process-events.md: Description of Process GUIDs is not right.
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Anfängerfreundlichkeit
- 42/100
- Issue-Typ
- Dokumentation
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Veraltet
- Tech-Stack
- c
- Bereich
- documentation
Rechercherichtung
Start with process-events.md and compare its Process GUID description with GenerateUniqueId in sysmonCommon/eventsCommon.h and set_ProcCreate_info in ebpfKern/sysmonProcCreate.c. Investigate the unresolved Windows behavior if possible, then update the documentation to accurately distinguish the machine ID, process start time, and process start key from the process ID.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Looking at the Sysmon/Linux sources, GUIDs are constructed by concatenating the "machine id", the start time of the process (UNIX-style, seconds since 1970-1-1), and a "process start key" which is not defined in the userspace component (function GenerateUniqueId in sysmonCommon/eventsCommon.h):
*(DWORD*) pResult = machineId;
pResult += sizeof(DWORD);
*(DWORD*) pResult = seconds;
pResult += sizeof(DWORD);
*(DWORD64*) pResult = ProcessStartKey;
The "process key" is taken from m_EventBody.m_ProcessCreateEvent.m_ProcessKey which for Linux is created in the eBPF code (set_ProcCreate_info in ebpfKern/sysmonProcCreate.c):
// get the process key - this is the end of the text segment currently as it should be
// a) randomised for a PIE executable; and
// b) dependent on the amount of code in the process
event->m_ProcessKey = (uint64_t)derefPtr(task, config->offsets.mm_end_code);
I'm still in the process of looking at Sysmon/Windows with a disassembler, so I can't yet speak to what happens there. However, from the logs I have looked at, I don't recognize the process id as part of the process GUID.
- Vorherrschende Sprache
- Python
- Sterne
- 1.4k
- Forks
- 186
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Entwicklungsumgebung
- Enthält ein Dockerfile oder eine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Kein Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus trustedsec/SysmonCommunityGuide
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
-
Broken PDFOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 35/100
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 20/100
trustedsec/SysmonCommunityGuide#29 · 9 Kommentare ·
-
Changelog UpdatesOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 35/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 38/100
trustedsec/SysmonCommunityGuide#24 · 1 Kommentar ·
Alle Issues in trustedsec/SysmonCommunityGuide
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
PedestrianDynamics/pyFDS-Evac#343 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
theskumar/python-dotenv#708 ·
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 2 Tagen
-
Docs Timedelta
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
pandas-dev/pandas#69919 ·
Maintainer antworten meist innerhalb von 1 Tag
-
API documentation
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
zephyrproject-rtos/west#1009 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 3 Tagen