Skip to content

Instantly share code, notes, and snippets.

@danielin917
Created April 18, 2023 21:16
Show Gist options
  • Save danielin917/e4d2d21b66c873460a58180ba731de8b to your computer and use it in GitHub Desktop.
Save danielin917/e4d2d21b66c873460a58180ba731de8b to your computer and use it in GitHub Desktop.
Data Sample
timestamp processId parentProcessId userId processName hostName eventId eventName argsNum returnValue args sus evil
0 124.952820 383 1 101 systemd-resolve ip-10-100-1-186 41 socket 3 15 [{'name': 'domain', 'type': 'int', 'value': 'A... 0 0
1 124.953139 380 1 100 systemd-network ip-10-100-1-186 41 socket 3 15 [{'name': 'domain', 'type': 'int', 'value': 'A... 0 0
2 124.953424 1 0 0 systemd ip-10-100-1-186 1005 security_file_open 4 0 [{'name': 'pathname', 'type': 'const char*', '... 0 0
3 124.953464 1 0 0 systemd ip-10-100-1-186 257 openat 4 17 [{'name': 'dirfd', 'type': 'int', 'value': -10... 0 0
4 124.953494 1 0 0 systemd ip-10-100-1-186 5 fstat 2 0 [{'name': 'fd', 'type': 'int', 'value': 17}, {... 0 0
... ... ... ... ... ... ... ... ... ... ... ... ... ...
713862 16026.611442 159 1 0 systemd-journal ip-10-100-1-186 1005 security_file_open 4 0 [{'name': 'pathname', 'type': 'const char*', '... 0 0
713863 16026.611475 159 1 0 systemd-journal ip-10-100-1-186 257 openat 4 34 [{'name': 'dirfd', 'type': 'int', 'value': -10... 0 0
713864 16026.611515 159 1 0 systemd-journal ip-10-100-1-186 5 fstat 2 0 [{'name': 'fd', 'type': 'int', 'value': 34}, {... 0 0
713865 16026.611582 159 1 0 systemd-journal ip-10-100-1-186 257 openat 4 -2 [{'name': 'dirfd', 'type': 'int', 'value': -10... 0 0
713866 16026.619387 506 1 104 rs:main Q:Reg ip-10-100-1-186 62 kill 2 0 [{'name': 'pid', 'type': 'pid_t', 'value': 506... 0 0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment