syscall-execute

October 15, 2025 · View on GitHub

Description

Syscall commands were executed on the system

Parameters

ParameterValue
Subjectsyscall
Activityexecute
Activity Typesyscall-execute
Pretty NameSyscall Execute

Fields

The possible fields for this activity type will vary depending on whether the activity was a success or a fail.

syscall-execute:success

FieldCoreDetectionInformational
system_architecture
syscall_number
syscall_name

syscall-execute:fail

FieldCoreDetectionInformational
system_architecture
syscall_number
syscall_name