A SOC analyst needs to investigate suspicious PowerShell behavior on a Windows server and wants process creation, network connections, file writes, and registry changes from a single host-based source. Which tool output should be prioritized?
Select an answer to reveal the explanation.
Short Explanation
Think of Sysmon like a host-level CCTV camera that records process starts, network connects, file writes, and registry edits. If you need to see what a suspicious process actually did on the endpoint, Sysmon events are the detailed tape; NetFlow only shows flows, and scan or isolation logs miss the behavior trail. Don't confuse any endpoint log with the one that captures all four artifacts.
Full Explanation
Sysmon is designed for granular host telemetry on Windows systems, so it is the right source when an analyst must reconstruct what a process did after execution. Its event stream can show process creation with command line and parent process, outbound network connections, file creation, and registry modifications, which are the artifacts commonly used to distinguish benign administration from malicious persistence or lateral movement. In a SOC workflow, those events are collected into the SIEM and correlated with indicators or hunting queries. NetFlow records describe communication metadata between hosts and can help identify unusual destinations, but they do not contain process, file, or registry details and therefore cannot answer endpoint behavior questions by themselves. An EDR isolation command history records containment actions taken by the agent, not the full behavioral trail that led to the decision, so it is too narrow for initial reconstruction. A vulnerability scanner report describes missing patches, misconfigurations, or exposed services, which supports remediation prioritization but does not reveal runtime activity or attacker actions. Exam caveat: when a scenario explicitly asks for process creation, network connections, file writes, and registry changes on a host, select the host-based telemetry source that captures all four. Operational check: confirm the Sysmon service is running and that event IDs for process creation, network connection, file creation, and registry changes are reaching the SIEM with host names and timestamps.