processes‑memoryacquire Audit

Prev Next

Acquires the memory space for a specified process of Windows host endpoints.

This audit was formerly known as the w32processes-memoryacquire audit.

This audit cannot be imported into a data acquisition script. See Audits That Cannot Be Imported on page 1.

Supported Platforms

Windows only

Memory-related audits are now supported for host endpoints running the following Windows operating system versions.

  • Windows 7 (32-bit & 64-bit)

  • Windows Server 2012 R2 (64-bit)

  • Windows Server 2016 (64-bit)

  • Windows Server 2019 (64-bit)

  • Windows Server 2022 (64-bit)

  • Windows 8.1 (32-bit & 64-bit)[2]

  • Windows 10 2015 LTSB, 2016 LTSB, 2019 LTSC

  • Windows 10 RS1 - 21H2 (64-bit)

  • Windows 11 21H2 (64-bit)

Input Parameters

The following input parameters are available for this audit.

pid

Details

Values

Description

Platform

Windows

Windows environments

Format

PID

Valid values are a process ID.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the process ID that the audit should analyze. This parameter cannot be specified in conjunction with the process name parameter.

process name

Details

Values

Description

Platform

Windows

Windows environments

Format

String

Valid values are a string of text.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

This parameter cannot be specified in conjunction with the pid parameter.

Content Regex

Details

Values

Description

Platform

Windows

Windows environments

Format

ArrayOfString

Valid values are specified in an array of string values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify a valid regex string for which to search.

memory file

Details

Values

Description

Platform

Windows

Windows environments

Format

FilePath

Valid values are a full file path and file name.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the full path and file name of the file that represents the host endpoint's physical memory.

Prevent Hibernation

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether to prevent the host endpoint from entering hibernation while this audit is executed.




[2] The Agent provides limited support for the driver-memoryacquire audit for host endpoints running Windows 8.1.