoft CorporationDismHost.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\dismhost.exe {0B110B20-DB9C-4E09-9922-52B90F4DCFD6}C:\Windows\system32\ATTACKRANGE\Administrator{7B03F3B2-319F-609C-E1A8-A20100000000}0x1a2a8e12HighMD5=A59C22B77871CC18970038B7FA43826F,SHA256=CB84B51713BAD689ABB96560E57A71B276D4B28B1C09C7116EE85F5782A1B144,IMPHASH=734010D3430DBD2CA51B599924FE1424{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\System32\cleanmgr.exeC:\Windows\system32\cleanmgr.exe /autoclean /d C:
11241100x8000000000000000671411Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-service-winsvc-l1-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671410Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-service-private-l1-1-1.dll2021-05-13 19:36:39.630
11241100x8000000000000000671409Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-service-private-l1-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671408Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-service-management-l2-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671407Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-service-management-l1-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671406Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-service-core-l1-1-1.dll2021-05-13 19:36:39.630
11241100x8000000000000000671405Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-service-core-l1-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671404Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-security-sddl-l1-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671403Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-security-provider-L1-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671402Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.630{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-security-lsapolicy-l1-1-0.dll2021-05-13 19:36:39.630
11241100x8000000000000000671401Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Security-Lsalookup-L2-1-1.dll2021-05-13 19:36:39.614
11241100x8000000000000000671400Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Security-Lsalookup-L2-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671399Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-security-cryptoapi-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671398Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-security-base-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671397Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-EventLog-Legacy-L1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671396Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Eventing-Provider-L1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671395Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Eventing-Legacy-L1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671394Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Eventing-Controller-L1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671393Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-eventing-consumer-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671392Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671391Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-devices-config-L1-1-1.dll2021-05-13 19:36:39.614
11241100x8000000000000000671390Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-devices-config-L1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671389Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-core-xstate-l2-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671388Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-xstate-l1-1-0.dll2021-05-13 19:36:39.614
23542300x8000000000000000671387Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.614{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=3A15C090154B3EEC3F7FCCF8289150F0,SHA256=F2A107F50D0CA8D646870DEC649EBE4CA17620E429891E92AFF4A7134F5D74C7,IMPHASH=00000000000000000000000000000000falsetrue
11241100x8000000000000000671386Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-wow64-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671385Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-version-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671384Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-util-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671383Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-url-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671382Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.614{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-timezone-l1-1-0.dll2021-05-13 19:36:39.614
11241100x8000000000000000671381Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-threadpool-private-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671380Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-threadpool-legacy-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671379Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-threadpool-l1-2-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671378Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-sysinfo-l1-2-1.dll2021-05-13 19:36:39.599
11241100x8000000000000000671377Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-sysinfo-l1-2-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671376Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-sysinfo-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671375Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-synch-l1-2-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671374Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-synch-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671373Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-stringloader-l1-1-1.dll2021-05-13 19:36:39.599
23542300x8000000000000000671372Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.599{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=3A15C090154B3EEC3F7FCCF8289150F0,SHA256=F2A107F50D0CA8D646870DEC649EBE4CA17620E429891E92AFF4A7134F5D74C7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671371Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.599{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DEB5A4516235FA2383C852EB57BAF8FE,SHA256=A7B838D0FF97B513D469857B468C63C37DA857B59DCA38557C2EC43F84452204,IMPHASH=00000000000000000000000000000000falsetrue
11241100x8000000000000000671370Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-stringansi-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671369Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-core-string-obsolete-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671368Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-core-string-l2-1-0.dll2021-05-13 19:36:39.599
23542300x8000000000000000671367Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.599{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CE49DCA84B2059C163C4A9382BD08B60,SHA256=0C1EF0365AA0B51A6753FB8712336D4A08E54E22850BB5E9FC5FE15823DD7815,IMPHASH=00000000000000000000000000000000falsetrue
11241100x8000000000000000671366Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-string-l1-1-0.dll2021-05-13 19:36:39.599
23542300x8000000000000000671365Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.599{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=C145C4D5E2C35FD12561ED0E19132289,SHA256=79D44ED3EB87BA76E1F3488B4ECD9D71D87F354B2066BC4F69B4F4C5EF377C31,IMPHASH=00000000000000000000000000000000falsetrue
11241100x8000000000000000671364Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-shutdown-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671363Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.599{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll2021-05-13 19:36:39.599
11241100x8000000000000000671362Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-shlwapi-legacy-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671361Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-rtlsupport-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671360Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-registry-l2-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671359Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-registry-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671358Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-realtime-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671357Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-profile-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671356Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-processtopology-obsolete-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671355Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-processthreads-l1-1-2.dll2021-05-13 19:36:39.583
11241100x8000000000000000671354Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-processthreads-l1-1-1.dll2021-05-13 19:36:39.583
11241100x8000000000000000671353Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-processthreads-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671352Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-processenvironment-l1-2-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671351Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-processenvironment-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671350Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-privateprofile-l1-1-1.dll2021-05-13 19:36:39.583
11241100x8000000000000000671349Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-privateprofile-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671348Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-namedpipe-l1-1-0.dll2021-05-13 19:36:39.583
11241100x8000000000000000671347Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-memory-l1-1-2.dll2021-05-13 19:36:39.583
11241100x8000000000000000671346Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-memory-l1-1-1.dll2021-05-13 19:36:39.583
11241100x8000000000000000671345Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.583{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-memory-l1-1-0.dll2021-05-13 19:36:39.582
11241100x8000000000000000671344Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.582{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-core-localization-obsolete-l1-2-0.dll2021-05-13 19:36:39.581
11241100x8000000000000000671343Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.581{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-localization-l1-2-1.dll2021-05-13 19:36:39.581
11241100x8000000000000000671342Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.580{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-localization-l1-2-0.dll2021-05-13 19:36:39.580
11241100x8000000000000000671341Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.580{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-libraryloader-l1-1-1.dll2021-05-13 19:36:39.578
11241100x8000000000000000671340Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.578{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-libraryloader-l1-1-0.dll2021-05-13 19:36:39.578
11241100x8000000000000000671339Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.577{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll2021-05-13 19:36:39.577
11241100x8000000000000000671338Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671337Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-kernel32-legacy-l1-1-1.dll2021-05-13 19:36:39.561
11241100x8000000000000000671336Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-kernel32-legacy-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671335Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-io-l1-1-1.dll2021-05-13 19:36:39.561
11241100x8000000000000000671334Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-io-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671333Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-interlocked-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671332Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671331Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-heap-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671330Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-handle-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671329Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-core-file-l2-1-1.dll2021-05-13 19:36:39.561
11241100x8000000000000000671328Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\API-MS-Win-core-file-l2-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671327Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-file-l1-2-1.dll2021-05-13 19:36:39.561
11241100x8000000000000000671326Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-file-l1-2-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671325Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-file-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671324Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-fibers-l1-1-1.dll2021-05-13 19:36:39.561
11241100x8000000000000000671323Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-fibers-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671322Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-errorhandling-l1-1-1.dll2021-05-13 19:36:39.561
11241100x8000000000000000671321Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-errorhandling-l1-1-0.dll2021-05-13 19:36:39.561
11241100x8000000000000000671320Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.561{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-delayload-l1-1-0.dll2021-05-13 19:36:39.546
11241100x8000000000000000671319Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.546{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-debug-l1-1-1.dll2021-05-13 19:36:39.546
11241100x8000000000000000671318Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-debug-l1-1-0.dll2021-05-13 19:36:39.530
11241100x8000000000000000671317Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-datetime-l1-1-1.dll2021-05-13 19:36:39.530
11241100x8000000000000000671316Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-datetime-l1-1-0.dll2021-05-13 19:36:39.530
11241100x8000000000000000671315Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-console-l1-1-0.dll2021-05-13 19:36:39.530
11241100x8000000000000000671314Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-comm-l1-1-0.dll2021-05-13 19:36:39.530
11241100x8000000000000000671313Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-core-com-l1-1-0.dll2021-05-13 19:36:39.530
11241100x8000000000000000671312Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\api-ms-win-base-util-l1-1-0.dll2021-05-13 19:36:39.530
11241100x8000000000000000671311Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\WimProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671310Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\VhdProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671309Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\UnattendProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671308Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\TransmogProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671307Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\SmiProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671306Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\ProvProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671305Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\OSProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671304Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\OfflineSetupProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671303Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.530{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\MsiProvider.dll2021-05-13 19:36:39.530
11241100x8000000000000000671302Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.514{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\LogProvider.dll2021-05-13 19:36:39.514
11241100x8000000000000000671301Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.514{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\IntlProvider.dll2021-05-13 19:36:39.514
11241100x8000000000000000671300Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.514{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\ImagingProvider.dll2021-05-13 19:36:39.514
11241100x8000000000000000671299Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.514{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\IBSProvider.dll2021-05-13 19:36:39.514
11241100x8000000000000000671298Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.514{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\GenericProvider.dll2021-05-13 19:36:39.514
11241100x8000000000000000671297Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.514{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\FolderProvider.dll2021-05-13 19:36:39.514
11241100x8000000000000000671296Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.514{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\FfuProvider.dll2021-05-13 19:36:39.514
10341000x8000000000000000671295Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.399{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-7FC7-609D-0356-00000000BA01}7868C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
11241100x8000000000000000671294Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.399{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\DmiProvider.dll2021-05-13 19:36:39.399
11241100x8000000000000000671293Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.399{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\DismProv.dll2021-05-13 19:36:39.383
11241100x8000000000000000671292Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localEXE2021-05-13 19:36:39.383{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\DismHost.exe2021-05-13 19:36:39.383
11241100x8000000000000000671291Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.383{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\DismCorePS.dll2021-05-13 19:36:39.383
11241100x8000000000000000671290Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.383{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\DismCore.dll2021-05-13 19:36:39.383
11241100x8000000000000000671289Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.383{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\CompatProvider.dll2021-05-13 19:36:39.383
11241100x8000000000000000671288Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.383{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\CbsProvider.dll2021-05-13 19:36:39.315
10341000x8000000000000000671287Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.362{7B03F3B2-7FC7-609D-0556-00000000BA01}11404520C:\Windows\system32\conhost.exe{7B03F3B2-7FC7-609D-0856-00000000BA01}5252C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671286Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.362{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0856-00000000BA01}5252C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671285Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.362{7B03F3B2-7FC7-609D-0356-00000000BA01}78681272C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe{7B03F3B2-7FC7-609D-0856-00000000BA01}5252C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.dll+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvc.DLL+35491|UNKNOWN(00007FFD2C345A07)
10341000x8000000000000000671284Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.346{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-7FC7-609D-0756-00000000BA01}7928C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671283Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.346{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-7FC7-609D-0756-00000000BA01}7928C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671282Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.330{7B03F3B2-7FC7-609D-0556-00000000BA01}11404520C:\Windows\system32\conhost.exe{7B03F3B2-7FC7-609D-0756-00000000BA01}7928C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671281Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.330{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0756-00000000BA01}7928C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671280Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.330{7B03F3B2-7FC7-609D-0356-00000000BA01}78681272C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe{7B03F3B2-7FC7-609D-0756-00000000BA01}7928C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.dll+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvc.DLL+35491|UNKNOWN(00007FFD2C345A07)
11241100x8000000000000000671279Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.315{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\AssocProvider.dll2021-05-13 19:36:39.315
11241100x8000000000000000671278Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localDLL2021-05-13 19:36:39.315{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exeC:\Users\ADMINI~1\AppData\Local\Temp\6AF9C314-069D-4590-9A0F-7150A71AA8F1\AppxProvider.dll2021-05-13 19:36:39.315
10341000x8000000000000000671277Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.262{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671276Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.215{7B03F3B2-7FC7-609D-0656-00000000BA01}10402780C:\Windows\system32\conhost.exe{7B03F3B2-7FC7-609D-0456-00000000BA01}7812C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671275Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.199{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0656-00000000BA01}1040C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671274Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.165{7B03F3B2-7FC7-609D-0556-00000000BA01}11404520C:\Windows\system32\conhost.exe{7B03F3B2-7FC7-609D-0356-00000000BA01}7868C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671273Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.156{7B03F3B2-D0C8-609A-0500-00000000BA01}412428C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0556-00000000BA01}1140C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671272Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.156{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671271Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.156{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671270Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.155{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671269Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.155{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671268Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.153{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0456-00000000BA01}7812C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671267Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.153{7B03F3B2-7FC6-609D-F455-00000000BA01}50447668C:\Windows\system32\taskhostw.exe{7B03F3B2-7FC7-609D-0456-00000000BA01}7812C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+384236|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+2c4809|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+2c4179|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+2c01b0|UNKNOWN(00007FFD2C3515F2)
154100x8000000000000000671266Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.152{7B03F3B2-7FC7-609D-0456-00000000BA01}7812C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngentask.exe4.8.4330.0 built by: NET48REL1LAST_BMicrosoft .NET Framework optimization serviceMicrosoft® .NET FrameworkMicrosoft CorporationNGenTask.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\NGenTask.exe" /RuntimeWide /StopEvent:388C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=196F531423F864F990B24F3D3AFA9AA1,SHA256=353C8C617C87A56F93C9914E219BE4E30A45A0DEA8D98BF34C6BD81A6A287916,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744{7B03F3B2-7FC6-609D-F455-00000000BA01}5044C:\Windows\System32\taskhostw.exetaskhostw.exe /RuntimeWide
10341000x8000000000000000671265Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.152{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671264Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.152{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671263Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.152{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671262Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.152{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671261Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.151{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FC7-609D-0356-00000000BA01}7868C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671260Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.151{7B03F3B2-7FC6-609D-F455-00000000BA01}50444024C:\Windows\system32\taskhostw.exe{7B03F3B2-7FC7-609D-0356-00000000BA01}7868C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+384236|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+2c4809|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+2c4179|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\c99ae323aa8566cc2c0b79b709b48095\System.ni.dll+2c01b0|UNKNOWN(00007FFD2C3515F2)
154100x8000000000000000671259Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.149{7B03F3B2-7FC7-609D-0356-00000000BA01}7868C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe4.8.4330.0 built by: NET48REL1LAST_BMicrosoft .NET Framework optimization serviceMicrosoft® .NET FrameworkMicrosoft CorporationNGenTask.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\NGenTask.exe" /RuntimeWide /StopEvent:892C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=D2DDF021EE6A8A649FB58F6DD05EDED7,SHA256=AC1B312B5D048DAC81327CF083BDEF2966AA883208455490E73D6E34C932B7D9,IMPHASH=00000000000000000000000000000000{7B03F3B2-7FC6-609D-F455-00000000BA01}5044C:\Windows\System32\taskhostw.exetaskhostw.exe /RuntimeWide
10341000x8000000000000000671258Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.147{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+24c07|C:\Windows\system32\lsasrv.dll+25d4d|C:\Windows\system32\lsasrv.dll+24a85|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671257Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.146{7B03F3B2-D0C8-609A-0B00-00000000BA01}6323024C:\Windows\system32\lsass.exe{7B03F3B2-7FC6-609D-FC55-00000000BA01}4988C:\Windows\system32\cleanmgr.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\lsasrv.dll+249cd|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671256Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.118{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671255Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.118{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671254Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.118{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671253Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.118{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671252Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.118{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671251Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.115{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671250Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.115{7B03F3B2-D0CA-609A-0C00-00000000BA01}8565480C:\Windows\system32\svchost.exe{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000572643Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:39.237{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=7E87B0B49DEFD40D6541DAD6640035D6,SHA256=67D86B10F5A3734694425B8E3D612BD1C7B4287B3D66C7D229B30CCF760CE14C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572642Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:39.097{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=29C467EC102D08D9F6A4D567CD17115C,SHA256=3B92838392587FA98DAD39C8A047821E934600EE05D1D523760C3734D7CA25BE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671438Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:40.912{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FC9EC468B70B93ADC0697AB9C4D82FEE,SHA256=E6A0CFAC1E3AF35B6F09B60DE9A6E450A52521382A1CB6CC4F67EC0A2E9D8ECF,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671437Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:40.513{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=DB4397DBD3B7155D65834CE4AD94D35E,SHA256=CAE51731A744C5570D93BAA65A0177138DB950F8E43D6E6FE941C41C2D1D3CF2,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572645Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:37.853{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52785-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572644Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:40.144{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=AA51ED69C823A5E3BFBECF5A91807BE2,SHA256=15CFF71035D595A1374910039061BFC236157372BB211FA0CE8EF449840AD654,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671445Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:41.926{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=27E3D5C17BAB74867AE06B066D7AAE9A,SHA256=44E6C7A4C9CF647EE551603DF19C8251A306D8F62DB3A1C60797C5A403EBB723,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572646Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:41.191{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E36243D0F375FB71F22534C15B6D7683,SHA256=6524BDE8018807972B51C1F62B7A5B296A3ED2248DDCA3E6CBEB32678BFE55FB,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671444Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:40.159{7B03F3B2-D0CA-609A-1200-00000000BA01}388C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEtcptruefalse10.0.1.14win-dc-18.attackrange.local51184-false23.199.80.166a23-199-80-166.deploy.static.akamaitechnologies.com443https
354300x8000000000000000671443Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:40.123{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local51160-
354300x8000000000000000671442Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.804{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51183-false40.126.29.5-443https
354300x8000000000000000671441Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.522{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51182-false72.21.91.29-80http
354300x8000000000000000671440Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.498{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53428-
354300x8000000000000000671439Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:39.426{7B03F3B2-D0CA-609A-1600-00000000BA01}1304C:\Windows\System32\svchost.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51181-false40.126.29.5-443https
23542300x8000000000000000671447Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:42.942{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D9694413BDFCB374F936CC3C806DE5AE,SHA256=D081178EAE96FCC130BFA0D945CE3E20CE5309FB384D4F52992FB2A4B39BC7FA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572647Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:42.206{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F01957EE8B5E4B637538080011C346CD,SHA256=7C19D0221F382DBE820694E17D8A59C1B4B278E8885E036A9A3B705FB30742B8,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671446Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:42.327{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=589B5A6A84CC431E799B8BCCD3C2B73F,SHA256=0168B3BE5D37D96607B8294388278D1F1B02EF7311D09E3DF4C8833B6DFF7B7F,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671454Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:43.957{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=CA1981341A08EE3AE0F4BDC491E5A5B2,SHA256=C07B2958BAF134BF989BCF960051D55548A7A12F5630B263C5B56526A8CFD546,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572648Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:43.237{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D587089AA014BD1932B93E713DCBCF6,SHA256=069583BFE7D7B21F5C0A7D672D5B2B90C3D565DE0DD7BEFB2F6A0061DB29C165,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671453Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:43.925{7B03F3B2-7FC6-609D-0256-00000000BA01}65928128C:\Windows\system32\CompatTelRunner.exe{7B03F3B2-7FC6-609D-F855-00000000BA01}8028C:\Windows\system32\compattelrunner.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\invagent.dll+427c2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
354300x8000000000000000671452Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:42.287{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51185-false10.0.1.12-8000-
354300x8000000000000000671451Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:41.572{7B03F3B2-D0CA-609A-1400-00000000BA01}1076C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEudpfalsefalse127.0.0.1win-dc-18.attackrange.local55096-false127.0.0.1win-dc-18.attackrange.local53domain
354300x8000000000000000671450Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:41.557{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsefalse127.0.0.1win-dc-18.attackrange.local53domainfalse127.0.0.1win-dc-18.attackrange.local55096-
354300x8000000000000000671449Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:41.557{7B03F3B2-D0CA-609A-1400-00000000BA01}1076C:\Windows\System32\svchost.exeNT AUTHORITY\NETWORK SERVICEudptruetrue7f00:1:0:0:98c0:c1eb:8987:ffff-55096-true7f00:1:5:0:10:0:0:0-53domain
354300x8000000000000000671448Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:41.520{7B03F3B2-D0D7-609A-2A00-00000000BA01}2996C:\Windows\System32\dns.exeNT AUTHORITY\SYSTEMudpfalsetrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local53domaintrue0:0:0:0:0:0:0:1win-dc-18.attackrange.local55096-
23542300x8000000000000000572649Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:44.269{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=44D0582A0BF2B4C79129F8455AC537A3,SHA256=F9055EF521C796CF22F9F1EAB7C1A5929CA636A627657FC449020CCB98E2F4EA,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572653Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:43.853{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52786-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572652Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:45.284{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=61A41F84B472632EBBB589FE16C073BA,SHA256=28946D798E2F6D1F4EB10F2239DF02612344BB719EC5AE3A972B812D4C3EDE9D,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671463Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.240{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7FCD-609D-0C56-00000000BA01}7184C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671462Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.224{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671461Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.224{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671460Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.224{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671459Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.224{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671458Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.224{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FCD-609D-0C56-00000000BA01}7184C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671457Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.224{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7FCD-609D-0C56-00000000BA01}7184C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671456Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.094{7B03F3B2-7FCD-609D-0C56-00000000BA01}7184C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671455Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.126{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=DB3FADC410BB21462412A202143212D7,SHA256=DC84085945E124209223AFD6F04EB8F5532426AC3CAB32BCDB3EE68AE22320FA,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572651Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:45.222{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5CB4172C3DE47D063A103AB61E97AF73,SHA256=2533AC08447C36F94A4381E3DD46553416A9DA2312FD16EB1205E785E29FD585,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572650Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:45.222{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=3C02D164BDEEFFC4057323F2D70AEFD5,SHA256=3602623983499072532D33DF02341F9BC7BD97EB66C6FE44D1D319FC023C64F2,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572654Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:46.331{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A50FA8AE91E3B412852DA8207CDD400D,SHA256=0AD6F782E23F9E9FDE7F5A1E2B2954FD6C6BE6618FA1C106BCB1AFBBE5841954,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671481Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.983{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7FCE-609D-0E56-00000000BA01}3528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671480Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.981{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671479Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.981{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671478Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.980{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671477Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.980{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671476Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.980{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FCE-609D-0E56-00000000BA01}3528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671475Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.980{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7FCE-609D-0E56-00000000BA01}3528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671474Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.856{7B03F3B2-7FCE-609D-0E56-00000000BA01}3528C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671473Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.209{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6AF1574AD632E3E2AF37F15DC578A23E,SHA256=C3C4CC122968FE0652A8C7EE649C5F812BA3434CA1D94EA654C698197A0474C7,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671472Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.146{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7FCD-609D-0D56-00000000BA01}7484C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671471Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.130{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671470Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.130{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671469Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.130{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671468Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.130{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671467Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.130{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FCD-609D-0D56-00000000BA01}7484C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671466Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.130{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7FCD-609D-0D56-00000000BA01}7484C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671465Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:45.972{7B03F3B2-7FCD-609D-0D56-00000000BA01}7484C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671464Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:46.114{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=CC5A6CC7AB1193A57900039207BFB799,SHA256=F3D4B32BF6D14C327A56AE375A780BEEFBAD646ACB296AA2ED431D4400B78293,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671493Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.800{7B03F3B2-7FCF-609D-0F56-00000000BA01}79965148C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671492Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.600{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7FCF-609D-0F56-00000000BA01}7996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671491Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.600{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671490Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.600{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671489Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.600{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671488Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.600{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671487Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.600{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FCF-609D-0F56-00000000BA01}7996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671486Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.600{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7FCF-609D-0F56-00000000BA01}7996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671485Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.480{7B03F3B2-7FCF-609D-0F56-00000000BA01}7996C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671484Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.316{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BBD8BE829533FFF1005EC5A5320E334D,SHA256=EF91E1FB111BDF56F81578E7B4A259AB7197B796CD09825E7AE873E1A5FC5331,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671483Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.216{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F6BC1211E46333D8EB2A21BE6D61BB7,SHA256=A521B41ED731EE431E36F3C97C5E7CD400AAE3F645E50C55F214B3DFCB4125A7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572655Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:47.367{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=FB9F1388775EEAC3419FA104E44B0918,SHA256=3C29C29745326105E27D931011AD8FE36EE945FABBAFA24EDCD0FF0B886580A8,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671482Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.175{7B03F3B2-7FCE-609D-0E56-00000000BA01}35286180C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671505Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.497{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FC56C34BA9F712D3AA20CA36C535F0E7,SHA256=C17933BD21D5F20ED5FD6C652B257511E6DC001AF74E3B7230BF490C7E387396,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671504Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:47.341{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51186-false10.0.1.12-8000-
10341000x8000000000000000671503Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.431{7B03F3B2-7FD0-609D-1056-00000000BA01}9886704C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671502Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.263{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7FD0-609D-1056-00000000BA01}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671501Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.263{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671500Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.263{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671499Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.263{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671498Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.263{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671497Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.263{7B03F3B2-D0C8-609A-0500-00000000BA01}412768C:\Windows\system32\csrss.exe{7B03F3B2-7FD0-609D-1056-00000000BA01}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671496Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.263{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7FD0-609D-1056-00000000BA01}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671495Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.264{7B03F3B2-7FD0-609D-1056-00000000BA01}988C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671494Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:48.232{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B6817F084DAD10B7622FCC4F8B891C08,SHA256=C4FBC1AD616FEC24C696C9DA5F657AF55FC70FB411175B9BEBCB8ACF606449D0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572656Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:48.398{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=507CD46995EFE9AE87F29A96943175A9,SHA256=28A1B9665BB06EFAF183E3CE709CB3538286C05D71D5E1855F0C7CDDB124A0D6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572657Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:49.476{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=85E4A5B450BC41A15CC29345808FF3BF,SHA256=D5759155EEA23BF535DEA55DA26D2AEC52793A40267BC1D72C24E4A94616E187,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671506Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:49.246{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=022F8FC4EFB3F8563B2641CD5E018CE2,SHA256=6F0EBF7E9202C100F0500986B0D6B0706FAF6BC02349F09031D7E8FDB40AE618,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572658Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:50.492{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=07AF3DA47AA0FF01A0E1C05DF7B9FEDB,SHA256=F7AD9757D933A04F191ED6304553AB8C53733155E0B32B6DB96E06D91EFF16A6,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671507Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:50.261{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C24D8CFC0C4BBBB1C74281CB39C43A7E,SHA256=19F101DE1ED4B8E524D2E8AE41F1DDB2D6BDFD320D478E8C28E9B58B64123273,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000572662Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:49.889{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52787-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
23542300x8000000000000000572661Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:51.538{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=4A9B6C001B2CA2F79127AFC2E3302B4D,SHA256=E09132CEDD9DBFBCD3B64E1BB0D90067DE87835BB06B0BD36F58EE46B5B8C31F,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671538Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.904{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7FD3-609D-1256-00000000BA01}7532C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671537Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.902{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671536Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.901{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671535Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.901{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671534Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.901{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671533Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.901{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FD3-609D-1256-00000000BA01}7532C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671532Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.900{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7FD3-609D-1256-00000000BA01}7532C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671531Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.747{7B03F3B2-7FD3-609D-1256-00000000BA01}7532C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000671530Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.877{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=19DC0AA6CBDEA81CF34596A19823EB21,SHA256=16A600437CC8813C663AF08EEFFB3165C761327FCCC22B6C5C9EDE57BF230648,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671529Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\firefox.exe|ebd16581180f4552\BinProductVersion88.0.1.0
13241300x8000000000000000671528Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\firefox.exe|ebd16581180f4552\LinkDate05/04/2021 16:36:51
13241300x8000000000000000671527Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\firefox.exe|ebd16581180f4552\Publishermozilla corporation
13241300x8000000000000000671526Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\firefox.exe|ebd16581180f4552\LowerCaseLongPathc:\program files\mozilla firefox\firefox.exe
13241300x8000000000000000671525Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\default-browser-|dc77861eecd2248\BinProductVersion88.0.1.7794
13241300x8000000000000000671524Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\default-browser-|dc77861eecd2248\LinkDate05/04/2021 16:38:09
13241300x8000000000000000671523Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\default-browser-|dc77861eecd2248\Publishermozilla foundation
13241300x8000000000000000671522Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\default-browser-|dc77861eecd2248\LowerCaseLongPathc:\program files\mozilla firefox\default-browser-agent.exe
13241300x8000000000000000671521Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\crashreporter.ex|63c55d3d1009672b\BinProductVersion88.0.1.7794
13241300x8000000000000000671520Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\crashreporter.ex|63c55d3d1009672b\LinkDate05/04/2021 16:37:29
13241300x8000000000000000671519Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\crashreporter.ex|63c55d3d1009672b\Publishermozilla foundation
13241300x8000000000000000671518Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:51.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\crashreporter.ex|63c55d3d1009672b\LowerCaseLongPathc:\program files\mozilla firefox\crashreporter.exe
10341000x8000000000000000671517Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.276{7B03F3B2-7FD2-609D-1156-00000000BA01}73324588C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671516Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.275{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9698E8321BEDECF7012249DDE6FC4D53,SHA256=8C8F72BAA41D4F4CB87E63B793CA950935C893B312443B097F362B3E01E036BE,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572660Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:51.304{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2199A56A502A14BD0E24EEB1C738E1B2,SHA256=0A5136020848DE8214B50609CA04CC46F2FDFD463F6C48A2F24DF0C623B927CD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572659Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:51.304{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=5CB4172C3DE47D063A103AB61E97AF73,SHA256=2533AC08447C36F94A4381E3DD46553416A9DA2312FD16EB1205E785E29FD585,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671515Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.031{7B03F3B2-5121-609D-3650-00000000BA01}11765040C:\Windows\system32\conhost.exe{7B03F3B2-7FD2-609D-1156-00000000BA01}7332C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671514Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.026{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671513Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.025{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671512Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.024{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671511Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.024{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FD2-609D-1156-00000000BA01}7332C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000671510Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.024{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671509Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:51.023{7B03F3B2-5120-609D-3250-00000000BA01}15325964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{7B03F3B2-7FD2-609D-1156-00000000BA01}7332C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000671508Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:50.877{7B03F3B2-7FD2-609D-1156-00000000BA01}7332C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{7B03F3B2-5120-609D-3250-00000000BA01}1532C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service
23542300x8000000000000000572663Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:52.554{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9BA9C9CD0A6B485CAF836D68637C5369,SHA256=2621F99510E19979B2C84F2EB425C2D27B142D9C3211532F0F79A8EA025D13A0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671539Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:52.346{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=634FEF018B6BA0AEF556BD0193EF7C10,SHA256=B4A2D7CE24D9AA3FAEBAC4A1DEDE5C96A87624EDDD7B2E154D38EE0D260DD588,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572664Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:53.601{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C7F994348DAD140E007D89771B4B81A2,SHA256=9EB8B4702B80C1F393BC883016BE75695DCDD8EC19C0FCEB72FEEEF2D256B9D7,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671543Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:52.391{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51187-false10.0.1.12-8000-
23542300x8000000000000000671542Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:53.561{7B03F3B2-D0CA-609A-1100-00000000BA01}620NT AUTHORITY\LOCAL SERVICEC:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.datMD5=379EC2CE3A47AB6A50AF0CDCE73F2ADB,SHA256=8E21787E1D910FF4AA35BB694565675B2498F6621F4721F513315A4C7D14E352,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671541Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:53.408{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=98F66BA3F5FEB65B5149C7DAC9FEE389,SHA256=55FBF2344DA0954F68682CFDDD759382B32A42C161B6691930CD86ADB102400B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671540Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:53.161{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=FDD8C992E314BE5087FA148E47DC18A1,SHA256=DA0B956137CFE75DB65DE83FB168D9A96FBF3D24282D28957063192F9D4D293C,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572665Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:54.632{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=6EBBD6C5B8D5D958F13F00101DCA072A,SHA256=FD6212ACB9DB403164DFF243E73F5738423759C3AFEA052FF54D94D84A18E084,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671544Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:54.427{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D7D82BEBB24A866DD05FBE6B29B75EFD,SHA256=EF41462269EEA9DA7D5E6EAE7AE25D4600ECE3387565B674BF984875E1DC932E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671545Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:55.444{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E92E3A9BEDD2B30671B7B6E3C5BFAD1D,SHA256=002684571B8484551CC885B95D4FCB3ACFE176A699A357A2B4C155F5C361DB0E,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572666Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:55.648{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=EA2F6851FE9AC36ACEA9E8E9B5A2D6F1,SHA256=0C7D8BC929D613CBDC5748A259FFA396C84614BEDD90D80B7AE2CEEE819E3DB4,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671550Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:56.474{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\helper.exe|e5fe7566efc548ac\BinProductVersion1.0.0.0
13241300x8000000000000000671549Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:56.474{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\helper.exe|e5fe7566efc548ac\LinkDate12/11/2016 21:50:55
13241300x8000000000000000671548Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:56.474{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\helper.exe|e5fe7566efc548ac\Publishermozilla corporation
13241300x8000000000000000671547Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:56.474{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\helper.exe|e5fe7566efc548ac\LowerCaseLongPathc:\program files\mozilla firefox\uninstall\helper.exe
23542300x8000000000000000671546Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:56.458{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2046A6BBB11D85384E0AB659095415E0,SHA256=760282CD3073AE8328A3285F3D5CC3D4D14E2B56B0C3FCFF9485847276469CB3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572667Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:56.648{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BCF46C06A5515D149B78FEBEBCEE5C59,SHA256=60B8BE076EAB1303B505A252C0B598019E28AA5147728AEADF3E4E509E15A8E7,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572670Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:57.664{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F250B12D6C69A467041DA9C36974FC49,SHA256=5D062C72023BFBD1958F1F3D5AA24B982926D90EB5EBD00CC428A8F98C628FBD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671552Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:57.489{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=1C4F1E6436231A31DED5732A7928A68F,SHA256=7A713A2EC41F3A1CB69F94291819A14D41B904742AAA1AD67B7B914087AA5306,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671551Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-SetValue2021-05-13 19:36:57.489{7B03F3B2-D0CA-609A-1200-00000000BA01}388C:\Windows\system32\svchost.exeHKLM\System\CurrentControlSet\Services\W32Time\Config\LastKnownGoodTimeQWORD (0x01d7482f-0x560a3ac1)
23542300x8000000000000000572669Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:57.039{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4C3B14A8A700FEC9B65E2826D25D1AD6,SHA256=E9D5298E884E0F65AC62DE96D7C90AF54F6ECD5F30AF084C16A93A98F018F63A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572668Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:57.039{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=2199A56A502A14BD0E24EEB1C738E1B2,SHA256=0A5136020848DE8214B50609CA04CC46F2FDFD463F6C48A2F24DF0C623B927CD,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572672Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:58.679{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B80E03753A0F94952F7A878B60D0B49C,SHA256=A0BA0E3BCAD41B895B65AD40EE0A5E7931C301100CEFBA38D5C5614C6258DBA8,IMPHASH=00000000000000000000000000000000falsetrue
354300x8000000000000000671655Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:57.665{7B03F3B2-D0CA-609A-1200-00000000BA01}388C:\Windows\System32\svchost.exeNT AUTHORITY\LOCAL SERVICEudptruefalse10.0.1.14win-dc-18.attackrange.local123ntpfalse13.86.101.172-123ntp
354300x8000000000000000671654Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:57.450{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51188-false10.0.1.12-8000-
23542300x8000000000000000671653Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:58.632{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=A99EF208203CE20AED5D7B6DE7E596C4,SHA256=24D3C1DE19F891112ABC2599E05354C3B4D5D6037E417337294ADA4999BA1479,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671652Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.626{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winevtlog|d8125e0c86684fca\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671651Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.626{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winevtlog|d8125e0c86684fca\LinkDate02/07/2020 15:18:57
13241300x8000000000000000671650Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.626{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winevtlog|d8125e0c86684fca\Publishersplunk inc.
13241300x8000000000000000671649Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.626{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winevtlog|d8125e0c86684fca\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-winevtlog.exe
13241300x8000000000000000671648Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.543{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-regmon.ex|618812230e4591fb\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671647Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.543{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-regmon.ex|618812230e4591fb\LinkDate02/07/2020 15:19:10
13241300x8000000000000000671646Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.543{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-regmon.ex|618812230e4591fb\Publishersplunk inc.
13241300x8000000000000000671645Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.537{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-regmon.ex|618812230e4591fb\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-regmon.exe
354300x8000000000000000572671Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:55.654{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52788-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
13241300x8000000000000000671644Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.486{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-powershel|2c084771581f2247\BinProductVersion(Empty)
13241300x8000000000000000671643Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.486{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-powershel|2c084771581f2247\LinkDate02/07/2020 15:18:45
13241300x8000000000000000671642Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.482{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-powershel|2c084771581f2247\Publisher(Empty)
13241300x8000000000000000671641Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.482{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-powershel|2c084771581f2247\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-powershell.exe
13241300x8000000000000000671640Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.360{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-perfmon.e|5179a15d38015aca\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671639Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.360{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-perfmon.e|5179a15d38015aca\LinkDate02/07/2020 15:18:45
13241300x8000000000000000671638Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.360{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-perfmon.e|5179a15d38015aca\Publishersplunk inc.
13241300x8000000000000000671637Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.360{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-perfmon.e|5179a15d38015aca\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-perfmon.exe
13241300x8000000000000000671636Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-netmon.ex|1a876d8838ded3dd\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671635Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-netmon.ex|1a876d8838ded3dd\LinkDate02/07/2020 15:18:57
13241300x8000000000000000671634Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-netmon.ex|1a876d8838ded3dd\Publishersplunk inc.
13241300x8000000000000000671633Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-netmon.ex|1a876d8838ded3dd\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-netmon.exe
13241300x8000000000000000671632Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-monitorno|903ef6eeb885a45b\BinProductVersion10.0.10011.16384
13241300x8000000000000000671631Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-monitorno|903ef6eeb885a45b\LinkDate02/07/2020 15:18:52
13241300x8000000000000000671630Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-monitorno|903ef6eeb885a45b\Publisherwindows (r) win 7 ddk provider
13241300x8000000000000000671629Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-monitorno|903ef6eeb885a45b\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-monitornohandle.exe
23542300x8000000000000000671628Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:58.228{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0828DBE286C6A65C40A8DCCC782651A4,SHA256=15585C0DA3644CB73C65D0E83DCBD67E31C703F2FC3CA86A276950F07D38E377,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671627Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:58.227{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=9FF862827F386546527FDF889B82699B,SHA256=E454D381579516AF7377019C7CA54F3CAB4010BCD90D7AAF9405B44F4FCC1716,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671626Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-compresst|40738d14a4b5ef86\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671625Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-compresst|40738d14a4b5ef86\LinkDate02/07/2020 15:13:21
13241300x8000000000000000671624Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-compresst|40738d14a4b5ef86\Publishersplunk inc.
13241300x8000000000000000671623Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-compresst|40738d14a4b5ef86\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-compresstool.exe
13241300x8000000000000000671622Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-admon.exe|eab473bd2c77f301\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671621Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-admon.exe|eab473bd2c77f301\LinkDate02/07/2020 15:19:19
13241300x8000000000000000671620Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-admon.exe|eab473bd2c77f301\Publishersplunk inc.
13241300x8000000000000000671619Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-admon.exe|eab473bd2c77f301\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-admon.exe
13241300x8000000000000000671618Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splknetdrv.sys|9d837bc7abc517f\BinProductVersion10.0.10011.16384
13241300x8000000000000000671617Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splknetdrv.sys|9d837bc7abc517f\LinkDate09/27/2019 18:25:44
13241300x8000000000000000671616Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splknetdrv.sys|9d837bc7abc517f\Publisherwindows (r) win 7 ddk provider
13241300x8000000000000000671615Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splknetdrv.sys|9d837bc7abc517f\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splknetdrv.sys
13241300x8000000000000000671614Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|fe2747d40e70e115\BinProductVersion(Empty)
13241300x8000000000000000671613Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|fe2747d40e70e115\LinkDate01/10/2020 00:48:57
13241300x8000000000000000671612Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|fe2747d40e70e115\Publisher(Empty)
13241300x8000000000000000671611Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|fe2747d40e70e115\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\openssl.exe
13241300x8000000000000000671610Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\classify.exe|c62b2c99ddbdcd65\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671609Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\classify.exe|c62b2c99ddbdcd65\LinkDate02/07/2020 15:13:14
13241300x8000000000000000671608Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\classify.exe|c62b2c99ddbdcd65\Publishersplunk inc.
13241300x8000000000000000671607Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\classify.exe|c62b2c99ddbdcd65\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\classify.exe
13241300x8000000000000000671606Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btprobe.exe|ca8341d242e7a488\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671605Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btprobe.exe|ca8341d242e7a488\LinkDate02/07/2020 15:12:56
13241300x8000000000000000671604Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btprobe.exe|ca8341d242e7a488\Publishersplunk inc.
13241300x8000000000000000671603Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.127{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btprobe.exe|ca8341d242e7a488\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\btprobe.exe
13241300x8000000000000000671602Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.121{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btool.exe|4e68b21196df7ca2\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671601Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.121{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btool.exe|4e68b21196df7ca2\LinkDate02/07/2020 15:12:56
13241300x8000000000000000671600Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.121{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btool.exe|4e68b21196df7ca2\Publishersplunk inc.
13241300x8000000000000000671599Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.121{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\btool.exe|4e68b21196df7ca2\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\btool.exe
13241300x8000000000000000671598Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\000062e2a9e9b14ba03c6c34d99bd37d04a50000ffff\PublisherIgor Pavlov
13241300x8000000000000000671597Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|987e0404a196a19e\BinProductVersion19.0.0.0
13241300x8000000000000000671596Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|987e0404a196a19e\LinkDate02/21/2019 17:00:00
13241300x8000000000000000671595Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|987e0404a196a19e\Publisherigor pavlov
13241300x8000000000000000671594Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|987e0404a196a19e\LowerCaseLongPathc:\program files\7-zip\uninstall.exe
13241300x8000000000000000671593Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zg.exe|66a2193c8967c10d\BinProductVersion19.0.0.0
13241300x8000000000000000671592Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zg.exe|66a2193c8967c10d\LinkDate02/21/2019 16:00:00
13241300x8000000000000000671591Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zg.exe|66a2193c8967c10d\Publisherigor pavlov
13241300x8000000000000000671590Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zg.exe|66a2193c8967c10d\LowerCaseLongPathc:\program files\7-zip\7zg.exe
13241300x8000000000000000671589Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.094{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zfm.exe|56d287950815a745\BinProductVersion19.0.0.0
13241300x8000000000000000671588Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.094{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zfm.exe|56d287950815a745\LinkDate02/21/2019 16:00:00
13241300x8000000000000000671587Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.094{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zfm.exe|56d287950815a745\Publisherigor pavlov
13241300x8000000000000000671586Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.094{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7zfm.exe|56d287950815a745\LowerCaseLongPathc:\program files\7-zip\7zfm.exe
13241300x8000000000000000671585Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.078{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7z.exe|afe683e0fa522625\BinProductVersion19.0.0.0
13241300x8000000000000000671584Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.078{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7z.exe|afe683e0fa522625\LinkDate02/21/2019 16:00:00
13241300x8000000000000000671583Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.078{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7z.exe|afe683e0fa522625\Publisherigor pavlov
13241300x8000000000000000671582Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.078{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\7z.exe|afe683e0fa522625\LowerCaseLongPathc:\program files\7-zip\7z.exe
13241300x8000000000000000671581Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.057{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\00002dbd602367c17150fd634e06518bb2b80000ffff\PublisherMozilla
13241300x8000000000000000671580Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.057{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\updater.exe|c1b2e9c223e636df\BinProductVersion88.0.1.7794
13241300x8000000000000000671579Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\updater.exe|c1b2e9c223e636df\LinkDate05/04/2021 16:36:40
13241300x8000000000000000671578Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\updater.exe|c1b2e9c223e636df\Publishermozilla foundation
13241300x8000000000000000671577Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\updater.exe|c1b2e9c223e636df\LowerCaseLongPathc:\program files\mozilla firefox\updater.exe
13241300x8000000000000000671576Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-hang-ui.e|29c2c5a171ba01f1\BinProductVersion88.0.1.0
13241300x8000000000000000671575Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-hang-ui.e|29c2c5a171ba01f1\LinkDate05/04/2021 16:36:23
13241300x8000000000000000671574Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-hang-ui.e|29c2c5a171ba01f1\Publishermozilla corporation
13241300x8000000000000000671573Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-hang-ui.e|29c2c5a171ba01f1\LowerCaseLongPathc:\program files\mozilla firefox\plugin-hang-ui.exe
13241300x8000000000000000671572Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-container|bff6e47ff7f94db5\BinProductVersion88.0.1.0
13241300x8000000000000000671571Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-container|bff6e47ff7f94db5\LinkDate05/04/2021 16:46:44
13241300x8000000000000000671570Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-container|bff6e47ff7f94db5\Publishermozilla corporation
13241300x8000000000000000671569Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\plugin-container|bff6e47ff7f94db5\LowerCaseLongPathc:\program files\mozilla firefox\plugin-container.exe
13241300x8000000000000000671568Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pingsender.exe|aaf23943349d4957\BinProductVersion88.0.1.7794
13241300x8000000000000000671567Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pingsender.exe|aaf23943349d4957\LinkDate05/04/2021 16:36:36
13241300x8000000000000000671566Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pingsender.exe|aaf23943349d4957\Publishermozilla foundation
13241300x8000000000000000671565Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pingsender.exe|aaf23943349d4957\LowerCaseLongPathc:\program files\mozilla firefox\pingsender.exe
13241300x8000000000000000671564Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidump-analyze|c30fa22ff3f6a149\BinProductVersion88.0.1.7794
13241300x8000000000000000671563Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidump-analyze|c30fa22ff3f6a149\LinkDate05/04/2021 16:36:37
13241300x8000000000000000671562Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidump-analyze|c30fa22ff3f6a149\Publishermozilla foundation
13241300x8000000000000000671561Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidump-analyze|c30fa22ff3f6a149\LowerCaseLongPathc:\program files\mozilla firefox\minidump-analyzer.exe
13241300x8000000000000000671560Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|a02830353e4ef7f\BinProductVersion1.0.0.0
13241300x8000000000000000671559Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|a02830353e4ef7f\LinkDate12/11/2016 21:50:55
13241300x8000000000000000671558Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|a02830353e4ef7f\Publishermozilla corporation
13241300x8000000000000000671557Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.026{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|a02830353e4ef7f\LowerCaseLongPathc:\program files\mozilla firefox\maintenanceservice_installer.exe
13241300x8000000000000000671556Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:36:58.023{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|97180995320ca115\BinProductVersion88.0.1.7794
13241300x8000000000000000671555Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:36:58.023{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|97180995320ca115\LinkDate05/04/2021 16:36:54
13241300x8000000000000000671554Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:36:58.023{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|97180995320ca115\Publishermozilla foundation
13241300x8000000000000000671553Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:36:58.023{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|97180995320ca115\LowerCaseLongPathc:\program files\mozilla firefox\maintenanceservice.exe
23542300x8000000000000000572673Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:36:59.679{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=402B18657BA4549E77F7692BA54B6A97,SHA256=12C9BBB6FF70538B4D0A5279C01C0EA221BE18CF9DC2C506316787E673942726,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000671687Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671686Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671685Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671684Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671683Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671682Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671681Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671680Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671679Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671678Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671677Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671676Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671675Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671674Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671673Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671672Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671671Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671670Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.939{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671669Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671668Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31A0-609C-522D-00000000BA01}1876C:\Windows\Explorer.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671667Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671666Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671665Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671664Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671663Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671662Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671661Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+ca3e|c:\windows\system32\rpcss.dll+ba7a|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671660Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AC-609C-622D-00000000BA01}2984C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671659Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.938{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AD-609C-632D-00000000BA01}4184C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671658Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.937{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AD-609C-632D-00000000BA01}4184C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000671657Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.937{7B03F3B2-D0CA-609A-0D00-00000000BA01}912936C:\Windows\system32\svchost.exe{7B03F3B2-31AD-609C-632D-00000000BA01}4184C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+ed71|c:\windows\system32\rpcss.dll+b954|c:\windows\system32\rpcss.dll+ce2e|c:\windows\system32\rpcss.dll+a853|c:\windows\system32\rpcss.dll+42251|c:\windows\system32\rpcss.dll+42382|c:\windows\system32\rpcss.dll+426bf|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
23542300x8000000000000000671656Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:36:59.560{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D0A10045BCA1B6A53E542EE626A9AB2,SHA256=37D76DEC34141621B8A9D9E35F2BE026F734031A601020B0019255EB1089F4D4,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671689Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:00.874{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=0828DBE286C6A65C40A8DCCC782651A4,SHA256=15585C0DA3644CB73C65D0E83DCBD67E31C703F2FC3CA86A276950F07D38E377,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671688Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:00.874{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BFA4D8C8C9D02BC1F503F96D1E6B5D14,SHA256=D3A0B8AFF395F87C85B01749C168552A2D5B35364A3D5006B3CA48F6090C5FF3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572674Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:00.695{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E57DE3DB7854EFDF8F0FF6FE39919DAC,SHA256=CD6428DB38C89ADFAA7F9CC5930E3DA80CD936FC5E52B8A8779D57DA11617EC0,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572675Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:01.710{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=D88E4B1F41DF015FE08605DD4F5F7876,SHA256=49BF1A188B96F1FA4D2B57A925AD0825D8C086F31EC66303A1376AC73C24BE48,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000671698Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:01.924{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=49970116531D08E5E8440A6AAE03886F,SHA256=F7D289AF8076BAB71F9E72CAB4CBD9E475AAC9F14928CD90BD41A5EC8CEAEA41,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671697Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:01.887{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winprintm|94e5804991a842aa\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671696Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:01.887{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winprintm|94e5804991a842aa\LinkDate02/07/2020 15:19:24
13241300x8000000000000000671695Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:01.887{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winprintm|94e5804991a842aa\Publishersplunk inc.
13241300x8000000000000000671694Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:01.887{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winprintm|94e5804991a842aa\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-winprintmon.exe
13241300x8000000000000000671693Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:01.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winhostin|9c2f9c50ce2f578e\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671692Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:01.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winhostin|9c2f9c50ce2f578e\LinkDate02/07/2020 15:19:16
13241300x8000000000000000671691Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:01.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winhostin|9c2f9c50ce2f578e\Publishersplunk inc.
13241300x8000000000000000671690Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:01.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-winhostin|9c2f9c50ce2f578e\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-winhostinfo.exe
23542300x8000000000000000572678Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:02.726{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=694A6FCBCBD0CA1557278ED880C914C7,SHA256=F01599E74022BAED4C5B93F5200716E61E6BB11CADAA7AFC10BD948623AA2978,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672055Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\BinProductVersion(Empty)
13241300x8000000000000000672054Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672053Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\Publisher(Empty)
13241300x8000000000000000672052Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.849{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\factor.exe|b56619397de59334\LowerCaseLongPathc:\program files\git\usr\bin\factor.exe
13241300x8000000000000000672051Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.841{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\BinProductVersion(Empty)
13241300x8000000000000000672050Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.841{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672049Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.841{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\Publisher(Empty)
13241300x8000000000000000672048Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.841{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expr.exe|2052e3951d88a155\LowerCaseLongPathc:\program files\git\usr\bin\expr.exe
13241300x8000000000000000672047Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.833{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\BinProductVersion(Empty)
13241300x8000000000000000672046Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.833{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672045Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.833{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\Publisher(Empty)
13241300x8000000000000000672044Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.833{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\expand.exe|48fc5987fb05c50d\LowerCaseLongPathc:\program files\git\usr\bin\expand.exe
13241300x8000000000000000672043Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\BinProductVersion(Empty)
13241300x8000000000000000672042Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672041Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\Publisher(Empty)
13241300x8000000000000000672040Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ex.exe|a5705edbed8fc6c4\LowerCaseLongPathc:\program files\git\usr\bin\ex.exe
13241300x8000000000000000672039Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\BinProductVersion0.19.8.0
13241300x8000000000000000672038Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672037Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\Publisherfree software foundation
13241300x8000000000000000672036Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|eadcd0623e89b9ae\LowerCaseLongPathc:\program files\git\mingw64\bin\envsubst.exe
23542300x8000000000000000672035Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:02.783{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=40191A0D050F89DB0BEE9070400C28BC,SHA256=FFABD5E3EF5DFA803464CC78DE317D84757F04D57C8994BE9F6FFF9C26A6402D,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672034Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.780{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\BinProductVersion0.19.8.0
13241300x8000000000000000672033Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.780{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\LinkDate12/01/2031 01:05:42
13241300x8000000000000000672032Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.780{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\Publisherfree software foundation
13241300x8000000000000000672031Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.780{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\envsubst.exe|660c72e4fd95bfd4\LowerCaseLongPathc:\program files\git\usr\bin\envsubst.exe
13241300x8000000000000000672030Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.775{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\BinProductVersion(Empty)
13241300x8000000000000000672029Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.775{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672028Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.775{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\Publisher(Empty)
13241300x8000000000000000672027Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.775{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\env.exe|7508509d7b06f998\LowerCaseLongPathc:\program files\git\usr\bin\env.exe
13241300x8000000000000000672026Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.772{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\BinProductVersion(Empty)
13241300x8000000000000000672025Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.772{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672024Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.772{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\Publisher(Empty)
13241300x8000000000000000672023Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.772{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test_dll.ex|2cd5024859c22e2e\LowerCaseLongPathc:\program files\git\mingw64\bin\edit_test_dll.exe
13241300x8000000000000000672022Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.770{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\BinProductVersion(Empty)
13241300x8000000000000000672021Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.770{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672020Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.770{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\Publisher(Empty)
13241300x8000000000000000672019Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.770{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit_test.exe|e47ad3e671162baa\LowerCaseLongPathc:\program files\git\mingw64\bin\edit_test.exe
13241300x8000000000000000672018Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.768{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\BinProductVersion(Empty)
13241300x8000000000000000672017Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.768{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\LinkDate03/27/2021 09:48:39
13241300x8000000000000000672016Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.767{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\Publisher(Empty)
13241300x8000000000000000672015Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.767{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\edit-git-bash.ex|c4b83d4312564a9\LowerCaseLongPathc:\program files\git\mingw64\share\git\edit-git-bash.exe
13241300x8000000000000000672014Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\echo.exe|263446599120623a\BinProductVersion(Empty)
13241300x8000000000000000672013Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\echo.exe|263446599120623a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672012Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\echo.exe|263446599120623a\Publisher(Empty)
13241300x8000000000000000672011Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\echo.exe|263446599120623a\LowerCaseLongPathc:\program files\git\usr\bin\echo.exe
13241300x8000000000000000672010Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.752{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\BinProductVersion(Empty)
13241300x8000000000000000672009Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.752{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672008Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.750{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\Publisher(Empty)
13241300x8000000000000000672007Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.750{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dumpsexp.exe|45a2659c07e3df2c\LowerCaseLongPathc:\program files\git\usr\bin\dumpsexp.exe
13241300x8000000000000000672006Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\BinProductVersion(Empty)
13241300x8000000000000000672005Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672004Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\Publisher(Empty)
13241300x8000000000000000672003Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\du.exe|2b10b32847099da7\LowerCaseLongPathc:\program files\git\usr\bin\du.exe
13241300x8000000000000000672002Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\BinProductVersion(Empty)
13241300x8000000000000000672001Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672000Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\Publisher(Empty)
13241300x8000000000000000671999Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dos2unix.exe|e819f56941027f1c\LowerCaseLongPathc:\program files\git\usr\bin\dos2unix.exe
13241300x8000000000000000671998Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\BinProductVersion(Empty)
13241300x8000000000000000671997Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671996Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\Publisher(Empty)
13241300x8000000000000000671995Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirname.exe|b029038512034ced\LowerCaseLongPathc:\program files\git\usr\bin\dirname.exe
13241300x8000000000000000671994Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\BinProductVersion(Empty)
13241300x8000000000000000671993Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671992Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\Publisher(Empty)
13241300x8000000000000000671991Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.731{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr.exe|fe24969724873327\LowerCaseLongPathc:\program files\git\usr\bin\dirmngr.exe
13241300x8000000000000000671990Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.723{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\BinProductVersion(Empty)
13241300x8000000000000000671989Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.723{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671988Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.723{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\Publisher(Empty)
13241300x8000000000000000671987Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.723{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dirmngr-client.e|d59c8fc399717975\LowerCaseLongPathc:\program files\git\usr\bin\dirmngr-client.exe
13241300x8000000000000000671986Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\BinProductVersion(Empty)
13241300x8000000000000000671985Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671984Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\Publisher(Empty)
13241300x8000000000000000671983Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dircolors.exe|2c054bf1c4846ccd\LowerCaseLongPathc:\program files\git\usr\bin\dircolors.exe
13241300x8000000000000000671982Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\BinProductVersion(Empty)
13241300x8000000000000000671981Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671980Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\Publisher(Empty)
13241300x8000000000000000671979Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dir.exe|100b2e6a725becca\LowerCaseLongPathc:\program files\git\usr\bin\dir.exe
13241300x8000000000000000671978Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.712{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\BinProductVersion(Empty)
13241300x8000000000000000671977Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.711{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671976Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.711{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\Publisher(Empty)
13241300x8000000000000000671975Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.711{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff3.exe|db0f57bb42b2e275\LowerCaseLongPathc:\program files\git\usr\bin\diff3.exe
13241300x8000000000000000671974Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.709{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\BinProductVersion(Empty)
13241300x8000000000000000671973Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.709{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671972Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.708{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\Publisher(Empty)
13241300x8000000000000000671971Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.708{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\diff.exe|c7ecb5c4d9c537e1\LowerCaseLongPathc:\program files\git\usr\bin\diff.exe
13241300x8000000000000000671970Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\BinProductVersion(Empty)
13241300x8000000000000000671969Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671968Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\Publisher(Empty)
13241300x8000000000000000671967Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\df.exe|65dd80792ce5f665\LowerCaseLongPathc:\program files\git\usr\bin\df.exe
13241300x8000000000000000671966Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\BinProductVersion(Empty)
13241300x8000000000000000671965Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671964Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\Publisher(Empty)
13241300x8000000000000000671963Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dd.exe|d6bffb363596af3e\LowerCaseLongPathc:\program files\git\usr\bin\dd.exe
13241300x8000000000000000671962Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\BinProductVersion(Empty)
13241300x8000000000000000671961Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671960Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\Publisher(Empty)
13241300x8000000000000000671959Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\date.exe|15400b5e3ba75572\LowerCaseLongPathc:\program files\git\usr\bin\date.exe
13241300x8000000000000000671958Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\BinProductVersion(Empty)
13241300x8000000000000000671957Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671956Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\Publisher(Empty)
13241300x8000000000000000671955Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\dash.exe|d7e7d55ce6ee5457\LowerCaseLongPathc:\program files\git\usr\bin\dash.exe
13241300x8000000000000000671954Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\BinProductVersion(Empty)
13241300x8000000000000000671953Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671952Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\Publisher(Empty)
13241300x8000000000000000671951Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\d2u.exe|9a42254ebeca6f7a\LowerCaseLongPathc:\program files\git\usr\bin\d2u.exe
13241300x8000000000000000671950Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\BinProductVersion(Empty)
13241300x8000000000000000671949Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\LinkDate03/26/2021 22:24:41
13241300x8000000000000000671948Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\Publisher(Empty)
13241300x8000000000000000671947Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.678{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygwin-console-h|5323f22aa324e252\LowerCaseLongPathc:\program files\git\usr\bin\cygwin-console-helper.exe
13241300x8000000000000000671946Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.662{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\BinProductVersion(Empty)
13241300x8000000000000000671945Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.662{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\LinkDate03/26/2021 22:24:39
13241300x8000000000000000671944Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.662{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\Publisher(Empty)
13241300x8000000000000000671943Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.662{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygpath.exe|89e407d49466bcd8\LowerCaseLongPathc:\program files\git\usr\bin\cygpath.exe
13241300x8000000000000000671942Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.647{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\BinProductVersion(Empty)
13241300x8000000000000000671941Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.647{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\LinkDate03/26/2021 22:24:41
13241300x8000000000000000671940Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.647{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\Publisher(Empty)
13241300x8000000000000000671939Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.647{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cygcheck.exe|6a2038f6387fe2d8\LowerCaseLongPathc:\program files\git\usr\bin\cygcheck.exe
13241300x8000000000000000671938Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\BinProductVersion(Empty)
13241300x8000000000000000671937Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671936Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\Publisher(Empty)
13241300x8000000000000000671935Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cut.exe|19b3f09ad648b49b\LowerCaseLongPathc:\program files\git\usr\bin\cut.exe
13241300x8000000000000000671934Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\BinProductVersion(Empty)
13241300x8000000000000000671933Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\LinkDate02/04/2021 08:40:35
13241300x8000000000000000671932Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\Publisher(Empty)
13241300x8000000000000000671931Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.631{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\curl.exe|34ac32e380c639e7\LowerCaseLongPathc:\program files\git\mingw64\bin\curl.exe
13241300x8000000000000000671930Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.620{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\BinProductVersion(Empty)
13241300x8000000000000000671929Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.620{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671928Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.620{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\Publisher(Empty)
13241300x8000000000000000671927Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.620{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\csplit.exe|86edd40dc8e531c1\LowerCaseLongPathc:\program files\git\usr\bin\csplit.exe
13241300x8000000000000000671926Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\BinProductVersion(Empty)
13241300x8000000000000000671925Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671924Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\Publisher(Empty)
13241300x8000000000000000671923Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\create-shortcut.|7be1e57c6a9b6d74\LowerCaseLongPathc:\program files\git\mingw64\bin\create-shortcut.exe
13241300x8000000000000000671922Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\BinProductVersion(Empty)
13241300x8000000000000000671921Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671920Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\Publisher(Empty)
13241300x8000000000000000671919Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cp.exe|a9aa2ba1cc55a1d1\LowerCaseLongPathc:\program files\git\usr\bin\cp.exe
13241300x8000000000000000671918Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\BinProductVersion(Empty)
13241300x8000000000000000671917Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671916Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\Publisher(Empty)
13241300x8000000000000000671915Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\connect.exe|98a1b69f7698c1b1\LowerCaseLongPathc:\program files\git\mingw64\bin\connect.exe
13241300x8000000000000000671914Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\BinProductVersion2.31.1.1
13241300x8000000000000000671913Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\LinkDate03/27/2021 09:48:40
13241300x8000000000000000671912Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\Publisherthe git development community
13241300x8000000000000000671911Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.599{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\compat-bash.exe|2353d7f66f7d8a47\LowerCaseLongPathc:\program files\git\mingw64\share\git\compat-bash.exe
13241300x8000000000000000671910Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.596{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\BinProductVersion(Empty)
13241300x8000000000000000671909Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.596{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671908Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.596{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\Publisher(Empty)
13241300x8000000000000000671907Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.596{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\comm.exe|9b9df3e9f04bb630\LowerCaseLongPathc:\program files\git\usr\bin\comm.exe
13241300x8000000000000000671906Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.596{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\BinProductVersion(Empty)
13241300x8000000000000000671905Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.596{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671904Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.595{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\Publisher(Empty)
13241300x8000000000000000671903Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.595{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\column.exe|a0a6e93c07d1168\LowerCaseLongPathc:\program files\git\usr\bin\column.exe
13241300x8000000000000000671902Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\BinProductVersion(Empty)
13241300x8000000000000000671901Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671900Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\Publisher(Empty)
13241300x8000000000000000671899Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cmp.exe|de6ed9764cfeeb7f\LowerCaseLongPathc:\program files\git\usr\bin\cmp.exe
13241300x8000000000000000671898Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\BinProductVersion(Empty)
13241300x8000000000000000671897Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671896Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\Publisher(Empty)
13241300x8000000000000000671895Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\clear.exe|23d1f6608a1d3194\LowerCaseLongPathc:\program files\git\usr\bin\clear.exe
13241300x8000000000000000671894Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\BinProductVersion(Empty)
13241300x8000000000000000671893Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\LinkDate10/26/1974 18:18:40
13241300x8000000000000000671892Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\Publisher(Empty)
13241300x8000000000000000671891Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cldr-plurals.exe|acec4b705bc23965\LowerCaseLongPathc:\program files\git\usr\lib\gettext\cldr-plurals.exe
13241300x8000000000000000671890Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\BinProductVersion(Empty)
13241300x8000000000000000671889Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671888Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\Publisher(Empty)
13241300x8000000000000000671887Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cksum.exe|877b1cc41ae31cae\LowerCaseLongPathc:\program files\git\usr\bin\cksum.exe
13241300x8000000000000000671886Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\BinProductVersion(Empty)
13241300x8000000000000000671885Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671884Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\Publisher(Empty)
13241300x8000000000000000671883Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chroot.exe|699e7ae138a98a36\LowerCaseLongPathc:\program files\git\usr\bin\chroot.exe
13241300x8000000000000000671882Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\BinProductVersion(Empty)
13241300x8000000000000000671881Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671880Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\Publisher(Empty)
13241300x8000000000000000671879Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chown.exe|6e51d9aedefdf80f\LowerCaseLongPathc:\program files\git\usr\bin\chown.exe
13241300x8000000000000000671878Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\BinProductVersion(Empty)
13241300x8000000000000000671877Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671876Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\Publisher(Empty)
13241300x8000000000000000671875Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chmod.exe|e3ddbff0fcd6c5e6\LowerCaseLongPathc:\program files\git\usr\bin\chmod.exe
13241300x8000000000000000671874Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\BinProductVersion(Empty)
13241300x8000000000000000671873Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671872Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\Publisher(Empty)
13241300x8000000000000000671871Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.576{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chgrp.exe|bb039b4cd0c6f545\LowerCaseLongPathc:\program files\git\usr\bin\chgrp.exe
13241300x8000000000000000671870Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\BinProductVersion(Empty)
13241300x8000000000000000671869Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671868Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\Publisher(Empty)
13241300x8000000000000000671867Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chcon.exe|8f0fac908d5773b6\LowerCaseLongPathc:\program files\git\usr\bin\chcon.exe
13241300x8000000000000000671866Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\BinProductVersion(Empty)
13241300x8000000000000000671865Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\LinkDate03/26/2021 22:24:39
13241300x8000000000000000671864Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\Publisher(Empty)
13241300x8000000000000000671863Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.564{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\chattr.exe|29db3d1af543269b\LowerCaseLongPathc:\program files\git\usr\bin\chattr.exe
13241300x8000000000000000671862Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\BinProductVersion(Empty)
13241300x8000000000000000671861Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671860Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\Publisher(Empty)
13241300x8000000000000000671859Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\cat.exe|c9bdbcd78462df5e\LowerCaseLongPathc:\program files\git\usr\bin\cat.exe
13241300x8000000000000000671858Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\BinProductVersion(Empty)
13241300x8000000000000000671857Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671856Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\Publisher(Empty)
13241300x8000000000000000671855Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.552{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\captoinfo.exe|ae170334068304db\LowerCaseLongPathc:\program files\git\usr\bin\captoinfo.exe
13241300x8000000000000000671854Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\BinProductVersion(Empty)
13241300x8000000000000000671853Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671852Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\Publisher(Empty)
13241300x8000000000000000671851Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|7b4916700fd7fa54\LowerCaseLongPathc:\program files\git\mingw64\bin\bzip2recover.exe
13241300x8000000000000000671850Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\BinProductVersion(Empty)
13241300x8000000000000000671849Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671848Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\Publisher(Empty)
13241300x8000000000000000671847Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2recover.exe|6fb043bab87a8c4c\LowerCaseLongPathc:\program files\git\usr\bin\bzip2recover.exe
13241300x8000000000000000671846Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\BinProductVersion(Empty)
13241300x8000000000000000671845Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671844Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\Publisher(Empty)
13241300x8000000000000000671843Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|cecf80293919b675\LowerCaseLongPathc:\program files\git\mingw64\bin\bzip2.exe
13241300x8000000000000000671842Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\BinProductVersion(Empty)
13241300x8000000000000000671841Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671840Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\Publisher(Empty)
13241300x8000000000000000671839Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzip2.exe|6e87155dac2f4c04\LowerCaseLongPathc:\program files\git\usr\bin\bzip2.exe
13241300x8000000000000000671838Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\BinProductVersion(Empty)
13241300x8000000000000000671837Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671836Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\Publisher(Empty)
13241300x8000000000000000671835Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.529{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|5bd95ec17b3dd431\LowerCaseLongPathc:\program files\git\usr\bin\bzcat.exe
13241300x8000000000000000671834Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\BinProductVersion(Empty)
13241300x8000000000000000671833Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671832Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\Publisher(Empty)
13241300x8000000000000000671831Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bzcat.exe|22efe6404fe377ef\LowerCaseLongPathc:\program files\git\mingw64\bin\bzcat.exe
13241300x8000000000000000671830Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\BinProductVersion(Empty)
13241300x8000000000000000671829Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671828Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\Publisher(Empty)
13241300x8000000000000000671827Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.514{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|e3db3453bc608648\LowerCaseLongPathc:\program files\git\mingw64\bin\bunzip2.exe
13241300x8000000000000000671826Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\BinProductVersion(Empty)
13241300x8000000000000000671825Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671824Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\Publisher(Empty)
13241300x8000000000000000671823Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bunzip2.exe|9ac74d590cb04f1a\LowerCaseLongPathc:\program files\git\usr\bin\bunzip2.exe
13241300x8000000000000000671822Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\BinProductVersion(Empty)
13241300x8000000000000000671821Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671820Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\Publisher(Empty)
13241300x8000000000000000671819Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.498{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\brotli.exe|31204f639af895eb\LowerCaseLongPathc:\program files\git\mingw64\bin\brotli.exe
13241300x8000000000000000671818Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\BinProductVersion(Empty)
13241300x8000000000000000671817Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671816Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\Publisher(Empty)
13241300x8000000000000000671815Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\blocked-file-uti|26a5d90fb1352887\LowerCaseLongPathc:\program files\git\mingw64\bin\blocked-file-util.exe
13241300x8000000000000000671814Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\BinProductVersion2.31.1.1
13241300x8000000000000000671813Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\LinkDate03/27/2021 09:48:40
13241300x8000000000000000671812Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\Publisherthe git development community
13241300x8000000000000000671811Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|82493e8a87323f44\LowerCaseLongPathc:\program files\git\bin\bash.exe
13241300x8000000000000000671810Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\BinProductVersion(Empty)
13241300x8000000000000000671809Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\LinkDate12/04/2018 10:21:15
13241300x8000000000000000671808Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\Publisher(Empty)
13241300x8000000000000000671807Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\bash.exe|5f326cb536e85740\LowerCaseLongPathc:\program files\git\usr\bin\bash.exe
13241300x8000000000000000671806Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\BinProductVersion(Empty)
23542300x8000000000000000572677Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:02.289{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=BDA7ACB26D74974DEC0D48F73D7BB024,SHA256=EBCAD8A31248ED81CCD4D6918C255CC5B1EDAB3E76A152CDEAABB164268334D3,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572676Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:02.289{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=4C3B14A8A700FEC9B65E2826D25D1AD6,SHA256=E9D5298E884E0F65AC62DE96D7C90AF54F6ECD5F30AF084C16A93A98F018F63A,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671805Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671804Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\Publisher(Empty)
13241300x8000000000000000671803Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basenc.exe|441974f40d711257\LowerCaseLongPathc:\program files\git\usr\bin\basenc.exe
13241300x8000000000000000671802Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\BinProductVersion(Empty)
13241300x8000000000000000671801Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671800Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\Publisher(Empty)
13241300x8000000000000000671799Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\basename.exe|47ada093d5bb600a\LowerCaseLongPathc:\program files\git\usr\bin\basename.exe
13241300x8000000000000000671798Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\BinProductVersion(Empty)
13241300x8000000000000000671797Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671796Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\Publisher(Empty)
13241300x8000000000000000671795Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base64.exe|962b95c6244d4b06\LowerCaseLongPathc:\program files\git\usr\bin\base64.exe
13241300x8000000000000000671794Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\BinProductVersion(Empty)
13241300x8000000000000000671793Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671792Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\Publisher(Empty)
13241300x8000000000000000671791Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.445{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\base32.exe|a314ab833a8613c9\LowerCaseLongPathc:\program files\git\usr\bin\base32.exe
13241300x8000000000000000671790Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\BinProductVersion(Empty)
13241300x8000000000000000671789Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671788Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\Publisher(Empty)
13241300x8000000000000000671787Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\b2sum.exe|29b37ad7ebd1394a\LowerCaseLongPathc:\program files\git\usr\bin\b2sum.exe
13241300x8000000000000000671786Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\BinProductVersion(Empty)
13241300x8000000000000000671785Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671784Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\Publisher(Empty)
13241300x8000000000000000671783Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\awk.exe|283395e55c831d1d\LowerCaseLongPathc:\program files\git\usr\bin\awk.exe
13241300x8000000000000000671782Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\BinProductVersion2.0.394.0
13241300x8000000000000000671781Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\LinkDate04/29/2104 14:55:02
13241300x8000000000000000671780Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\Publisheratlassian.bitbucket.ui
13241300x8000000000000000671779Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\atlassian.bitbuc|c03cc9e8c801d513\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\atlassian.bitbucket.ui.exe
13241300x8000000000000000671778Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\BinProductVersion(Empty)
13241300x8000000000000000671777Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671776Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\Publisher(Empty)
13241300x8000000000000000671775Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\arch.exe|6cd29c8ee920e833\LowerCaseLongPathc:\program files\git\usr\bin\arch.exe
13241300x8000000000000000671774Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\BinProductVersion(Empty)
13241300x8000000000000000671773Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671772Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\Publisher(Empty)
13241300x8000000000000000671771Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.413{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\antiword.exe|f9989c5a06cca46c\LowerCaseLongPathc:\program files\git\mingw64\bin\antiword.exe
13241300x8000000000000000671770Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\BinProductVersion(Empty)
13241300x8000000000000000671769Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671768Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\Publisher(Empty)
13241300x8000000000000000671767Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ahost.exe|40c7db6e62088170\LowerCaseLongPathc:\program files\git\mingw64\bin\ahost.exe
13241300x8000000000000000671766Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\BinProductVersion(Empty)
13241300x8000000000000000671765Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671764Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\Publisher(Empty)
13241300x8000000000000000671763Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\adig.exe|8c2dc2d7e3156644\LowerCaseLongPathc:\program files\git\mingw64\bin\adig.exe
13241300x8000000000000000671762Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\BinProductVersion(Empty)
13241300x8000000000000000671761Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671760Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\Publisher(Empty)
13241300x8000000000000000671759Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.398{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\acountry.exe|45550c852fce5231\LowerCaseLongPathc:\program files\git\mingw64\bin\acountry.exe
13241300x8000000000000000671758Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.393{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000c1df386b1b2c5d48d4b44564d46655ae0000ffff\PublisherMozilla
13241300x8000000000000000671757Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.392{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|c3a2a248a1867c34\BinProductVersion1.0.0.0
13241300x8000000000000000671756Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.392{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|c3a2a248a1867c34\LinkDate12/11/2016 21:50:55
13241300x8000000000000000671755Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.392{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|c3a2a248a1867c34\Publishermozilla corporation
13241300x8000000000000000671754Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.392{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|c3a2a248a1867c34\LowerCaseLongPathc:\program files (x86)\mozilla maintenance service\uninstall.exe
13241300x8000000000000000671753Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.390{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|f537de1e8599ad9d\BinProductVersion88.0.1.7794
13241300x8000000000000000671752Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.390{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|f537de1e8599ad9d\LinkDate05/04/2021 16:36:54
13241300x8000000000000000671751Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.390{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|f537de1e8599ad9d\Publishermozilla foundation
13241300x8000000000000000671750Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.389{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\maintenanceservi|f537de1e8599ad9d\LowerCaseLongPathc:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
23542300x8000000000000000671749Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:02.385{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=A7325A5356DA7441A63ACFC8DCCC9D5A,SHA256=39DD1B42A6C231FF6AB6E2310238DB1963B5B86CB0F1695DD9DA1EB974900CEE,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000671748Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.371{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000a9678529fb5fa8569685ef3e4543583f0000ffff\PublisherAmazon Web Services
13241300x8000000000000000671747Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.370{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\amazonssmagentse|9538aa2019cf27d0\BinProductVersion3.0.529.0
13241300x8000000000000000671746Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.370{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\amazonssmagentse|9538aa2019cf27d0\LinkDate05/01/2017 14:33:52
13241300x8000000000000000671745Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.370{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\amazonssmagentse|9538aa2019cf27d0\Publisheramazon web services
13241300x8000000000000000671744Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.370{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\amazonssmagentse|9538aa2019cf27d0\LowerCaseLongPathc:\programdata\package cache\{674c5ef7-9d50-4540-a711-6b82e2469bd0}\amazonssmagentsetup.exe
13241300x8000000000000000671743Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.358{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000a9678529fb5fa8569685ef3e4543583f00000904\PublisherAmazon Web Services
13241300x8000000000000000671742Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.356{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssm-agent-worker|7d818f178f6c8fa8\BinProductVersion(Empty)
13241300x8000000000000000671741Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.356{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssm-agent-worker|7d818f178f6c8fa8\LinkDate01/01/1970 00:00:00
13241300x8000000000000000671740Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.356{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssm-agent-worker|7d818f178f6c8fa8\Publisher(Empty)
13241300x8000000000000000671739Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.356{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssm-agent-worker|7d818f178f6c8fa8\LowerCaseLongPathc:\program files\amazon\ssm\ssm-agent-worker.exe
13241300x8000000000000000671738Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.179{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000a32b64966830ad0100b29547ca5511020000ffff\PublisherAmazon Web Services
13241300x8000000000000000671737Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.163{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\aws-cfn-bootstra|65c81b6df64de18d\BinProductVersion2.0.6.0
13241300x8000000000000000671736Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.163{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\aws-cfn-bootstra|65c81b6df64de18d\LinkDate09/17/2019 05:33:38
13241300x8000000000000000671735Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.163{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\aws-cfn-bootstra|65c81b6df64de18d\Publisheramazon web services
13241300x8000000000000000671734Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.163{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\aws-cfn-bootstra|65c81b6df64de18d\LowerCaseLongPathc:\programdata\package cache\{09259595-ce26-4705-b47e-59d9e3ccebb9}\aws-cfn-bootstrap-bundle.exe
13241300x8000000000000000671733Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.147{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000a0119b997e1ff1f405659fca10378fff0000ffff\PublisherMicrosoft Corporation
13241300x8000000000000000671732Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.147{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\vc_redist.x64.ex|b72113d8ab25b2ea\BinProductVersion14.28.29913.0
13241300x8000000000000000671731Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.147{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\vc_redist.x64.ex|b72113d8ab25b2ea\LinkDate11/18/2017 21:37:28
13241300x8000000000000000671730Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.147{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\vc_redist.x64.ex|b72113d8ab25b2ea\Publishermicrosoft corporation
13241300x8000000000000000671729Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.147{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\vc_redist.x64.ex|b72113d8ab25b2ea\LowerCaseLongPathc:\programdata\package cache\{855e31d2-9031-46e1-b06d-c9d7777deefb}\vc_redist.x64.exe
13241300x8000000000000000671728Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.125{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\000093234134b3a2576f4dc4445ca91cb81100000904\PublisherOpen Information Security Foundation
13241300x8000000000000000671727Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.125{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.exe|5ae00036de77062f\BinProductVersion5.1.20.305
13241300x8000000000000000671726Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.125{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.exe|5ae00036de77062f\LinkDate08/01/2020 03:02:30
13241300x8000000000000000671725Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.125{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.exe|5ae00036de77062f\Publisher(Empty)
13241300x8000000000000000671724Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.125{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.exe|5ae00036de77062f\LowerCaseLongPathc:\temp\npcap.exe
13241300x8000000000000000671723Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\00006e465eb93b9ef9ed1111015f594f733000000904\PublisherSplunk, Inc.
13241300x8000000000000000671722Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\srm.exe|928901d4ccf4225c\BinProductVersion(Empty)
13241300x8000000000000000671721Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\srm.exe|928901d4ccf4225c\LinkDate01/10/2020 01:30:07
13241300x8000000000000000671720Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\srm.exe|928901d4ccf4225c\Publisher(Empty)
13241300x8000000000000000671719Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\srm.exe|928901d4ccf4225c\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\srm.exe
13241300x8000000000000000671718Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkmonitornoh|e59d09056446ab10\BinProductVersion10.0.10011.16384
13241300x8000000000000000671717Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkmonitornoh|e59d09056446ab10\LinkDate10/02/2019 17:37:14
13241300x8000000000000000671716Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkmonitornoh|e59d09056446ab10\Publisherwindows (r) win 7 ddk provider
13241300x8000000000000000671715Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.111{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkmonitornoh|e59d09056446ab10\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunkmonitornohandledrv.sys
13241300x8000000000000000671714Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkdrv.sys|d26d9681615e2fde\BinProductVersion10.0.10011.16384
13241300x8000000000000000671713Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkdrv.sys|d26d9681615e2fde\LinkDate10/02/2019 17:37:08
13241300x8000000000000000671712Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkdrv.sys|d26d9681615e2fde\Publisherwindows (r) win 7 ddk provider
13241300x8000000000000000671711Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkdrv.sys|d26d9681615e2fde\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunkdrv.sys
13241300x8000000000000000671710Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkd.exe|97fa29633c3fe2cc\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671709Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkd.exe|97fa29633c3fe2cc\LinkDate02/07/2020 15:26:19
13241300x8000000000000000671708Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkd.exe|97fa29633c3fe2cc\Publishersplunk inc.
13241300x8000000000000000671707Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.079{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunkd.exe|97fa29633c3fe2cc\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunkd.exe
13241300x8000000000000000671706Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk.exe|a8c4bd649036a5f1\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671705Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk.exe|a8c4bd649036a5f1\LinkDate02/07/2020 15:13:21
13241300x8000000000000000671704Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk.exe|a8c4bd649036a5f1\Publishersplunk inc.
13241300x8000000000000000671703Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk.exe|a8c4bd649036a5f1\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk.exe
13241300x8000000000000000671702Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-wmi.exe|fd58174ea9e370c0\BinProductVersion2048.512.24125.32311
13241300x8000000000000000671701Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-wmi.exe|fd58174ea9e370c0\LinkDate02/07/2020 15:24:43
13241300x8000000000000000671700Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-wmi.exe|fd58174ea9e370c0\Publishersplunk inc.
13241300x8000000000000000671699Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:01.992{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\splunk-wmi.exe|fd58174ea9e370c0\LowerCaseLongPathc:\program files\splunkuniversalforwarder\bin\splunk-wmi.exe
23542300x8000000000000000572680Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:03.726{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=80E90F94771750D5E19DCD64DE5E402C,SHA256=4B46E0E01CE06D1270DAECB1D540636C02BDCEE12FA1AE17F75ED8EB1FECD073,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672419Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.991{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-push.ex|68d3cf7d040e7329\BinProductVersion2.31.1.1
13241300x8000000000000000672418Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.991{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-push.ex|68d3cf7d040e7329\LinkDate03/27/2021 09:56:32
13241300x8000000000000000672417Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.991{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-push.ex|68d3cf7d040e7329\Publisherthe git development community
13241300x8000000000000000672416Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.991{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-push.ex|68d3cf7d040e7329\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-http-push.exe
13241300x8000000000000000672415Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.972{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-fetch.e|ab1d6cbc9e29e771\BinProductVersion2.31.1.1
13241300x8000000000000000672414Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.972{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-fetch.e|ab1d6cbc9e29e771\LinkDate03/27/2021 09:56:30
13241300x8000000000000000672413Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.972{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-fetch.e|ab1d6cbc9e29e771\Publisherthe git development community
13241300x8000000000000000672412Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.972{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-fetch.e|ab1d6cbc9e29e771\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-http-fetch.exe
354300x8000000000000000672411Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:02.471{7B03F3B2-5129-609D-6050-00000000BA01}7104C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-18.attackrange.local51189-false10.0.1.12-8000-
13241300x8000000000000000672410Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.953{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-backend|bf2a9779f0e0f190\BinProductVersion2.31.1.1
13241300x8000000000000000672409Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.953{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-backend|bf2a9779f0e0f190\LinkDate03/27/2021 09:56:26
13241300x8000000000000000672408Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.953{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-backend|bf2a9779f0e0f190\Publisherthe git development community
13241300x8000000000000000672407Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.953{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-http-backend|bf2a9779f0e0f190\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-http-backend.exe
13241300x8000000000000000672406Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.937{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-help.exe|d3d7cc6cd9ec775b\BinProductVersion2.31.1.1
13241300x8000000000000000672405Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.937{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-help.exe|d3d7cc6cd9ec775b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672404Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.936{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-help.exe|d3d7cc6cd9ec775b\Publisherthe git development community
13241300x8000000000000000672403Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.936{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-help.exe|d3d7cc6cd9ec775b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-help.exe
13241300x8000000000000000672402Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.922{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-hash-object.|ea29aa5df7dca895\BinProductVersion2.31.1.1
13241300x8000000000000000672401Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.922{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-hash-object.|ea29aa5df7dca895\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672400Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.921{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-hash-object.|ea29aa5df7dca895\Publisherthe git development community
13241300x8000000000000000672399Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.921{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-hash-object.|ea29aa5df7dca895\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-hash-object.exe
13241300x8000000000000000672398Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.911{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gui.exe|d3e16d00d6d9753e\BinProductVersion2.31.1.1
13241300x8000000000000000672397Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.911{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gui.exe|d3e16d00d6d9753e\LinkDate03/27/2021 09:48:41
13241300x8000000000000000672396Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.911{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gui.exe|d3e16d00d6d9753e\Publisherthe git development community
13241300x8000000000000000672395Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gui.exe|d3e16d00d6d9753e\LowerCaseLongPathc:\program files\git\cmd\git-gui.exe
13241300x8000000000000000672394Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.906{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-grep.exe|ed39fb46aff75ef0\BinProductVersion2.31.1.1
13241300x8000000000000000672393Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.906{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-grep.exe|ed39fb46aff75ef0\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672392Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.906{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-grep.exe|ed39fb46aff75ef0\Publisherthe git development community
13241300x8000000000000000672391Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.906{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-grep.exe|ed39fb46aff75ef0\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-grep.exe
13241300x8000000000000000672390Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.892{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-get-tar-comm|7f010af0ea09c9e6\BinProductVersion2.31.1.1
13241300x8000000000000000672389Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.892{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-get-tar-comm|7f010af0ea09c9e6\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672388Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.892{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-get-tar-comm|7f010af0ea09c9e6\Publisherthe git development community
13241300x8000000000000000672387Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.892{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-get-tar-comm|7f010af0ea09c9e6\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-get-tar-commit-id.exe
13241300x8000000000000000672386Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.881{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gc.exe|fdbdc98f5cb28d88\BinProductVersion2.31.1.1
13241300x8000000000000000672385Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.881{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gc.exe|fdbdc98f5cb28d88\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672384Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.881{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gc.exe|fdbdc98f5cb28d88\Publisherthe git development community
13241300x8000000000000000672383Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.881{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-gc.exe|fdbdc98f5cb28d88\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-gc.exe
13241300x8000000000000000672382Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.871{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsmonitor--d|e5fc2f5ce2dcd18a\BinProductVersion2.31.1.1
13241300x8000000000000000672381Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.871{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsmonitor--d|e5fc2f5ce2dcd18a\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672380Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.871{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsmonitor--d|e5fc2f5ce2dcd18a\Publisherthe git development community
13241300x8000000000000000672379Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.871{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsmonitor--d|e5fc2f5ce2dcd18a\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fsmonitor--daemon.exe
13241300x8000000000000000672378Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck.exe|d8efbaa5b906f8b2\BinProductVersion2.31.1.1
13241300x8000000000000000672377Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck.exe|d8efbaa5b906f8b2\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672376Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck.exe|d8efbaa5b906f8b2\Publisherthe git development community
13241300x8000000000000000672375Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck.exe|d8efbaa5b906f8b2\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fsck.exe
13241300x8000000000000000672374Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck-objects|2121e55928d75601\BinProductVersion2.31.1.1
13241300x8000000000000000672373Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.849{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck-objects|2121e55928d75601\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672372Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.849{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck-objects|2121e55928d75601\Publisherthe git development community
13241300x8000000000000000672371Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.849{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fsck-objects|2121e55928d75601\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fsck-objects.exe
13241300x8000000000000000672370Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.838{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-format-patch|9e2e07188f28a95d\BinProductVersion2.31.1.1
13241300x8000000000000000672369Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.838{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-format-patch|9e2e07188f28a95d\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672368Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.838{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-format-patch|9e2e07188f28a95d\Publisherthe git development community
13241300x8000000000000000672367Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.838{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-format-patch|9e2e07188f28a95d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-format-patch.exe
13241300x8000000000000000672366Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.827{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-rep|c87afe0458a928d\BinProductVersion2.31.1.1
13241300x8000000000000000672365Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.827{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-rep|c87afe0458a928d\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672364Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.827{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-rep|c87afe0458a928d\Publisherthe git development community
13241300x8000000000000000672363Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.827{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-rep|c87afe0458a928d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-for-each-repo.exe
13241300x8000000000000000672362Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.817{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-ref|3abb92553793f6f\BinProductVersion2.31.1.1
13241300x8000000000000000672361Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.817{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-ref|3abb92553793f6f\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672360Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.816{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-ref|3abb92553793f6f\Publisherthe git development community
13241300x8000000000000000672359Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.816{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-for-each-ref|3abb92553793f6f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-for-each-ref.exe
13241300x8000000000000000672358Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.806{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fmt-merge-ms|d963dc4ca06323fa\BinProductVersion2.31.1.1
13241300x8000000000000000672357Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.806{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fmt-merge-ms|d963dc4ca06323fa\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672356Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.806{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fmt-merge-ms|d963dc4ca06323fa\Publisherthe git development community
13241300x8000000000000000672355Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.806{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fmt-merge-ms|d963dc4ca06323fa\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fmt-merge-msg.exe
13241300x8000000000000000672354Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.794{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\BinProductVersion2.31.1.1
13241300x8000000000000000672353Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.794{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672352Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.794{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\Publisherthe git development community
13241300x8000000000000000672351Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.794{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch.exe|26836f160b2136d8\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fetch.exe
13241300x8000000000000000672350Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\BinProductVersion2.31.1.1
13241300x8000000000000000672349Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672348Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\Publisherthe git development community
13241300x8000000000000000672347Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fetch-pack.e|eaa13da8b960bb8f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fetch-pack.exe
13241300x8000000000000000672346Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.773{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\BinProductVersion2.31.1.1
13241300x8000000000000000672345Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.773{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672344Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.773{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\Publisherthe git development community
13241300x8000000000000000672343Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.773{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-import.|6e2bb2de2d0c9142\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fast-import.exe
13241300x8000000000000000672342Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.762{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\BinProductVersion2.31.1.1
13241300x8000000000000000672341Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.762{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672340Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.762{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\Publisherthe git development community
13241300x8000000000000000672339Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.762{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-fast-export.|a89216de984913cf\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-fast-export.exe
13241300x8000000000000000672338Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.749{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\BinProductVersion2.31.1.1
13241300x8000000000000000672337Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.749{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672336Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.749{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\Publisherthe git development community
13241300x8000000000000000672335Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.749{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-env--helper.|2c74ba6e4fc1d4ec\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-env--helper.exe
13241300x8000000000000000672334Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.736{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\BinProductVersion2.31.1.1
13241300x8000000000000000672333Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.736{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672332Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.736{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\Publisherthe git development community
13241300x8000000000000000672331Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.736{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-difftool.exe|903a2ba27de6fa88\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-difftool.exe
13241300x8000000000000000672330Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.730{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\BinProductVersion2.31.1.1
13241300x8000000000000000672329Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.730{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672328Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.730{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\Publisherthe git development community
13241300x8000000000000000672327Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.730{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff.exe|fe3e1c9d29f52286\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff.exe
13241300x8000000000000000672326Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.715{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\BinProductVersion2.31.1.1
13241300x8000000000000000672325Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.715{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672324Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.715{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\Publisherthe git development community
13241300x8000000000000000672323Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.715{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-tree.ex|d17f2f481ab32d12\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff-tree.exe
13241300x8000000000000000672322Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.702{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\BinProductVersion2.31.1.1
13241300x8000000000000000672321Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.702{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672320Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.701{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\Publisherthe git development community
13241300x8000000000000000672319Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.701{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-index.e|3e5a108a9f567115\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff-index.exe
13241300x8000000000000000672318Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.687{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\BinProductVersion2.31.1.1
13241300x8000000000000000672317Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.687{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672316Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.687{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\Publisherthe git development community
13241300x8000000000000000672315Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.687{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-diff-files.e|4b52f8fbf7fa68d0\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-diff-files.exe
13241300x8000000000000000672314Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.674{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\BinProductVersion2.31.1.1
13241300x8000000000000000672313Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.674{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672312Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.674{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\Publisherthe git development community
13241300x8000000000000000672311Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.674{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-describe.exe|ca93040df5afaed5\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-describe.exe
13241300x8000000000000000672310Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.666{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\BinProductVersion2.31.1.1
13241300x8000000000000000672309Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.665{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\LinkDate03/27/2021 09:56:24
13241300x8000000000000000672308Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.665{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\Publisherthe git development community
13241300x8000000000000000672307Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.665{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-daemon.exe|4df8efdd24573ae6\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-daemon.exe
13241300x8000000000000000672306Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.641{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\BinProductVersion2.31.1.1
13241300x8000000000000000672305Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.641{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672304Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.640{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\Publisherthe git development community
13241300x8000000000000000672303Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.640{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential.e|7fcfd8585219b3da\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential.exe
13241300x8000000000000000672302Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.629{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\BinProductVersion(Empty)
13241300x8000000000000000672301Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.629{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\LinkDate03/27/2021 09:48:42
13241300x8000000000000000672300Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.628{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\Publisher(Empty)
13241300x8000000000000000672299Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.628{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-w|dd4fe27e45e1fd6b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-wincred.exe
13241300x8000000000000000672298Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.627{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\BinProductVersion2.31.1.1
13241300x8000000000000000672297Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.627{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672296Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.627{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\Publisherthe git development community
13241300x8000000000000000672295Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.627{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-s|f72ca269558b1404\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-store.exe
13241300x8000000000000000672294Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.607{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\BinProductVersion1.20.0.0
13241300x8000000000000000672293Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.607{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\LinkDate09/05/2019 15:02:13
13241300x8000000000000000672292Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\Publishermicrosoft corporation
13241300x8000000000000000672291Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|55d73dc387b631bc\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-manager.exe
13241300x8000000000000000672290Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.601{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\BinProductVersion2.0.394.0
13241300x8000000000000000672289Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.601{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\LinkDate11/18/2091 14:46:43
13241300x8000000000000000672288Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.601{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\Publishergit-credential-manager-core
13241300x8000000000000000672287Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.600{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-m|425ee5c501baf173\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-manager-core.exe
13241300x8000000000000000672286Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.598{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\BinProductVersion(Empty)
13241300x8000000000000000672285Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.598{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672284Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.598{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\Publisher(Empty)
13241300x8000000000000000672283Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.598{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-h|e6dcddb0bd298778\LowerCaseLongPathc:\program files\git\mingw64\bin\git-credential-helper-selector.exe
13241300x8000000000000000672282Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.597{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\BinProductVersion2.31.1.1
13241300x8000000000000000672281Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.597{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672280Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.597{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\Publisherthe git development community
13241300x8000000000000000672279Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.597{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|2da56af252cfcd16\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-cache.exe
13241300x8000000000000000672278Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.583{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\BinProductVersion2.31.1.1
13241300x8000000000000000672277Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.583{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672276Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.583{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\Publisherthe git development community
13241300x8000000000000000672275Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.582{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-credential-c|17175c202eed73b7\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-credential-cache--daemon.exe
13241300x8000000000000000672274Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.565{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\BinProductVersion2.31.1.1
13241300x8000000000000000672273Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.565{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672272Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.565{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\Publisherthe git development community
13241300x8000000000000000672271Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.565{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-count-object|9f950d53a6a442ff\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-count-objects.exe
13241300x8000000000000000672270Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.553{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\BinProductVersion2.31.1.1
13241300x8000000000000000672269Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.553{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672268Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.553{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\Publisherthe git development community
13241300x8000000000000000672267Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.553{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-config.exe|e75be4b0a6770696\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-config.exe
13241300x8000000000000000672266Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.543{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\BinProductVersion2.31.1.1
13241300x8000000000000000672265Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.543{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672264Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.543{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\Publisherthe git development community
13241300x8000000000000000672263Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.543{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit.exe|6e74d5dae67b444b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-commit.exe
13241300x8000000000000000672262Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.527{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\BinProductVersion2.31.1.1
13241300x8000000000000000672261Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.527{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672260Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.527{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\Publisherthe git development community
13241300x8000000000000000672259Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.527{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-tree.|e83233ce3cd9ee79\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-commit-tree.exe
13241300x8000000000000000672258Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.509{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\BinProductVersion2.31.1.1
13241300x8000000000000000672257Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.509{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672256Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.509{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\Publisherthe git development community
13241300x8000000000000000672255Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.509{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-commit-graph|d249b2d5436de447\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-commit-graph.exe
13241300x8000000000000000672254Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.497{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\BinProductVersion2.31.1.1
13241300x8000000000000000672253Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.497{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672252Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.497{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\Publisherthe git development community
13241300x8000000000000000672251Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.497{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-column.exe|218c406abdb7f5d8\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-column.exe
13241300x8000000000000000672250Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\BinProductVersion2.31.1.1
13241300x8000000000000000672249Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\LinkDate03/27/2021 09:48:40
13241300x8000000000000000672248Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\Publisherthe git development community
13241300x8000000000000000672247Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cmd.exe|7955156508a74f3e\LowerCaseLongPathc:\program files\git\git-cmd.exe
13241300x8000000000000000672246Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\BinProductVersion2.31.1.1
13241300x8000000000000000672245Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672244Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\Publisherthe git development community
13241300x8000000000000000672243Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.478{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clone.exe|d02aef8e1b723e2e\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-clone.exe
13241300x8000000000000000672242Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.457{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\BinProductVersion2.31.1.1
13241300x8000000000000000672241Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.457{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672240Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.457{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\Publisherthe git development community
13241300x8000000000000000672239Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.457{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-clean.exe|d4eb9fccf53085a4\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-clean.exe
13241300x8000000000000000672238Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\BinProductVersion2.31.1.1
13241300x8000000000000000672237Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672236Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\Publisherthe git development community
13241300x8000000000000000672235Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.429{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry.exe|e775100e4df4ef32\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-cherry.exe
23542300x8000000000000000672234Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:03.416{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=E049C5C6F47F0EA19BC83AB5D6BDE5D7,SHA256=77CA0823D123BB74FB0ACABC9B0D07F2DC0D626B1D43BF238F24763245632F15,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672233Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.396{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\BinProductVersion2.31.1.1
13241300x8000000000000000672232Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.396{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672231Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.395{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\Publisherthe git development community
13241300x8000000000000000672230Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.395{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cherry-pick.|997eacdc80577639\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-cherry-pick.exe
13241300x8000000000000000672229Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.371{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\BinProductVersion2.31.1.1
13241300x8000000000000000672228Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.371{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672227Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.371{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\Publisherthe git development community
13241300x8000000000000000672226Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.371{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout.exe|76b55428c67a380b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-checkout.exe
13241300x8000000000000000672225Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.349{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\BinProductVersion2.31.1.1
13241300x8000000000000000672224Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.349{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\LinkDate03/27/2021 09:56:23
354300x8000000000000000572679Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:00.873{E1BD9FC2-D33D-609A-CB00-00000000BB01}1016C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream\windows_x86_64\bin\streamfwd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.15win-host-681.attackrange.local52789-false10.0.1.12ip-10-0-1-12.us-west-2.compute.internal8000-
13241300x8000000000000000672223Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.349{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\Publisherthe git development community
23542300x8000000000000000672222Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:03.345{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=267443EDF66C3EF02A4AA77A9074E76C,SHA256=909622F8659DFEA6CB6676B9CB107E1AF2FC62EDFB83D9F3EA14F195CB622FCB,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672221Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.345{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-checkout-ind|7b051b3e6750a804\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-checkout-index.exe
13241300x8000000000000000672220Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\BinProductVersion2.31.1.1
13241300x8000000000000000672219Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672218Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\Publisherthe git development community
13241300x8000000000000000672217Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ref-fo|4c4aae0ebfb00b85\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-ref-format.exe
13241300x8000000000000000672216Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.298{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\BinProductVersion2.31.1.1
13241300x8000000000000000672215Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.298{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672214Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.298{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\Publisherthe git development community
13241300x8000000000000000672213Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.298{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-mailma|ed52c712797b00dc\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-mailmap.exe
13241300x8000000000000000672212Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\BinProductVersion2.31.1.1
13241300x8000000000000000672211Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672210Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\Publisherthe git development community
13241300x8000000000000000672209Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-ignore|9bc04723247ac2dd\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-ignore.exe
13241300x8000000000000000672208Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.231{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\BinProductVersion2.31.1.1
13241300x8000000000000000672207Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.231{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672206Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.231{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\Publisherthe git development community
13241300x8000000000000000672205Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.231{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-check-attr.e|57c1145da335bf27\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-check-attr.exe
13241300x8000000000000000672204Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.198{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\BinProductVersion2.31.1.1
13241300x8000000000000000672203Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.198{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672202Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.198{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\Publisherthe git development community
13241300x8000000000000000672201Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.198{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-cat-file.exe|d0e6669a50eba4df\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-cat-file.exe
23542300x8000000000000000672200Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:03.166{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=16FB7729A53D4AD8A802CF2ACE902AC2,SHA256=C5D96FC02B5E5A7FCF44515B70DE8C7F5AD940911992D0BEE204A070DF0400EB,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672199Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.150{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\BinProductVersion2.31.1.1
13241300x8000000000000000672198Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.150{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672197Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.150{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\Publisherthe git development community
13241300x8000000000000000672196Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.150{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bundle.exe|fac576bd3a94d60b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-bundle.exe
13241300x8000000000000000672195Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\BinProductVersion2.31.1.1
13241300x8000000000000000672194Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672193Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\Publisherthe git development community
13241300x8000000000000000672192Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bugreport.ex|59a0df6a91883120\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-bugreport.exe
13241300x8000000000000000672191Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.116{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\BinProductVersion2.31.1.1
13241300x8000000000000000672190Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.116{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672189Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.116{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\Publisherthe git development community
13241300x8000000000000000672188Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.116{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-branch.exe|60e03a3ca4e1184b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-branch.exe
13241300x8000000000000000672187Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.105{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\BinProductVersion2.31.1.1
13241300x8000000000000000672186Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.105{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672185Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.105{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\Publisherthe git development community
13241300x8000000000000000672184Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.105{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-blame.exe|695e1b21d217f64a\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-blame.exe
13241300x8000000000000000672183Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.088{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\BinProductVersion2.31.1.1
13241300x8000000000000000672182Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.088{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672181Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.087{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\Publisherthe git development community
13241300x8000000000000000672180Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.087{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bisect--help|2b85661c358f83f3\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-bisect--helper.exe
13241300x8000000000000000672179Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.076{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\BinProductVersion2.31.1.1
13241300x8000000000000000672178Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.076{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\LinkDate03/27/2021 09:48:40
13241300x8000000000000000672177Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.076{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\Publisherthe git development community
13241300x8000000000000000672176Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.076{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-bash.exe|bb55e09d0018cc9\LowerCaseLongPathc:\program files\git\git-bash.exe
13241300x8000000000000000672175Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\BinProductVersion(Empty)
13241300x8000000000000000672174Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672173Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\Publisher(Empty)
13241300x8000000000000000672172Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askyesno.exe|307382c653791a6b\LowerCaseLongPathc:\program files\git\mingw64\bin\git-askyesno.exe
13241300x8000000000000000672171Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.067{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\BinProductVersion1.20.0.0
13241300x8000000000000000672170Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.067{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\LinkDate09/06/2019 12:59:42
13241300x8000000000000000672169Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.067{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\Publishermicrosoft corporation
13241300x8000000000000000672168Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.067{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-askpass.exe|ac0f34128b42387d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-askpass.exe
13241300x8000000000000000672167Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.061{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\BinProductVersion2.31.1.1
13241300x8000000000000000672166Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.060{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672165Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.060{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\Publisherthe git development community
13241300x8000000000000000672164Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.060{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-archive.exe|36a80009064dc962\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-archive.exe
13241300x8000000000000000672163Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.039{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\BinProductVersion2.31.1.1
13241300x8000000000000000672162Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.039{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672161Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.039{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\Publisherthe git development community
13241300x8000000000000000672160Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.039{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-apply.exe|12e49d92e436268f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-apply.exe
13241300x8000000000000000672159Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:03.010{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\BinProductVersion2.31.1.1
13241300x8000000000000000672158Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:03.010{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672157Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:03.010{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\Publisherthe git development community
13241300x8000000000000000672156Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:03.010{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-annotate.exe|a44a56d360566d96\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-annotate.exe
13241300x8000000000000000672155Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.999{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\BinProductVersion2.31.1.1
13241300x8000000000000000672154Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.999{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672153Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.999{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\Publisherthe git development community
13241300x8000000000000000672152Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.998{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-am.exe|4f482c30f10b83a7\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-am.exe
13241300x8000000000000000672151Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.988{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\BinProductVersion2.31.1.1
13241300x8000000000000000672150Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.988{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672149Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.988{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\Publisherthe git development community
13241300x8000000000000000672148Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.988{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-add.exe|cbf55eec74d083b3\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-add.exe
13241300x8000000000000000672147Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\BinProductVersion(Empty)
13241300x8000000000000000672146Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672145Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\Publisher(Empty)
13241300x8000000000000000672144Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gio-querymodules|c9cec5f8077b3334\LowerCaseLongPathc:\program files\git\usr\bin\gio-querymodules.exe
13241300x8000000000000000672143Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\BinProductVersion0.19.8.0
13241300x8000000000000000672142Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\LinkDate01/01/1970 04:44:00
13241300x8000000000000000672141Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\Publisherfree software foundation
13241300x8000000000000000672140Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.950{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|8596cb6c6d32afb4\LowerCaseLongPathc:\program files\git\usr\bin\gettext.exe
13241300x8000000000000000672139Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.949{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\BinProductVersion0.19.8.0
13241300x8000000000000000672138Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.948{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672137Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.948{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\Publisherfree software foundation
13241300x8000000000000000672136Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.948{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gettext.exe|3980488749a39656\LowerCaseLongPathc:\program files\git\mingw64\bin\gettext.exe
13241300x8000000000000000672135Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.944{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\BinProductVersion(Empty)
13241300x8000000000000000672134Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.944{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\LinkDate03/26/2021 22:24:41
13241300x8000000000000000672133Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.944{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\Publisher(Empty)
13241300x8000000000000000672132Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.944{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr64.ex|683e30977215239e\LowerCaseLongPathc:\program files\git\usr\libexec\getprocaddr64.exe
13241300x8000000000000000672131Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.934{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\BinProductVersion(Empty)
13241300x8000000000000000672130Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.934{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\LinkDate03/26/2021 22:24:41
13241300x8000000000000000672129Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.934{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\Publisher(Empty)
13241300x8000000000000000672128Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.934{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getprocaddr32.ex|11de5925d9c6baa7\LowerCaseLongPathc:\program files\git\usr\libexec\getprocaddr32.exe
13241300x8000000000000000672127Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\BinProductVersion(Empty)
13241300x8000000000000000672126Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672125Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\Publisher(Empty)
13241300x8000000000000000672124Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getopt.exe|b37205341d75e599\LowerCaseLongPathc:\program files\git\usr\bin\getopt.exe
13241300x8000000000000000672123Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\BinProductVersion(Empty)
13241300x8000000000000000672122Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.925{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\LinkDate03/26/2021 22:24:39
13241300x8000000000000000672121Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.925{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\Publisher(Empty)
13241300x8000000000000000672120Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.925{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getfacl.exe|69b0f93924f494f7\LowerCaseLongPathc:\program files\git\usr\bin\getfacl.exe
13241300x8000000000000000672119Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.919{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\BinProductVersion(Empty)
13241300x8000000000000000672118Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.919{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\LinkDate03/26/2021 22:24:39
13241300x8000000000000000672117Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.919{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\Publisher(Empty)
13241300x8000000000000000672116Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.919{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\getconf.exe|c7f6d864684a6d19\LowerCaseLongPathc:\program files\git\usr\bin\getconf.exe
13241300x8000000000000000672115Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.913{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\BinProductVersion(Empty)
13241300x8000000000000000672114Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.913{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\LinkDate03/26/2021 22:24:39
13241300x8000000000000000672113Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.913{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\Publisher(Empty)
13241300x8000000000000000672112Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.913{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gencat.exe|89f29a911ad31f09\LowerCaseLongPathc:\program files\git\usr\bin\gencat.exe
13241300x8000000000000000672111Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\BinProductVersion(Empty)
13241300x8000000000000000672110Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672109Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\Publisher(Empty)
13241300x8000000000000000672108Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gdbus.exe|bf2693ac7275e90\LowerCaseLongPathc:\program files\git\usr\bin\gdbus.exe
13241300x8000000000000000672107Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\BinProductVersion(Empty)
13241300x8000000000000000672106Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672105Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\Publisher(Empty)
13241300x8000000000000000672104Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.910{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk.exe|33613608746cae13\LowerCaseLongPathc:\program files\git\usr\bin\gawk.exe
13241300x8000000000000000672103Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.900{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\BinProductVersion(Empty)
13241300x8000000000000000672102Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.900{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672101Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.900{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\Publisher(Empty)
13241300x8000000000000000672100Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.900{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gawk-5.0.0.exe|709e9d005b0b4928\LowerCaseLongPathc:\program files\git\usr\bin\gawk-5.0.0.exe
13241300x8000000000000000672099Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.891{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\BinProductVersion(Empty)
13241300x8000000000000000672098Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.891{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672097Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.891{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\Publisher(Empty)
13241300x8000000000000000672096Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.891{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gapplication.exe|4ee0a6aaade17793\LowerCaseLongPathc:\program files\git\usr\bin\gapplication.exe
13241300x8000000000000000672095Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.890{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\BinProductVersion(Empty)
13241300x8000000000000000672094Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.890{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\LinkDate05/08/2031 18:06:26
13241300x8000000000000000672093Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.889{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\Publisher(Empty)
13241300x8000000000000000672092Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.889{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\funzip.exe|8d9537366e67e65c\LowerCaseLongPathc:\program files\git\usr\bin\funzip.exe
13241300x8000000000000000672091Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.883{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\BinProductVersion(Empty)
13241300x8000000000000000672090Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.883{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672089Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.883{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\Publisher(Empty)
13241300x8000000000000000672088Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.883{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\frcode.exe|c02ff0fb50c67deb\LowerCaseLongPathc:\program files\git\usr\libexec\frcode.exe
13241300x8000000000000000672087Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.882{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\BinProductVersion(Empty)
13241300x8000000000000000672086Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.882{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672085Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.882{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\Publisher(Empty)
13241300x8000000000000000672084Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.882{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fold.exe|84163f1e2201dd71\LowerCaseLongPathc:\program files\git\usr\bin\fold.exe
13241300x8000000000000000672083Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\BinProductVersion(Empty)
13241300x8000000000000000672082Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672081Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\Publisher(Empty)
13241300x8000000000000000672080Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fmt.exe|74780154d3c66e14\LowerCaseLongPathc:\program files\git\usr\bin\fmt.exe
13241300x8000000000000000672079Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\BinProductVersion(Empty)
13241300x8000000000000000672078Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672077Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\Publisher(Empty)
13241300x8000000000000000672076Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\find.exe|d79fa77470677f17\LowerCaseLongPathc:\program files\git\usr\bin\find.exe
13241300x8000000000000000672075Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\BinProductVersion(Empty)
13241300x8000000000000000672074Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672073Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\Publisher(Empty)
13241300x8000000000000000672072Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\file.exe|9412a967e2d15f0f\LowerCaseLongPathc:\program files\git\usr\bin\file.exe
13241300x8000000000000000672071Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\BinProductVersion(Empty)
13241300x8000000000000000672070Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672069Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\Publisher(Empty)
13241300x8000000000000000672068Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.861{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-token.exe|a3c5680a4f7259a\LowerCaseLongPathc:\program files\git\usr\bin\fido2-token.exe
13241300x8000000000000000672067Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.858{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\BinProductVersion(Empty)
13241300x8000000000000000672066Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.858{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672065Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.858{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\Publisher(Empty)
13241300x8000000000000000672064Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.858{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-cred.exe|c2222f8371b081a5\LowerCaseLongPathc:\program files\git\usr\bin\fido2-cred.exe
13241300x8000000000000000672063Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.855{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\BinProductVersion(Empty)
13241300x8000000000000000672062Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.855{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672061Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.855{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\Publisher(Empty)
13241300x8000000000000000672060Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.855{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\fido2-assert.exe|94d2ea2ef1445ec9\LowerCaseLongPathc:\program files\git\usr\bin\fido2-assert.exe
13241300x8000000000000000672059Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:02.853{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\BinProductVersion(Empty)
13241300x8000000000000000672058Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:02.852{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672057Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:02.852{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\Publisher(Empty)
13241300x8000000000000000672056Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:02.852{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\false.exe|8d9fec6786dfc816\LowerCaseLongPathc:\program files\git\usr\bin\false.exe
23542300x8000000000000000572681Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:04.742{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=82EC7779205D8E8F6C061E7A8DB66627,SHA256=C45CDF0A584862A6EA935CF0AA698BFFD3BB66A67223458152395C56AC30B5C4,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672750Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.994{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-objec|93ac7618bed9528f\BinProductVersion2.31.1.1
13241300x8000000000000000672749Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.994{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-objec|93ac7618bed9528f\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672748Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.994{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-objec|93ac7618bed9528f\Publisherthe git development community
13241300x8000000000000000672747Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.994{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-objec|93ac7618bed9528f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-unpack-objects.exe
10341000x8000000000000000672746Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.987{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-7FE0-609D-1456-00000000BA01}4712C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.4349_none_7f09d74e21ec00ab\TiWorker.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
13241300x8000000000000000672745Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.985{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-file.|7756b160cc2cfb66\BinProductVersion2.31.1.1
13241300x8000000000000000672744Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.985{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-file.|7756b160cc2cfb66\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672743Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.985{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-file.|7756b160cc2cfb66\Publisherthe git development community
13241300x8000000000000000672742Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.985{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-unpack-file.|7756b160cc2cfb66\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-unpack-file.exe
23542300x8000000000000000672741Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.983{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=465B2894CADA135B6F484D6F915D7D44,SHA256=0AD9CBCF2CF46544E30D0033DAD740F971855F2BB4FF6C440D5EC1C9DB11683B,IMPHASH=00000000000000000000000000000000falsetrue
10341000x8000000000000000672740Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.979{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672739Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.978{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672738Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.978{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672737Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.978{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672736Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.975{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FE0-609D-1456-00000000BA01}4712C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.4349_none_7f09d74e21ec00ab\TiWorker.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000672735Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.974{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-7FE0-609D-1456-00000000BA01}4712C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.4349_none_7f09d74e21ec00ab\TiWorker.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000672734Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.962{7B03F3B2-7FE0-609D-1456-00000000BA01}4712C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.4349_none_7f09d74e21ec00ab\TiWorker.exe10.0.14393.4222 (rs1_release.210113-1739)Windows Modules Installer WorkerMicrosoft® Windows® Operating SystemMicrosoft CorporationTiWorker.exeC:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.4349_none_7f09d74e21ec00ab\TiWorker.exe -EmbeddingC:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=1571A4132449A317F66DF783E9468783,SHA256=5CFF48937FAE7F0CF5935248959141E2A60E88FE8105C43676B866FDAC36ADD2,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19{7B03F3B2-D0CA-609A-0C00-00000000BA01}856C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch
13241300x8000000000000000672733Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.974{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-tag.exe|7666d39e6cc8f3cc\BinProductVersion2.31.1.1
13241300x8000000000000000672732Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.974{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-tag.exe|7666d39e6cc8f3cc\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672731Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.974{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-tag.exe|7666d39e6cc8f3cc\Publisherthe git development community
13241300x8000000000000000672730Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.974{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-tag.exe|7666d39e6cc8f3cc\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-tag.exe
13241300x8000000000000000672729Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.965{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-symbolic-ref|ce473368350d320a\BinProductVersion2.31.1.1
13241300x8000000000000000672728Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.965{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-symbolic-ref|ce473368350d320a\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672727Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.965{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-symbolic-ref|ce473368350d320a\Publisherthe git development community
13241300x8000000000000000672726Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.965{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-symbolic-ref|ce473368350d320a\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-symbolic-ref.exe
13241300x8000000000000000672725Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.956{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-switch.exe|ff6e85f065529228\BinProductVersion2.31.1.1
13241300x8000000000000000672724Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.956{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-switch.exe|ff6e85f065529228\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672723Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.956{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-switch.exe|ff6e85f065529228\Publisherthe git development community
13241300x8000000000000000672722Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.956{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-switch.exe|ff6e85f065529228\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-switch.exe
10341000x8000000000000000672721Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.953{7B03F3B2-D0CA-609A-0C00-00000000BA01}856676C:\Windows\system32\svchost.exe{7B03F3B2-7FE0-609D-1356-00000000BA01}5204C:\Windows\servicing\TrustedInstaller.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
13241300x8000000000000000672720Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.946{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-submodule--h|a577781a96a63623\BinProductVersion2.31.1.1
13241300x8000000000000000672719Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.946{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-submodule--h|a577781a96a63623\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672718Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.946{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-submodule--h|a577781a96a63623\Publisherthe git development community
13241300x8000000000000000672717Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.946{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-submodule--h|a577781a96a63623\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-submodule--helper.exe
10341000x8000000000000000672716Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.941{7B03F3B2-D0C8-609A-0A00-00000000BA01}6247656C:\Windows\system32\services.exe{7B03F3B2-7FE0-609D-1356-00000000BA01}5204C:\Windows\servicing\TrustedInstaller.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6cc4|C:\Windows\System32\RPCRT4.dll+67d2f|C:\Windows\system32\services.exe+1713f|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672715Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.935{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672714Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.935{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
13241300x8000000000000000672713Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.935{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stripspace.e|7f2324fbc967deaa\BinProductVersion2.31.1.1
13241300x8000000000000000672712Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.935{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stripspace.e|7f2324fbc967deaa\LinkDate03/27/2021 09:56:23
10341000x8000000000000000672711Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.935{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
13241300x8000000000000000672710Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.935{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stripspace.e|7f2324fbc967deaa\Publisherthe git development community
10341000x8000000000000000672709Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.935{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0D7-609A-2C00-00000000BA01}1572C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
13241300x8000000000000000672708Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.935{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stripspace.e|7f2324fbc967deaa\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-stripspace.exe
10341000x8000000000000000672707Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.935{7B03F3B2-D0C8-609A-0500-00000000BA01}412532C:\Windows\system32\csrss.exe{7B03F3B2-7FE0-609D-1356-00000000BA01}5204C:\Windows\servicing\TrustedInstaller.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+5178f
10341000x8000000000000000672706Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.934{7B03F3B2-D0C8-609A-0A00-00000000BA01}6245532C:\Windows\system32\services.exe{7B03F3B2-7FE0-609D-1356-00000000BA01}5204C:\Windows\servicing\TrustedInstaller.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7404|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+307d|C:\Windows\system32\services.exe+6334|C:\Windows\system32\services.exe+dc24|C:\Windows\system32\services.exe+d3ee|C:\Windows\system32\services.exe+4d0c|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+22b4b|C:\Windows\System32\RPCRT4.dll+653fa|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
154100x8000000000000000672705Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.923{7B03F3B2-7FE0-609D-1356-00000000BA01}5204C:\Windows\servicing\TrustedInstaller.exe10.0.14393.3564 (rs1_release.200303-1942)Windows Modules InstallerMicrosoft® Windows® Operating SystemMicrosoft CorporationTrustedInstaller.exeC:\Windows\servicing\TrustedInstaller.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{7B03F3B2-D0C8-609A-E703-000000000000}0x3e70SystemMD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4{7B03F3B2-D0C8-609A-0A00-00000000BA01}624C:\Windows\System32\services.exeC:\Windows\system32\services.exe
13241300x8000000000000000672704Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-status.exe|f379629630fb27d9\BinProductVersion2.31.1.1
13241300x8000000000000000672703Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-status.exe|f379629630fb27d9\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672702Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-status.exe|f379629630fb27d9\Publisherthe git development community
13241300x8000000000000000672701Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.926{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-status.exe|f379629630fb27d9\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-status.exe
10341000x8000000000000000672700Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.922{7B03F3B2-D0C8-609A-0B00-00000000BA01}6325688C:\Windows\system32\lsass.exe{7B03F3B2-D0C8-609A-0A00-00000000BA01}624C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+10d9e|C:\Windows\system32\lsasrv.dll+1d1e8|C:\Windows\system32\lsasrv.dll+1c411|C:\Windows\system32\lsasrv.dll+1ac30|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672699Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.922{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672698Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.922{7B03F3B2-D0CA-609A-0C00-00000000BA01}8564308C:\Windows\system32\svchost.exe{7B03F3B2-D0C8-609A-0B00-00000000BA01}632C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
10341000x8000000000000000672697Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.921{7B03F3B2-D0C8-609A-0B00-00000000BA01}6325688C:\Windows\system32\lsass.exe{7B03F3B2-D0C8-609A-0A00-00000000BA01}624C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\system32\lsasrv.dll+1a18d|C:\Windows\system32\lsasrv.dll+2706b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+62d4c|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49a3b|C:\Windows\System32\RPCRT4.dll+310ac|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+51781
13241300x8000000000000000672696Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.917{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stash.exe|a40e77c71ac2aede\BinProductVersion2.31.1.1
13241300x8000000000000000672695Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.917{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stash.exe|a40e77c71ac2aede\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672694Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.917{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stash.exe|a40e77c71ac2aede\Publisherthe git development community
13241300x8000000000000000672693Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.917{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stash.exe|a40e77c71ac2aede\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-stash.exe
13241300x8000000000000000672692Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.903{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stage.exe|f500735b2eec0385\BinProductVersion2.31.1.1
13241300x8000000000000000672691Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.903{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stage.exe|f500735b2eec0385\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672690Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.903{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stage.exe|f500735b2eec0385\Publisherthe git development community
13241300x8000000000000000672689Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.903{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-stage.exe|f500735b2eec0385\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-stage.exe
13241300x8000000000000000672688Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.890{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sparse-check|f4825f9ae19d20b3\BinProductVersion2.31.1.1
13241300x8000000000000000672687Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.890{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sparse-check|f4825f9ae19d20b3\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672686Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.890{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sparse-check|f4825f9ae19d20b3\Publisherthe git development community
13241300x8000000000000000672685Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.890{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sparse-check|f4825f9ae19d20b3\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-sparse-checkout.exe
13241300x8000000000000000672684Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.877{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show.exe|6e9a2dd47e6867ba\BinProductVersion2.31.1.1
13241300x8000000000000000672683Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.877{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show.exe|6e9a2dd47e6867ba\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672682Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.877{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show.exe|6e9a2dd47e6867ba\Publisherthe git development community
13241300x8000000000000000672681Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.877{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show.exe|6e9a2dd47e6867ba\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-show.exe
13241300x8000000000000000672680Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.863{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-ref.exe|f7f4cf76175660d6\BinProductVersion2.31.1.1
13241300x8000000000000000672679Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.863{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-ref.exe|f7f4cf76175660d6\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672678Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.863{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-ref.exe|f7f4cf76175660d6\Publisherthe git development community
13241300x8000000000000000672677Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.863{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-ref.exe|f7f4cf76175660d6\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-show-ref.exe
13241300x8000000000000000672676Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-index.e|8286f2c5e311f4dd\BinProductVersion2.31.1.1
13241300x8000000000000000672675Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-index.e|8286f2c5e311f4dd\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672674Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-index.e|8286f2c5e311f4dd\Publisherthe git development community
13241300x8000000000000000672673Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.850{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-index.e|8286f2c5e311f4dd\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-show-index.exe
13241300x8000000000000000672672Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.837{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-branch.|e7aa2817ea598ca5\BinProductVersion2.31.1.1
13241300x8000000000000000672671Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.837{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-branch.|e7aa2817ea598ca5\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672670Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.837{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-branch.|e7aa2817ea598ca5\Publisherthe git development community
13241300x8000000000000000672669Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.836{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-show-branch.|e7aa2817ea598ca5\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-show-branch.exe
13241300x8000000000000000672668Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-shortlog.exe|6690a566fa773a48\BinProductVersion2.31.1.1
13241300x8000000000000000672667Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-shortlog.exe|6690a566fa773a48\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672666Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-shortlog.exe|6690a566fa773a48\Publisherthe git development community
13241300x8000000000000000672665Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-shortlog.exe|6690a566fa773a48\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-shortlog.exe
23542300x8000000000000000672664Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.814{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=B5DEA0DE7C7FF10462CD2D394DC09D5D,SHA256=45C861CB078F4593345E3C49D42AF4FD33E67CE6EC53DE5C8F29F391CE323000,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672663Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.807{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sh-i18n--env|4053f372896ace9d\BinProductVersion2.31.1.1
13241300x8000000000000000672662Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.807{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sh-i18n--env|4053f372896ace9d\LinkDate03/27/2021 09:56:28
13241300x8000000000000000672661Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.806{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sh-i18n--env|4053f372896ace9d\Publisherthe git development community
13241300x8000000000000000672660Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.806{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-sh-i18n--env|4053f372896ace9d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-sh-i18n--envsubst.exe
13241300x8000000000000000672659Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.789{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-send-pack.ex|da651d512f55be29\BinProductVersion2.31.1.1
13241300x8000000000000000672658Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.789{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-send-pack.ex|da651d512f55be29\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672657Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.789{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-send-pack.ex|da651d512f55be29\Publisherthe git development community
13241300x8000000000000000672656Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.789{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-send-pack.ex|da651d512f55be29\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-send-pack.exe
13241300x8000000000000000672655Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.776{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rm.exe|8e86f766b6479aa7\BinProductVersion2.31.1.1
13241300x8000000000000000672654Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.776{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rm.exe|8e86f766b6479aa7\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672653Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.776{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rm.exe|8e86f766b6479aa7\Publisherthe git development community
13241300x8000000000000000672652Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.775{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rm.exe|8e86f766b6479aa7\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-rm.exe
13241300x8000000000000000672651Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.765{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-revert.exe|7aa27432655fad81\BinProductVersion2.31.1.1
13241300x8000000000000000672650Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.765{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-revert.exe|7aa27432655fad81\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672649Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.764{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-revert.exe|7aa27432655fad81\Publisherthe git development community
13241300x8000000000000000672648Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.764{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-revert.exe|7aa27432655fad81\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-revert.exe
13241300x8000000000000000672647Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.753{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-parse.ex|d6a8e773756ed1d6\BinProductVersion2.31.1.1
13241300x8000000000000000672646Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.753{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-parse.ex|d6a8e773756ed1d6\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672645Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.752{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-parse.ex|d6a8e773756ed1d6\Publisherthe git development community
13241300x8000000000000000672644Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.752{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-parse.ex|d6a8e773756ed1d6\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-rev-parse.exe
13241300x8000000000000000672643Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-list.exe|269a9e57005af766\BinProductVersion2.31.1.1
13241300x8000000000000000672642Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-list.exe|269a9e57005af766\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672641Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-list.exe|269a9e57005af766\Publisherthe git development community
13241300x8000000000000000672640Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rev-list.exe|269a9e57005af766\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-rev-list.exe
13241300x8000000000000000672639Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.726{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-restore.exe|8e7fc8b24c23bae3\BinProductVersion2.31.1.1
13241300x8000000000000000672638Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.726{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-restore.exe|8e7fc8b24c23bae3\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672637Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.726{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-restore.exe|8e7fc8b24c23bae3\Publisherthe git development community
13241300x8000000000000000672636Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.726{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-restore.exe|8e7fc8b24c23bae3\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-restore.exe
13241300x8000000000000000672635Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.713{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reset.exe|36c5794b3e41dd77\BinProductVersion2.31.1.1
13241300x8000000000000000672634Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.713{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reset.exe|36c5794b3e41dd77\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672633Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.713{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reset.exe|36c5794b3e41dd77\Publisherthe git development community
13241300x8000000000000000672632Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.713{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reset.exe|36c5794b3e41dd77\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-reset.exe
13241300x8000000000000000672631Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rerere.exe|fc745b45c205e431\BinProductVersion2.31.1.1
13241300x8000000000000000672630Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rerere.exe|fc745b45c205e431\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672629Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rerere.exe|fc745b45c205e431\Publisherthe git development community
13241300x8000000000000000672628Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.699{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rerere.exe|fc745b45c205e431\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-rerere.exe
13241300x8000000000000000672627Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.686{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-replace.exe|3cfc7710e33c88bb\BinProductVersion2.31.1.1
13241300x8000000000000000672626Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.686{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-replace.exe|3cfc7710e33c88bb\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672625Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.686{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-replace.exe|3cfc7710e33c88bb\Publisherthe git development community
13241300x8000000000000000672624Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.686{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-replace.exe|3cfc7710e33c88bb\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-replace.exe
13241300x8000000000000000672623Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.672{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-repack.exe|b1385c9cee9c0160\BinProductVersion2.31.1.1
13241300x8000000000000000672622Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.672{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-repack.exe|b1385c9cee9c0160\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672621Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.672{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-repack.exe|b1385c9cee9c0160\Publisherthe git development community
13241300x8000000000000000672620Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.672{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-repack.exe|b1385c9cee9c0160\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-repack.exe
13241300x8000000000000000672619Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.659{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote.exe|2eac402aac5dd179\BinProductVersion2.31.1.1
13241300x8000000000000000672618Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.659{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote.exe|2eac402aac5dd179\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672617Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.659{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote.exe|2eac402aac5dd179\Publisherthe git development community
13241300x8000000000000000672616Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.659{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote.exe|2eac402aac5dd179\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-remote.exe
13241300x8000000000000000672615Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.645{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-https|726221edb644a582\BinProductVersion2.31.1.1
13241300x8000000000000000672614Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.645{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-https|726221edb644a582\LinkDate03/27/2021 09:56:32
13241300x8000000000000000672613Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.645{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-https|726221edb644a582\Publisherthe git development community
13241300x8000000000000000672612Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.645{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-https|726221edb644a582\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-remote-https.exe
13241300x8000000000000000672611Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.626{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-http.|7c133653a586f83\BinProductVersion2.31.1.1
13241300x8000000000000000672610Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.626{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-http.|7c133653a586f83\LinkDate03/27/2021 09:56:32
13241300x8000000000000000672609Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.626{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-http.|7c133653a586f83\Publisherthe git development community
13241300x8000000000000000672608Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.625{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-http.|7c133653a586f83\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-remote-http.exe
13241300x8000000000000000672607Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.608{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftps.|3aad054899c73a4b\BinProductVersion2.31.1.1
13241300x8000000000000000672606Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.608{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftps.|3aad054899c73a4b\LinkDate03/27/2021 09:56:32
13241300x8000000000000000672605Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.608{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftps.|3aad054899c73a4b\Publisherthe git development community
13241300x8000000000000000672604Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.608{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftps.|3aad054899c73a4b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-remote-ftps.exe
13241300x8000000000000000672603Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.590{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftp.e|a2604470889ec908\BinProductVersion2.31.1.1
13241300x8000000000000000672602Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.590{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftp.e|a2604470889ec908\LinkDate03/27/2021 09:56:32
13241300x8000000000000000672601Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.590{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftp.e|a2604470889ec908\Publisherthe git development community
13241300x8000000000000000672600Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.589{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ftp.e|a2604470889ec908\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-remote-ftp.exe
13241300x8000000000000000672599Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.570{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-fd.ex|e557f81c4381d7b0\BinProductVersion2.31.1.1
13241300x8000000000000000672598Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.570{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-fd.ex|e557f81c4381d7b0\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672597Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.570{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-fd.ex|e557f81c4381d7b0\Publisherthe git development community
13241300x8000000000000000672596Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.570{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-fd.ex|e557f81c4381d7b0\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-remote-fd.exe
13241300x8000000000000000672595Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ext.e|bd6596e1f05a9659\BinProductVersion2.31.1.1
13241300x8000000000000000672594Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ext.e|bd6596e1f05a9659\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672593Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ext.e|bd6596e1f05a9659\Publisherthe git development community
13241300x8000000000000000672592Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-remote-ext.e|bd6596e1f05a9659\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-remote-ext.exe
13241300x8000000000000000672591Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reflog.exe|34db507846fa6f12\BinProductVersion2.31.1.1
13241300x8000000000000000672590Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reflog.exe|34db507846fa6f12\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672589Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reflog.exe|34db507846fa6f12\Publisherthe git development community
13241300x8000000000000000672588Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.513{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-reflog.exe|34db507846fa6f12\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-reflog.exe
13241300x8000000000000000672587Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.504{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|8e78e4fb26db059a\BinProductVersion2.31.1.1
13241300x8000000000000000672586Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.504{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|8e78e4fb26db059a\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672585Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.504{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|8e78e4fb26db059a\Publisherthe git development community
13241300x8000000000000000672584Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.504{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|8e78e4fb26db059a\LowerCaseLongPathc:\program files\git\mingw64\bin\git-receive-pack.exe
13241300x8000000000000000672583Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.494{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|4bf4387fd198488d\BinProductVersion2.31.1.1
13241300x8000000000000000672582Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.494{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|4bf4387fd198488d\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672581Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.494{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|4bf4387fd198488d\Publisherthe git development community
13241300x8000000000000000672580Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.494{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-receive-pack|4bf4387fd198488d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-receive-pack.exe
13241300x8000000000000000672579Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.485{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rebase.exe|80d1b0e35c07195b\BinProductVersion2.31.1.1
13241300x8000000000000000672578Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.485{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rebase.exe|80d1b0e35c07195b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672577Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.485{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rebase.exe|80d1b0e35c07195b\Publisherthe git development community
13241300x8000000000000000672576Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.485{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-rebase.exe|80d1b0e35c07195b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-rebase.exe
13241300x8000000000000000672575Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-read-tree.ex|22941f40e639aef1\BinProductVersion2.31.1.1
13241300x8000000000000000672574Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-read-tree.ex|22941f40e639aef1\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672573Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-read-tree.ex|22941f40e639aef1\Publisherthe git development community
13241300x8000000000000000672572Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.477{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-read-tree.ex|22941f40e639aef1\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-read-tree.exe
13241300x8000000000000000672571Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.467{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-range-diff.e|27a041f8d99ea5e9\BinProductVersion2.31.1.1
13241300x8000000000000000672570Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.467{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-range-diff.e|27a041f8d99ea5e9\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672569Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.466{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-range-diff.e|27a041f8d99ea5e9\Publisherthe git development community
13241300x8000000000000000672568Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.466{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-range-diff.e|27a041f8d99ea5e9\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-range-diff.exe
13241300x8000000000000000672567Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.458{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-push.exe|6b8bbc843881b879\BinProductVersion2.31.1.1
13241300x8000000000000000672566Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.458{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-push.exe|6b8bbc843881b879\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672565Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.458{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-push.exe|6b8bbc843881b879\Publisherthe git development community
13241300x8000000000000000672564Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.458{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-push.exe|6b8bbc843881b879\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-push.exe
23542300x8000000000000000672563Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.454{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SecurityMD5=C5F7F2448140ACB627F9FA8E6EE44843,SHA256=D893C6635927C5DF9411F1CF821ED02D2B652A9C2631099B42BA7C76A1BC3015,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672562Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.449{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pull.exe|5c528221eaacce43\BinProductVersion2.31.1.1
13241300x8000000000000000672561Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.449{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pull.exe|5c528221eaacce43\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672560Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.449{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pull.exe|5c528221eaacce43\Publisherthe git development community
13241300x8000000000000000672559Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.449{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pull.exe|5c528221eaacce43\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-pull.exe
13241300x8000000000000000672558Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.440{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune.exe|8dd360f83decd04c\BinProductVersion2.31.1.1
13241300x8000000000000000672557Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.440{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune.exe|8dd360f83decd04c\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672556Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.440{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune.exe|8dd360f83decd04c\Publisherthe git development community
13241300x8000000000000000672555Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.440{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune.exe|8dd360f83decd04c\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-prune.exe
13241300x8000000000000000672554Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.427{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune-packed|7ea14beb272e20eb\BinProductVersion2.31.1.1
13241300x8000000000000000672553Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.427{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune-packed|7ea14beb272e20eb\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672552Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.427{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune-packed|7ea14beb272e20eb\Publisherthe git development community
13241300x8000000000000000672551Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.427{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-prune-packed|7ea14beb272e20eb\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-prune-packed.exe
23542300x8000000000000000672550Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.415{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=57FB185EC1EFE129E4ECD32869BA9C7D,SHA256=49495906CEB238470B5464157E2A59E49ED02F9217FB2F7F3D4F28A88DAD6DA5,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672549Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.410{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-patch-id.exe|280f7dfabbed9aa0\BinProductVersion2.31.1.1
13241300x8000000000000000672548Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.410{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-patch-id.exe|280f7dfabbed9aa0\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672547Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.409{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-patch-id.exe|280f7dfabbed9aa0\Publisherthe git development community
13241300x8000000000000000672546Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.409{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-patch-id.exe|280f7dfabbed9aa0\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-patch-id.exe
13241300x8000000000000000672545Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.400{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-refs.ex|a72849c27ec32acf\BinProductVersion2.31.1.1
13241300x8000000000000000672544Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.400{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-refs.ex|a72849c27ec32acf\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672543Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.400{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-refs.ex|a72849c27ec32acf\Publisherthe git development community
13241300x8000000000000000672542Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.400{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-refs.ex|a72849c27ec32acf\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-pack-refs.exe
13241300x8000000000000000672541Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.391{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-redunda|3bea7e0b47bae351\BinProductVersion2.31.1.1
13241300x8000000000000000672540Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.391{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-redunda|3bea7e0b47bae351\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672539Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.391{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-redunda|3bea7e0b47bae351\Publisherthe git development community
13241300x8000000000000000672538Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.391{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-redunda|3bea7e0b47bae351\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-pack-redundant.exe
13241300x8000000000000000672537Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.382{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-objects|b6ba6e682d1328e9\BinProductVersion2.31.1.1
13241300x8000000000000000672536Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.382{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-objects|b6ba6e682d1328e9\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672535Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.382{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-objects|b6ba6e682d1328e9\Publisherthe git development community
13241300x8000000000000000672534Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.382{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-pack-objects|b6ba6e682d1328e9\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-pack-objects.exe
13241300x8000000000000000672533Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.373{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-notes.exe|cadb47a79807ad03\BinProductVersion2.31.1.1
13241300x8000000000000000672532Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.373{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-notes.exe|cadb47a79807ad03\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672531Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.373{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-notes.exe|cadb47a79807ad03\Publisherthe git development community
13241300x8000000000000000672530Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.373{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-notes.exe|cadb47a79807ad03\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-notes.exe
13241300x8000000000000000672529Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.364{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-name-rev.exe|7b3ad17acd0ba124\BinProductVersion2.31.1.1
13241300x8000000000000000672528Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.364{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-name-rev.exe|7b3ad17acd0ba124\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672527Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.364{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-name-rev.exe|7b3ad17acd0ba124\Publisherthe git development community
13241300x8000000000000000672526Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.364{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-name-rev.exe|7b3ad17acd0ba124\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-name-rev.exe
13241300x8000000000000000672525Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.355{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mv.exe|e80e8664561f73b6\BinProductVersion2.31.1.1
13241300x8000000000000000672524Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.355{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mv.exe|e80e8664561f73b6\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672523Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.355{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mv.exe|e80e8664561f73b6\Publisherthe git development community
13241300x8000000000000000672522Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.355{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mv.exe|e80e8664561f73b6\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-mv.exe
13241300x8000000000000000672521Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-multi-pack-i|b0da66b3239cc0aa\BinProductVersion2.31.1.1
13241300x8000000000000000672520Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-multi-pack-i|b0da66b3239cc0aa\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672519Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-multi-pack-i|b0da66b3239cc0aa\Publisherthe git development community
13241300x8000000000000000672518Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.346{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-multi-pack-i|b0da66b3239cc0aa\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-multi-pack-index.exe
13241300x8000000000000000672517Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.337{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktree.exe|9fb15060439194e9\BinProductVersion2.31.1.1
13241300x8000000000000000672516Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.337{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktree.exe|9fb15060439194e9\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672515Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.337{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktree.exe|9fb15060439194e9\Publisherthe git development community
13241300x8000000000000000672514Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.337{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktree.exe|9fb15060439194e9\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-mktree.exe
13241300x8000000000000000672513Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktag.exe|f9ff9b0e12a2d151\BinProductVersion2.31.1.1
13241300x8000000000000000672512Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktag.exe|f9ff9b0e12a2d151\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672511Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktag.exe|f9ff9b0e12a2d151\Publisherthe git development community
13241300x8000000000000000672510Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mktag.exe|f9ff9b0e12a2d151\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-mktag.exe
13241300x8000000000000000672509Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.319{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge.exe|882533b7baebdf26\BinProductVersion2.31.1.1
13241300x8000000000000000672508Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge.exe|882533b7baebdf26\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672507Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge.exe|882533b7baebdf26\Publisherthe git development community
13241300x8000000000000000672506Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge.exe|882533b7baebdf26\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge.exe
13241300x8000000000000000672505Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.309{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-tree.e|2091c16f572d3b68\BinProductVersion2.31.1.1
13241300x8000000000000000672504Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.308{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-tree.e|2091c16f572d3b68\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672503Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.308{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-tree.e|2091c16f572d3b68\Publisherthe git development community
13241300x8000000000000000672502Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.308{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-tree.e|2091c16f572d3b68\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge-tree.exe
13241300x8000000000000000672501Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-subtre|334ec69ba0fedd6f\BinProductVersion2.31.1.1
13241300x8000000000000000672500Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-subtre|334ec69ba0fedd6f\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672499Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-subtre|334ec69ba0fedd6f\Publisherthe git development community
13241300x8000000000000000672498Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-subtre|334ec69ba0fedd6f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge-subtree.exe
13241300x8000000000000000672497Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.279{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-recurs|5342cf57bbb67b35\BinProductVersion2.31.1.1
13241300x8000000000000000672496Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.279{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-recurs|5342cf57bbb67b35\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672495Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.279{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-recurs|5342cf57bbb67b35\Publisherthe git development community
13241300x8000000000000000672494Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.279{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-recurs|5342cf57bbb67b35\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge-recursive.exe
13241300x8000000000000000672493Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-ours.e|8a9c9030af4fea1\BinProductVersion2.31.1.1
13241300x8000000000000000672492Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-ours.e|8a9c9030af4fea1\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672491Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-ours.e|8a9c9030af4fea1\Publisherthe git development community
13241300x8000000000000000672490Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-ours.e|8a9c9030af4fea1\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge-ours.exe
13241300x8000000000000000672489Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.262{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-index.|21be940b8e49773d\BinProductVersion2.31.1.1
13241300x8000000000000000672488Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.262{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-index.|21be940b8e49773d\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672487Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.262{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-index.|21be940b8e49773d\Publisherthe git development community
13241300x8000000000000000672486Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.262{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-index.|21be940b8e49773d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge-index.exe
13241300x8000000000000000672485Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.253{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-file.e|daffc665e459523c\BinProductVersion2.31.1.1
13241300x8000000000000000672484Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.253{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-file.e|daffc665e459523c\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672483Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.253{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-file.e|daffc665e459523c\Publisherthe git development community
13241300x8000000000000000672482Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.253{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-file.e|daffc665e459523c\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge-file.exe
13241300x8000000000000000672481Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-base.e|30dc1b69df66ab7c\BinProductVersion2.31.1.1
13241300x8000000000000000672480Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-base.e|30dc1b69df66ab7c\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672479Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-base.e|30dc1b69df66ab7c\Publisherthe git development community
13241300x8000000000000000672478Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.244{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-merge-base.e|30dc1b69df66ab7c\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-merge-base.exe
13241300x8000000000000000672477Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.236{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-maintenance.|3bae5fb74f39ca3b\BinProductVersion2.31.1.1
13241300x8000000000000000672476Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.236{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-maintenance.|3bae5fb74f39ca3b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672475Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.236{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-maintenance.|3bae5fb74f39ca3b\Publisherthe git development community
13241300x8000000000000000672474Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.236{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-maintenance.|3bae5fb74f39ca3b\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-maintenance.exe
13241300x8000000000000000672473Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailsplit.ex|6b4c4fb0ebcb699d\BinProductVersion2.31.1.1
13241300x8000000000000000672472Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailsplit.ex|6b4c4fb0ebcb699d\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672471Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailsplit.ex|6b4c4fb0ebcb699d\Publisherthe git development community
13241300x8000000000000000672470Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailsplit.ex|6b4c4fb0ebcb699d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-mailsplit.exe
13241300x8000000000000000672469Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.219{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailinfo.exe|301710ecfb7896f7\BinProductVersion2.31.1.1
13241300x8000000000000000672468Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.219{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailinfo.exe|301710ecfb7896f7\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672467Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.218{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailinfo.exe|301710ecfb7896f7\Publisherthe git development community
13241300x8000000000000000672466Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.218{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-mailinfo.exe|301710ecfb7896f7\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-mailinfo.exe
13241300x8000000000000000672465Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-tree.exe|3da7a7da61dca8d3\BinProductVersion2.31.1.1
13241300x8000000000000000672464Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-tree.exe|3da7a7da61dca8d3\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672463Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-tree.exe|3da7a7da61dca8d3\Publisherthe git development community
13241300x8000000000000000672462Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-tree.exe|3da7a7da61dca8d3\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-ls-tree.exe
13241300x8000000000000000672461Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.201{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-remote.ex|70eaf315f15c7a6d\BinProductVersion2.31.1.1
13241300x8000000000000000672460Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.201{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-remote.ex|70eaf315f15c7a6d\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672459Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.201{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-remote.ex|70eaf315f15c7a6d\Publisherthe git development community
13241300x8000000000000000672458Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.201{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-remote.ex|70eaf315f15c7a6d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-ls-remote.exe
13241300x8000000000000000672457Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-files.exe|1e3ad688e0cb54cf\BinProductVersion2.31.1.1
13241300x8000000000000000672456Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-files.exe|1e3ad688e0cb54cf\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672455Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-files.exe|1e3ad688e0cb54cf\Publisherthe git development community
13241300x8000000000000000672454Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-ls-files.exe|1e3ad688e0cb54cf\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-ls-files.exe
13241300x8000000000000000672453Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-log.exe|8e73c205e9f2f0be\BinProductVersion2.31.1.1
13241300x8000000000000000672452Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-log.exe|8e73c205e9f2f0be\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672451Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-log.exe|8e73c205e9f2f0be\Publisherthe git development community
13241300x8000000000000000672450Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-log.exe|8e73c205e9f2f0be\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-log.exe
13241300x8000000000000000672449Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|a5073c52b01e7b5b\BinProductVersion0.0.0.0
13241300x8000000000000000672448Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|a5073c52b01e7b5b\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672447Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|a5073c52b01e7b5b\Publisher(Empty)
13241300x8000000000000000672446Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|a5073c52b01e7b5b\LowerCaseLongPathc:\program files\git\mingw64\bin\git-lfs.exe
23542300x8000000000000000672445Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.108{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=BECDEA221BCEBFB660A6A5966ACE7971,SHA256=18FF2FD0F92A2B7C633B9987760855B48155A8012B18D31E26C4A79E8C057AEC,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672444Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.063{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|5a5fd3616aa3e5b5\BinProductVersion2.31.1.1
13241300x8000000000000000672443Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.063{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|5a5fd3616aa3e5b5\LinkDate03/27/2021 09:48:40
13241300x8000000000000000672442Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.063{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|5a5fd3616aa3e5b5\Publisherthe git development community
13241300x8000000000000000672441Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.063{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-lfs.exe|5a5fd3616aa3e5b5\LowerCaseLongPathc:\program files\git\cmd\git-lfs.exe
13241300x8000000000000000672440Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.061{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-interpret-tr|64a626455ecf8a98\BinProductVersion2.31.1.1
13241300x8000000000000000672439Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.061{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-interpret-tr|64a626455ecf8a98\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672438Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.061{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-interpret-tr|64a626455ecf8a98\Publisherthe git development community
13241300x8000000000000000672437Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.061{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-interpret-tr|64a626455ecf8a98\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-interpret-trailers.exe
13241300x8000000000000000672436Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.051{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init.exe|bfcd122907ddc590\BinProductVersion2.31.1.1
13241300x8000000000000000672435Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.051{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init.exe|bfcd122907ddc590\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672434Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.051{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init.exe|bfcd122907ddc590\Publisherthe git development community
13241300x8000000000000000672433Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.051{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init.exe|bfcd122907ddc590\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-init.exe
13241300x8000000000000000672432Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.040{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init-db.exe|b6baf86f656c9cd\BinProductVersion2.31.1.1
13241300x8000000000000000672431Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.040{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init-db.exe|b6baf86f656c9cd\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672430Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.039{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init-db.exe|b6baf86f656c9cd\Publisherthe git development community
13241300x8000000000000000672429Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.039{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-init-db.exe|b6baf86f656c9cd\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-init-db.exe
13241300x8000000000000000672428Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.025{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-index-pack.e|a057507fd54823f\BinProductVersion2.31.1.1
13241300x8000000000000000672427Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.025{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-index-pack.e|a057507fd54823f\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672426Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.025{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-index-pack.e|a057507fd54823f\Publisherthe git development community
13241300x8000000000000000672425Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.025{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-index-pack.e|a057507fd54823f\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-index-pack.exe
23542300x8000000000000000672424Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:04.016{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=ED08323D650F7DE5E4E8B6BA9EB982E9,SHA256=FEB771598F996CBEF70E5EC21C7402DBC344AB9FF4923FCDC1FCE4CEF5EE8A0B,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672423Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:04.011{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-imap-send.ex|b89b2f1409a90d85\BinProductVersion2.31.1.1
13241300x8000000000000000672422Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:04.011{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-imap-send.ex|b89b2f1409a90d85\LinkDate03/27/2021 09:56:26
13241300x8000000000000000672421Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:04.011{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-imap-send.ex|b89b2f1409a90d85\Publisherthe git development community
13241300x8000000000000000672420Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:04.011{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-imap-send.ex|b89b2f1409a90d85\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-imap-send.exe
23542300x8000000000000000572682Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:05.773{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9D585469B4A1C701BC86C521F5CA9E9E,SHA256=A5305242ED43C71D8CC773D600751A945DB6EB2413C07EAECE6CFE8D04870F90,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000673560Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.916{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh86.exe|4994964426e57062\BinProductVersion8.6.2.11
13241300x8000000000000000673559Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.916{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh86.exe|4994964426e57062\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673558Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.916{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh86.exe|4994964426e57062\Publisheractivestate corporation
13241300x8000000000000000673557Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.916{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh86.exe|4994964426e57062\LowerCaseLongPathc:\program files\git\mingw64\bin\tclsh86.exe
13241300x8000000000000000673556Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.915{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh8.6.exe|f4af2187e95edf36\BinProductVersion(Empty)
13241300x8000000000000000673555Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.915{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh8.6.exe|f4af2187e95edf36\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673554Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.914{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh8.6.exe|f4af2187e95edf36\Publisher(Empty)
13241300x8000000000000000673553Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.914{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh8.6.exe|f4af2187e95edf36\LowerCaseLongPathc:\program files\git\usr\bin\tclsh8.6.exe
13241300x8000000000000000673552Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.914{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|c680bc50ff765224\BinProductVersion8.6.2.11
13241300x8000000000000000673551Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.914{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|c680bc50ff765224\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673550Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.914{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|c680bc50ff765224\Publisheractivestate corporation
13241300x8000000000000000673549Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.914{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|c680bc50ff765224\LowerCaseLongPathc:\program files\git\mingw64\bin\tclsh.exe
13241300x8000000000000000673548Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|5e019a1593cf699d\BinProductVersion(Empty)
13241300x8000000000000000673547Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|5e019a1593cf699d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673546Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|5e019a1593cf699d\Publisher(Empty)
13241300x8000000000000000673545Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tclsh.exe|5e019a1593cf699d\LowerCaseLongPathc:\program files\git\usr\bin\tclsh.exe
13241300x8000000000000000673544Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tar.exe|1dbed49e1ef6b70d\BinProductVersion(Empty)
13241300x8000000000000000673543Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tar.exe|1dbed49e1ef6b70d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673542Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tar.exe|1dbed49e1ef6b70d\Publisher(Empty)
13241300x8000000000000000673541Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.912{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tar.exe|1dbed49e1ef6b70d\LowerCaseLongPathc:\program files\git\usr\bin\tar.exe
13241300x8000000000000000673540Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.905{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tail.exe|6acc971f2533f90e\BinProductVersion(Empty)
13241300x8000000000000000673539Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.905{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tail.exe|6acc971f2533f90e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673538Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.905{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tail.exe|6acc971f2533f90e\Publisher(Empty)
13241300x8000000000000000673537Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.905{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tail.exe|6acc971f2533f90e\LowerCaseLongPathc:\program files\git\usr\bin\tail.exe
13241300x8000000000000000673536Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.904{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tac.exe|e73e5023bd74098e\BinProductVersion(Empty)
13241300x8000000000000000673535Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.904{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tac.exe|e73e5023bd74098e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673534Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.904{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tac.exe|e73e5023bd74098e\Publisher(Empty)
13241300x8000000000000000673533Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.904{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tac.exe|e73e5023bd74098e\LowerCaseLongPathc:\program files\git\usr\bin\tac.exe
13241300x8000000000000000673532Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.871{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tabs.exe|743d286408f97c6a\BinProductVersion(Empty)
13241300x8000000000000000673531Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.871{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tabs.exe|743d286408f97c6a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673530Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.870{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tabs.exe|743d286408f97c6a\Publisher(Empty)
13241300x8000000000000000673529Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.870{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\tabs.exe|743d286408f97c6a\LowerCaseLongPathc:\program files\git\usr\bin\tabs.exe
13241300x8000000000000000673528Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.870{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sync.exe|5031e1e27bd724c8\BinProductVersion(Empty)
13241300x8000000000000000673527Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.870{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sync.exe|5031e1e27bd724c8\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673526Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.870{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sync.exe|5031e1e27bd724c8\Publisher(Empty)
13241300x8000000000000000673525Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.870{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sync.exe|5031e1e27bd724c8\LowerCaseLongPathc:\program files\git\usr\bin\sync.exe
13241300x8000000000000000673524Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.869{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sum.exe|624682ccf5cba616\BinProductVersion(Empty)
13241300x8000000000000000673523Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.868{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sum.exe|624682ccf5cba616\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673522Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.868{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sum.exe|624682ccf5cba616\Publisher(Empty)
13241300x8000000000000000673521Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.868{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sum.exe|624682ccf5cba616\LowerCaseLongPathc:\program files\git\usr\bin\sum.exe
13241300x8000000000000000673520Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.868{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stty.exe|4906c606dce675\BinProductVersion(Empty)
13241300x8000000000000000673519Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.868{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stty.exe|4906c606dce675\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673518Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.868{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stty.exe|4906c606dce675\Publisher(Empty)
13241300x8000000000000000673517Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.868{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stty.exe|4906c606dce675\LowerCaseLongPathc:\program files\git\usr\bin\stty.exe
13241300x8000000000000000673516Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.866{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\strace.exe|2e71f496c5d1f2c3\BinProductVersion(Empty)
13241300x8000000000000000673515Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.866{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\strace.exe|2e71f496c5d1f2c3\LinkDate03/26/2021 22:24:41
13241300x8000000000000000673514Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.866{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\strace.exe|2e71f496c5d1f2c3\Publisher(Empty)
13241300x8000000000000000673513Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.866{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\strace.exe|2e71f496c5d1f2c3\LowerCaseLongPathc:\program files\git\usr\bin\strace.exe
13241300x8000000000000000673512Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stat.exe|1f444a67c4725e6b\BinProductVersion(Empty)
13241300x8000000000000000673511Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stat.exe|1f444a67c4725e6b\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673510Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stat.exe|1f444a67c4725e6b\Publisher(Empty)
13241300x8000000000000000673509Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.857{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\stat.exe|1f444a67c4725e6b\LowerCaseLongPathc:\program files\git\usr\bin\stat.exe
13241300x8000000000000000673508Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.856{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssp.exe|e0a08db5e80ffcdd\BinProductVersion(Empty)
13241300x8000000000000000673507Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.856{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssp.exe|e0a08db5e80ffcdd\LinkDate03/26/2021 22:24:41
13241300x8000000000000000673506Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.856{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssp.exe|e0a08db5e80ffcdd\Publisher(Empty)
13241300x8000000000000000673505Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.856{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssp.exe|e0a08db5e80ffcdd\LowerCaseLongPathc:\program files\git\usr\bin\ssp.exe
13241300x8000000000000000673504Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.853{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sshd.exe|5f6404603331db89\BinProductVersion(Empty)
13241300x8000000000000000673503Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.853{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sshd.exe|5f6404603331db89\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673502Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.853{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sshd.exe|5f6404603331db89\Publisher(Empty)
13241300x8000000000000000673501Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.853{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sshd.exe|5f6404603331db89\LowerCaseLongPathc:\program files\git\usr\bin\sshd.exe
13241300x8000000000000000673500Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.844{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh.exe|4c8b77151293e36e\BinProductVersion(Empty)
13241300x8000000000000000673499Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.844{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh.exe|4c8b77151293e36e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673498Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.844{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh.exe|4c8b77151293e36e\Publisher(Empty)
13241300x8000000000000000673497Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.844{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh.exe|4c8b77151293e36e\LowerCaseLongPathc:\program files\git\usr\bin\ssh.exe
13241300x8000000000000000673496Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.835{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-sk-helper.ex|526e238c0df646d1\BinProductVersion(Empty)
13241300x8000000000000000673495Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.835{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-sk-helper.ex|526e238c0df646d1\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673494Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.835{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-sk-helper.ex|526e238c0df646d1\Publisher(Empty)
13241300x8000000000000000673493Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.835{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-sk-helper.ex|526e238c0df646d1\LowerCaseLongPathc:\program files\git\usr\lib\ssh\ssh-sk-helper.exe
13241300x8000000000000000673492Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.829{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pkcs11-helpe|d67a44ebac5d5f31\BinProductVersion(Empty)
13241300x8000000000000000673491Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.829{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pkcs11-helpe|d67a44ebac5d5f31\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673490Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.829{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pkcs11-helpe|d67a44ebac5d5f31\Publisher(Empty)
13241300x8000000000000000673489Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.829{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pkcs11-helpe|d67a44ebac5d5f31\LowerCaseLongPathc:\program files\git\usr\lib\ssh\ssh-pkcs11-helper.exe
13241300x8000000000000000673488Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pageant.exe|f558d3a8a2e8201c\BinProductVersion(Empty)
13241300x8000000000000000673487Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pageant.exe|f558d3a8a2e8201c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673486Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pageant.exe|f558d3a8a2e8201c\Publisher(Empty)
13241300x8000000000000000673485Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.823{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-pageant.exe|f558d3a8a2e8201c\LowerCaseLongPathc:\program files\git\usr\bin\ssh-pageant.exe
13241300x8000000000000000673484Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.822{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keysign.exe|9428dc5f875b1cbe\BinProductVersion(Empty)
13241300x8000000000000000673483Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.822{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keysign.exe|9428dc5f875b1cbe\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673482Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.822{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keysign.exe|9428dc5f875b1cbe\Publisher(Empty)
13241300x8000000000000000673481Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.822{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keysign.exe|9428dc5f875b1cbe\LowerCaseLongPathc:\program files\git\usr\lib\ssh\ssh-keysign.exe
13241300x8000000000000000673480Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.815{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keyscan.exe|54318a1f39629d66\BinProductVersion(Empty)
13241300x8000000000000000673479Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.815{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keyscan.exe|54318a1f39629d66\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673478Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.815{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keyscan.exe|54318a1f39629d66\Publisher(Empty)
13241300x8000000000000000673477Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.815{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keyscan.exe|54318a1f39629d66\LowerCaseLongPathc:\program files\git\usr\bin\ssh-keyscan.exe
23542300x8000000000000000673476Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:05.809{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=3960B0C0A7722CA9252B354A77BEF6E3,SHA256=AFE4CAF191B64BB4B8ECA37F2CA0DF219B5E7EF55771B16CDCC31C65BFBA9E5B,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000673475Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.809{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keygen.exe|4fd9485267bf242f\BinProductVersion(Empty)
13241300x8000000000000000673474Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.809{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keygen.exe|4fd9485267bf242f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673473Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.809{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keygen.exe|4fd9485267bf242f\Publisher(Empty)
13241300x8000000000000000673472Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.809{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-keygen.exe|4fd9485267bf242f\LowerCaseLongPathc:\program files\git\usr\bin\ssh-keygen.exe
13241300x8000000000000000673471Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.802{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-agent.exe|1411e9f6efc17c0f\BinProductVersion(Empty)
13241300x8000000000000000673470Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.802{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-agent.exe|1411e9f6efc17c0f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673469Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.802{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-agent.exe|1411e9f6efc17c0f\Publisher(Empty)
13241300x8000000000000000673468Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.802{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-agent.exe|1411e9f6efc17c0f\LowerCaseLongPathc:\program files\git\usr\bin\ssh-agent.exe
13241300x8000000000000000673467Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.796{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-add.exe|52771e80916527e6\BinProductVersion(Empty)
13241300x8000000000000000673466Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.796{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-add.exe|52771e80916527e6\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673465Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.796{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-add.exe|52771e80916527e6\Publisher(Empty)
13241300x8000000000000000673464Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.796{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ssh-add.exe|52771e80916527e6\LowerCaseLongPathc:\program files\git\usr\bin\ssh-add.exe
13241300x8000000000000000673463Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.791{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\split.exe|6b78af18101c82a4\BinProductVersion(Empty)
13241300x8000000000000000673462Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.791{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\split.exe|6b78af18101c82a4\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673461Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.791{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\split.exe|6b78af18101c82a4\Publisher(Empty)
13241300x8000000000000000673460Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.791{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\split.exe|6b78af18101c82a4\LowerCaseLongPathc:\program files\git\usr\bin\split.exe
13241300x8000000000000000673459Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.790{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sort.exe|5a1eaeebcdfdfa5b\BinProductVersion(Empty)
13241300x8000000000000000673458Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.790{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sort.exe|5a1eaeebcdfdfa5b\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673457Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.790{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sort.exe|5a1eaeebcdfdfa5b\Publisher(Empty)
13241300x8000000000000000673456Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.790{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sort.exe|5a1eaeebcdfdfa5b\LowerCaseLongPathc:\program files\git\usr\bin\sort.exe
13241300x8000000000000000673455Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.788{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sleep.exe|1e8f62417166ba32\BinProductVersion(Empty)
13241300x8000000000000000673454Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.788{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sleep.exe|1e8f62417166ba32\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673453Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.788{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sleep.exe|1e8f62417166ba32\Publisher(Empty)
13241300x8000000000000000673452Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.788{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sleep.exe|1e8f62417166ba32\LowerCaseLongPathc:\program files\git\usr\bin\sleep.exe
13241300x8000000000000000673451Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shuf.exe|cfb51deed9f02428\BinProductVersion(Empty)
13241300x8000000000000000673450Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shuf.exe|cfb51deed9f02428\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673449Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shuf.exe|cfb51deed9f02428\Publisher(Empty)
13241300x8000000000000000673448Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shuf.exe|cfb51deed9f02428\LowerCaseLongPathc:\program files\git\usr\bin\shuf.exe
13241300x8000000000000000673447Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shred.exe|43071571d2a31944\BinProductVersion(Empty)
13241300x8000000000000000673446Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shred.exe|43071571d2a31944\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673445Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shred.exe|43071571d2a31944\Publisher(Empty)
13241300x8000000000000000673444Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.786{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\shred.exe|43071571d2a31944\LowerCaseLongPathc:\program files\git\usr\bin\shred.exe
13241300x8000000000000000673443Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.785{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha512sum.exe|f96cb84497fcdcc3\BinProductVersion(Empty)
13241300x8000000000000000673442Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.785{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha512sum.exe|f96cb84497fcdcc3\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673441Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.785{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha512sum.exe|f96cb84497fcdcc3\Publisher(Empty)
13241300x8000000000000000673440Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.785{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha512sum.exe|f96cb84497fcdcc3\LowerCaseLongPathc:\program files\git\usr\bin\sha512sum.exe
13241300x8000000000000000673439Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha384sum.exe|ea7c3d331520b41a\BinProductVersion(Empty)
13241300x8000000000000000673438Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha384sum.exe|ea7c3d331520b41a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673437Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha384sum.exe|ea7c3d331520b41a\Publisher(Empty)
13241300x8000000000000000673436Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.784{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha384sum.exe|ea7c3d331520b41a\LowerCaseLongPathc:\program files\git\usr\bin\sha384sum.exe
13241300x8000000000000000673435Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha256sum.exe|d1427df5ba9eb839\BinProductVersion(Empty)
13241300x8000000000000000673434Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha256sum.exe|d1427df5ba9eb839\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673433Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha256sum.exe|d1427df5ba9eb839\Publisher(Empty)
13241300x8000000000000000673432Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha256sum.exe|d1427df5ba9eb839\LowerCaseLongPathc:\program files\git\usr\bin\sha256sum.exe
13241300x8000000000000000673431Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha224sum.exe|fc63c300ff87f33f\BinProductVersion(Empty)
13241300x8000000000000000673430Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha224sum.exe|fc63c300ff87f33f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673429Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.783{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha224sum.exe|fc63c300ff87f33f\Publisher(Empty)
13241300x8000000000000000673428Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.782{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha224sum.exe|fc63c300ff87f33f\LowerCaseLongPathc:\program files\git\usr\bin\sha224sum.exe
13241300x8000000000000000673427Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.782{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha1sum.exe|f6d44c369684cd7e\BinProductVersion(Empty)
13241300x8000000000000000673426Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.782{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha1sum.exe|f6d44c369684cd7e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673425Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.782{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha1sum.exe|f6d44c369684cd7e\Publisher(Empty)
13241300x8000000000000000673424Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.782{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sha1sum.exe|f6d44c369684cd7e\LowerCaseLongPathc:\program files\git\usr\bin\sha1sum.exe
13241300x8000000000000000673423Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.781{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|464d78a7aeef6674\BinProductVersion2.31.1.1
13241300x8000000000000000673422Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.781{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|464d78a7aeef6674\LinkDate03/27/2021 09:48:40
13241300x8000000000000000673421Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.781{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|464d78a7aeef6674\Publisherthe git development community
13241300x8000000000000000673420Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.781{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|464d78a7aeef6674\LowerCaseLongPathc:\program files\git\bin\sh.exe
13241300x8000000000000000673419Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.780{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|1bb90a29aab21f25\BinProductVersion(Empty)
13241300x8000000000000000673418Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.780{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|1bb90a29aab21f25\LinkDate12/04/2018 10:21:15
13241300x8000000000000000673417Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.779{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|1bb90a29aab21f25\Publisher(Empty)
13241300x8000000000000000673416Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.779{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sh.exe|1bb90a29aab21f25\LowerCaseLongPathc:\program files\git\usr\bin\sh.exe
13241300x8000000000000000673415Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.764{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp.exe|e3eb45112610e0ab\BinProductVersion(Empty)
13241300x8000000000000000673414Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.764{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp.exe|e3eb45112610e0ab\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673413Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.764{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp.exe|e3eb45112610e0ab\Publisher(Empty)
13241300x8000000000000000673412Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.764{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp.exe|e3eb45112610e0ab\LowerCaseLongPathc:\program files\git\usr\bin\sftp.exe
13241300x8000000000000000673411Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.761{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp-server.exe|88c04bc0a95e22d3\BinProductVersion(Empty)
13241300x8000000000000000673410Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.761{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp-server.exe|88c04bc0a95e22d3\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673409Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.761{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp-server.exe|88c04bc0a95e22d3\Publisher(Empty)
13241300x8000000000000000673408Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.761{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sftp-server.exe|88c04bc0a95e22d3\LowerCaseLongPathc:\program files\git\usr\lib\ssh\sftp-server.exe
13241300x8000000000000000673407Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.759{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|ff49bfd2063ca556\BinProductVersion(Empty)
13241300x8000000000000000673406Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.759{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|ff49bfd2063ca556\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673405Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.759{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|ff49bfd2063ca556\Publisher(Empty)
13241300x8000000000000000673404Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.759{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|ff49bfd2063ca556\LowerCaseLongPathc:\program files\git\mingw64\bin\sexp-conv.exe
13241300x8000000000000000673403Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|8bde837678ce07ac\BinProductVersion(Empty)
13241300x8000000000000000673402Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|8bde837678ce07ac\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673401Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|8bde837678ce07ac\Publisher(Empty)
13241300x8000000000000000673400Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.758{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sexp-conv.exe|8bde837678ce07ac\LowerCaseLongPathc:\program files\git\usr\bin\sexp-conv.exe
13241300x8000000000000000673399Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setmetamode.exe|2c2c0eb5bddaec82\BinProductVersion(Empty)
13241300x8000000000000000673398Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setmetamode.exe|2c2c0eb5bddaec82\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673397Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setmetamode.exe|2c2c0eb5bddaec82\Publisher(Empty)
13241300x8000000000000000673396Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.757{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setmetamode.exe|2c2c0eb5bddaec82\LowerCaseLongPathc:\program files\git\usr\bin\setmetamode.exe
13241300x8000000000000000673395Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.755{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setfacl.exe|3de57f6a3e2d7242\BinProductVersion(Empty)
13241300x8000000000000000673394Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.755{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setfacl.exe|3de57f6a3e2d7242\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673393Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.755{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setfacl.exe|3de57f6a3e2d7242\Publisher(Empty)
13241300x8000000000000000673392Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.755{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\setfacl.exe|3de57f6a3e2d7242\LowerCaseLongPathc:\program files\git\usr\bin\setfacl.exe
13241300x8000000000000000673391Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.753{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\seq.exe|1f2e494e389bf41a\BinProductVersion(Empty)
13241300x8000000000000000673390Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.753{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\seq.exe|1f2e494e389bf41a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673389Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.753{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\seq.exe|1f2e494e389bf41a\Publisher(Empty)
13241300x8000000000000000673388Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.752{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\seq.exe|1f2e494e389bf41a\LowerCaseLongPathc:\program files\git\usr\bin\seq.exe
13241300x8000000000000000673387Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.751{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sed.exe|cef6dc9db4fd3f4e\BinProductVersion(Empty)
13241300x8000000000000000673386Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.751{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sed.exe|cef6dc9db4fd3f4e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673385Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.751{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sed.exe|cef6dc9db4fd3f4e\Publisher(Empty)
13241300x8000000000000000673384Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.751{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sed.exe|cef6dc9db4fd3f4e\LowerCaseLongPathc:\program files\git\usr\bin\sed.exe
13241300x8000000000000000673383Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sdiff.exe|4d47b8c2d2524c04\BinProductVersion(Empty)
13241300x8000000000000000673382Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sdiff.exe|4d47b8c2d2524c04\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673381Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sdiff.exe|4d47b8c2d2524c04\Publisher(Empty)
13241300x8000000000000000673380Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.748{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\sdiff.exe|4d47b8c2d2524c04\LowerCaseLongPathc:\program files\git\usr\bin\sdiff.exe
13241300x8000000000000000673379Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.747{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scp.exe|7ba9f24b1c00395a\BinProductVersion(Empty)
13241300x8000000000000000673378Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.747{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scp.exe|7ba9f24b1c00395a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673377Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.747{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scp.exe|7ba9f24b1c00395a\Publisher(Empty)
13241300x8000000000000000673376Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.747{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scp.exe|7ba9f24b1c00395a\LowerCaseLongPathc:\program files\git\usr\bin\scp.exe
13241300x8000000000000000673375Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.745{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scdaemon.exe|53479827260a265e\BinProductVersion(Empty)
13241300x8000000000000000673374Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.745{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scdaemon.exe|53479827260a265e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673373Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.745{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scdaemon.exe|53479827260a265e\Publisher(Empty)
13241300x8000000000000000673372Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.745{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\scdaemon.exe|53479827260a265e\LowerCaseLongPathc:\program files\git\usr\lib\gnupg\scdaemon.exe
13241300x8000000000000000673371Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rvim.exe|58eacdb700b2ffd3\BinProductVersion(Empty)
13241300x8000000000000000673370Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rvim.exe|58eacdb700b2ffd3\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673369Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rvim.exe|58eacdb700b2ffd3\Publisher(Empty)
13241300x8000000000000000673368Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.739{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rvim.exe|58eacdb700b2ffd3\LowerCaseLongPathc:\program files\git\usr\bin\rvim.exe
13241300x8000000000000000673367Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rview.exe|1b8d8c7426c49f6d\BinProductVersion(Empty)
13241300x8000000000000000673366Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rview.exe|1b8d8c7426c49f6d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673365Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rview.exe|1b8d8c7426c49f6d\Publisher(Empty)
13241300x8000000000000000673364Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.719{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rview.exe|1b8d8c7426c49f6d\LowerCaseLongPathc:\program files\git\usr\bin\rview.exe
13241300x8000000000000000673363Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.700{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\runcon.exe|9d9d38ca848c2576\BinProductVersion(Empty)
13241300x8000000000000000673362Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.700{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\runcon.exe|9d9d38ca848c2576\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673361Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.700{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\runcon.exe|9d9d38ca848c2576\Publisher(Empty)
13241300x8000000000000000673360Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.700{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\runcon.exe|9d9d38ca848c2576\LowerCaseLongPathc:\program files\git\usr\bin\runcon.exe
13241300x8000000000000000673359Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rnano.exe|59695cb2874e092d\BinProductVersion(Empty)
13241300x8000000000000000673358Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rnano.exe|59695cb2874e092d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673357Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rnano.exe|59695cb2874e092d\Publisher(Empty)
13241300x8000000000000000673356Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rnano.exe|59695cb2874e092d\LowerCaseLongPathc:\program files\git\usr\bin\rnano.exe
13241300x8000000000000000673355Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmt.exe|dda7820342efab83\BinProductVersion(Empty)
13241300x8000000000000000673354Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmt.exe|dda7820342efab83\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673353Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmt.exe|dda7820342efab83\Publisher(Empty)
13241300x8000000000000000673352Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmt.exe|dda7820342efab83\LowerCaseLongPathc:\program files\git\usr\lib\tar\rmt.exe
13241300x8000000000000000673351Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmdir.exe|1053bde30940b254\BinProductVersion(Empty)
13241300x8000000000000000673350Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmdir.exe|1053bde30940b254\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673349Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmdir.exe|1053bde30940b254\Publisher(Empty)
13241300x8000000000000000673348Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rmdir.exe|1053bde30940b254\LowerCaseLongPathc:\program files\git\usr\bin\rmdir.exe
13241300x8000000000000000673347Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rm.exe|1eee459e666dde29\BinProductVersion(Empty)
13241300x8000000000000000673346Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rm.exe|1eee459e666dde29\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673345Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rm.exe|1eee459e666dde29\Publisher(Empty)
13241300x8000000000000000673344Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rm.exe|1eee459e666dde29\LowerCaseLongPathc:\program files\git\usr\bin\rm.exe
13241300x8000000000000000673343Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\reset.exe|bb8c4a8b474d3d85\BinProductVersion(Empty)
13241300x8000000000000000673342Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\reset.exe|bb8c4a8b474d3d85\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673341Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\reset.exe|bb8c4a8b474d3d85\Publisher(Empty)
13241300x8000000000000000673340Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\reset.exe|bb8c4a8b474d3d85\LowerCaseLongPathc:\program files\git\usr\bin\reset.exe
13241300x8000000000000000673339Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\regtool.exe|2c34de713dfed575\BinProductVersion(Empty)
13241300x8000000000000000673338Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\regtool.exe|2c34de713dfed575\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673337Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\regtool.exe|2c34de713dfed575\Publisher(Empty)
13241300x8000000000000000673336Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\regtool.exe|2c34de713dfed575\LowerCaseLongPathc:\program files\git\usr\bin\regtool.exe
13241300x8000000000000000673335Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\recode-sr-latin.|fef01b1a870bf6ba\BinProductVersion(Empty)
13241300x8000000000000000673334Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\recode-sr-latin.|fef01b1a870bf6ba\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673333Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\recode-sr-latin.|fef01b1a870bf6ba\Publisher(Empty)
13241300x8000000000000000673332Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\recode-sr-latin.|fef01b1a870bf6ba\LowerCaseLongPathc:\program files\git\usr\bin\recode-sr-latin.exe
13241300x8000000000000000673331Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rebase.exe|227817bf057aff56\BinProductVersion(Empty)
13241300x8000000000000000673330Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rebase.exe|227817bf057aff56\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673329Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rebase.exe|227817bf057aff56\Publisher(Empty)
13241300x8000000000000000673328Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.685{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\rebase.exe|227817bf057aff56\LowerCaseLongPathc:\program files\git\usr\bin\rebase.exe
13241300x8000000000000000673327Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\realpath.exe|c0afeb0f661fb0d7\BinProductVersion(Empty)
13241300x8000000000000000673326Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\realpath.exe|c0afeb0f661fb0d7\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673325Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\realpath.exe|c0afeb0f661fb0d7\Publisher(Empty)
13241300x8000000000000000673324Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\realpath.exe|c0afeb0f661fb0d7\LowerCaseLongPathc:\program files\git\usr\bin\realpath.exe
13241300x8000000000000000673323Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\readlink.exe|95adf512ea71f082\BinProductVersion(Empty)
13241300x8000000000000000673322Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\readlink.exe|95adf512ea71f082\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673321Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\readlink.exe|95adf512ea71f082\Publisher(Empty)
13241300x8000000000000000673320Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\readlink.exe|95adf512ea71f082\LowerCaseLongPathc:\program files\git\usr\bin\readlink.exe
13241300x8000000000000000673319Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwd.exe|d284abac49ab21f2\BinProductVersion(Empty)
13241300x8000000000000000673318Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwd.exe|d284abac49ab21f2\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673317Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwd.exe|d284abac49ab21f2\Publisher(Empty)
13241300x8000000000000000673316Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwd.exe|d284abac49ab21f2\LowerCaseLongPathc:\program files\git\usr\bin\pwd.exe
13241300x8000000000000000673315Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwcat.exe|8b9017bb0d797817\BinProductVersion(Empty)
13241300x8000000000000000673314Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwcat.exe|8b9017bb0d797817\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673313Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwcat.exe|8b9017bb0d797817\Publisher(Empty)
13241300x8000000000000000673312Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pwcat.exe|8b9017bb0d797817\LowerCaseLongPathc:\program files\git\usr\lib\awk\pwcat.exe
13241300x8000000000000000673311Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ptx.exe|e8f065049d3c881d\BinProductVersion(Empty)
13241300x8000000000000000673310Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ptx.exe|e8f065049d3c881d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673309Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ptx.exe|e8f065049d3c881d\Publisher(Empty)
13241300x8000000000000000673308Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ptx.exe|e8f065049d3c881d\LowerCaseLongPathc:\program files\git\usr\bin\ptx.exe
13241300x8000000000000000673307Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\psl.exe|c168c852dc0b9a95\BinProductVersion(Empty)
13241300x8000000000000000673306Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\psl.exe|c168c852dc0b9a95\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673305Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\psl.exe|c168c852dc0b9a95\Publisher(Empty)
13241300x8000000000000000673304Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\psl.exe|c168c852dc0b9a95\LowerCaseLongPathc:\program files\git\usr\bin\psl.exe
13241300x8000000000000000673303Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ps.exe|c0f5c870a00cafd8\BinProductVersion(Empty)
13241300x8000000000000000673302Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ps.exe|c0f5c870a00cafd8\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673301Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ps.exe|c0f5c870a00cafd8\Publisher(Empty)
13241300x8000000000000000673300Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ps.exe|c0f5c870a00cafd8\LowerCaseLongPathc:\program files\git\usr\bin\ps.exe
13241300x8000000000000000673299Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\proxy-lookup.exe|1b18ebec8d870bc5\BinProductVersion(Empty)
13241300x8000000000000000673298Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\proxy-lookup.exe|1b18ebec8d870bc5\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673297Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\proxy-lookup.exe|1b18ebec8d870bc5\Publisher(Empty)
13241300x8000000000000000673296Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.669{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\proxy-lookup.exe|1b18ebec8d870bc5\LowerCaseLongPathc:\program files\git\mingw64\bin\proxy-lookup.exe
13241300x8000000000000000673295Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printf.exe|89ffa032389ba988\BinProductVersion(Empty)
13241300x8000000000000000673294Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printf.exe|89ffa032389ba988\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673293Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printf.exe|89ffa032389ba988\Publisher(Empty)
13241300x8000000000000000673292Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printf.exe|89ffa032389ba988\LowerCaseLongPathc:\program files\git\usr\bin\printf.exe
13241300x8000000000000000673291Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printenv.exe|f3bb2a19296ad0a0\BinProductVersion(Empty)
13241300x8000000000000000673290Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printenv.exe|f3bb2a19296ad0a0\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673289Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printenv.exe|f3bb2a19296ad0a0\Publisher(Empty)
13241300x8000000000000000673288Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\printenv.exe|f3bb2a19296ad0a0\LowerCaseLongPathc:\program files\git\usr\bin\printenv.exe
13241300x8000000000000000673287Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pr.exe|4e05d5efd64cfc18\BinProductVersion(Empty)
13241300x8000000000000000673286Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pr.exe|4e05d5efd64cfc18\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673285Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pr.exe|4e05d5efd64cfc18\Publisher(Empty)
13241300x8000000000000000673284Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pr.exe|4e05d5efd64cfc18\LowerCaseLongPathc:\program files\git\usr\bin\pr.exe
13241300x8000000000000000673283Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pluginviewer.exe|f40dc68beb42a176\BinProductVersion(Empty)
13241300x8000000000000000673282Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pluginviewer.exe|f40dc68beb42a176\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673281Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pluginviewer.exe|f40dc68beb42a176\Publisher(Empty)
13241300x8000000000000000673280Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pluginviewer.exe|f40dc68beb42a176\LowerCaseLongPathc:\program files\git\usr\bin\pluginviewer.exe
13241300x8000000000000000673279Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pldd.exe|2d0b12ded17c614c\BinProductVersion(Empty)
13241300x8000000000000000673278Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pldd.exe|2d0b12ded17c614c\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673277Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pldd.exe|2d0b12ded17c614c\Publisher(Empty)
13241300x8000000000000000673276Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pldd.exe|2d0b12ded17c614c\LowerCaseLongPathc:\program files\git\usr\bin\pldd.exe
13241300x8000000000000000673275Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|8fa2ffc9f6076c8c\BinProductVersion(Empty)
13241300x8000000000000000673274Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|8fa2ffc9f6076c8c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673273Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|8fa2ffc9f6076c8c\Publisher(Empty)
13241300x8000000000000000673272Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|8fa2ffc9f6076c8c\LowerCaseLongPathc:\program files\git\mingw64\bin\pkcs1-conv.exe
13241300x8000000000000000673271Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|5cc5d2e050d9b487\BinProductVersion(Empty)
13241300x8000000000000000673270Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|5cc5d2e050d9b487\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673269Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|5cc5d2e050d9b487\Publisher(Empty)
13241300x8000000000000000673268Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pkcs1-conv.exe|5cc5d2e050d9b487\LowerCaseLongPathc:\program files\git\usr\bin\pkcs1-conv.exe
13241300x8000000000000000673267Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinky.exe|852da7421d64c177\BinProductVersion(Empty)
13241300x8000000000000000673266Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinky.exe|852da7421d64c177\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673265Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinky.exe|852da7421d64c177\Publisher(Empty)
13241300x8000000000000000673264Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinky.exe|852da7421d64c177\LowerCaseLongPathc:\program files\git\usr\bin\pinky.exe
13241300x8000000000000000673263Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry.exe|5a096695f03f1450\BinProductVersion(Empty)
13241300x8000000000000000673262Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry.exe|5a096695f03f1450\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673261Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry.exe|5a096695f03f1450\Publisher(Empty)
13241300x8000000000000000673260Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry.exe|5a096695f03f1450\LowerCaseLongPathc:\program files\git\usr\bin\pinentry.exe
13241300x8000000000000000673259Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry-w32.exe|24e0f01a1d2b39e8\BinProductVersion(Empty)
13241300x8000000000000000673258Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry-w32.exe|24e0f01a1d2b39e8\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673257Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry-w32.exe|24e0f01a1d2b39e8\Publisher(Empty)
13241300x8000000000000000673256Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pinentry-w32.exe|24e0f01a1d2b39e8\LowerCaseLongPathc:\program files\git\usr\bin\pinentry-w32.exe
13241300x8000000000000000673255Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl5.32.1.exe|c43f6e17b4097a52\BinProductVersion(Empty)
13241300x8000000000000000673254Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl5.32.1.exe|c43f6e17b4097a52\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673253Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl5.32.1.exe|c43f6e17b4097a52\Publisher(Empty)
13241300x8000000000000000673252Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl5.32.1.exe|c43f6e17b4097a52\LowerCaseLongPathc:\program files\git\usr\bin\perl5.32.1.exe
13241300x8000000000000000673251Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl.exe|196d1afec7915eef\BinProductVersion(Empty)
13241300x8000000000000000673250Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl.exe|196d1afec7915eef\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673249Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl.exe|196d1afec7915eef\Publisher(Empty)
13241300x8000000000000000673248Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\perl.exe|196d1afec7915eef\LowerCaseLongPathc:\program files\git\usr\bin\perl.exe
13241300x8000000000000000673247Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pdftotext.exe|69d0d84ca547f7ea\BinProductVersion(Empty)
13241300x8000000000000000673246Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pdftotext.exe|69d0d84ca547f7ea\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673245Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pdftotext.exe|69d0d84ca547f7ea\Publisher(Empty)
13241300x8000000000000000673244Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.653{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pdftotext.exe|69d0d84ca547f7ea\LowerCaseLongPathc:\program files\git\mingw64\bin\pdftotext.exe
13241300x8000000000000000673243Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pathchk.exe|815a4f847b55a65e\BinProductVersion(Empty)
13241300x8000000000000000673242Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pathchk.exe|815a4f847b55a65e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673241Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pathchk.exe|815a4f847b55a65e\Publisher(Empty)
13241300x8000000000000000673240Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\pathchk.exe|815a4f847b55a65e\LowerCaseLongPathc:\program files\git\usr\bin\pathchk.exe
13241300x8000000000000000673239Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\BinProductVersion(Empty)
13241300x8000000000000000673238Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673237Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\Publisher(Empty)
13241300x8000000000000000673236Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.638{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\patch.exe|ec282c9a0120237a\LowerCaseLongPathc:\program files\git\usr\bin\patch.exe
13241300x8000000000000000673235Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\BinProductVersion(Empty)
13241300x8000000000000000673234Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673233Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\Publisher(Empty)
13241300x8000000000000000673232Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\paste.exe|4b6449e13df12ac2\LowerCaseLongPathc:\program files\git\usr\bin\paste.exe
13241300x8000000000000000673231Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\BinProductVersion(Empty)
13241300x8000000000000000673230Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673229Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\Publisher(Empty)
13241300x8000000000000000673228Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\passwd.exe|3074fd45afd21d5a\LowerCaseLongPathc:\program files\git\usr\bin\passwd.exe
13241300x8000000000000000673227Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\BinProductVersion(Empty)
13241300x8000000000000000673226Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673225Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\Publisher(Empty)
13241300x8000000000000000673224Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit.exe|8bade04a6e35b25c\LowerCaseLongPathc:\program files\git\usr\bin\p11-kit.exe
13241300x8000000000000000673223Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\BinProductVersion(Empty)
13241300x8000000000000000673222Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673221Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\Publisher(Empty)
13241300x8000000000000000673220Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-server.e|2949625778c73062\LowerCaseLongPathc:\program files\git\usr\libexec\p11-kit\p11-kit-server.exe
13241300x8000000000000000673219Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\BinProductVersion(Empty)
13241300x8000000000000000673218Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673217Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\Publisher(Empty)
13241300x8000000000000000673216Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\p11-kit-remote.e|51a36587ed162938\LowerCaseLongPathc:\program files\git\usr\libexec\p11-kit\p11-kit-remote.exe
13241300x8000000000000000673215Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\BinProductVersion1.1.1.11
13241300x8000000000000000673214Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\LinkDate03/25/2021 15:20:47
13241300x8000000000000000673213Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\Publisherthe openssl project, https://www.openssl.org/
13241300x8000000000000000673212Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.622{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|f1700e8a34a30f68\LowerCaseLongPathc:\program files\git\mingw64\bin\openssl.exe
13241300x8000000000000000673211Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\BinProductVersion1.1.1.11
13241300x8000000000000000673210Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673209Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\Publisherthe openssl project, https://www.openssl.org/
13241300x8000000000000000673208Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\openssl.exe|171f6196cf43df96\LowerCaseLongPathc:\program files\git\usr\bin\openssl.exe
13241300x8000000000000000673207Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\BinProductVersion(Empty)
13241300x8000000000000000673206Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673205Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\Publisher(Empty)
13241300x8000000000000000673204Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\odt2txt.exe|6473e7d965a98c3a\LowerCaseLongPathc:\program files\git\mingw64\bin\odt2txt.exe
13241300x8000000000000000673203Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\BinProductVersion(Empty)
13241300x8000000000000000673202Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673201Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\Publisher(Empty)
13241300x8000000000000000673200Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\od.exe|4327ce9d2e91b98c\LowerCaseLongPathc:\program files\git\usr\bin\od.exe
13241300x8000000000000000673199Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\BinProductVersion(Empty)
13241300x8000000000000000673198Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673197Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\Publisher(Empty)
13241300x8000000000000000673196Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\numfmt.exe|8ee1d73a41ab2c69\LowerCaseLongPathc:\program files\git\usr\bin\numfmt.exe
13241300x8000000000000000673195Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\BinProductVersion(Empty)
13241300x8000000000000000673194Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673193Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\Publisher(Empty)
13241300x8000000000000000673192Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nproc.exe|4b998916d3f3a9c7\LowerCaseLongPathc:\program files\git\usr\bin\nproc.exe
13241300x8000000000000000673191Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\BinProductVersion(Empty)
13241300x8000000000000000673190Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673189Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\Publisher(Empty)
13241300x8000000000000000673188Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.606{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nohup.exe|b6d740d02d8e649a\LowerCaseLongPathc:\program files\git\usr\bin\nohup.exe
13241300x8000000000000000673187Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.605{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\BinProductVersion(Empty)
13241300x8000000000000000673186Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.605{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673185Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.605{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\Publisher(Empty)
13241300x8000000000000000673184Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.605{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nl.exe|a11f2aa66e5f8174\LowerCaseLongPathc:\program files\git\usr\bin\nl.exe
13241300x8000000000000000673183Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.601{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\BinProductVersion(Empty)
13241300x8000000000000000673182Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.601{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673181Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.601{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\Publisher(Empty)
13241300x8000000000000000673180Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.601{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nice.exe|d195556bd0ad811f\LowerCaseLongPathc:\program files\git\usr\bin\nice.exe
23542300x8000000000000000673179Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:05.522{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=84489B3FA6842ED8B82FF2EB274776A0,SHA256=B4ABE2F3BB62A16DC75200DF3F3B17E7C266C68B6DA35C1AD1CD9B4DE478D17A,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000673178Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:05.472{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C8C025A2F2AC3E2108A4519937D827A5,SHA256=4A565803B87BCCC880CFD1A6B8AD3EF382C87B67444C10728E863FE23DAE4DE3,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000673177Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.454{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\BinProductVersion0.19.8.0
13241300x8000000000000000673176Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.454{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\LinkDate01/01/1970 00:00:02
13241300x8000000000000000673175Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.453{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\Publisherfree software foundation
13241300x8000000000000000673174Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.453{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ngettext.exe|b3b7f8b500cfd995\LowerCaseLongPathc:\program files\git\usr\bin\ngettext.exe
13241300x8000000000000000673173Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.453{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\BinProductVersion(Empty)
13241300x8000000000000000673172Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.453{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673171Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.453{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\Publisher(Empty)
13241300x8000000000000000673170Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.453{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-pbkdf2.ex|97ba977fde0c62d6\LowerCaseLongPathc:\program files\git\usr\bin\nettle-pbkdf2.exe
13241300x8000000000000000673169Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.452{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\BinProductVersion(Empty)
13241300x8000000000000000673168Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.452{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673167Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.452{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\Publisher(Empty)
13241300x8000000000000000673166Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.452{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-lfib-stre|884dcfac9ef75867\LowerCaseLongPathc:\program files\git\usr\bin\nettle-lfib-stream.exe
13241300x8000000000000000673165Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.452{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\BinProductVersion(Empty)
13241300x8000000000000000673164Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.452{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673163Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.451{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\Publisher(Empty)
13241300x8000000000000000673162Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.451{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nettle-hash.exe|b53503615f207ffa\LowerCaseLongPathc:\program files\git\usr\bin\nettle-hash.exe
13241300x8000000000000000673161Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.451{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\BinProductVersion(Empty)
13241300x8000000000000000673160Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.451{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673159Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.451{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\Publisher(Empty)
13241300x8000000000000000673158Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.451{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\nano.exe|b50a21634bf0fc7\LowerCaseLongPathc:\program files\git\usr\bin\nano.exe
13241300x8000000000000000673157Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.444{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\BinProductVersion(Empty)
13241300x8000000000000000673156Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.444{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673155Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.444{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\Publisher(Empty)
13241300x8000000000000000673154Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.444{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mv.exe|929878a0fb05584e\LowerCaseLongPathc:\program files\git\usr\bin\mv.exe
23542300x8000000000000000673153Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:05.350{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=2F3A3C3967F05EC213A3D47E20D0D206,SHA256=1F8F434E2CCC7F36A1057DBC8AFA78A8EAF13132C28BBB1EDBAB7FD71A3E1A8B,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000673152Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\BinProductVersion(Empty)
13241300x8000000000000000673151Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\LinkDate01/01/1970 00:00:01
13241300x8000000000000000673150Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\Publisher(Empty)
13241300x8000000000000000673149Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msguniq.exe|630e939fcdce570c\LowerCaseLongPathc:\program files\git\usr\bin\msguniq.exe
13241300x8000000000000000673148Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\BinProductVersion(Empty)
13241300x8000000000000000673147Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673146Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\Publisher(Empty)
13241300x8000000000000000673145Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.330{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgunfmt.exe|e224c743b2bfe999\LowerCaseLongPathc:\program files\git\usr\bin\msgunfmt.exe
13241300x8000000000000000673144Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.329{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\BinProductVersion(Empty)
13241300x8000000000000000673143Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.329{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673142Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.329{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\Publisher(Empty)
13241300x8000000000000000673141Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.329{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgmerge.exe|70a7277cc4533b58\LowerCaseLongPathc:\program files\git\usr\bin\msgmerge.exe
13241300x8000000000000000673140Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\BinProductVersion(Empty)
13241300x8000000000000000673139Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\LinkDate01/18/2021 06:51:50
13241300x8000000000000000673138Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\Publisher(Empty)
13241300x8000000000000000673137Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.328{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msginit.exe|5aa0cd7045e63438\LowerCaseLongPathc:\program files\git\usr\bin\msginit.exe
13241300x8000000000000000673136Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.327{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\BinProductVersion(Empty)
13241300x8000000000000000673135Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.327{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673134Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.327{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\Publisher(Empty)
13241300x8000000000000000673133Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.327{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msggrep.exe|983cdb3b51d722e3\LowerCaseLongPathc:\program files\git\usr\bin\msggrep.exe
13241300x8000000000000000673132Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.325{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\BinProductVersion(Empty)
13241300x8000000000000000673131Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.325{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673130Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.325{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\Publisher(Empty)
13241300x8000000000000000673129Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.325{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfmt.exe|b876ce85e126a312\LowerCaseLongPathc:\program files\git\usr\bin\msgfmt.exe
13241300x8000000000000000673128Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\BinProductVersion(Empty)
13241300x8000000000000000673127Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673126Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\Publisher(Empty)
13241300x8000000000000000673125Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.323{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgfilter.exe|aaac2b93f137f1ae\LowerCaseLongPathc:\program files\git\usr\bin\msgfilter.exe
13241300x8000000000000000673124Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.322{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\BinProductVersion(Empty)
13241300x8000000000000000673123Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.322{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\LinkDate01/01/1970 00:00:01
13241300x8000000000000000673122Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.322{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\Publisher(Empty)
13241300x8000000000000000673121Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.322{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgexec.exe|9c976ab4ff6e1c54\LowerCaseLongPathc:\program files\git\usr\bin\msgexec.exe
13241300x8000000000000000673120Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.321{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\BinProductVersion(Empty)
13241300x8000000000000000673119Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.321{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673118Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.321{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\Publisher(Empty)
13241300x8000000000000000673117Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.321{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgen.exe|da6af5ac56e9716\LowerCaseLongPathc:\program files\git\usr\bin\msgen.exe
13241300x8000000000000000673116Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.321{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\BinProductVersion(Empty)
13241300x8000000000000000673115Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.321{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673114Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.320{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\Publisher(Empty)
13241300x8000000000000000673113Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.320{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgconv.exe|be24512a01e4ec35\LowerCaseLongPathc:\program files\git\usr\bin\msgconv.exe
13241300x8000000000000000673112Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.320{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\BinProductVersion(Empty)
13241300x8000000000000000673111Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.320{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673110Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.320{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\Publisher(Empty)
13241300x8000000000000000673109Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.320{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcomm.exe|6ef471fb1825a1cd\LowerCaseLongPathc:\program files\git\usr\bin\msgcomm.exe
13241300x8000000000000000673108Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.319{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\BinProductVersion(Empty)
13241300x8000000000000000673107Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.319{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\LinkDate05/08/2031 18:06:26
13241300x8000000000000000673106Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.319{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\Publisher(Empty)
13241300x8000000000000000673105Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.319{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcmp.exe|7c2e229e6e1c68a8\LowerCaseLongPathc:\program files\git\usr\bin\msgcmp.exe
13241300x8000000000000000673104Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.318{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\BinProductVersion(Empty)
13241300x8000000000000000673103Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.318{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\LinkDate01/01/1970 00:00:01
13241300x8000000000000000673102Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.318{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\Publisher(Empty)
13241300x8000000000000000673101Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.318{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgcat.exe|5596b37e57e3e044\LowerCaseLongPathc:\program files\git\usr\bin\msgcat.exe
13241300x8000000000000000673100Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.318{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\BinProductVersion(Empty)
13241300x8000000000000000673099Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.318{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\LinkDate01/01/1970 00:00:01
13241300x8000000000000000673098Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\Publisher(Empty)
13241300x8000000000000000673097Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\msgattrib.exe|ef0e87f6c6fba86f\LowerCaseLongPathc:\program files\git\usr\bin\msgattrib.exe
13241300x8000000000000000673096Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\BinProductVersion(Empty)
13241300x8000000000000000673095Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673094Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\Publisher(Empty)
13241300x8000000000000000673093Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.317{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mpicalc.exe|f96ca699905a957b\LowerCaseLongPathc:\program files\git\usr\bin\mpicalc.exe
13241300x8000000000000000673092Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.316{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\BinProductVersion(Empty)
13241300x8000000000000000673091Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.316{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673090Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.316{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\Publisher(Empty)
13241300x8000000000000000673089Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.316{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mount.exe|9be5c50fa3ad3871\LowerCaseLongPathc:\program files\git\usr\bin\mount.exe
13241300x8000000000000000673088Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.313{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\BinProductVersion(Empty)
13241300x8000000000000000673087Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.313{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673086Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.313{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\Publisher(Empty)
13241300x8000000000000000673085Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.313{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mktemp.exe|f571057b3b322073\LowerCaseLongPathc:\program files\git\usr\bin\mktemp.exe
13241300x8000000000000000673084Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.312{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\BinProductVersion(Empty)
13241300x8000000000000000673083Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.312{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673082Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.312{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\Publisher(Empty)
13241300x8000000000000000673081Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.312{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkpasswd.exe|73ea587603f838db\LowerCaseLongPathc:\program files\git\usr\bin\mkpasswd.exe
13241300x8000000000000000673080Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.310{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\BinProductVersion(Empty)
13241300x8000000000000000673079Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.310{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673078Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.310{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\Publisher(Empty)
13241300x8000000000000000673077Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.310{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mknod.exe|1c9cc79f3ba29852\LowerCaseLongPathc:\program files\git\usr\bin\mknod.exe
13241300x8000000000000000673076Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.309{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\BinProductVersion(Empty)
13241300x8000000000000000673075Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.309{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673074Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.309{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\Publisher(Empty)
13241300x8000000000000000673073Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.309{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkgroup.exe|b0fed08db39d16e4\LowerCaseLongPathc:\program files\git\usr\bin\mkgroup.exe
13241300x8000000000000000673072Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.306{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\BinProductVersion(Empty)
13241300x8000000000000000673071Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.306{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673070Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.306{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\Publisher(Empty)
13241300x8000000000000000673069Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.306{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkfifo.exe|1676140672f1cfe0\LowerCaseLongPathc:\program files\git\usr\bin\mkfifo.exe
13241300x8000000000000000673068Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.305{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\BinProductVersion(Empty)
13241300x8000000000000000673067Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.305{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673066Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.305{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\Publisher(Empty)
13241300x8000000000000000673065Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.305{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mkdir.exe|d166f5452ec8d3f1\LowerCaseLongPathc:\program files\git\usr\bin\mkdir.exe
13241300x8000000000000000673064Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.303{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\BinProductVersion0.0.0.0
13241300x8000000000000000673063Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.303{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673062Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.303{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\Publisherandy koppe / thomas wolff
13241300x8000000000000000673061Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.303{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mintty.exe|49e751352c5fb46d\LowerCaseLongPathc:\program files\git\usr\bin\mintty.exe
13241300x8000000000000000673060Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.293{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\BinProductVersion(Empty)
13241300x8000000000000000673059Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.293{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\LinkDate03/26/2021 22:24:40
13241300x8000000000000000673058Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.293{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\Publisher(Empty)
13241300x8000000000000000673057Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.293{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\minidumper.exe|54796dc6e15198fd\LowerCaseLongPathc:\program files\git\usr\bin\minidumper.exe
13241300x8000000000000000673056Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.291{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\BinProductVersion(Empty)
13241300x8000000000000000673055Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.291{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673054Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.291{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\Publisher(Empty)
13241300x8000000000000000673053Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.291{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\md5sum.exe|24d7cfd4f0a567ad\LowerCaseLongPathc:\program files\git\usr\bin\md5sum.exe
13241300x8000000000000000673052Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.290{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\BinProductVersion(Empty)
13241300x8000000000000000673051Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.290{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673050Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.290{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\Publisher(Empty)
13241300x8000000000000000673049Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.290{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\mac2unix.exe|fa8c232fc2ace248\LowerCaseLongPathc:\program files\git\usr\bin\mac2unix.exe
13241300x8000000000000000673048Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.289{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\BinProductVersion5.2.5.0
13241300x8000000000000000673047Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.289{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673046Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.289{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\Publisherthe tukaani project <https://tukaani.org/>
13241300x8000000000000000673045Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.289{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmainfo.exe|3070267691718925\LowerCaseLongPathc:\program files\git\mingw64\bin\lzmainfo.exe
13241300x8000000000000000673044Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\BinProductVersion5.2.5.0
13241300x8000000000000000673043Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673042Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\Publisherthe tukaani project <https://tukaani.org/>
13241300x8000000000000000673041Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.288{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lzmadec.exe|d4a4f5d09de2ad9f\LowerCaseLongPathc:\program files\git\mingw64\bin\lzmadec.exe
13241300x8000000000000000673040Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.287{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\BinProductVersion(Empty)
13241300x8000000000000000673039Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.287{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\LinkDate03/26/2021 22:24:39
13241300x8000000000000000673038Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.287{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\Publisher(Empty)
13241300x8000000000000000673037Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.287{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lsattr.exe|e9598ad07d9f1abe\LowerCaseLongPathc:\program files\git\usr\bin\lsattr.exe
13241300x8000000000000000673036Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.285{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\BinProductVersion(Empty)
13241300x8000000000000000673035Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.285{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673034Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.285{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\Publisher(Empty)
13241300x8000000000000000673033Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.285{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ls.exe|dfaab3a81c3b31c6\LowerCaseLongPathc:\program files\git\usr\bin\ls.exe
13241300x8000000000000000673032Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.282{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\BinProductVersion(Empty)
13241300x8000000000000000673031Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.282{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673030Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.282{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\Publisher(Empty)
13241300x8000000000000000673029Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.282{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\logname.exe|12359a62b40825c8\LowerCaseLongPathc:\program files\git\usr\bin\logname.exe
13241300x8000000000000000673028Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.281{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\BinProductVersion(Empty)
13241300x8000000000000000673027Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.281{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673026Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.281{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\Publisher(Empty)
13241300x8000000000000000673025Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.281{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locate.exe|62a0c84839d4a077\LowerCaseLongPathc:\program files\git\usr\bin\locate.exe
13241300x8000000000000000673024Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.278{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\BinProductVersion(Empty)
13241300x8000000000000000673023Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.278{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\LinkDate03/26/2021 22:24:39
13241300x8000000000000000673022Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.278{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\Publisher(Empty)
13241300x8000000000000000673021Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.278{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\locale.exe|5d75359b8fae4864\LowerCaseLongPathc:\program files\git\usr\bin\locale.exe
13241300x8000000000000000673020Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\BinProductVersion(Empty)
13241300x8000000000000000673019Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673018Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\Publisher(Empty)
13241300x8000000000000000673017Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.275{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ln.exe|79dda9f517ff22bc\LowerCaseLongPathc:\program files\git\usr\bin\ln.exe
13241300x8000000000000000673016Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.273{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\BinProductVersion(Empty)
13241300x8000000000000000673015Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.273{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673014Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.273{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\Publisher(Empty)
13241300x8000000000000000673013Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.273{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\link.exe|293c50e422886ac8\LowerCaseLongPathc:\program files\git\usr\bin\link.exe
13241300x8000000000000000673012Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\BinProductVersion(Empty)
13241300x8000000000000000673011Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673010Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\Publisher(Empty)
13241300x8000000000000000673009Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lesskey.exe|6d817558b9a5216\LowerCaseLongPathc:\program files\git\usr\bin\lesskey.exe
13241300x8000000000000000673008Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\BinProductVersion(Empty)
13241300x8000000000000000673007Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.271{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673006Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.270{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\Publisher(Empty)
13241300x8000000000000000673005Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.270{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\lessecho.exe|3b7a4aa7df4af94e\LowerCaseLongPathc:\program files\git\usr\bin\lessecho.exe
13241300x8000000000000000673004Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.270{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\BinProductVersion(Empty)
13241300x8000000000000000673003Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.270{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673002Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.270{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\Publisher(Empty)
13241300x8000000000000000673001Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.270{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\less.exe|a02ef69e95f97e25\LowerCaseLongPathc:\program files\git\usr\bin\less.exe
13241300x8000000000000000673000Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.267{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\BinProductVersion(Empty)
13241300x8000000000000000672999Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.267{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\LinkDate03/26/2021 22:24:41
13241300x8000000000000000672998Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.266{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\Publisher(Empty)
13241300x8000000000000000672997Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.266{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldh.exe|da4d63a2fca071c0\LowerCaseLongPathc:\program files\git\usr\bin\ldh.exe
13241300x8000000000000000672996Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.266{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\BinProductVersion(Empty)
13241300x8000000000000000672995Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.266{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\LinkDate03/26/2021 22:24:39
13241300x8000000000000000672994Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.266{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\Publisher(Empty)
13241300x8000000000000000672993Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.266{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ldd.exe|15068ec08ef3ecfc\LowerCaseLongPathc:\program files\git\usr\bin\ldd.exe
13241300x8000000000000000672992Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.263{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\BinProductVersion(Empty)
13241300x8000000000000000672991Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.263{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\LinkDate03/26/2021 22:24:39
13241300x8000000000000000672990Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.263{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\Publisher(Empty)
13241300x8000000000000000672989Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.263{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kill.exe|4bade27621c021e4\LowerCaseLongPathc:\program files\git\usr\bin\kill.exe
13241300x8000000000000000672988Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.261{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\BinProductVersion(Empty)
13241300x8000000000000000672987Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.261{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672986Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.261{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\Publisher(Empty)
13241300x8000000000000000672985Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.261{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\kbxutil.exe|1308e71e0c8d3207\LowerCaseLongPathc:\program files\git\usr\bin\kbxutil.exe
13241300x8000000000000000672984Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\BinProductVersion(Empty)
13241300x8000000000000000672983Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672982Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\Publisher(Empty)
13241300x8000000000000000672981Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.258{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\join.exe|dc913e518f010b9e\LowerCaseLongPathc:\program files\git\usr\bin\join.exe
13241300x8000000000000000672980Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.257{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\BinProductVersion(Empty)
13241300x8000000000000000672979Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.257{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672978Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.257{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\Publisher(Empty)
13241300x8000000000000000672977Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.257{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\install.exe|6fbae492ae887311\LowerCaseLongPathc:\program files\git\usr\bin\install.exe
13241300x8000000000000000672976Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.254{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\BinProductVersion(Empty)
13241300x8000000000000000672975Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.254{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672974Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.254{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\Publisher(Empty)
13241300x8000000000000000672973Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.254{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infotocap.exe|b30daf4370dfb24c\LowerCaseLongPathc:\program files\git\usr\bin\infotocap.exe
13241300x8000000000000000672972Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.252{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\BinProductVersion(Empty)
13241300x8000000000000000672971Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.252{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672970Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.252{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\Publisher(Empty)
13241300x8000000000000000672969Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.252{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\infocmp.exe|bf56519423b7f5b4\LowerCaseLongPathc:\program files\git\usr\bin\infocmp.exe
13241300x8000000000000000672968Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.252{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\id.exe|58d5aeed1760e581\BinProductVersion(Empty)
13241300x8000000000000000672967Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.251{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\id.exe|58d5aeed1760e581\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672966Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.251{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\id.exe|58d5aeed1760e581\Publisher(Empty)
13241300x8000000000000000672965Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.251{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\id.exe|58d5aeed1760e581\LowerCaseLongPathc:\program files\git\usr\bin\id.exe
13241300x8000000000000000672964Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.251{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\iconv.exe|aa01f87ce2558a5a\BinProductVersion(Empty)
13241300x8000000000000000672963Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.251{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\iconv.exe|aa01f87ce2558a5a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672962Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.251{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\iconv.exe|aa01f87ce2558a5a\Publisher(Empty)
13241300x8000000000000000672961Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.250{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\iconv.exe|aa01f87ce2558a5a\LowerCaseLongPathc:\program files\git\usr\bin\iconv.exe
13241300x8000000000000000672960Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.250{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|87d3101f283dd346\BinProductVersion(Empty)
13241300x8000000000000000672959Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.250{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|87d3101f283dd346\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672958Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.250{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|87d3101f283dd346\Publisher(Empty)
13241300x8000000000000000672957Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.250{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|87d3101f283dd346\LowerCaseLongPathc:\program files\git\usr\bin\hostname.exe
13241300x8000000000000000672956Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.248{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|810b252b242085fc\BinProductVersion(Empty)
13241300x8000000000000000672955Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.248{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|810b252b242085fc\LinkDate06/19/2025 15:30:53
13241300x8000000000000000672954Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.248{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|810b252b242085fc\Publisher(Empty)
13241300x8000000000000000672953Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.248{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostname.exe|810b252b242085fc\LowerCaseLongPathc:\program files\git\usr\lib\gettext\hostname.exe
13241300x8000000000000000672952Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostid.exe|6d4143f0897c8d41\BinProductVersion(Empty)
13241300x8000000000000000672951Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostid.exe|6d4143f0897c8d41\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672950Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostid.exe|6d4143f0897c8d41\Publisher(Empty)
13241300x8000000000000000672949Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hostid.exe|6d4143f0897c8d41\LowerCaseLongPathc:\program files\git\usr\bin\hostid.exe
13241300x8000000000000000672948Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hmac256.exe|32958ea17350316\BinProductVersion(Empty)
13241300x8000000000000000672947Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hmac256.exe|32958ea17350316\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672946Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hmac256.exe|32958ea17350316\Publisher(Empty)
13241300x8000000000000000672945Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.247{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\hmac256.exe|32958ea17350316\LowerCaseLongPathc:\program files\git\usr\bin\hmac256.exe
13241300x8000000000000000672944Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.246{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\headless-git.exe|785e29ace5e8bd40\BinProductVersion2.31.1.1
13241300x8000000000000000672943Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.246{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\headless-git.exe|785e29ace5e8bd40\LinkDate03/27/2021 09:56:19
13241300x8000000000000000672942Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.246{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\headless-git.exe|785e29ace5e8bd40\Publisherthe git development community
13241300x8000000000000000672941Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.246{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\headless-git.exe|785e29ace5e8bd40\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\headless-git.exe
13241300x8000000000000000672940Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\head.exe|fc7ddc9982db949a\BinProductVersion(Empty)
13241300x8000000000000000672939Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\head.exe|fc7ddc9982db949a\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672938Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\head.exe|fc7ddc9982db949a\Publisher(Empty)
13241300x8000000000000000672937Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\head.exe|fc7ddc9982db949a\LowerCaseLongPathc:\program files\git\usr\bin\head.exe
13241300x8000000000000000672936Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.244{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gzip.exe|5579843dbc752d44\BinProductVersion(Empty)
13241300x8000000000000000672935Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.244{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gzip.exe|5579843dbc752d44\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672934Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.244{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gzip.exe|5579843dbc752d44\Publisher(Empty)
13241300x8000000000000000672933Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.244{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gzip.exe|5579843dbc752d44\LowerCaseLongPathc:\program files\git\usr\bin\gzip.exe
13241300x8000000000000000672932Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.242{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gsettings.exe|4246bb34aefdd57f\BinProductVersion(Empty)
13241300x8000000000000000672931Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.242{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gsettings.exe|4246bb34aefdd57f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672930Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.242{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gsettings.exe|4246bb34aefdd57f\Publisher(Empty)
13241300x8000000000000000672929Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.241{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gsettings.exe|4246bb34aefdd57f\LowerCaseLongPathc:\program files\git\usr\bin\gsettings.exe
13241300x8000000000000000672928Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.241{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\groups.exe|2cd133bd6998e5fb\BinProductVersion(Empty)
13241300x8000000000000000672927Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.241{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\groups.exe|2cd133bd6998e5fb\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672926Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.241{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\groups.exe|2cd133bd6998e5fb\Publisher(Empty)
13241300x8000000000000000672925Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.241{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\groups.exe|2cd133bd6998e5fb\LowerCaseLongPathc:\program files\git\usr\bin\groups.exe
13241300x8000000000000000672924Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.239{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grep.exe|e40de301f2861b6e\BinProductVersion(Empty)
13241300x8000000000000000672923Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.239{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grep.exe|e40de301f2861b6e\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672922Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.239{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grep.exe|e40de301f2861b6e\Publisher(Empty)
13241300x8000000000000000672921Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.239{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grep.exe|e40de301f2861b6e\LowerCaseLongPathc:\program files\git\usr\bin\grep.exe
13241300x8000000000000000672920Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.236{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grcat.exe|dafb27ccdda3446f\BinProductVersion(Empty)
13241300x8000000000000000672919Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.235{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grcat.exe|dafb27ccdda3446f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672918Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.235{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grcat.exe|dafb27ccdda3446f\Publisher(Empty)
13241300x8000000000000000672917Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.235{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\grcat.exe|dafb27ccdda3446f\LowerCaseLongPathc:\program files\git\usr\lib\awk\grcat.exe
13241300x8000000000000000672916Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.235{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgv.exe|3e8076918b3dc637\BinProductVersion(Empty)
13241300x8000000000000000672915Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.235{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgv.exe|3e8076918b3dc637\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672914Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.235{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgv.exe|3e8076918b3dc637\Publisher(Empty)
13241300x8000000000000000672913Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.235{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgv.exe|3e8076918b3dc637\LowerCaseLongPathc:\program files\git\usr\bin\gpgv.exe
13241300x8000000000000000672912Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgtar.exe|83e2bc192363db05\BinProductVersion(Empty)
13241300x8000000000000000672911Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgtar.exe|83e2bc192363db05\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672910Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgtar.exe|83e2bc192363db05\Publisher(Empty)
13241300x8000000000000000672909Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.228{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgtar.exe|83e2bc192363db05\LowerCaseLongPathc:\program files\git\usr\bin\gpgtar.exe
13241300x8000000000000000672908Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.226{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsplit.exe|87bafc2530c840f0\BinProductVersion(Empty)
13241300x8000000000000000672907Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.226{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsplit.exe|87bafc2530c840f0\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672906Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.226{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsplit.exe|87bafc2530c840f0\Publisher(Empty)
13241300x8000000000000000672905Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.226{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsplit.exe|87bafc2530c840f0\LowerCaseLongPathc:\program files\git\usr\bin\gpgsplit.exe
13241300x8000000000000000672904Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.225{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsm.exe|c489439d65554f2c\BinProductVersion(Empty)
13241300x8000000000000000672903Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.225{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsm.exe|c489439d65554f2c\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672902Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.225{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsm.exe|c489439d65554f2c\Publisher(Empty)
13241300x8000000000000000672901Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.225{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgsm.exe|c489439d65554f2c\LowerCaseLongPathc:\program files\git\usr\bin\gpgsm.exe
13241300x8000000000000000672900Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.219{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgscm.exe|afd870348aad8e2b\BinProductVersion(Empty)
13241300x8000000000000000672899Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.219{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgscm.exe|afd870348aad8e2b\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672898Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.219{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgscm.exe|afd870348aad8e2b\Publisher(Empty)
13241300x8000000000000000672897Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.218{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgscm.exe|afd870348aad8e2b\LowerCaseLongPathc:\program files\git\usr\bin\gpgscm.exe
13241300x8000000000000000672896Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.214{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgparsemail.exe|a1d04daf32233825\BinProductVersion(Empty)
13241300x8000000000000000672895Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.214{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgparsemail.exe|a1d04daf32233825\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672894Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.214{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgparsemail.exe|a1d04daf32233825\Publisher(Empty)
13241300x8000000000000000672893Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.214{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgparsemail.exe|a1d04daf32233825\LowerCaseLongPathc:\program files\git\usr\bin\gpgparsemail.exe
13241300x8000000000000000672892Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.213{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgconf.exe|871b799717455ba3\BinProductVersion(Empty)
13241300x8000000000000000672891Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.213{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgconf.exe|871b799717455ba3\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672890Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.213{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgconf.exe|871b799717455ba3\Publisher(Empty)
13241300x8000000000000000672889Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.213{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpgconf.exe|871b799717455ba3\LowerCaseLongPathc:\program files\git\usr\bin\gpgconf.exe
13241300x8000000000000000672888Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg.exe|6cedb1e2633436b0\BinProductVersion(Empty)
13241300x8000000000000000672887Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg.exe|6cedb1e2633436b0\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672886Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg.exe|6cedb1e2633436b0\Publisher(Empty)
13241300x8000000000000000672885Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg.exe|6cedb1e2633436b0\LowerCaseLongPathc:\program files\git\usr\bin\gpg.exe
13241300x8000000000000000672884Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.201{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-server.e|61034539dd4597ca\BinProductVersion(Empty)
13241300x8000000000000000672883Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.200{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-server.e|61034539dd4597ca\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672882Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.200{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-server.e|61034539dd4597ca\Publisher(Empty)
13241300x8000000000000000672881Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.200{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-server.e|61034539dd4597ca\LowerCaseLongPathc:\program files\git\usr\bin\gpg-wks-server.exe
13241300x8000000000000000672880Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.197{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-client.e|2e2d230f1afcaaed\BinProductVersion(Empty)
13241300x8000000000000000672879Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.197{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-client.e|2e2d230f1afcaaed\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672878Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.197{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-client.e|2e2d230f1afcaaed\Publisher(Empty)
13241300x8000000000000000672877Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.197{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-wks-client.e|2e2d230f1afcaaed\LowerCaseLongPathc:\program files\git\usr\lib\gnupg\gpg-wks-client.exe
13241300x8000000000000000672876Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-protect-tool|5c31ebeff73373e2\BinProductVersion(Empty)
13241300x8000000000000000672875Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-protect-tool|5c31ebeff73373e2\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672874Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-protect-tool|5c31ebeff73373e2\Publisher(Empty)
13241300x8000000000000000672873Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-protect-tool|5c31ebeff73373e2\LowerCaseLongPathc:\program files\git\usr\lib\gnupg\gpg-protect-tool.exe
13241300x8000000000000000672872Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.191{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-preset-passp|fd30c53215b384cf\BinProductVersion(Empty)
13241300x8000000000000000672871Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.191{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-preset-passp|fd30c53215b384cf\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672870Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.191{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-preset-passp|fd30c53215b384cf\Publisher(Empty)
13241300x8000000000000000672869Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.191{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-preset-passp|fd30c53215b384cf\LowerCaseLongPathc:\program files\git\usr\lib\gnupg\gpg-preset-passphrase.exe
13241300x8000000000000000672868Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-error.exe|5a340ac79026d48f\BinProductVersion(Empty)
13241300x8000000000000000672867Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-error.exe|5a340ac79026d48f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672866Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-error.exe|5a340ac79026d48f\Publisher(Empty)
13241300x8000000000000000672865Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-error.exe|5a340ac79026d48f\LowerCaseLongPathc:\program files\git\usr\bin\gpg-error.exe
13241300x8000000000000000672864Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.188{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-connect-agen|faaecb1ec9697c58\BinProductVersion(Empty)
13241300x8000000000000000672863Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.188{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-connect-agen|faaecb1ec9697c58\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672862Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.188{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-connect-agen|faaecb1ec9697c58\Publisher(Empty)
13241300x8000000000000000672861Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.188{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-connect-agen|faaecb1ec9697c58\LowerCaseLongPathc:\program files\git\usr\bin\gpg-connect-agent.exe
13241300x8000000000000000672860Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.185{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-check-patter|e2542f724e45af1f\BinProductVersion(Empty)
13241300x8000000000000000672859Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.185{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-check-patter|e2542f724e45af1f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672858Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.185{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-check-patter|e2542f724e45af1f\Publisher(Empty)
13241300x8000000000000000672857Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.185{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-check-patter|e2542f724e45af1f\LowerCaseLongPathc:\program files\git\usr\lib\gnupg\gpg-check-pattern.exe
13241300x8000000000000000672856Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.183{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-agent.exe|a7286887843abc16\BinProductVersion(Empty)
13241300x8000000000000000672855Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.183{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-agent.exe|a7286887843abc16\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672854Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.182{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-agent.exe|a7286887843abc16\Publisher(Empty)
13241300x8000000000000000672853Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.182{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gpg-agent.exe|a7286887843abc16\LowerCaseLongPathc:\program files\git\usr\bin\gpg-agent.exe
13241300x8000000000000000672852Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gobject-query.ex|134cc30a240ef385\BinProductVersion(Empty)
13241300x8000000000000000672851Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gobject-query.ex|134cc30a240ef385\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672850Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gobject-query.ex|134cc30a240ef385\Publisher(Empty)
13241300x8000000000000000672849Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gobject-query.ex|134cc30a240ef385\LowerCaseLongPathc:\program files\git\usr\bin\gobject-query.exe
13241300x8000000000000000672848Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.176{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\glib-compile-sch|5f50bc4882f3c325\BinProductVersion(Empty)
13241300x8000000000000000672847Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.176{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\glib-compile-sch|5f50bc4882f3c325\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672846Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.176{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\glib-compile-sch|5f50bc4882f3c325\Publisher(Empty)
13241300x8000000000000000672845Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.176{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\glib-compile-sch|5f50bc4882f3c325\LowerCaseLongPathc:\program files\git\usr\bin\glib-compile-schemas.exe
13241300x8000000000000000672844Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gkill.exe|16f69740130f5810\BinProductVersion(Empty)
13241300x8000000000000000672843Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gkill.exe|16f69740130f5810\LinkDate01/01/1970 00:00:00
13241300x8000000000000000672842Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gkill.exe|16f69740130f5810\Publisher(Empty)
13241300x8000000000000000672841Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gkill.exe|16f69740130f5810\LowerCaseLongPathc:\program files\git\usr\bin\gkill.exe
13241300x8000000000000000672840Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gitk.exe|f586b11c21ec8a1b\BinProductVersion2.31.1.1
13241300x8000000000000000672839Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gitk.exe|f586b11c21ec8a1b\LinkDate03/27/2021 09:48:41
13241300x8000000000000000672838Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gitk.exe|f586b11c21ec8a1b\Publisherthe git development community
13241300x8000000000000000672837Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.174{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gitk.exe|f586b11c21ec8a1b\LowerCaseLongPathc:\program files\git\cmd\gitk.exe
13241300x8000000000000000672836Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.170{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.ui.exe|1ab248feff39f24\BinProductVersion2.0.394.0
13241300x8000000000000000672835Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.170{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.ui.exe|1ab248feff39f24\LinkDate09/29/2055 20:33:00
13241300x8000000000000000672834Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.170{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.ui.exe|1ab248feff39f24\Publishergithub.ui
13241300x8000000000000000672833Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.170{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.ui.exe|1ab248feff39f24\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\github.ui.exe
13241300x8000000000000000672832Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.authentic|8ce4a82757c1afc5\BinProductVersion1.5.0.0
13241300x8000000000000000672831Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.authentic|8ce4a82757c1afc5\LinkDate09/05/2019 15:01:45
13241300x8000000000000000672830Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.authentic|8ce4a82757c1afc5\Publishergithub
13241300x8000000000000000672829Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.167{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\github.authentic|8ce4a82757c1afc5\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\github.authentication.exe
13241300x8000000000000000672828Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.162{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|f578b1fba462cbf9\BinProductVersion2.31.1.1
13241300x8000000000000000672827Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.162{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|f578b1fba462cbf9\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672826Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.162{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|f578b1fba462cbf9\Publisherthe git development community
13241300x8000000000000000672825Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.162{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|f578b1fba462cbf9\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git.exe
23542300x8000000000000000672824Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:05.151{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=9A8198E4CD85477D45C3130EF92BC282,SHA256=4159C5B4890196D822483BE9E3AAA4695387A11D238E55333DCB16AFC5963D1E,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000672823Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.140{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|ce9561cbd46d08cb\BinProductVersion2.31.1.1
13241300x8000000000000000672822Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.140{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|ce9561cbd46d08cb\LinkDate03/27/2021 09:48:40
13241300x8000000000000000672821Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.140{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|ce9561cbd46d08cb\Publisherthe git development community
13241300x8000000000000000672820Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.140{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|ce9561cbd46d08cb\LowerCaseLongPathc:\program files\git\bin\git.exe
13241300x8000000000000000672819Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.138{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|5a45dbb5af7f9d72\BinProductVersion2.31.1.1
13241300x8000000000000000672818Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.138{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|5a45dbb5af7f9d72\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672817Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.138{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|5a45dbb5af7f9d72\Publisherthe git development community
13241300x8000000000000000672816Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.138{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|5a45dbb5af7f9d72\LowerCaseLongPathc:\program files\git\mingw64\bin\git.exe
13241300x8000000000000000672815Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.129{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|52b02c4a618839ad\BinProductVersion2.31.1.1
13241300x8000000000000000672814Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.129{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|52b02c4a618839ad\LinkDate03/27/2021 09:48:40
13241300x8000000000000000672813Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.129{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|52b02c4a618839ad\Publisherthe git development community
13241300x8000000000000000672812Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.129{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git.exe|52b02c4a618839ad\LowerCaseLongPathc:\program files\git\cmd\git.exe
13241300x8000000000000000672811Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-write-tree.e|792c1951a5d77083\BinProductVersion2.31.1.1
13241300x8000000000000000672810Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-write-tree.e|792c1951a5d77083\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672809Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-write-tree.e|792c1951a5d77083\Publisherthe git development community
13241300x8000000000000000672808Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.128{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-write-tree.e|792c1951a5d77083\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-write-tree.exe
13241300x8000000000000000672807Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-wrapper.exe|76f08d89fd716e41\BinProductVersion2.31.1.1
13241300x8000000000000000672806Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-wrapper.exe|76f08d89fd716e41\LinkDate03/27/2021 09:48:40
13241300x8000000000000000672805Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-wrapper.exe|76f08d89fd716e41\Publisherthe git development community
13241300x8000000000000000672804Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.118{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-wrapper.exe|76f08d89fd716e41\LowerCaseLongPathc:\program files\git\mingw64\share\git\git-wrapper.exe
13241300x8000000000000000672803Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.117{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-worktree.exe|334239d9fbdc7a11\BinProductVersion2.31.1.1
13241300x8000000000000000672802Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.117{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-worktree.exe|334239d9fbdc7a11\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672801Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.116{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-worktree.exe|334239d9fbdc7a11\Publisherthe git development community
13241300x8000000000000000672800Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.116{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-worktree.exe|334239d9fbdc7a11\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-worktree.exe
13241300x8000000000000000672799Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.107{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-whatchanged.|b8fb62958eb786da\BinProductVersion2.31.1.1
13241300x8000000000000000672798Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.107{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-whatchanged.|b8fb62958eb786da\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672797Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.107{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-whatchanged.|b8fb62958eb786da\Publisherthe git development community
13241300x8000000000000000672796Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.107{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-whatchanged.|b8fb62958eb786da\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-whatchanged.exe
13241300x8000000000000000672795Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.097{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-tag.e|d492b12e36f71329\BinProductVersion2.31.1.1
13241300x8000000000000000672794Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.097{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-tag.e|d492b12e36f71329\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672793Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.097{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-tag.e|d492b12e36f71329\Publisherthe git development community
13241300x8000000000000000672792Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.097{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-tag.e|d492b12e36f71329\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-verify-tag.exe
13241300x8000000000000000672791Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.087{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-pack.|d565dfc7b34b65aa\BinProductVersion2.31.1.1
13241300x8000000000000000672790Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.087{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-pack.|d565dfc7b34b65aa\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672789Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.087{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-pack.|d565dfc7b34b65aa\Publisherthe git development community
13241300x8000000000000000672788Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.087{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-pack.|d565dfc7b34b65aa\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-verify-pack.exe
13241300x8000000000000000672787Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.077{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-commi|f37a5e9bd2f4578a\BinProductVersion2.31.1.1
13241300x8000000000000000672786Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.077{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-commi|f37a5e9bd2f4578a\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672785Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.077{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-commi|f37a5e9bd2f4578a\Publisherthe git development community
13241300x8000000000000000672784Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.077{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-verify-commi|f37a5e9bd2f4578a\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-verify-commit.exe
10341000x8000000000000000672783Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:05.075{7B03F3B2-7FE0-609D-1456-00000000BA01}47122132C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.4349_none_7f09d74e21ec00ab\TiWorker.exe{7B03F3B2-7FE0-609D-1356-00000000BA01}5204C:\Windows\servicing\TrustedInstaller.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6134|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.4349_none_7f09d74e21ec00ab\TiWorker.exe+3611|C:\Windows\System32\RPCRT4.dll+7a593|C:\Windows\System32\RPCRT4.dll+d9f41|C:\Windows\System32\RPCRT4.dll+618a9|C:\Windows\System32\combase.dll+27a9|C:\Windows\System32\RPCRT4.dll+62d9b|C:\Windows\System32\combase.dll+64ddc|C:\Windows\System32\combase.dll+64a92|C:\Windows\System32\combase.dll+633a8|C:\Windows\System32\combase.dll+6112d|C:\Windows\System32\combase.dll+6080f|C:\Windows\System32\combase.dll+7bfe9|C:\Windows\System32\RPCRT4.dll+4a274|C:\Windows\System32\RPCRT4.dll+4918d|C:\Windows\System32\RPCRT4.dll+49cde|C:\Windows\System32\RPCRT4.dll+30ed7|C:\Windows\System32\RPCRT4.dll+3152c|C:\Windows\System32\RPCRT4.dll+1ae1c|C:\Windows\System32\RPCRT4.dll+1c67b|C:\Windows\System32\RPCRT4.dll+43a2a|C:\Windows\SYSTEM32\ntdll.dll+1d34e|C:\Windows\SYSTEM32\ntdll.dll+1ecb9
13241300x8000000000000000672782Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-var.exe|751104bdaadb1181\BinProductVersion2.31.1.1
13241300x8000000000000000672781Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-var.exe|751104bdaadb1181\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672780Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-var.exe|751104bdaadb1181\Publisherthe git development community
13241300x8000000000000000672779Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.068{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-var.exe|751104bdaadb1181\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-var.exe
13241300x8000000000000000672778Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.059{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|e0593a4774ace4ad\BinProductVersion2.31.1.1
13241300x8000000000000000672777Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.059{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|e0593a4774ace4ad\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672776Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.059{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|e0593a4774ace4ad\Publisherthe git development community
13241300x8000000000000000672775Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.059{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|e0593a4774ace4ad\LowerCaseLongPathc:\program files\git\mingw64\bin\git-upload-pack.exe
13241300x8000000000000000672774Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.050{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|4bc571ea2cc47819\BinProductVersion2.31.1.1
13241300x8000000000000000672773Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.050{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|4bc571ea2cc47819\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672772Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.050{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|4bc571ea2cc47819\Publisherthe git development community
13241300x8000000000000000672771Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.050{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-pack.|4bc571ea2cc47819\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-upload-pack.exe
13241300x8000000000000000672770Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|f4cda268b43d63d5\BinProductVersion2.31.1.1
13241300x8000000000000000672769Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|f4cda268b43d63d5\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672768Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|f4cda268b43d63d5\Publisherthe git development community
13241300x8000000000000000672767Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.041{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|f4cda268b43d63d5\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-upload-archive.exe
13241300x8000000000000000672766Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.032{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|970cdd550165a34b\BinProductVersion2.31.1.1
13241300x8000000000000000672765Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.032{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|970cdd550165a34b\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672764Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.032{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|970cdd550165a34b\Publisherthe git development community
13241300x8000000000000000672763Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.032{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-upload-archi|970cdd550165a34b\LowerCaseLongPathc:\program files\git\mingw64\bin\git-upload-archive.exe
13241300x8000000000000000672762Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.022{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-serve|d3496551fcee326\BinProductVersion2.31.1.1
13241300x8000000000000000672761Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.022{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-serve|d3496551fcee326\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672760Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.022{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-serve|d3496551fcee326\Publisherthe git development community
13241300x8000000000000000672759Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.022{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-serve|d3496551fcee326\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-update-server-info.exe
13241300x8000000000000000672758Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.013{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-ref.e|636e33b932a7ad4\BinProductVersion2.31.1.1
13241300x8000000000000000672757Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.013{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-ref.e|636e33b932a7ad4\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672756Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.013{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-ref.e|636e33b932a7ad4\Publisherthe git development community
13241300x8000000000000000672755Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.013{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-ref.e|636e33b932a7ad4\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-update-ref.exe
13241300x8000000000000000672754Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:05.003{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-index|cc5c84a1add7114d\BinProductVersion2.31.1.1
13241300x8000000000000000672753Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:05.003{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-index|cc5c84a1add7114d\LinkDate03/27/2021 09:56:23
13241300x8000000000000000672752Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:05.003{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-index|cc5c84a1add7114d\Publisherthe git development community
13241300x8000000000000000672751Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:05.003{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\git-update-index|cc5c84a1add7114d\LowerCaseLongPathc:\program files\git\mingw64\libexec\git-core\git-update-index.exe
23542300x8000000000000000673848Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:06.961{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=0D22F72CCC6C152B73420E6AAF318DFD,SHA256=670CBE40C7750BD3AA976ECC816231B18D3F0FAD3748DC0E3C850367F2D92174,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000572683Microsoft-Windows-Sysmon/Operationalwin-host-681.attackrange.local-2021-05-13 19:37:06.778{E1BD9FC2-D343-609A-D400-00000000BB01}2696NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=07427988B82E79F69A81AE587CB5332C,SHA256=176FBB15ACBB6B2B8A11955860061074070E7AB31940EE99B6DB012E48A0DB1B,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000673847Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:06.325{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=C45D80BD060412C176604B9C134E641D,SHA256=040273BFA0867371EF42A1907DB581C0A44DB1516227D9C59203634813D65C80,IMPHASH=00000000000000000000000000000000falsetrue
23542300x8000000000000000673846Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:06.259{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=443453CE57BE5604FBC42B764192710D,SHA256=2C50C6B002A41CE798EBD7A40F68AFB260877C1BC25404DD1C6A4B006F3C7231,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000673845Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.245{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000e88c864b87418038dd1cb1c0f40fac4b0000ffff\PublisherNmap Project
13241300x8000000000000000673844Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.243{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|af59766a7e5a8c5a\BinProductVersion5.1.20.305
13241300x8000000000000000673843Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.243{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|af59766a7e5a8c5a\LinkDate08/01/2020 03:04:08
13241300x8000000000000000673842Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.243{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|af59766a7e5a8c5a\Publisher(Empty)
13241300x8000000000000000673841Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.243{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|af59766a7e5a8c5a\LowerCaseLongPathc:\program files\npcap\uninstall.exe
13241300x8000000000000000673840Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npfinstall.exe|4fcd245e63e11e31\BinProductVersion5.1.20.305
13241300x8000000000000000673839Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npfinstall.exe|4fcd245e63e11e31\LinkDate03/05/2021 22:42:31
13241300x8000000000000000673838Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npfinstall.exe|4fcd245e63e11e31\Publisherinsecure.com llc.
13241300x8000000000000000673837Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npfinstall.exe|4fcd245e63e11e31\LowerCaseLongPathc:\program files\npcap\npfinstall.exe
13241300x8000000000000000673836Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.sys|3741aa4c3d128834\BinProductVersion5.1.20.305
13241300x8000000000000000673835Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.sys|3741aa4c3d128834\LinkDate03/05/2021 22:42:37
13241300x8000000000000000673834Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.sys|3741aa4c3d128834\Publisherinsecure.com llc.
13241300x8000000000000000673833Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\npcap.sys|3741aa4c3d128834\LowerCaseLongPathc:\program files\npcap\npcap.sys
13241300x8000000000000000673832Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000e22a0949596eef20fe03957e1f2fbd7e0000ffff\PublisherNotepad++ Team
13241300x8000000000000000673831Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|bd4762a4deb0ebdc\BinProductVersion7.9.5.0
13241300x8000000000000000673830Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|bd4762a4deb0ebdc\LinkDate12/15/2018 22:24:36
13241300x8000000000000000673829Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|bd4762a4deb0ebdc\Publisherdon ho don.h@free.fr
13241300x8000000000000000673828Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\uninstall.exe|bd4762a4deb0ebdc\LowerCaseLongPathc:\program files\notepad++\uninstall.exe
13241300x8000000000000000673827Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\notepad++.exe|9b63189e96115672\BinProductVersion7.9.5.0
13241300x8000000000000000673826Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\notepad++.exe|9b63189e96115672\LinkDate03/21/2021 01:15:42
13241300x8000000000000000673825Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\notepad++.exe|9b63189e96115672\Publisherdon ho don.h@free.fr
13241300x8000000000000000673824Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.227{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\notepad++.exe|9b63189e96115672\LowerCaseLongPathc:\program files\notepad++\notepad++.exe
13241300x8000000000000000673823Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.221{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gup.exe|eaab466dc417ed01\BinProductVersion5.1.3.0
13241300x8000000000000000673822Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.221{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gup.exe|eaab466dc417ed01\LinkDate03/08/2021 20:02:13
13241300x8000000000000000673821Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.221{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gup.exe|eaab466dc417ed01\Publisherdon ho don.h@free.fr
13241300x8000000000000000673820Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.221{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\gup.exe|eaab466dc417ed01\LowerCaseLongPathc:\program files\notepad++\updater\gup.exe
13241300x8000000000000000673819Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.216{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplication\0000df264dabd056fd627673f81b364e56d90000ffff\PublisherThe Git Development Community
13241300x8000000000000000673818Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.211{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\BinProductVersion(Empty)
13241300x8000000000000000673817Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.211{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673816Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.211{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\Publisher(Empty)
13241300x8000000000000000673815Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.211{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\[.exe|b6eac39997c90239\LowerCaseLongPathc:\program files\git\usr\bin\[.exe
13241300x8000000000000000673814Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ziptool.exe|7269435f129e6e01\BinProductVersion(Empty)
13241300x8000000000000000673813Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ziptool.exe|7269435f129e6e01\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673812Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ziptool.exe|7269435f129e6e01\Publisher(Empty)
13241300x8000000000000000673811Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.210{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\ziptool.exe|7269435f129e6e01\LowerCaseLongPathc:\program files\git\mingw64\bin\ziptool.exe
13241300x8000000000000000673810Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.207{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipmerge.exe|13ce9e43b33787b4\BinProductVersion(Empty)
13241300x8000000000000000673809Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.207{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipmerge.exe|13ce9e43b33787b4\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673808Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.207{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipmerge.exe|13ce9e43b33787b4\Publisher(Empty)
13241300x8000000000000000673807Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.207{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipmerge.exe|13ce9e43b33787b4\LowerCaseLongPathc:\program files\git\mingw64\bin\zipmerge.exe
13241300x8000000000000000673806Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.204{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipinfo.exe|221fb78378e3082e\BinProductVersion(Empty)
13241300x8000000000000000673805Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.204{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipinfo.exe|221fb78378e3082e\LinkDate05/08/2031 18:06:26
13241300x8000000000000000673804Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.204{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipinfo.exe|221fb78378e3082e\Publisher(Empty)
13241300x8000000000000000673803Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.204{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipinfo.exe|221fb78378e3082e\LowerCaseLongPathc:\program files\git\usr\bin\zipinfo.exe
13241300x8000000000000000673802Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.200{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipcmp.exe|72e4c18935f10855\BinProductVersion(Empty)
13241300x8000000000000000673801Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.200{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipcmp.exe|72e4c18935f10855\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673800Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.200{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipcmp.exe|72e4c18935f10855\Publisher(Empty)
13241300x8000000000000000673799Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.200{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\zipcmp.exe|72e4c18935f10855\LowerCaseLongPathc:\program files\git\mingw64\bin\zipcmp.exe
13241300x8000000000000000673798Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.196{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yes.exe|101013f8ea4cecdc\BinProductVersion(Empty)
13241300x8000000000000000673797Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.196{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yes.exe|101013f8ea4cecdc\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673796Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.196{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yes.exe|101013f8ea4cecdc\Publisher(Empty)
13241300x8000000000000000673795Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.196{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yes.exe|101013f8ea4cecdc\LowerCaseLongPathc:\program files\git\usr\bin\yes.exe
13241300x8000000000000000673794Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.195{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yat2m.exe|e602d782765213bc\BinProductVersion(Empty)
13241300x8000000000000000673793Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.195{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yat2m.exe|e602d782765213bc\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673792Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.195{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yat2m.exe|e602d782765213bc\Publisher(Empty)
13241300x8000000000000000673791Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.195{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\yat2m.exe|e602d782765213bc\LowerCaseLongPathc:\program files\git\usr\bin\yat2m.exe
13241300x8000000000000000673790Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzdec.exe|aa41a1b6191a17c5\BinProductVersion5.2.5.0
13241300x8000000000000000673789Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzdec.exe|aa41a1b6191a17c5\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673788Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzdec.exe|aa41a1b6191a17c5\Publisherthe tukaani project <https://tukaani.org/>
13241300x8000000000000000673787Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzdec.exe|aa41a1b6191a17c5\LowerCaseLongPathc:\program files\git\mingw64\bin\xzdec.exe
13241300x8000000000000000673786Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzcat.exe|6c454d521625ef75\BinProductVersion5.2.5.0
13241300x8000000000000000673785Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzcat.exe|6c454d521625ef75\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673784Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzcat.exe|6c454d521625ef75\Publisherthe tukaani project <https://tukaani.org/>
13241300x8000000000000000673783Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.194{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xzcat.exe|6c454d521625ef75\LowerCaseLongPathc:\program files\git\mingw64\bin\xzcat.exe
13241300x8000000000000000673782Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xz.exe|f5dd0ac934ca84a7\BinProductVersion5.2.5.0
13241300x8000000000000000673781Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xz.exe|f5dd0ac934ca84a7\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673780Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xz.exe|f5dd0ac934ca84a7\Publisherthe tukaani project <https://tukaani.org/>
13241300x8000000000000000673779Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.192{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xz.exe|f5dd0ac934ca84a7\LowerCaseLongPathc:\program files\git\mingw64\bin\xz.exe
13241300x8000000000000000673778Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xxd.exe|ec817b4721384459\BinProductVersion(Empty)
13241300x8000000000000000673777Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xxd.exe|ec817b4721384459\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673776Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xxd.exe|ec817b4721384459\Publisher(Empty)
13241300x8000000000000000673775Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xxd.exe|ec817b4721384459\LowerCaseLongPathc:\program files\git\usr\bin\xxd.exe
13241300x8000000000000000673774Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xmlwf.exe|db82f10a63bc087f\BinProductVersion(Empty)
13241300x8000000000000000673773Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xmlwf.exe|db82f10a63bc087f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673772Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xmlwf.exe|db82f10a63bc087f\Publisher(Empty)
13241300x8000000000000000673771Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.190{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xmlwf.exe|db82f10a63bc087f\LowerCaseLongPathc:\program files\git\mingw64\bin\xmlwf.exe
13241300x8000000000000000673770Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xgettext.exe|d70e9fbf1e3251f9\BinProductVersion(Empty)
13241300x8000000000000000673769Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xgettext.exe|d70e9fbf1e3251f9\LinkDate07/19/2029 06:51:46
13241300x8000000000000000673768Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xgettext.exe|d70e9fbf1e3251f9\Publisher(Empty)
13241300x8000000000000000673767Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.189{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xgettext.exe|d70e9fbf1e3251f9\LowerCaseLongPathc:\program files\git\usr\bin\xgettext.exe
13241300x8000000000000000673766Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.183{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xargs.exe|b26b4866fba2ace6\BinProductVersion(Empty)
13241300x8000000000000000673765Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.183{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xargs.exe|b26b4866fba2ace6\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673764Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.183{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xargs.exe|b26b4866fba2ace6\Publisher(Empty)
13241300x8000000000000000673763Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.183{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\xargs.exe|b26b4866fba2ace6\LowerCaseLongPathc:\program files\git\usr\bin\xargs.exe
13241300x8000000000000000673762Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.182{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|dda5875a0a94e702\BinProductVersion(Empty)
13241300x8000000000000000673761Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.182{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|dda5875a0a94e702\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673760Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.182{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|dda5875a0a94e702\Publisher(Empty)
13241300x8000000000000000673759Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|dda5875a0a94e702\LowerCaseLongPathc:\program files\git\mingw64\bin\x86_64-w64-mingw32-deflatehd.exe
13241300x8000000000000000673758Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|d480e6241e2b429f\BinProductVersion(Empty)
13241300x8000000000000000673757Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|d480e6241e2b429f\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673756Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|d480e6241e2b429f\Publisher(Empty)
13241300x8000000000000000673755Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.181{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|d480e6241e2b429f\LowerCaseLongPathc:\program files\git\mingw64\bin\x86_64-w64-mingw32-inflatehd.exe
13241300x8000000000000000673754Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.180{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|721349a4c3d19334\BinProductVersion(Empty)
13241300x8000000000000000673753Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.180{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|721349a4c3d19334\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673752Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.180{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|721349a4c3d19334\Publisher(Empty)
13241300x8000000000000000673751Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.180{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\x86_64-w64-mingw|721349a4c3d19334\LowerCaseLongPathc:\program files\git\mingw64\bin\x86_64-w64-mingw32-agrep.exe
13241300x8000000000000000673750Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.179{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish86.exe|b43e477f47c04c0d\BinProductVersion8.6.2.11
13241300x8000000000000000673749Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.179{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish86.exe|b43e477f47c04c0d\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673748Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.178{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish86.exe|b43e477f47c04c0d\Publisheractivestate corporation
13241300x8000000000000000673747Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.178{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish86.exe|b43e477f47c04c0d\LowerCaseLongPathc:\program files\git\mingw64\bin\wish86.exe
13241300x8000000000000000673746Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish.exe|387f467bcbc945b9\BinProductVersion8.6.2.11
13241300x8000000000000000673745Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish.exe|387f467bcbc945b9\LinkDate01/01/1970 00:00:00
13241300x8000000000000000673744Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish.exe|387f467bcbc945b9\Publisheractivestate corporation
13241300x8000000000000000673743Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.177{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wish.exe|387f467bcbc945b9\LowerCaseLongPathc:\program files\git\mingw64\bin\wish.exe
13241300x8000000000000000673742Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wintoast.exe|a56a902040daad41\BinProductVersion(Empty)
13241300x8000000000000000673741Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wintoast.exe|a56a902040daad41\LinkDate11/17/2017 22:11:01
13241300x8000000000000000673740Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wintoast.exe|a56a902040daad41\Publisher(Empty)
13241300x8000000000000000673739Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.175{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\wintoast.exe|a56a902040daad41\LowerCaseLongPathc:\program files\git\mingw64\bin\wintoast.exe
23542300x8000000000000000673738Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:06.172{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\Microsoft-Windows-Sysmon_OperationalMD5=F5A0B7C7CEB7458DEF840E492904CB37,SHA256=93AE8009483CC824B6E133902F1ECDE9BC1E413653757E580E09A2442A01CCD6,IMPHASH=00000000000000000000000000000000falsetrue
13241300x8000000000000000673737Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.168{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty.exe|b62f1084964abfa7\BinProductVersion(Empty)
13241300x8000000000000000673736Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.168{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty.exe|b62f1084964abfa7\LinkDate06/19/2025 15:30:53
13241300x8000000000000000673735Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.168{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty.exe|b62f1084964abfa7\Publisher(Empty)
13241300x8000000000000000673734Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.168{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty.exe|b62f1084964abfa7\LowerCaseLongPathc:\program files\git\usr\bin\winpty.exe
13241300x8000000000000000673733Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.158{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-debugserv|fa3a25afb3dba9c5\BinProductVersion(Empty)
13241300x8000000000000000673732Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.158{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-debugserv|fa3a25afb3dba9c5\LinkDate05/08/2031 18:06:26
13241300x8000000000000000673731Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.158{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-debugserv|fa3a25afb3dba9c5\Publisher(Empty)
13241300x8000000000000000673730Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.158{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-debugserv|fa3a25afb3dba9c5\LowerCaseLongPathc:\program files\git\usr\bin\winpty-debugserver.exe
13241300x8000000000000000673729Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-VerSetValue2021-05-13 19:37:06.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-agent.exe|f42c4e896f998b23\BinProductVersion(Empty)
13241300x8000000000000000673728Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-CompileTimeClaimSetValue2021-05-13 19:37:06.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-agent.exe|f42c4e896f998b23\LinkDate05/08/2031 18:06:26
13241300x8000000000000000673727Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PubSetValue2021-05-13 19:37:06.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-agent.exe|f42c4e896f998b23\Publisher(Empty)
13241300x8000000000000000673726Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.localInvDB-PathSetValue2021-05-13 19:37:06.143{7B03F3B2-7FC6-609D-0256-00000000BA01}6592C:\Windows\system32\CompatTelRunner.exe\REGISTRY\A\{5f4499c3-b0c2-9c54-76a0-07542524398e}\Root\InventoryApplicationFile\winpty-agent.exe|f42c4e896f998b23\LowerCaseLongPathc:\program files\git\usr\bin\winpty-agent.exe
23542300x8000000000000000673725Microsoft-Windows-Sysmon/Operationalwin-dc-18.attackrange.local-2021-05-13 19:37:06.140{7B03F3B2-5130-609D-6950-00000000BA01}7212NT AUTHORITY\SYSTEMC:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exeC:\Program Files\SplunkUniversalForwarder\var\lib\splunk\modinputs\WinEventLog\SystemMD5=22F201BCB9872CA7DD447E54C1254ECD,SHA256=2E9E33E26A9E14B64E8B09303288ECA32233D07A0422913F0B2AEF46733857