The LoadedModules collector shows the loaded modules of running processes.
You can run a search query to display all loaded modules of a process to investigate and perform actions such as:
Determine if a process is compromised.
Reconfigure reputations for a proper process reputation calculation.
Change the reputation of a loaded module.
Display modules injected from other processes.
Field | Type | Description |
|---|---|---|
process_id | Number | The process's system identifier. |
process_name | String | The name of the running process. |
process_imagepath | String | Path to the process's image name. |
module_name | String | The name of the module. |
module_imagepath | String | Path to the module's image name. |
module_reputation | String | The module's reputation name and level (range) defined by TIE or ATP.
|
module_sha1 | String | The SHA-1 hash code for the module. |
module_sha2 | String | The SHA-256 hash code for the module. |
module_md5 | String | The MD5 hash code for the module. |
Windows | Linux | macOS |
|---|---|---|
3.0 and later | 3.0 and later | 3.0 and later |
LoadedModules where HostInfo hostname equals "osx-elcapitan-01" and LoadedModules id equals 71
LoadedModules where HostInfo hostname equals "osx-elcapitan-01" and LoadedModules id equals 71