PastePile

Evidence formats

Sysmon log analysis

Sysmon records the process, network and registry activity that the Security log misses. Upload the Microsoft-Windows-Sysmon/Operational .evtx file and PastePile reads it with the same Windows compromise pack it uses for Security and System logs. Each case gets a timeline, findings that cite the exact records behind them, a list of what the evidence cannot establish, and hunts compiled to Defender KQL, Sentinel KQL, Splunk SPL, Elastic ES|QL and Sigma for the tools you already run.

What you can upload

  • Sysmon Operational channel exported as .evtx
  • Sysmon records in Windows System/EventData JSON or JSONL, including compatible Velociraptor output

What PastePile checks

  • Process creation chains: Office or browser parents launching script hosts, encoded PowerShell, PowerShell downloads
  • Suspicious built-in binary use, certutil decode or download, remote wmic, bcdedit recovery changes, shadow copy deletion
  • Registry Run keys that launch a script interpreter
  • Defender exclusions added from the command line
  • Rare parent/child pairs and first-seen external destinations, reported as rarity within your upload

Every finding cites the records behind it and states what it does not establish. Statistical signals are reported as rarity within your upload and never become findings. ATT&CK mappings describe what a behavior resembles, not proof that an adversary was present.

What it does not do

  • PastePile reads the events Sysmon was configured to record; it cannot report activity your Sysmon configuration did not capture
  • Rarity is measured only against what you uploaded, not against a global baseline

Try it

Open the synthetic Office document to encoded PowerShell case to see the timeline, findings, unknowns and report without an account. When you are ready, create an account and compare plans.

Other evidence formats