문서API 참조
Documentation

프로세스 데이터

Process data에는 Sandfly Security 또는 사용자가 어떤 이유로든 플래그한 프로세스에 대한 모든 속성이 포함됩니다. 이 항목에는 프로세스 고유 정보뿐만 아니라, 가능한 경우 해당 프로세스와 연관된 바이너리에 대한 정보도 포함됩니다. 바이너리 정보는 File Data 유형에서 제공되는 내용과 동일합니다.

{ "name": "", "extension": "", "cmdline": "", "cmdargs": null, "command": "", "date": { "created": "", "created_minutes": 0 }, "pid": 0, "ppid": 0, "pgid": 0, "uid": 0, "username": "", "gid": 0, "groupname": "", "path": "", "true_path": "", "cwd": "", "entropy": 0, "state": "", "system_uptime": "", "flags": { "deleted": false, "immutable": false, "containerized": false, "hidden": false }, "selinux_context": "", "file_descriptors": null, "environ": null, "maps_list": null, "stack": null, "cgroup": null, "container": { "id": "", "id_short": "", "rootdir": "" }, "network_ports": { "operating": false, "established": false, "established_num": 0, "listening": false, "listening_num": 0, "tcp": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "tcp6": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "udp": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "udp6": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "icmp": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "icmp6": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "raw": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "raw6": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null }, "sctp": { "operating": false, "listening": false, "listening_num": 0, "established": false, "established_num": 0, "connections": null } }, "hash": { "md5": "", "sha1": "", "sha256": "", "sha512": "" }, "file": { "date": { "created": "", "created_minutes": 0, "modified": "", "modified_minutes": 0, "accessed": "", "accessed_minutes": 0 }, "inode": 0, "device": 0, "rdevice": 0, "nlink": 0, "mode": "", "uid": 0, "username": "", "gid": 0, "groupname": "", "size": 0, "size_byte_count": 0, "size_byte_count_status": "", "size_mismatch": false, "blksize": 0, "blocks": 0, "path": "", "path_root": "", "path_link": "", "true_path": "", "name": "", "extension": "", "selinux_context": "", "flags": { "directory": false, "regular": false, "link": false, "suid": false, "suid_root": false, "sgid": false, "sgid_root": false, "socket": false, "device": false, "char_device": false, "named_pipe": false, "sticky": false, "immutable": false, "hidden": false, "deleted": false, "containerized": false }, "entropy": 0, "hash": { "md5": "", "sha1": "", "sha256": "", "sha512": "" }, "magic_num": { "hex": "", "text": "", "type": "", "class": "", "expected_extensions": null }, "mount": { "mountpoint": "", "device": "", "fs_type": "" }, "container": { "id": "", "id_short": "", "rootdir": "" }, "data": null }, "stat": { "pid": 0, "comm": "", "state": "", "ppid": 0, "pgrp": 0, "session": 0, "tty_nr": 0, "tpgid": 0, "flags": 0, "minflt": 0, "cminflt": 0, "majflt": 0, "cmajflt": 0, "utime": 0, "stime": 0, "cutime": 0, "cstime": 0, "priority": 0, "nice": 0, "num_threads": 0, "itrealvalue": 0, "starttime": 0, "vsize": 0, "rss": 0, "rsslim": 0, "startcode": 0, "endcode": 0, "startstack": 0, "kstkesp": 0, "kstkeip": 0, "signal": 0, "locked": 0, "sigignore": 0, "sigcatch": 0, "wchan": 0, "nswap": 0, "cnswap": 0, "exit_signal": 0, "processor": 0, "rt_priority": 0, "policy": 0, "delayacct_blkio_ticks": 0, "guest_time": 0, "cguest_time": 0, "start_data": 0, "end_data": 0, "start_brk": 0, "arg_start": 0, "arg_end": 0, "env_start": 0, "env_end": 0, "exit_code": 0 }, "status": { "name": "", "umask": "", "state": "", "tgid": 0, "ngid": 0, "pid": 0, "ppid": 0, "tracer_pid": 0, "uid": 0, "uid_effective": 0, "uid_saved_set": 0, "uid_file_system": 0, "gid": 0, "gid_effective": 0, "gid_saved_set": 0, "gid_file_system": 0, "fdsize": 0, "groupids": null, "groupnames": null, "ns_tgid": 0, "ns_pid": 0, "ns_pgid": 0, "ns_sid": 0, "vm_peak": 0, "vm_size": 0, "vm_lck": 0, "vm_pin": 0, "vm_hwm": 0, "vm_rss": 0, "rss_anon": 0, "rss_file": 0, "rss_shmem": 0, "vm_data": 0, "vm_stk": 0, "vm_exe": 0, "vm_lib": 0, "vm_pte": 0, "vm_swap": 0, "hugeltb_pages": 0, "threads": 0, "sig_q": "", "sig_pnd": "", "shd_pnd": "", "sig_blk": "", "sig_ign": "", "sig_cgt": "", "cap_inh": "", "cap_prm": "", "cap_eff": "", "cap_bnd": "", "cap_amb": "", "seccomp": 0, "seccomp_filters": 0, "speculation_store_bypass": "", "cpus_allowed": "", "cpus_allowed_list": "", "mems_allowed": "", "mems_allowed_list": "", "voluntary_ctxt_switches": 0, "nonvoluntar_ctxt_switches": 0, "flags": null } }

이 페이지가 도움이 되었나요?