Event ID 5: Process terminated
Contents
Event ID 5: Process terminated¶
Version: 4.81¶
Description¶
The process terminate event reports when a process terminates. It provides the UtcTime, ProcessGuid and ProcessId of the process.
Data Dictionary¶
Field Name |
Type |
Description |
Sample Value |
---|---|---|---|
RuleName |
string |
custom tag mapped to event. i.e ATT&CK technique ID |
|
UtcTime |
date |
Time in UTC when event was created |
|
ProcessGuid |
string |
Process Guid of the process that terminated |
|
ProcessId |
integer |
Process ID used by the os to identify the process that terminated |
|
Image |
string |
File path of the process that terminated |
|
User |
string |
Name of the account that terminated the process. |
|