-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Clarify Property Definitions on Process Object #47
Comments
So I think the biggest issue here is that the |
As far as "Specifies the full command line used in executing the process, including the process name (depending on the operating system)." To the new version: "Specifies the full command line used in executing the process, including the process name (which may be specified individually via the binary_ref.name property) and any arguments." |
FYI, this is what Osquery has for these properties: name | TEXT | The process path or shorthand argv[0] |
I've had this same question, definitely agree with fixing this for 2.1. |
There are plenty of cases where a process name doesn't align with the binary filepath. For example, in *nix, where you have one binary with a number of different executable symlinks pointing to it and the binary alters its behavior based on how it's called (i.e., argv[0].) Similarly, in Windows™ where you have a callable DLL (with a main() function) with symbolic links as in the previous example. |
@treyka interesting. I ran an experiment on this on my MacBook, and it least in OS X it looks like the name of the symlink is captured in the command-line (CMD) but not the name of the process.
|
@jordan2175 it looks like we've already made these changes to the Process SCO ( |
Looks like this was done some time back. Closing. |
Jason had some confusion with regards to the process image name vs filename vs command line on the Cyber Observable Process Object and when you'd use each, so we should try to clarify the descriptions of these properties as necessary.
The text was updated successfully, but these errors were encountered: