PSTree for Splunk

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

PSTree for Splunk

PSTree for Splunk
This apps main function is to enable a custom Splunk search command to reconstruct a pstree from Sysmon process creation events (EventCode 1). Information from memory forensics, such as Volatility's pstree, can be very helpful to detect malicious processes. By ingesting Sysmon events in Splunk and using this command you can quickly get similar information without performing memory forensics.
0 topics and 0 replies mentioned PSTree for Splunk in View all 0
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.