Watchlist Hit : Process

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Watchlist Hit : Process

Base Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

alliance_score_virustotal

<quantity>

Number

cb_version

<version>

Number

cmdline

<command>

Text/String

comms_ip

<sip>

IP Address

hostname

<dname>

Text/String

interface_ip

<sip>

IP Address

parent_name

<parentprocessname>

Text/String

parent_pid

<parentprocessid>

Number

path

<process>

Text/String

process_md5

<objectname>

Text/String

process_md5

<hash>

Text/String

process_name

<object>

Text/String

username

<domain>

Text/String

username

<login>

Text/String

watchlist_name

<vmid>

Text/String