murchisd / splunk_pstree_app

Custom Splunk search command to reconstruct a pstree from Sysmon process creation events (EventCode 1)
23Updated 2 years ago

Alternatives and similar repositories for splunk_pstree_app:

Users that are interested in splunk_pstree_app are comparing it to the libraries listed below