Skip to content

RA2406: Find Process By Executable Content Pattern

Summary

ID RA2406
Brief Description Find a process that is being executed at the moment or at a particular time in the past by its executable content (i.e. specific string, keyword, binary pattern etc)
Author your name/nickname/twitter
Creation Date YYYY/MM/DD
Requirements
  • DN_zeek_conn_log
References
Response Stage Identification

Description

Description of the extended_description for single Response Action in markdown format. Here newlines will be saved.