Sysmon 13.30 SourceUser and TargetUser values different than expected for EventID 10

Hubert Sękowski 1 Reputation point

Tests done in one sandbox (AWS instance with Windows 2022; security protection disabled).
Events generated with use of mimikatz, where local user was running the tool.
I was getting '<Data Name='SourceUser'>NT AUTHORITY\SYSTEM</Data><Data Name='TargetUser'>IP-0ACA0544\localuser</Data>' in most cases and '<Data Name='SourceUser'>IP-0ACA0544\localuser</Data><Data Name='TargetUser'>NT AUTHORITY\SYSTEM</Data>' in few cases.
Tests done in another sandbox were showing localuser as a TargetUser till first restart of machine and then it was as expected.

I think that can be also observed here: (vs )

Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,034 questions
0 comments No comments
{count} votes