{
    "Event": {
        "xmlns": "http://schemas.microsoft.com/win/2004/08/events/event",
        "System": {
            "Provider": {
                "Name": "Microsoft-Windows-Sysmon",
                "Guid": "{5770385F-C22A-43E0-BF4C-06F5698FFBD9}"
            },
            "EventID": "10",
            "Version": "3",
            "Level": "4",
            "Task": "10",
            "Opcode": "0",
            "Keywords": "0x8000000000000000",
            "TimeCreated": {
                "SystemTime": "2018-11-19T12:28:01.424247700Z"
            },
            "EventRecordID": "69",
            "Correlation": null,
            "Execution": {
                "ProcessID": "7084",
                "ThreadID": "6012"
            },
            "Channel": "Microsoft-Windows-Sysmon/Operational",
            "Computer": "server16.server16.int",
            "Security": {
                "UserID": "S-1-5-18"
            }
        },
        "EventData": {
            "Data": [{
                    "Name": "RuleName"
                }, {
                    "text": "2018-11-19 12:28:01.390",
                    "Name": "UtcTime"
                }, {
                    "text": "{222467B7-74C1-5BEE-0000-0010C9900000}",
                    "Name": "SourceProcessGUID"
                }, {
                    "text": "576",
                    "Name": "SourceProcessId"
                }, {
                    "text": "6224",
                    "Name": "SourceThreadId"
                }, {
                    "text": "C:\\Windows\\system32\\lsass.exe",
                    "Name": "SourceImage"
                }, {
                    "text": "{222467B7-AC4F-5BF2-0000-00102DC0A702}",
                    "Name": "TargetProcessGUID"
                }, {
                    "text": "6860",
                    "Name": "TargetProcessId"
                }, {
                    "text": "C:\\Windows\\system32\\winlogon.exe",
                    "Name": "TargetImage"
                }, {
                    "text": "0x1478",
                    "Name": "GrantedAccess"
                }, {
                    "text": "C:\\Windows\\SYSTEM32\\ntdll.dll+a5314|C:\\Windows\\system32\\lsasrv.dll+d127|C:\\Windows\\system32\\lsasrv.dll+e1dd|C:\\Windows\\system32\\lsasrv.dll+cfa5|C:\\Windows\\SYSTEM32\\SspiSrv.dll+11a2|C:\\Windows\\System32\\RPCRT4.dll+77d63|C:\\Windows\\System32\\RPCRT4.dll+db98d|C:\\Windows\\System32\\RPCRT4.dll+60edc|C:\\Windows\\System32\\RPCRT4.dll+4a2b4|C:\\Windows\\System32\\RPCRT4.dll+491cd|C:\\Windows\\System32\\RPCRT4.dll+49a7b|C:\\Windows\\System32\\RPCRT4.dll+29c1c|C:\\Windows\\System32\\RPCRT4.dll+2a09c|C:\\Windows\\System32\\RPCRT4.dll+4438c|C:\\Windows\\System32\\RPCRT4.dll+45beb|C:\\Windows\\System32\\RPCRT4.dll+386ea|C:\\Windows\\SYSTEM32\\ntdll.dll+325fe|C:\\Windows\\SYSTEM32\\ntdll.dll+330d9|C:\\Windows\\System32\\KERNEL32.DLL+8364|C:\\Windows\\SYSTEM32\\ntdll.dll+65e91",
                    "Name": "CallTrace"
                }
            ]
        }
    }
}
