How does a DNSRequest event link to its responsible process?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, a DNSRequest event contains information about a DNS query made by a process2.The event has several fields, such as DomainName, QueryType, QueryResponseCode, etc2.The field that links a DNSRequest event to its responsible process is ContextProcessId_decimal, which contains the decimal value of the process ID of the process that generated the event2.You can use this field to trace the process lineage and identify malicious or suspicious activities2.
Limited Time Offer
25%
Off
Helga
5 months agoNatalya
5 months agoMonroe
5 months agoHailey
5 months agoAlethea
5 months agoFrank
6 months ago