{
    "Event": {
        "xmlns": "http://schemas.microsoft.com/win/2004/08/events/event",
        "System": {
            "Provider": {
                "Name": "Microsoft-Windows-Sysmon",
                "Guid": "{5770385F-C22A-43E0-BF4C-06F5698FFBD9}"
            },
            "EventID": "1",
            "Version": "5",
            "Level": "4",
            "Task": "1",
            "Opcode": "0",
            "Keywords": "0x8000000000000000",
            "TimeCreated": {
                "SystemTime": "2020-10-01T11:31:09.793595700Z"
            },
            "EventRecordID": "757728",
            "Correlation": null,
            "Execution": {
                "ProcessID": "2816",
                "ThreadID": "3188"
            },
            "Channel": "Microsoft-Windows-Sysmon/Operational",
            "Computer": "server16.server16.int",
            "Security": {
                "UserID": "S-1-5-18"
            }
        },
        "EventData": {
            "Data": [
                {
                    "text": "psexec_run",
                    "Name": "RuleName"
                },
                {
                    "text": "2020-10-01 11:31:09.757",
                    "Name": "UtcTime"
                },
                {
                    "text": "{222467B7-BDFD-5F75-0000-00108000E404}",
                    "Name": "ProcessGuid"
                },
                {
                    "text": "5672",
                    "Name": "ProcessId"
                },
                {
                    "text": "C:\\Users\\Administrator\\Downloads\\PSTools\\PsExec.exe",
                    "Name": "Image"
                },
                {
                    "text": "2.2",
                    "Name": "FileVersion"
                },
                {
                    "text": "Execute processes remotely",
                    "Name": "Description"
                },
                {
                    "text": "Sysinternals PsExec",
                    "Name": "Product"
                },
                {
                    "text": "Sysinternals - www.sysinternals.com",
                    "Name": "Company"
                },
                {
                    "text": "psexec.c",
                    "Name": "OriginalFileName"
                },
                {
                    "text": "C:\\Users\\Administrator\\Downloads\\PSTools\\PsExec.exe  -s cmd",
                    "Name": "CommandLine"
                },
                {
                    "text": "C:\\Users\\Administrator\\",
                    "Name": "CurrentDirectory"
                },
                {
                    "text": "SERVER160\\Administrator",
                    "Name": "User"
                },
                {
                    "text": "{222467B7-BFBA-5F6D-0000-002030250500}",
                    "Name": "LogonGuid"
                },
                {
                    "text": "0x52530",
                    "Name": "LogonId"
                },
                {
                    "text": "1",
                    "Name": "TerminalSessionId"
                },
                {
                    "text": "High",
                    "Name": "IntegrityLevel"
                },
                {
                    "text": "SHA256=3337E3875B05E0BFBA69AB926532E3F179E8CFBF162EBB60CE58A0281437A7EF",
                    "Name": "Hashes"
                },
                {
                    "text": "{222467B7-D29C-5F6D-0000-0010BC7E2F00}",
                    "Name": "ParentProcessGuid"
                },
                {
                    "text": "3904",
                    "Name": "ParentProcessId"
                },
                {
                    "text": "C:\\Windows\\System32\\cmd.exe",
                    "Name": "ParentImage"
                },
                {
                    "text": "\"C:\\Windows\\system32\\cmd.exe\" ",
                    "Name": "ParentCommandLine"
                }
            ]
        }
    }
}