IOC Management
: Read and Write.
IOCs (Indicators of Compromise)
: Read.
Parameter | Description |
---|---|
Process ID | The running process you want to get details on. |
{
"meta": {
"query_time": 0.036953655,
"trace_id": ""
},
"resources": [
{
"device_id": "2dd7xxxxxxxxfb3c2",
"command_line": "\\AppData\\Local\\Temp\\svchost.exe.4406xxxxxxxx5051.fuzz\"",
"process_id": "2dd7xxxxxxxxb3c2:922xxx411",
"process_id_local": "298xxx772",
"file_name": "\\Users\\example\\AppData\\Local\\Temp\\svchost.exe.4406xxxxxxxx5051.fuzz",
"start_timestamp": "2016-01-07T08:51:13Z",
"start_timestamp_raw": "130966302736257500",
"stop_timestamp": "2016-01-07T08:51:14Z",
"stop_timestamp_raw": "130966302744226250"
}
],
"errors": []
}
Was this page helpful?