This section describes general process parameters—the Props
section structure.
The list may be incomplete as it may change during bases update.
Props section structure
Parameter |
Description |
---|---|
|
Process ID. |
|
Path to the executed file. |
|
Command line parameters. |
|
Process ID of process which requests RPC. |
|
Path to the parent executed file of the process which requests RPC. |
|
Command line parameters for the parent executed file of the process which requests RPC. |
|
Parent process ID. |
|
Path to the parent executed file. |
|
Parent command line parameters. |
|
Service name. |
|
File path for services. |
|
Windows registry key (for example, |
|
Windows registry value name (for example, |
|
Windows registry value (for example, |
|
The |
|
The |
|
The |
|
Path to file on the disk. |
|
Path to target file on disk. |
|
Target process ID. |
|
Path to target executed file. |
|
Command line of target process. |
|
Destination web address. |
|
Source IP address. |
|
Source port number. |
|
Destination IP address, may include port number. |
|
Destination port number. |
|
Network protocol. |
|
Extracted string from executed process memory. |
|
Name of pipe. |
|
Privilege name. |
|
Time of sleep mode. |