Acquires the memory space for a specified process of Windows host endpoints.
This audit was formerly known as the w32processes-memoryacquire audit.
This audit cannot be imported into a data acquisition script. See Audits That Cannot Be Imported on page 1.
Supported Platforms
Windows only
Memory-related audits are now supported for host endpoints running the following Windows operating system versions.
Windows 7 (32-bit & 64-bit)
Windows Server 2012 R2 (64-bit)
Windows Server 2016 (64-bit)
Windows Server 2019 (64-bit)
Windows Server 2022 (64-bit)
Windows 8.1 (32-bit & 64-bit)[2]
Windows 10 2015 LTSB, 2016 LTSB, 2019 LTSC
Windows 10 RS1 - 21H2 (64-bit)
Windows 11 21H2 (64-bit)
Input Parameters
The following input parameters are available for this audit.
pid
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | PID | Valid values are a process ID. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Specify the process ID that the audit should analyze. This parameter cannot be specified in conjunction with the |
process name
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | String | Valid values are a string of text. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | This parameter cannot be specified in conjunction with the |
Content Regex
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | ArrayOfString | Valid values are specified in an array of string values. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Specify a valid regex string for which to search. |
memory file
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | FilePath | Valid values are a full file path and file name. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Specify the full path and file name of the file that represents the host endpoint's physical memory. |
Prevent Hibernation
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | Bool | Valid values are Boolean values. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Use Boolean values to indicate whether to prevent the host endpoint from entering hibernation while this audit is executed. |
[2] The Agent provides limited support for the driver-memoryacquire audit for host endpoints running Windows 8.1.