Skip to content

RA1403: Get Ability To Find Process By Executable Metadata

Summary

ID RA1403
Brief Description Make sure you have the ability to find process executed at a particular time in the past by its executable metadata (i.e. signature, permissions, MAC times)
Author your name/nickname/twitter
Creation Date YYYY/MM/DD
Requirements
  • DN_zeek_conn_log
References
Response Stage Preparation

Description

Description of the extended_description for single Response Action in markdown format. Here newlines will be saved.