To learn more, visit the EchoTrail documentation.

Parameters

ParameterDescription
FieldThe specific field to retrieve from the search results.
QueryThe name or hash of an endpoint process to lookup.Must be a Windows filename with extension, a SHA256 hash of a windows process, or a md5 hash of a windows process.If the search yields no results, the response will include the message: No results found.
SubsearchThe string to search for within the process field.

Example Output

[    "services.exe",    99.88]

Workflow Library Example

Insights Subsearch with Echotrail and Send Results Via Email

Preview this Workflow on desktop