Endpoint configuration · GraphQL type

ProcessWindows type

MS Windows O/S specific process information.

Fields

Field Name Description
userSid - String! Security identifier (SID) of the user this process is running as, a variable-length string that uniquely identifies users or groups in the MS Windows O/S.
userName - String! The user name of the user this process is running as.
groupSid - String! Security identifier (SID) of the group this process is running as, a variable-length string that uniquely identifies users or groups in the MS Windows O/S.
groupName - String! The group name of the group this process is running as.
tokenElevationFull - Boolean! True if the process has an elevated (TokenElevationTypeFull) token. An elevated token is used when User Account Control (UAC) is enabled and the user chooses to start the program using "Run as administrator".
isolatedUserMode - Boolean! True of the process is running in Isolated User Mode (IUM). IUM is a virtualization-based security feature in MS Windows 10+ that uses secure kernels to keep business data and processes separate from the underlying operating system (OS).
handleCount - Int64! Total count of handles being used by the process. A handle is a reference to a operating system resource in MS Windows.
priorityClass - ProcessWindowsPriorityClass! The MS Windows process priority class represented as an integer. See ProcessPriorityClass Enum (Microsoft)

Used by

Example

Example

{
  "userSid": "abc123",
  "userName": "abc123",
  "groupSid": "xyz789",
  "groupName": "abc123",
  "tokenElevationFull": true,
  "isolatedUserMode": false,
  "handleCount": "-8589934592",
  "priorityClass": "ABOVE_NORMAL"
}