process-memory-read

March 22, 2023 · View on GitHub

Description

Virtual memory was read from a process

Parameters

ParameterValue
Subjectprocess
Activitymemory-read
Activity Typeprocess-memory-read
Pretty NameProcess Memory Read

Fields

The possible fields for this activity type will vary depending on whether the activity was a success or a fail.

process-memory-read:success

FieldCoreDetectionInformational
memory_address
memory_size
memory_protection

process-memory-read:fail

FieldCoreDetectionInformational
failure_code
memory_address
failure_reason
memory_size
memory_protection