Skip to main content

Header

The header structure contains general information about the events. It contains the following fields:

Field nameTypeDescription
pidi32Pid of the process that generated the event
is_threatboolIndicates if the event is a threat
sourceStringName of the module that generated the evnt
timestampSystemTimeTimestamp of the event
imageStringName of the executable that generated the event
parenti32Parent PID of the process that generated the event
fork_timeSystemTimeTimestamp of the fork of the process