Since I received no answer I tested this myself. Company field is taken from the executable metadata, as Version and other similar fields are. Therefore, it is not even minimally reliable, since anyone can manipulate it with basic resources.
Sysmon Event ID 1 Company field
Anonymous
Hi,
We are working on some security analytics based on Sysmon logs. Sysmon Event ID 1 (process creation) include a field named "Company" which seems to be the signer of the executable being used by the process.
We would need to know how trustable the value in this field is: is it actually based on the code signing certificate used for the executable? If so, is the certificate validated?
Thanks in advance to everyone, have a nice day!
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,251 questions