Skip to content

Latest commit

 

History

History
15 lines (13 loc) · 881 Bytes

RA_2403_find_process_by_executable_metadata.md

File metadata and controls

15 lines (13 loc) · 881 Bytes
Title Find process by executable metadata
ID RA2403
Description Find a process that is being executed at the moment or at a particular time in the past by its executable metadata (i.e. signature, permissions, MAC times)
Author your name/nickname/twitter
Creation Date YYYY/MM/DD
Category Process
Stage RS0002: Identification
References
Requirements
  • DN_zeek_conn_log

Workflow

Description of the workflow for single Response Action in markdown format.
Here newlines will be saved.