ESET Inspect – Table of Contents

ProcessInfo/ServiceProcessInfo

Return information about the current process

Property

Type

Description

Example

CaseSensitiveCommandLine

String

Allows creating rules for command line that is case sensitive

 

CommandLine

String

Process command line

file.txt

CommandLineLength

Int

Length of the command line

123

Compromised

Bool

The process was marked as compromised by a rule with MarkAsCompromised action

true/false or 1/0

IntegrityLevel

Int/Symbols

Integrity level of the process

Possible values are:

Untrusted—0

Low—4096

Medium—8192

High—12288

System—16384

Protected process—20480

LnkPath

String

Contains a path to a shortcut execution

 

ProcessDistance

Int

The distance of the process from the current process

123

ProcessLevel

Int

Depth of the process in process hierarchy

123

ProcessOwner

String

The user that created the process

 

RiskScore

Int

The threshold at which the process becomes a risk.

1000

SentBytes

Int

Total number of bytes sent by the process.

 

 

Supported Operations and their components:

 

Module

CreateProcess

X

LoadDLL

X

CodeInjection

X