[sysmon-eventid]
REGEX = (\d+)
FORMAT = EventCode::$1
[sysmon-version]
REGEX = (\d+)
FORMAT = Version::$1
[sysmon-level]
REGEX = (\d+)
FORMAT = Level::$1
[sysmon-task]
REGEX = (\d+)
FORMAT = Task::$1
[sysmon-opcode]
REGEX = (\d+)
FORMAT = Opcode::$1
[sysmon-keywords]
REGEX = (0x[0-9a-fA-F]+)
FORMAT = Keywords::$1
[sysmon-created]
REGEX =
FORMAT = TimeCreated::$1
[sysmon-record]
REGEX = (\d+)
FORMAT = RecordID::$1
[sysmon-correlation]
REGEX = (.*?)
FORMAT = Correlation::$1
[sysmon-channel]
REGEX = (.*?)
FORMAT = EventChannel::$1
[sysmon-computer]
REGEX = (.*?)
FORMAT = Computer::$1
[sysmon-sid]
REGEX =
FORMAT = SecurityID::$1
[sysmon-data]
REGEX = (.*?)
FORMAT = $1::$2
[sysmon-md5]
REGEX = MD5\=([a-fA-F0-9]{32}?)
FORMAT = MD5::$1
[sysmon-sha1]
REGEX = SHA1\=([a-fA-F0-9]{40}?)
FORMAT = SHA1::$1
[sysmon-sha256]
REGEX = SHA256\=([a-fA-F0-9]{64}?)
FORMAT = SHA256::$1
[sysmon-imphash]
REGEX = IMPHASH\=([a-fA-F0-9]{32}?)
FORMAT = IMPHASH::$1
[sysmon-hashes]
SOURCE_KEY = Hashes
REGEX = (?[A-Fa-f0-9]{32,})
MV_ADD = true
REPEAT_MATCH=true
[sysmon-filename]
SOURCE_KEY = TargetFilename
REGEX = (?[^\\\\]+$)
[sysmon-registry]
SOURCE_KEY = TargetObject
REGEX = (?