murchisd / splunk_pstree_app

Custom Splunk search command to reconstruct a pstree from Sysmon process creation events (EventCode 1)
23Updated last year

Related projects

Alternatives and complementary repositories for splunk_pstree_app