Hostname | {{event.station.hostname}} |
IP Address | {{event.station.ip_address}} |
Username | {{event.username}} |
Timestamp | {{event.event_timestamp}} |
Binary | {{event.binary.file_path}} |
Binary PID | {{event.binary.pid}} | {% if eventtree %}
{% endif %}
|
|
Binary SHA1 | {{event.binary.binary_sha1}} |
Parent Binary | {{event.parent_binary.file_path}} |
Parent Binary PID | {{event.parent_binary.pid}} |
Parent Binary SHA1 | {{event.parent_binary.binary_sha1}} |
CmdLine | {{event.cmdline}} |
Flags | {{event.flags}} |
Creation Class Name | {{event.creation_class_name}} |
Handle | {{event.handle}} |
Handle Count | {{event.handle_count}} |
Kernel Mode Time | {{event.kernel_mode_time}} |
User Mode Time | {{event.user_mode_time}} |
Working Set Size | {{event.working_set_size}} |
Max Working Set Size | {{event.max_working_set_size}} |
Min Working Set Size | {{event.min_working_set_size}} |
OS Name | {{event.os_name}} |
OS Version | {{event.windows_version}} |
Session ID | {{event.session_id}} |
Priority | {{event.priority}} |
Pages Faults | {{event.page_faults}} |
Page File Usage | {{event.page_file_usage}} |
Private Page Count: | {{event.private_page_count}} |
Virtual Size | {{event.virtual_size}} |
Thread Count | {{event.thread_count}} |
Peak Working Set Size | {{event.peak_working_set_size}} |
Peak Page File Usage | {{event.peak_page_file_usage}} |
Peak Virtual Size | {{event.peak_virtual_size}} |
Read Operation Count | {{event.read_operation_count}} |
Write Operation Count | {{event.write_operation_count}} |
Other Operation Count | {{event.other_operation_count}} |
Read Transfer Count | {{event.read_transfer_count}} |
Write Transfer Count | {{event.write_transfer_count}} |
Other Transfer Count | {{event.other_transfer_count}} |
Quota Non Paged Pool Usage | {{event.quota_non_paged_pool_usage}} |
Quota Paged Pool Usage | {{event.quota_paged_pool_usage}} |
Quota Peak Non Paged Pool Usage | {{event.quota_peak_non_paged_pool_usage}} |
Quota Peak Paged Pool Usage | {{event.quota_peak_paged_pool_usage}} |