Software Secure Workload
Activity Configure

Machine information

Machine info describes all the processes running on the host. In addition, it contains network information that is associated with the processes and the command used to launch the processes. Machine info is exported every minute and includes the following information:

  • Process ID

  • User ID: owner of the process

  • Parent Process ID

  • Command string used to launch the process

  • Socket information: protocol (such as UDP or TCP), address type: IPv4 or IPv6, source and destination IP, source and destination port, TCP state, process’s start and end time, path to process binary

  • Forensic information: for more information, see the section Compatibility.