How does a DNSRequest event link to its responsible process?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, a DNSRequest event contains information about a DNS query made by a process2.The event has several fields, such as DomainName, QueryType, QueryResponseCode, etc2.The field that links a DNSRequest event to its responsible process is ContextProcessId_decimal, which contains the decimal value of the process ID of the process that generated the event2.You can use this field to trace the process lineage and identify malicious or suspicious activities2.
Domonique
29 days agoMona
1 month agoRemedios
1 month agoDesmond
1 month agoNan
2 months agoLindsey
2 months agoDottie
2 months agoTheron
2 months agoGladys
2 months agoMicah
3 months agoMajor
3 months agoTherese
3 months agoRex
4 months agoMindy
4 months agoTina
4 months agoArleen
4 months agoRoselle
4 months agoThurman
4 months agoCherry
5 months ago