mirror of https://github.com/MISP/misp-objects
chg: [process] Added sane defaults.
parent
c1a5a52155
commit
eaf0301fe3
|
@ -42,7 +42,23 @@
|
|||
"disable_correlation": true
|
||||
},
|
||||
"process-state": {
|
||||
"description": "State of process. (ps codes R/S/Z...)",
|
||||
"description": "State of process.",
|
||||
"sane_default": [
|
||||
"D uninterruptible sleep (usually IO)",
|
||||
"R running or runnable (on run queue)",
|
||||
"S interruptible sleep (waiting for an event to complete)",
|
||||
"T stopped by job control signal",
|
||||
"t stopped by debugger during the tracing",
|
||||
"W paging (not valid since the 2.6.xx kernel)",
|
||||
"X dead (should never be seen)",
|
||||
"Z defunct ('zombie') process, terminated but not reaped by its parent",
|
||||
"< high-priority (not nice to other users)",
|
||||
"N low-priority (nice to other users)",
|
||||
"L has pages locked into memory (for real-time and custom IO)",
|
||||
"s is a session leader",
|
||||
"l is multi-threaded (using CLONE_THREAD, like NPTL pthreads do)",
|
||||
"+ is in the foreground process group"
|
||||
],
|
||||
"ui-priority": 1,
|
||||
"misp-attribute": "text",
|
||||
"multiple": false,
|
||||
|
@ -50,6 +66,10 @@
|
|||
},
|
||||
"fake-process-name": {
|
||||
"description": "Is the process spawned under a false name.",
|
||||
"sane_default": [
|
||||
"1",
|
||||
"0"
|
||||
],
|
||||
"ui-priority": 1,
|
||||
"misp-attribute": "boolean",
|
||||
"multiple": false,
|
||||
|
|
Loading…
Reference in New Issue