- "original": "{\"timestamp\":\"18:32:29.495\",\"src.process.parent.isStorylineRoot\":true,\"event.category\":\"dns\",\"src.process.parent.image.sha1\":\"f9bc4c756eab5121ace7ec1cf6a394be0439dec0\",\"site.id\":\"123456789123456789\",\"osSrc.process.isRedirectCmdProcessor\":false,\"src.process.image.binaryIsExecutable\":true,\"src.process.parent.displayName\":\"VIERO-RMSLaunchBar\",\"osSrc.process.image.md5\":\"f905359ab27db1dda964d77442735cb8\",\"osSrc.process.crossProcessOpenProcessCount\":0,\"osSrc.process.publisher\":\"MICROSOFTWINDOWSPUBLISHER\",\"osSrc.process.crossProcessDupThreadHandleCount\":0,\"src.process.user\":\"asdf\\\\SYSTEM\",\"osSrc.process.indicatorPersistenceCount\":0,\"src.process.parent.subsystem\":\"SYS_WIN32\",\"src.process.indicatorRansomwareCount\":0,\"src.process.crossProcessDupRemoteProcessHandleCount\":0,\"osSrc.process.crossProcessOutOfStorylineCount\":0,\"osSrc.process.image.sha1\":\"bfacfa096a56e3d149634e15e1b6470ff5a03957\",\"src.process.tgtFileCreationCount\":6,\"osSrc.process.childProcCount\":0,\"src.process.indicatorInjectionCount\":0,\"osSrc.process.indicatorReconnaissanceCount\":0,\"src.process.moduleCount\":251,\"src.process.parent.name\":\"VIERO.exe\",\"i.version\":\"preprocess-lib-1.0\",\"osSrc.process.signedStatus\":\"signed\",\"sca:atlantisIngestTime\":1664811166298,\"src.process.image.md5\":\"421f6d5ec86f6b930646321fc6ed2c46\",\"src.process.indicatorReconnaissanceCount\":0,\"src.process.storyline.id\":\"8DD23004051AA366\",\"src.process.childProcCount\":1,\"mgmt.url\":\"asdf-123.sentinelone.org\",\"src.process.crossProcessOpenProcessCount\":0,\"osSrc.process.crossProcessThreadCreateCount\":0,\"osSrc.process.moduleCount\":472,\"osSrc.process.indicatorPostExploitationCount\":0,\"osSrc.process.indicatorInfostealerCount\":0,\"src.process.subsystem\":\"SYS_WIN32\",\"meta.event.name\":\"DNS\",\"src.process.parent.integrityLevel\":\"HIGH\",\"osSrc.process.user\":\"NTAUTHORITY\\\\NETWORKSERVICE\",\"osSrc.process.image.binaryIsExecutable\":true,\"osSrc.process.tgtFileModificationCount\":0,\"src.process.indicatorExploitationCount\":0,\"osSrc.process.registryChangeCount\":0,\"src.process.parent.storyline.id\":\"8DD23004051AA366\",\"osSrc.process.netConnInCount\":0,\"i.scheme\":\"edr\",\"src.process.integrityLevel\":\"HIGH\",\"osSrc.process.indicatorInjectionCount\":0,\"osSrc.process.pid\":1340,\"site.name\":\"ASDF\",\"src.process.netConnInCount\":0,\"event.time\":1664811149495,\"account.id\":\"123456789123456789\",\"dataSource.name\":\"SentinelOne\",\"osSrc.process.crossProcessCount\":0,\"endpoint.name\":\"asdf1\",\"src.process.image.sha1\":\"d8b12c9072fdcf68ec152befb004add14b5c25b8\",\"src.process.isStorylineRoot\":false,\"src.process.parent.image.path\":\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\stuff\\\\stuff\\\\Application\\\\stuff\\\\stuff.exe\",\"osSrc.process.isNative64Bit\":false,\"src.process.pid\":3924,\"osSrc.process.uid\":\"73833004051AA366\",\"tgt.file.isSigned\":\"unsigned\",\"sca:ingestTime\":1664811166,\"dataSource.category\":\"security\",\"src.process.cmdline\":\"C:\\\\ProgramFiles(x86)\\\\Microsoft\\\\important_stuff\\\\stuff.EXE\\\\\",\"src.process.crossProcessThreadCreateCount\":0,\"src.process.parent.isNative64Bit\":true,\"osSrc.process.isStorylineRoot\":true,\"src.process.parent.isRedirectCmdProcessor\":false,\"osSrc.process.integrityLevel\":\"SYSTEM\",\"src.process.signedStatus\":\"unsigned\",\"src.process.crossProcessCount\":0,\"osSrc.process.subsystem\":\"SYS_WIN32\",\"event.id\":\"01GEF7MT4CB2DBKG1NGZ8XA7E0_105\",\"osSrc.process.crossProcessDupRemoteProcessHandleCount\":0,\"osSrc.process.tgtFileCreationCount\":0,\"src.process.parent.cmdline\":\"\\\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\LANInternational\\\\VIERO\\\\Application\\\\7.22.1.105\\\\VIERO.exe\\\"\",\"src.process.image.path\":\"C:\\\\Users\\\\asdf\\\\AppData\\\\Local\\\\LANInternational\\\\VIERO\\\\Application\\\\7.22.1.105\\\\CC.Falcon.OrderModule.exe\",\"src.process.tgtFileModificationCount\":4,\"osSrc.process.name\":\"svchost.exe\",\"src.process.indicatorEvasionCount\":26,\"src.process.netConnOutCount\":26,\"osSrc.process.startTime\":1664800506863,\"src.process.crossProcessDupThreadHandleCount\":0,\"endpoint.os\":\"windows\",\"osSrc.process.netConnOutCount\":53,\"osSrc.process.image.sha256\":\"e3d84df77b279ea288cc726cbf68867dc6ae00d24e0e24985141a2ee4753682a\",\"src.process.tgtFileDeletionCount\":6,\"src.process.startTime\":1664803358244,\"mgmt.id\":\"1337\",\"osSrc.process.indicatorRansomwareCount\":0,\"osSrc.process.netConnCount\":53,\"os.name\":\"Windows8.1Pro\",\"osSrc.process.indicatorGeneral.count\":7,\"src.process.displayName\":\"OrderEntryApplication(Client)\",\"osSrc.process.dnsCount\":6126,\"event.dns.request\":\"blog.example.com\",\"event.dns.response\":\"infra-cdn.example.com;216.160.83.57\",\"src.process.isNative64Bit\":true,\"src.process.parent.sessionId\":1,\"osSrc.process.sessionId\":0,\"src.process.uid\":\"AFD43004051AA366\",\"src.process.parent.image.md5\":\"1f3d8a05852ee60fb475e86a0ae74e27\",\"osSrc.process.verifiedStatus\":\"verified\",\"osSrc.process.cmdline\":\"C:\\\\WINDOWS\\\\system32\\\\svchost.exe-kNetworkService\",\"src.process.indicatorInfostealerCount\":0,\"src.process.indicatorBootConfigurationUpdateCount\":0,\"process.unique.key\":\"AFD43004051AA366\",\"src.process.parent.uid\":\"8CD23004051AA366\",\"agent.version\":\"22.1.2.217\",\"src.process.parent.image.sha256\":\"d2213413a6a558981670676ff0575e31542067ef69ee7e061c0308c4f0c0888d\",\"src.process.sessionId\":1,\"src.process.netConnCount\":26,\"mgmt.osRevision\":\"9600\",\"osSrc.process.image.path\":\"C:\\\\WINDOWS\\\\System32\\\\svchost.exe\",\"group.id\":\"asdf\",\"osSrc.process.indicatorBootConfigurationUpdateCount\":0,\"src.process.isRedirectCmdProcessor\":false,\"src.process.parent.startTime\":1664802966680,\"osSrc.process.indicatorExploitationCount\":0,\"src.process.dnsCount\":26,\"osSrc.process.tgtFileDeletionCount\":0,\"endpoint.type\":\"laptop\",\"osSrc.process.indicatorEvasionCount\":6,\"trace.id\":\"01GEF7MT4CB2DBKG1NGZ8XA7E0\",\"src.process.name\":\"CC.Falcon.OrderModule.exe\",\"agent.uuid\":\"asdf356783457dfds4456d65\",\"osSrc.process.displayName\":\"HostProcessforWindowsServices\",\"src.process.image.sha256\":\"ca261f1061485488d08e4c4618b18b42d559f4288dbad3a5c758523347ab3e7c\",\"src.process.indicatorGeneralCount\":6,\"src.process.crossProcessOutOfStorylineCount\":0,\"src.process.registryChangeCount\":0,\"packet.id\":\"1A1DF4D521014F9C90F4CF31E5446B91\",\"src.process.indicatorPersistenceCount\":0,\"src.process.parent.signedStatus\":\"unsigned\",\"src.process.parent.user\":\"asdf\\\\SYSTEM\",\"osSrc.process.storyline.id\":\"74833004051AA366\",\"event.type\":\"DNS Resolved\",\"src.process.indicatorPostExploitationCount\":0,\"src.process.parent.pid\":2728}",
0 commit comments