2014-06-10
04:28 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Monitoring "a new process has been created"
I just attended a seminar where they suggested to watch Windows event #592/4688 "A new process has been created". Is anyone monitoring this? Is there a way to watch for any new processes that have not been seen for x number of days? Some way to create a list of known processes? Any ideas would be great.
- Tags:
- 4688
- 592
- Community Thread
- Discussion
- Forum Thread
- NetWitness
- NW
- NWP
- RSA NetWitness
- RSA NetWitness Platform
1 Reply
2014-06-10
09:37 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
looks a function of ECAT
