title: DN_0011_7_windows_sysmon_image_loaded description: > The image loaded event logs when a module is loaded in a specific process loggingpolicy: - LP_0006_windows_sysmon_image_loaded references: - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90007 - https://github.com/Cyb3rWard0g/OSSEM/blob/master/data_dictionaries/windows/sysmon/event-7.md category: OS Logs platform: Windows type: Applications and Services Logs channel: Microsoft-Windows-Sysmon/Operational provider: Microsoft-Windows-Sysmon fields: - EventID - Computer - Hostname # redundant - UtcTime - ProcessGuid - ProcessId - Image - ImageLoaded - FileVersion - Description - Product - Company - OriginalFileName - Hashes - Signed - Signature - SignatureStatus sample: | - - 7 3 4 7 0 0x8000000000000000 9146 Microsoft-Windows-Sysmon/Operational atc-win-10 - 2019-07-09 04:13:59.602 {717CFEC0-1487-5D24-0000-00103F202900} 2352 C:\Windows\System32\sihost.exe C:\Windows\System32\msvcrt.dll 7.0.14393.0 (rs1_release.160715-1616) Windows NT CRT DLL Microsoft® Windows® Operating System Microsoft Corporation msvcrt.dll MD5=94EF9321C287FC1B179419E662996A41,SHA256=555B434EC9E8628820905A8F1D7BC7F8EE99C6D44A01892ADD16E39E6B675A0D true Microsoft Windows Valid