When you select a single Process Guard alert on the Alerts page, the details of the alert are shown on the Hosts page of the Endpoint Security Web UI.
Process Guard Home Page on Endpoint Security Server
The current version of the Endpoint Security server provides a raw view of the alert details in JSON format. Most of the information available in the Process Guard home page is reformatted to generalize the alerts data coming from various modules. The following alerts represent notable alert fields that the Process Guard Module generates.
Alert Fields | Description |
|---|---|
| Process file path accessing LSASS. |
| File path of LSASS. |
| Hash of the source process file. |
| True, if the signature of the source process is verified. |
| True, if the signature exists for the source process. |
| Command line arguments passed to source process. |