ESET Online Help

Search English
Select the topic

Working with a parent-child relationship

This topic addresses whether malware is delivered as a script in an email attachment or in a document.

We want to create a rule monitoring execution of some sort of script interpreter (executing scripts) originating from Microsoft Office application, that is, some document or email.

Rule

Things to notice in the rule example above:

1.We used process to identify the execution of the script interpreter and parentprocess to identify Microsoft Office application, so "Process executed by" is modeled by the processparentprocess relation.