ocsf-schema icon indicating copy to clipboard operation
ocsf-schema copied to clipboard

Support remote process memory & handle operations in Process Activity

Open Noafr opened this issue 2 years ago • 0 comments

SentinelOne Distinguishes between different Remote Process Activities. Code Injection & Process Termination are covered by Activity ID 4 (Inject) & 2 (Terminate), however missing Remote Memory Operations (e.g. readLsass, writeToEAT, libraryRemoteWrite, remoteAlloc) as well as Remote Handle Operations (Duplicate Process Handle, Duplicate Thread Handle, Open Remote Process Handle)

Noafr avatar Sep 29 '22 14:09 Noafr