MS Windows O/S specific process information.
Fields
| Field Name | Description |
|---|---|
userSid - String!
|
Security identifier (SID) of the user this process is running as, a variable-length string that uniquely identifies users or groups in the MS Windows O/S. |
userName - String!
|
The user name of the user this process is running as. |
groupSid - String!
|
Security identifier (SID) of the group this process is running as, a variable-length string that uniquely identifies users or groups in the MS Windows O/S. |
groupName - String!
|
The group name of the group this process is running as. |
tokenElevationFull - Boolean!
|
True if the process has an elevated (TokenElevationTypeFull) token. An elevated token is used when User Account Control (UAC) is enabled and the user chooses to start the program using "Run as administrator". |
isolatedUserMode - Boolean!
|
True of the process is running in Isolated User Mode (IUM). IUM is a virtualization-based security feature in MS Windows 10+ that uses secure kernels to keep business data and processes separate from the underlying operating system (OS). |
handleCount - Int64!
|
Total count of handles being used by the process. A handle is a reference to a operating system resource in MS Windows. |
priorityClass - ProcessWindowsPriorityClass!
|
The MS Windows process priority class represented as an integer. See ProcessPriorityClass Enum (Microsoft) |
Used by
ProcessOsSpecificunion: OS-specific process information union type.
Example
Example
{
"userSid": "abc123",
"userName": "abc123",
"groupSid": "xyz789",
"groupName": "abc123",
"tokenElevationFull": true,
"isolatedUserMode": false,
"handleCount": "-8589934592",
"priorityClass": "ABOVE_NORMAL"
}