process-events.md: Description of Process GUIDs is not right.
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 42/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- c
- Domain
- documentation
Research direction
Start with process-events.md and compare its Process GUID description with GenerateUniqueId in sysmonCommon/eventsCommon.h and set_ProcCreate_info in ebpfKern/sysmonProcCreate.c. Investigate the unresolved Windows behavior if possible, then update the documentation to accurately distinguish the machine ID, process start time, and process start key from the process ID.
Written by the indexing model from the issue text.
Description
Looking at the Sysmon/Linux sources, GUIDs are constructed by concatenating the "machine id", the start time of the process (UNIX-style, seconds since 1970-1-1), and a "process start key" which is not defined in the userspace component (function GenerateUniqueId in sysmonCommon/eventsCommon.h):
*(DWORD*) pResult = machineId;
pResult += sizeof(DWORD);
*(DWORD*) pResult = seconds;
pResult += sizeof(DWORD);
*(DWORD64*) pResult = ProcessStartKey;
The "process key" is taken from m_EventBody.m_ProcessCreateEvent.m_ProcessKey which for Linux is created in the eBPF code (set_ProcCreate_info in ebpfKern/sysmonProcCreate.c):
// get the process key - this is the end of the text segment currently as it should be
// a) randomised for a PIE executable; and
// b) dependent on the amount of code in the process
event->m_ProcessKey = (uint64_t)derefPtr(task, config->offsets.mm_end_code);
I'm still in the process of looking at Sysmon/Windows with a disassembler, so I can't yet speak to what happens there. However, from the logs I have looked at, I don't recognize the process id as part of the process GUID.
- Dominant language
- Python
- Stars
- 1.4k
- Forks
- 186
- PR merge metrics
- No merged PRs in 30d
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from trustedsec/SysmonCommunityGuide
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
-
Broken PDFOpen
Difficulty 2/5 1-3 hours Newbie friendliness 35/100
-
Difficulty 4/5 3-5 days Newbie friendliness 20/100
trustedsec/SysmonCommunityGuide#29 · 9 comments ·
-
Changelog UpdatesOpen
Difficulty 2/5 1-3 hours Newbie friendliness 35/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 38/100
trustedsec/SysmonCommunityGuide#24 · 1 comment ·
All issues in trustedsec/SysmonCommunityGuide
Similar issues
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
workflow: a tick's dispatch counts as 'only this step', and no review self-grants a round unattendedOpenworkflow
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
kristofdegrave/homeassistant-smart-charging#1505 ·
Maintainers usually reply within 1 day
-
metadata submission
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
canonical/content-cache-operator#163 · 1 comment ·
Maintainers usually reply within 1 day
-
[submission]Opensubmission
Difficulty 1/5 Under an hour Newbie friendliness 65/100
leanprover/lean-eval-submissions#1852 ·
Maintainers usually reply within 1 day