process-create

September 3, 2025 · View on GitHub

Description

A process was executed

Parameters

ParameterValue
Subjectprocess
Activitycreate
Activity Typeprocess-create
Pretty NameProcess Create

Legacy Names

SuccessFail
process-created
process-created-failed

Fields

The possible fields for this activity type will vary depending on whether the activity was a success or a fail.

process-create:success

FieldCoreDetectionInformational
parent_process_id
parent_process_command_line
command_module
parent_process_name
domain_user_name
parent_process_dir
dest_zone
hash_sha256
dest_user_entity_id
process_guid
src_zone
domain
process_integrity
dest_host
parent_process_guid
control_panel_item
parent_process_path
user
dest_device_entity_id
cid

process-create:fail

FieldCoreDetectionInformational
parent_process_id
failure_code
parent_process_command_line
parent_process_name
domain_user_name
failure_reason
parent_process_dir
dest_zone
hash_sha256
process_guid
src_zone
domain
process_integrity
dest_host
parent_process_guid
control_panel_item
parent_process_path
user
cid