Skip to content

Event Examples

Jonathan Johnson edited this page Sep 28, 2023 · 2 revisions

Page show examples of some of the events exposed through JonMon

Event ID 1 - Process Create

image

Event ID 2 - Process Open

image

Event ID 4 - Image Load

image

Event ID 5 - Registry Create Key

image

Event ID 6 - Registry Delete Key

image

Event ID 7 - Registry Set Value

image

Event ID 8 - Process ReParenting

image

Event ID 11 - RPC Client Call

image

Event ID 12 - RPC Server Call

image

Event ID 13 - Network Connection

HTTPS Beacon

image

HTTP Beacon

image

Event ID 17 - Thread Impersonation

image

Event ID 21 - File Create

image

Event ID 23 - NamedPipe Create

image

Event ID 25 - WMI Event Subscription

image

Event ID 26 - QueueUserAPC

image

Event ID 27 - Driver Load

image

Event ID 29 - Process Write

image

Event ID 30 - Process Read

image

Event ID 31 - Thread Token Impersonation

image