How does a DNSRequest event link to its responsible process?
According to theCrowdStrike Falcon Devices Add-on for Splunk Installation and Configuration Guide v3.1.5+, a DNSRequest event contains information about a DNS query made by a process2.The event has several fields, such as DomainName, QueryType, QueryResponseCode, etc2.The field that links a DNSRequest event to its responsible process is ContextProcessId_decimal, which contains the decimal value of the process ID of the process that generated the event2.You can use this field to trace the process lineage and identify malicious or suspicious activities2.
Limited Time Offer
25%
Off
Amie
5 months agoLeonard
5 months agoHelga
4 months agoRonald
5 months agoJeniffer
5 months agoCarman
5 months agoDetra
5 months agoArthur
5 months agoDiane
5 months agoAshlee
5 months agoMarkus
6 months agoMarnie
4 months agoPaulina
5 months agoMarilynn
5 months agoDanica
5 months agoTamra
5 months agoJamey
5 months agoQueen
6 months agoKristel
5 months agoAmie
5 months agoMelita
5 months agoRobt
6 months agoAudria
6 months agoMerrilee
6 months ago