ocsf-schema
ocsf-schema copied to clipboard
Support remote process memory & handle operations in Process Activity
SentinelOne Distinguishes between different Remote Process Activities. Code Injection & Process Termination are covered by Activity ID 4 (Inject) & 2 (Terminate), however missing Remote Memory Operations (e.g. readLsass, writeToEAT, libraryRemoteWrite, remoteAlloc) as well as Remote Handle Operations (Duplicate Process Handle, Duplicate Thread Handle, Open Remote Process Handle)