https://github.com/osquery/osquery logo
#core
Title
b

Bhargav koduru

12/20/2022, 12:34 PM
Can anyone suggest the best way to detect a short lived process on windows ?
s

sharvil

12/20/2022, 4:29 PM
hey @Bhargav koduru, for something this, an evented table (a la
process_events
) is the way to go, this doesn’t exist right now for Windows, but is actively worked on https://github.com/osquery/osquery/pull/7821
m

Mike Myers

12/20/2022, 4:50 PM
I believe you can turn on process auditing in Windows and collect the event log
b

Bhargav koduru

12/22/2022, 4:22 AM
Thanks for the suggestions guys @sharvil @Mike Myers