[
  {
    "id": "sample-001",
    "timestamp": "2026-07-15T13:00:12Z",
    "host": "WIN11-SAMPLE-01",
    "channel": "Sysmon",
    "eventId": 1,
    "eventType": "Process Create",
    "user": "SAMPLE\\analyst",
    "image": "C:\\Windows\\explorer.exe",
    "parentImage": "C:\\Windows\\System32\\userinit.exe",
    "commandLine": "C:\\Windows\\explorer.exe",
    "processGuid": "sample-proc-explorer",
    "parentProcessGuid": "sample-proc-userinit"
  },
  {
    "id": "sample-002",
    "timestamp": "2026-07-15T13:01:03Z",
    "host": "WIN11-SAMPLE-01",
    "channel": "Sysmon",
    "eventId": 1,
    "eventType": "Process Create",
    "user": "SAMPLE\\analyst",
    "image": "C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE",
    "parentImage": "C:\\Windows\\explorer.exe",
    "commandLine": "WINWORD.EXE C:\\Sample\\security-review.docx",
    "processGuid": "sample-proc-word",
    "parentProcessGuid": "sample-proc-explorer"
  },
  {
    "id": "sample-003",
    "timestamp": "2026-07-15T13:02:05Z",
    "host": "WIN11-SAMPLE-01",
    "channel": "Sysmon",
    "eventId": 1,
    "eventType": "Process Create",
    "user": "SAMPLE\\analyst",
    "image": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "parentImage": "C:\\Program Files\\Microsoft Office\\root\\Office16\\WINWORD.EXE",
    "commandLine": "powershell.exe -NoProfile -EncodedCommand SAFE-SAMPLE-TEST",
    "processGuid": "sample-proc-powershell",
    "parentProcessGuid": "sample-proc-word"
  },
  {
    "id": "sample-004",
    "timestamp": "2026-07-15T13:03:44Z",
    "host": "WIN11-SAMPLE-01",
    "channel": "Sysmon",
    "eventId": 22,
    "eventType": "DNS Query",
    "user": "SAMPLE\\analyst",
    "image": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "queryName": "encoded-sample-telemetry-channel-0001.security-validation.example",
    "processGuid": "sample-proc-powershell"
  },
  {
    "id": "sample-005",
    "timestamp": "2026-07-15T13:04:09Z",
    "host": "WIN11-SAMPLE-02",
    "channel": "Security",
    "eventId": 4732,
    "eventType": "Local Group Membership Changed",
    "user": "SAMPLE\\helpdesk",
    "targetUser": "sample-temp-admin",
    "groupName": "Administrators",
    "detail": "Member sample-temp-admin added to local group Administrators"
  }
]
