title: DN_0009_5_windows_sysmon_process_terminated description: > Process has been terminated loggingpolicy: - None references: - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90005 category: OS Logs platform: Windows type: Applications and Services Logs channel: Microsoft-Windows-Sysmon/Operational provider: Microsoft-Windows-Sysmon fields: - EventID - Computer - Hostname # redundant - UtcTime - ProcessGuid - ProcessId - Image sample: | - - 5 3 4 5 0 0x8000000000000000 57994 Microsoft-Windows-Sysmon/Operational atc-win-10.atc.local - 2019-02-05 15:16:38.821 {9683FBB1-A8D6-5C59-0000-001009797000} 2440 C:\Windows\PSEXESVC.exe