Definitely not B. If it's not useful, why is it there in the first place? Sounds like someone was just lazy in their field naming conventions. *rolls eyes*
Hmm, I'm torn between A and C. I feel like it could go either way, but C seems a bit more logical. Although, who knows what kind of bizarre logic these security tools use. *shrugs*
B has to be the right answer. An 'internal value not useful for an investigation' sounds like the kind of cryptic field that security tools love to include. #JustSecurityThings
I'm going with D. The TargetProcessld_decimal value for the process that made the DNS request seems like the most relevant information to have in this field.
I think the purpose of the ContextProcessId_decimal field is to contain the ContextProcessId_decimal value for the parent process that made the DNS request.
I think it's C. The ContextProcessld_decimal field should contain the parent process that made the DNS request, not the target process. That makes the most sense in the context of a DNS event.
I think it's C. The ContextProcessld_decimal field should contain the parent process that made the DNS request, not the target process. That makes the most sense in the context of a DNS event.
upvoted 0 times
...
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Edelmira
10 months agoMargurite
9 months agoMargarita
9 months agoAlease
10 months agoRichelle
10 months agoBok
9 months agoShaun
10 months agoKara
10 months agoViola
10 months agoAnna
10 months agoWayne
9 months agoKaty
9 months agoMariko
9 months agoEllsworth
10 months agoBroderick
10 months agoCurtis
11 months agoLaurel
11 months agoVerona
11 months agoFelice
9 months agoMarcos
10 months agoRodney
10 months agoBettye
10 months ago