How does a DNSRequest event link to its responsible process?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, a DNSRequest event contains information about a DNS query made by a process2.The event has several fields, such as DomainName, QueryType, QueryResponseCode, etc2.The field that links a DNSRequest event to its responsible process is ContextProcessId_decimal, which contains the decimal value of the process ID of the process that generated the event2.You can use this field to trace the process lineage and identify malicious or suspicious activities2.
Nan
4 days agoLindsey
9 days agoDottie
14 days agoTheron
20 days agoGladys
25 days agoMicah
30 days agoMajor
1 month agoTherese
1 month agoRex
2 months agoMindy
2 months agoTina
2 months agoArleen
3 months agoRoselle
3 months agoThurman
3 months agoCherry
3 months ago