Sysmon Event ID 3 and 22: Network Connections and DNS Queries

Sysmon Event ID 3 and 22 requires reading the full event, not just the Event ID: time, computer, user, Logon ID, Process, network source, and organizational context. The conclusion is formed by correlating multiple sources.
Windows and Identity investigations rely on a combination of authentication events, process creation, permission changes, Sysmon telemetry, and organizational context. A single event almost never provides a complete conclusion. This article focuses on Sysmon Event ID 3 and 22 and is intended for SOC analysts and Endpoint investigators. The goal is to provide a working methodology that can be applied in practice, in a professional interview, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. ProcessGuid, DestinationIp, DestinationPort can point to a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the investigation around an investigative question, required evidence, and clear termination criteria.
The practical scenario in the article is: Connecting a Query to a process and IP in a Timeline. All examples are lab data or process descriptions. When it comes to Penetration Testing, Web, or Cloud, one must only work with explicit authorization, a defined Scope, and the ability to stop the test.




