Titre | Obtenir la capacité de trouver un processus par les métadonnées d’un exécutable |
---|---|
ID | RA1403 |
Description | Make sure you have the ability to find process executed at a particular time in the past by its executable metadata (i.e. signature, permissions, MAC times) |
Auteur | your name/nickname/twitter |
Creation Date | DD.MM.YYYY |
Catégorie | Process |
Étapes | RS0001: Préparation |
References | <ul><li>https://example.com</li></ul> |
Requirements | <ul><li>DN_zeek_conn_log</li></ul> |
Workflow
Description of the workflow for single Response Action in markdown format.
Here newlines will be saved.