Hello..
How would one build a decoder for the SYsmon 22 event?
Example Event:
2023 Jul 31 01:03:22 (SDL23) any->EventChannel {"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"22","version":"5","level":"4","task":"22","opcode":"0","keywords":"0x8000000000000000","systemTime":"2023-07-31T01:03:20.8337940Z","eventRecordID":"3965131","processID":"4436","threadID":"6364","channel":"Microsoft-Windows-Sysmon/Operational","computer":"SDL23.ssi.private","severityValue":"INFORMATION","message":"\"Dns query:\r\nRuleName: -\r\nUtcTime: 2023-07-31 01:03:35.106\r\nProcessGuid: {6b0aea5e-7e12-64af-e300-000000000d00}\r\nProcessId: 896\r\nQueryName:
huntress.io\r\nQueryStatus: 0\r\nQueryResults: ::ffff:54.205.213.128;::ffff:54.144.158.23;::ffff:44.214.241.73;::ffff:35.172.187.164;::ffff:44.206.18.117;::ffff:3.86.123.150;\r\nImage: C:\\Program Files\\Huntress\\HuntressAgent.exe\r\nUser: NT AUTHORITY\\SYSTEM\""},"eventdata":{"utcTime":"2023-07-31 01:03:35.106","processGuid":"{6b0aea5e-7e12-64af-e300-000000000d00}","processId":"896","queryName":"
huntress.io","queryStatus":"0","queryResults":"::ffff:54.205.213.128;::ffff:54.144.158.23;::ffff:44.214.241.73;::ffff:35.172.187.164;::ffff:44.206.18.117;::ffff:3.86.123.150;","image":"C:\\\\Program Files\\\\Huntress\\\\HuntressAgent.exe","user":"NT AUTHORITY\\\\SYSTEM"}}}