Process Tracker evaluates process execution to detect malicious behavior. It reconstructs attack chains by tracing parent–child process relationships, starting from a suspicious process and walking back to its origin. Using the process grid and sequential view, analysts can map how a process was launched — for example, through a malicious document, scheduled task, or compromised process. This reconstruction provides evidence of execution flow and helps establish the root cause of suspicious activity.
Evaluate events to detect malicious processes with Process Tracker
- Published on Aug 26, 2026
- 1 minute(s) read
Was this article helpful?