Skip to content

Commit

Permalink
additional process callstack fields (#435)
Browse files Browse the repository at this point in the history
* add missing process.parent.thread.Ext.call_stack fields

* add generated file
  • Loading branch information
jdu2600 authored Oct 3, 2023
1 parent b551419 commit b412bfe
Show file tree
Hide file tree
Showing 2 changed files with 6 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,9 @@ This event is generated when a process is created.
| process.parent.name |
| process.parent.pid |
| process.parent.thread.Ext.call_stack.symbol_info |
| process.parent.thread.Ext.call_stack.protection |
| process.parent.thread.Ext.call_stack.callsite_leading_bytes |
| process.parent.thread.Ext.call_stack.callsite_trailing_bytes |
| process.parent.thread.Ext.call_stack_contains_unbacked |
| process.parent.thread.Ext.call_stack_summary |
| process.pe.imphash |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,9 @@ fields:
- process.parent.name
- process.parent.pid
- process.parent.thread.Ext.call_stack.symbol_info
- process.parent.thread.Ext.call_stack.protection
- process.parent.thread.Ext.call_stack.callsite_leading_bytes
- process.parent.thread.Ext.call_stack.callsite_trailing_bytes
- process.parent.thread.Ext.call_stack_contains_unbacked
- process.parent.thread.Ext.call_stack_summary
- process.pe.imphash
Expand Down

0 comments on commit b412bfe

Please sign in to comment.