{ "cells": [ { "cell_type": "markdown", "metadata": { "toc": true }, "source": [ "
\n", " | TenantId | \n", "Account | \n", "EventID | \n", "TimeGenerated | \n", "Computer | \n", "SubjectUserSid | \n", "SubjectUserName | \n", "SubjectDomainName | \n", "SubjectLogonId | \n", "NewProcessId | \n", "NewProcessName | \n", "TokenElevationType | \n", "ProcessId | \n", "CommandLine | \n", "ParentProcessName | \n", "TargetLogonId | \n", "SourceComputerId | \n", "TimeCreatedUtc | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
0 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 15:21:06.890 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0xd78 | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "%%1936 | \n", "0x1994 | \n", "\"CollectGuestLogs.exe\" -Mode:ga -FileName:C:\\W... | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "0x0 | \n", "263a788b-6526-4cdc-8ed9-d79402fe4aa0 | \n", "2019-02-10 15:21:06.890 | \n", "
1 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 15:21:06.907 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x221c | \n", "C:\\Windows\\System32\\conhost.exe | \n", "%%1936 | \n", "0xd78 | \n", "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff... | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "0x0 | \n", "263a788b-6526-4cdc-8ed9-d79402fe4aa0 | \n", "2019-02-10 15:21:06.907 | \n", "
2 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 14:15:36.253 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x638 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "%%1936 | \n", "0xe24 | \n", "\"C:\\Program Files\\Microsoft Monitoring Agent\\A... | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "0x0 | \n", "263a788b-6526-4cdc-8ed9-d79402fe4aa0 | \n", "2019-02-10 14:15:36.253 | \n", "
3 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 14:15:36.270 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x115c | \n", "C:\\Windows\\System32\\conhost.exe | \n", "%%1936 | \n", "0x638 | \n", "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff... | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "0x0 | \n", "263a788b-6526-4cdc-8ed9-d79402fe4aa0 | \n", "2019-02-10 14:15:36.270 | \n", "
4 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 15:48:18.437 | \n", "MSTICAlertsWin1 | \n", "S-1-5-20 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e4 | \n", "0x2364 | \n", "C:\\Windows\\System32\\reg.exe | \n", "%%1936 | \n", "0x1c24 | \n", "reg \"C:\\diagnostics\\WinBenignActivity.cmd\" -2... | \n", "C:\\Windows\\System32\\cmd.exe | \n", "0x0 | \n", "263a788b-6526-4cdc-8ed9-d79402fe4aa0 | \n", "2019-02-10 15:48:18.437 | \n", "
\\n\"+\n", " \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n", " \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n", " \"
\\n\"+\n", " \"\\n\"+\n",
" \"from bokeh.resources import INLINE\\n\"+\n",
" \"output_notebook(resources=INLINE)\\n\"+\n",
" \"
\\n\"+\n",
" \"\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"\n", " | EventID | \n", "TenantId | \n", "Computer | \n", "mssg_id | \n", "TimeGenerated | \n", "a0 | \n", "a1 | \n", "a2 | \n", "argc | \n", "auid | \n", "... | \n", "TimeGenerated_orig_par | \n", "NewProcessId_par | \n", "ParentProcessName | \n", "parent_proc_lc | \n", "parent_key | \n", "IsRoot | \n", "IsLeaf | \n", "IsBranch | \n", "path | \n", "parent_index | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n", "\n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " |
unknown13501970-01-01 00:00:00.000000 | \n", "SYSCALL_EXECVE | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "MSTICAlertsLxVM2 | \n", "NaN | \n", "1970-01-01 00:00:00.000 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "... | \n", "NaT | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1002 | \n", "NaN | \n", "
/usr/bin/sudo263732019-02-17 22:01:26.357000 | \n", "SYSCALL_EXECVE | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "MSTICAlertsLxVM2 | \n", "1550440886.357:8972854 | \n", "2019-02-17 22:01:26.357 | \n", "sudo | \n", "/opt/microsoft/omsagent/ruby/bin/ruby | \n", "/opt/microsoft/omsagent/plugin/tailfilereader.rb | \n", "6 | \n", "-1 | \n", "... | \n", "1970-01-01 00:00:00.000 | \n", "1350 | \n", "unknown | \n", "unknown | \n", "unknown13501970-01-01 00:00:00.000000 | \n", "False | \n", "False | \n", "True | \n", "1002/159 | \n", "1002 | \n", "
/opt/microsoft/omsagent/ruby/bin/ruby263752019-02-17 22:01:26.369000 | \n", "SYSCALL_EXECVE | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "MSTICAlertsLxVM2 | \n", "1550440886.369:8972858 | \n", "2019-02-17 22:01:26.369 | \n", "/opt/microsoft/omsagent/ruby/bin/ruby | \n", "/opt/microsoft/omsagent/plugin/tailfilereader.rb | \n", "/var/log/audit/audit.log | \n", "5 | \n", "-1 | \n", "... | \n", "2019-02-17 22:01:26.357 | \n", "NaN | \n", "/usr/bin/sudo | \n", "/usr/bin/sudo | \n", "/usr/bin/sudo263732019-02-17 22:01:26.357000 | \n", "False | \n", "False | \n", "True | \n", "1002/159/160 | \n", "159 | \n", "
/usr/bin/sudo263772019-02-17 22:01:26.449000 | \n", "SYSCALL_EXECVE | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "MSTICAlertsLxVM2 | \n", "1550440886.449:8972859 | \n", "2019-02-17 22:01:26.449 | \n", "sudo | \n", "test | \n", "-f | \n", "4 | \n", "-1 | \n", "... | \n", "2019-02-17 22:01:26.369 | \n", "NaN | \n", "/opt/microsoft/omsagent/ruby/bin/ruby | \n", "/opt/microsoft/omsagent/ruby/bin/ruby | \n", "/opt/microsoft/omsagent/ruby/bin/ruby263752019... | \n", "False | \n", "False | \n", "True | \n", "1002/159/160/161 | \n", "160 | \n", "
/usr/bin/test263782019-02-17 22:01:26.465000 | \n", "SYSCALL_EXECVE | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "MSTICAlertsLxVM2 | \n", "1550440886.465:8972863 | \n", "2019-02-17 22:01:26.465 | \n", "test | \n", "-f | \n", "/var/log/audit/audit.log | \n", "3 | \n", "-1 | \n", "... | \n", "2019-02-17 22:01:26.449 | \n", "NaN | \n", "/usr/bin/sudo | \n", "/usr/bin/sudo | \n", "/usr/bin/sudo263772019-02-17 22:01:26.449000 | \n", "False | \n", "True | \n", "False | \n", "1002/159/160/161/162 | \n", "161 | \n", "
5 rows × 41 columns
\n", "\\n\"+\n", " \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n", " \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n", " \"
\\n\"+\n", " \"\\n\"+\n",
" \"from bokeh.resources import INLINE\\n\"+\n",
" \"output_notebook(resources=INLINE)\\n\"+\n",
" \"
\\n\"+\n",
" \"\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"\n", " | Row | \n", "RootProcess | \n", "TreeSize: | \n", "AverageRarity | \n", "
---|---|---|---|---|
27 | \n", "27 | \n", "C:\\Windows\\System32\\svchost.exe | \n", "4 | \n", "0.666726 | \n", "
23 | \n", "23 | \n", "C:\\Windows\\System32\\svchost.exe | \n", "2 | \n", "0.500000 | \n", "
22 | \n", "22 | \n", "C:\\Windows\\System32\\smss.exe | \n", "30 | \n", "0.398288 | \n", "
20 | \n", "20 | \n", "C:\\Windows\\SoftwareDistribution\\Download\\Insta... | \n", "2 | \n", "0.333333 | \n", "
9 | \n", "9 | \n", "C:\\Windows\\System32\\smss.exe | \n", "7 | \n", "0.250000 | \n", "
7 | \n", "7 | \n", "C:\\ProgramData\\Microsoft\\Windows Defender\\plat... | \n", "46 | \n", "0.190123 | \n", "
10 | \n", "10 | \n", "C:\\Windows\\System32\\winlogon.exe | \n", "2 | \n", "0.166667 | \n", "
5 | \n", "5 | \n", "C:\\Windows\\System32\\svchost.exe | \n", "21 | \n", "0.146667 | \n", "
18 | \n", "18 | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "3 | \n", "0.125089 | \n", "
13 | \n", "13 | \n", "C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.3031... | \n", "2 | \n", "0.125000 | \n", "
29 | \n", "29 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "4 | \n", "0.095297 | \n", "
25 | \n", "25 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "4 | \n", "0.095297 | \n", "
21 | \n", "21 | \n", "C:\\ProgramData\\Microsoft\\Windows Defender\\plat... | \n", "21 | \n", "0.059754 | \n", "
16 | \n", "16 | \n", "C:\\Windows\\System32\\services.exe | \n", "320 | \n", "0.056118 | \n", "
15 | \n", "15 | \n", "C:\\Windows\\System32\\svchost.exe | \n", "1381 | \n", "0.038497 | \n", "
2 | \n", "2 | \n", "C:\\Windows\\System32\\svchost.exe | \n", "2192 | \n", "0.025462 | \n", "
4 | \n", "4 | \n", "C:\\Windows\\System32\\services.exe | \n", "105 | \n", "0.025112 | \n", "
3 | \n", "3 | \n", "C:\\Windows\\System32\\svchost.exe | \n", "689 | \n", "0.019825 | \n", "
0 | \n", "0 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "13 | \n", "0.012703 | \n", "
11 | \n", "11 | \n", "unknown | \n", "8936 | \n", "0.011424 | \n", "
1 | \n", "1 | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "259 | \n", "0.007365 | \n", "
19 | \n", "19 | \n", "C:\\Windows\\System32\\svchost.exe | \n", "4949 | \n", "0.007174 | \n", "
17 | \n", "17 | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "11 | \n", "0.007138 | \n", "
14 | \n", "14 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "274 | \n", "0.003676 | \n", "
8 | \n", "8 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "3703 | \n", "0.000194 | \n", "
12 | \n", "12 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "2 | \n", "0.000178 | \n", "
24 | \n", "24 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "2 | \n", "0.000178 | \n", "
26 | \n", "26 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "2 | \n", "0.000178 | \n", "
28 | \n", "28 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "2 | \n", "0.000178 | \n", "
6 | \n", "6 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "2 | \n", "0.000178 | \n", "
30 | \n", "30 | \n", "C:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n", "2 | \n", "0.000178 | \n", "
\\n\"+\n", " \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n", " \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n", " \"
\\n\"+\n", " \"\\n\"+\n",
" \"from bokeh.resources import INLINE\\n\"+\n",
" \"output_notebook(resources=INLINE)\\n\"+\n",
" \"
\\n\"+\n",
" \"\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"\n", " | TenantId | \n", "Account | \n", "EventID | \n", "TimeGenerated | \n", "Computer | \n", "SubjectUserSid | \n", "SubjectUserName | \n", "SubjectDomainName | \n", "SubjectLogonId | \n", "NewProcessId | \n", "... | \n", "source_index_par | \n", "ProcessId_par | \n", "NewProcessName_par | \n", "TimeGenerated_orig_par | \n", "parent_key | \n", "IsRoot | \n", "IsLeaf | \n", "IsBranch | \n", "path | \n", "parent_index | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n", "\n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " |
c:\\windows\\system32\\svchost.exe0x2701970-01-01 00:00:00.000000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "NaN | \n", "4688 | \n", "1970-01-01 | \n", "MSTICAlertsWin1 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "0x3e7 | \n", "0x270 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaT | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1000 | \n", "NaN | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x7981970-01-01 00:00:00.000000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "NaN | \n", "4688 | \n", "1970-01-01 | \n", "MSTICAlertsWin1 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "0x3e7 | \n", "0x798 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaT | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1001 | \n", "NaN | \n", "
c:\\windows\\system32\\svchost.exe0xb3c1970-01-01 00:00:00.000000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "NaN | \n", "4688 | \n", "1970-01-01 | \n", "MSTICAlertsWin1 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "0x3e7 | \n", "0xb3c | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaT | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1002 | \n", "NaN | \n", "
c:\\windows\\system32\\services.exe0x2201970-01-01 00:00:00.000000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "NaN | \n", "4688 | \n", "1970-01-01 | \n", "MSTICAlertsWin1 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "0x3e7 | \n", "0x220 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaT | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1003 | \n", "NaN | \n", "
c:\\program files\\microsoft monitoring agent\\agent\\monitoringhost.exe0x8641970-01-01 00:00:00.000000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "NaN | \n", "4688 | \n", "1970-01-01 | \n", "MSTICAlertsWin1 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "0x3e7 | \n", "0x864 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaT | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1004 | \n", "NaN | \n", "
5 rows × 35 columns
\n", "\n", " | TenantId | \n", "Account | \n", "EventID | \n", "TimeGenerated | \n", "Computer | \n", "SubjectUserSid | \n", "SubjectUserName | \n", "SubjectDomainName | \n", "SubjectLogonId | \n", "NewProcessId | \n", "... | \n", "source_index_par | \n", "ProcessId_par | \n", "NewProcessName_par | \n", "TimeGenerated_orig_par | \n", "parent_key | \n", "IsRoot | \n", "IsLeaf | \n", "IsBranch | \n", "path | \n", "parent_index | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n", "\n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " |
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\waappagent.exe0x19941970-01-01 00:00:00.000000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "NaN | \n", "4688 | \n", "1970-01-01 00:00:00.000 | \n", "MSTICAlertsWin1 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "0x3e7 | \n", "0x1994 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaT | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1007 | \n", "NaN | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x123c2019-02-09 23:16:28.153000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:16:28.153 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x123c | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 00:00:00.000 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/103 | \n", "1007 | \n", "
c:\\windows\\system32\\conhost.exe0x20b02019-02-09 23:16:28.163000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:16:28.163 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x20b0 | \n", "... | \n", "986.0 | \n", "0x1994 | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "2019-02-09 23:16:28.153 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "True | \n", "False | \n", "1007/103/104 | \n", "103 | \n", "
c:\\windows\\system32\\cmd.exe0xccc2019-02-09 23:20:15.547000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:20:15.547 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0xccc | \n", "... | \n", "986.0 | \n", "0x1994 | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "2019-02-09 23:16:28.153 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/103/105 | \n", "103 | \n", "
c:\\windows\\system32\\conhost.exe0x14ec2019-02-09 23:20:15.560000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:20:15.560 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x14ec | \n", "... | \n", "988.0 | \n", "0x123c | \n", "C:\\Windows\\System32\\cmd.exe | \n", "2019-02-09 23:20:15.547 | \n", "c:\\windows\\system32\\cmd.exe0xccc2019-02-09 23:... | \n", "False | \n", "True | \n", "False | \n", "1007/103/105/106 | \n", "105 | \n", "
5 rows × 35 columns
\n", "\n", " | TenantId | \n", "Account | \n", "EventID | \n", "TimeGenerated | \n", "Computer | \n", "SubjectUserSid | \n", "SubjectUserName | \n", "SubjectDomainName | \n", "SubjectLogonId | \n", "NewProcessId | \n", "... | \n", "source_index_par | \n", "ProcessId_par | \n", "NewProcessName_par | \n", "TimeGenerated_orig_par | \n", "parent_key | \n", "IsRoot | \n", "IsLeaf | \n", "IsBranch | \n", "path | \n", "parent_index | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n", "\n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " |
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x1c542019-02-09 22:11:59.877000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 22:11:59.877 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x1c54 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/69 | \n", "1007 | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x123c2019-02-09 23:16:28.153000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:16:28.153 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x123c | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/103 | \n", "1007 | \n", "
c:\\windowsazure\\secagent\\wasecagentprov.exe0xda82019-02-09 23:55:46.057000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:55:46.057 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0xda8 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/123 | \n", "1007 | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x7fc2019-02-10 00:22:33.813000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 00:22:33.813 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x7fc | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/134 | \n", "1007 | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x172c2019-02-10 01:27:25.173000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 01:27:25.173 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x172c | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/343 | \n", "1007 | \n", "
5 rows × 35 columns
\n", "\n", " | TenantId | \n", "Account | \n", "EventID | \n", "TimeGenerated | \n", "Computer | \n", "SubjectUserSid | \n", "SubjectUserName | \n", "SubjectDomainName | \n", "SubjectLogonId | \n", "NewProcessId | \n", "... | \n", "source_index_par | \n", "ProcessId_par | \n", "NewProcessName_par | \n", "TimeGenerated_orig_par | \n", "parent_key | \n", "IsRoot | \n", "IsLeaf | \n", "IsBranch | \n", "path | \n", "parent_index | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n", "\n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " |
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\waappagent.exe0x19941970-01-01 00:00:00.000000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "NaN | \n", "4688 | \n", "1970-01-01 00:00:00.000 | \n", "MSTICAlertsWin1 | \n", "NaN | \n", "NaN | \n", "NaN | \n", "0x3e7 | \n", "0x1994 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaT | \n", "NaN | \n", "True | \n", "False | \n", "False | \n", "1007 | \n", "NaN | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x123c2019-02-09 23:16:28.153000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:16:28.153 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x123c | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 00:00:00.000 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/103 | \n", "1007 | \n", "
c:\\windows\\system32\\cmd.exe0xccc2019-02-09 23:20:15.547000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:20:15.547 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0xccc | \n", "... | \n", "986.0 | \n", "0x1994 | \n", "C:\\WindowsAzure\\GuestAgent_2.7.41491.901_2019-... | \n", "2019-02-09 23:16:28.153 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/103/105 | \n", "103 | \n", "
c:\\windows\\system32\\conhost.exe0x14ec2019-02-09 23:20:15.560000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:20:15.560 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x14ec | \n", "... | \n", "988.0 | \n", "0x123c | \n", "C:\\Windows\\System32\\cmd.exe | \n", "2019-02-09 23:20:15.547 | \n", "c:\\windows\\system32\\cmd.exe0xccc2019-02-09 23:... | \n", "False | \n", "True | \n", "False | \n", "1007/103/105/106 | \n", "105 | \n", "
4 rows × 35 columns
\n", "\n", " | TenantId | \n", "Account | \n", "EventID | \n", "TimeGenerated | \n", "Computer | \n", "SubjectUserSid | \n", "SubjectUserName | \n", "SubjectDomainName | \n", "SubjectLogonId | \n", "NewProcessId | \n", "... | \n", "source_index_par | \n", "ProcessId_par | \n", "NewProcessName_par | \n", "TimeGenerated_orig_par | \n", "parent_key | \n", "IsRoot | \n", "IsLeaf | \n", "IsBranch | \n", "path | \n", "parent_index | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n", "\n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " | \n", " |
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x1c542019-02-09 22:11:59.877000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 22:11:59.877 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x1c54 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/69 | \n", "1007 | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x123c2019-02-09 23:16:28.153000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:16:28.153 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x123c | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/103 | \n", "1007 | \n", "
c:\\windowsazure\\secagent\\wasecagentprov.exe0xda82019-02-09 23:55:46.057000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-09 23:55:46.057 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0xda8 | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/123 | \n", "1007 | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x7fc2019-02-10 00:22:33.813000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 00:22:33.813 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x7fc | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/134 | \n", "1007 | \n", "
c:\\windowsazure\\guestagent_2.7.41491.901_2019-01-14_202614\\collectguestlogs.exe0x172c2019-02-10 01:27:25.173000 | \n", "52b1ab41-869e-4138-9e40-2a4457f09bf0 | \n", "WORKGROUP\\MSTICAlertsWin1$ | \n", "4688 | \n", "2019-02-10 01:27:25.173 | \n", "MSTICAlertsWin1 | \n", "S-1-5-18 | \n", "MSTICAlertsWin1$ | \n", "WORKGROUP | \n", "0x3e7 | \n", "0x172c | \n", "... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "1970-01-01 | \n", "c:\\windowsazure\\guestagent_2.7.41491.901_2019-... | \n", "False | \n", "False | \n", "True | \n", "1007/343 | \n", "1007 | \n", "
5 rows × 35 columns
\n", "\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\program files\\microsoft monitoring agent\\agent\\monitoringhost.exe0x8641970-01-01 00:00:00.000000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nNaN | \n4688 | \n1970-01-01 00:00:00.000 | \nMSTICAlertsWin1 | \nNaN | \nNaN | \nNaN | \n0x3e7 | \n0x864 | \n... | \nNaN | \nNaN | \nNaN | \nNaT | \nNaN | \nTrue | \nFalse | \nFalse | \n1004 | \nNaN | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x8dc2019-02-09 21:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x8dc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/10 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x183c2019-02-09 21:02:56.273000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.273 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x183c | \n... | \n998.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 21:02:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/10/11 | \n10 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xd742019-02-09 23:22:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd74 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/107 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x21c82019-02-09 23:22:56.267000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.267 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x21c8 | \n... | \n749.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 23:22:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/107/108 | \n107 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x6f82019-02-09 23:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x6f8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/120 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x1c242019-02-09 23:32:56.280000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.280 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1c24 | \n... | \n883.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 23:32:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/120/121 | \n120 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x1fc02019-02-10 00:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1fc0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/127 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x17a42019-02-10 00:02:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x17a4 | \n... | \n549.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-10 00:02:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/127/128 | \n127 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x10bc2019-02-10 00:12:56.253000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.253 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x10bc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/129 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x1c102019-02-10 00:12:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1c10 | \n... | \n478.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-10 00:12:56.252999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/129/130 | \n129 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xb482019-02-10 00:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xb48 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/139 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x235c2019-02-10 00:32:56.287000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.287 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x235c | \n... | \n553.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-10 00:32:56.270000128 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/139/140 | \n139 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xbd02019-02-09 21:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbd0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/15 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x14682019-02-09 21:32:56.290000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.290 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1468 | \n... | \n848.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 21:32:56.270000128 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/15/16 | \n15 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x15c82019-02-09 20:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x15c8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/5 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x12782019-02-09 20:32:56.280000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:32:56.280 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1278 | \n... | \n850.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 20:32:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/5/6 | \n5 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xe342019-02-09 22:02:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xe34 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/67 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0xbc2019-02-09 22:02:56.277000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.277 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbc | \n... | \n984.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 22:02:56.263000064 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/67/68 | \n67 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x53c2019-02-09 22:32:56.247000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.247 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x53c | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/76 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x18342019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1834 | \n... | \n738.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 22:32:56.247000064 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/76/77 | \n76 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xef42019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xef4 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/78 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x15f42019-02-09 22:32:56.273000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.273 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x15f4 | \n... | \n736.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 22:32:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/78/79 | \n78 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xcd82019-02-09 20:52:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xcd8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/8 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0xfd42019-02-09 20:52:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xfd4 | \n... | \n887.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 20:52:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/8/9 | \n8 | \n
25 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x8dc2019-02-09 21:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x8dc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/10 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xd742019-02-09 23:22:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd74 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/107 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x6f82019-02-09 23:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x6f8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/120 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x1fc02019-02-10 00:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1fc0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/127 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x10bc2019-02-10 00:12:56.253000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.253 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x10bc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/129 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xb482019-02-10 00:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xb48 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/139 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xbd02019-02-09 21:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbd0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/15 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x15c82019-02-09 20:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x15c8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/5 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xe342019-02-09 22:02:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xe34 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/67 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x53c2019-02-09 22:32:56.247000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.247 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x53c | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/76 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xef42019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xef4 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/78 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xcd82019-02-09 20:52:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xcd8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/8 | \n1004 | \n
12 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\windows\\system32\\conhost.exe0x183c2019-02-09 21:02:56.273000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.273 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x183c | \n... | \n998.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 21:02:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/10/11 | \n10 | \n
c:\\windows\\system32\\conhost.exe0x21c82019-02-09 23:22:56.267000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.267 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x21c8 | \n... | \n749.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 23:22:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/107/108 | \n107 | \n
c:\\windows\\system32\\conhost.exe0x1c242019-02-09 23:32:56.280000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.280 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1c24 | \n... | \n883.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 23:32:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/120/121 | \n120 | \n
c:\\windows\\system32\\conhost.exe0x17a42019-02-10 00:02:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x17a4 | \n... | \n549.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-10 00:02:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/127/128 | \n127 | \n
c:\\windows\\system32\\conhost.exe0x1c102019-02-10 00:12:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1c10 | \n... | \n478.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-10 00:12:56.252999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/129/130 | \n129 | \n
c:\\windows\\system32\\conhost.exe0x235c2019-02-10 00:32:56.287000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.287 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x235c | \n... | \n553.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-10 00:32:56.270000128 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/139/140 | \n139 | \n
c:\\windows\\system32\\conhost.exe0x14682019-02-09 21:32:56.290000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.290 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1468 | \n... | \n848.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 21:32:56.270000128 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/15/16 | \n15 | \n
c:\\windows\\system32\\conhost.exe0x12782019-02-09 20:32:56.280000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:32:56.280 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1278 | \n... | \n850.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 20:32:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/5/6 | \n5 | \n
c:\\windows\\system32\\conhost.exe0xbc2019-02-09 22:02:56.277000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.277 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbc | \n... | \n984.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 22:02:56.263000064 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/67/68 | \n67 | \n
c:\\windows\\system32\\conhost.exe0x18342019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1834 | \n... | \n738.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 22:32:56.247000064 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/76/77 | \n76 | \n
c:\\windows\\system32\\conhost.exe0x15f42019-02-09 22:32:56.273000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.273 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x15f4 | \n... | \n736.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 22:32:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/78/79 | \n78 | \n
c:\\windows\\system32\\conhost.exe0xfd42019-02-09 20:52:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xfd4 | \n... | \n887.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 20:52:56.260000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/8/9 | \n8 | \n
12 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\program files\\microsoft monitoring agent\\agent\\monitoringhost.exe0x8641970-01-01 00:00:00.000000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nNaN | \n4688 | \n1970-01-01 00:00:00.000 | \nMSTICAlertsWin1 | \nNaN | \nNaN | \nNaN | \n0x3e7 | \n0x864 | \n... | \nNaN | \nNaN | \nNaN | \nNaT | \nNaN | \nTrue | \nFalse | \nFalse | \n1004 | \nNaN | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x8dc2019-02-09 21:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x8dc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 00:00:00.000000000 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/10 | \n1004 | \n
c:\\windows\\system32\\conhost.exe0x183c2019-02-09 21:02:56.273000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.273 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x183c | \n... | \n998.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 21:02:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/10/11 | \n10 | \n
3 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\windows\\system32\\conhost.exe0x183c2019-02-09 21:02:56.273000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.273 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x183c | \n... | \n998.0 | \n0x864 | \nC:\\Program Files\\Microsoft Monitoring Agent\\Ag... | \n2019-02-09 21:02:56.256999936 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nTrue | \nFalse | \n1004/10/11 | \n10 | \n
1 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x15c82019-02-09 20:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x15c8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/5 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xcd82019-02-09 20:52:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xcd8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/8 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x8dc2019-02-09 21:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x8dc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/10 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xbd02019-02-09 21:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbd0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/15 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xe342019-02-09 22:02:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xe34 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/67 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x53c2019-02-09 22:32:56.247000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.247 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x53c | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/76 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xef42019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xef4 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/78 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xd742019-02-09 23:22:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd74 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/107 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x6f82019-02-09 23:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x6f8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/120 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x1fc02019-02-10 00:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1fc0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/127 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x10bc2019-02-10 00:12:56.253000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.253 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x10bc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/129 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xb482019-02-10 00:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xb48 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/139 | \n1004 | \n
12 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x15c82019-02-09 20:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x15c8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/5 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xcd82019-02-09 20:52:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xcd8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/8 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x8dc2019-02-09 21:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x8dc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/10 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xbd02019-02-09 21:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbd0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/15 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xe342019-02-09 22:02:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xe34 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/67 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x53c2019-02-09 22:32:56.247000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.247 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x53c | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/76 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xef42019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xef4 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/78 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xd742019-02-09 23:22:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd74 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/107 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x6f82019-02-09 23:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x6f8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/120 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x1fc02019-02-10 00:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1fc0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/127 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x10bc2019-02-10 00:12:56.253000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.253 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x10bc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/129 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xb482019-02-10 00:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xb48 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/139 | \n1004 | \n
12 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x15c82019-02-09 20:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x15c8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/5 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xcd82019-02-09 20:52:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xcd8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/8 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x8dc2019-02-09 21:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x8dc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/10 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xbd02019-02-09 21:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbd0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/15 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xe342019-02-09 22:02:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xe34 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/67 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x53c2019-02-09 22:32:56.247000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.247 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x53c | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/76 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xef42019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xef4 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/78 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xd742019-02-09 23:22:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd74 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/107 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x6f82019-02-09 23:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x6f8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/120 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x1fc02019-02-10 00:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1fc0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/127 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x10bc2019-02-10 00:12:56.253000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.253 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x10bc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/129 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xb482019-02-10 00:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xb48 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/139 | \n1004 | \n
12 rows × 35 columns
\n\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \nsource_index_par | \nProcessId_par | \nNewProcessName_par | \nTimeGenerated_orig_par | \nparent_key | \nIsRoot | \nIsLeaf | \nIsBranch | \npath | \nparent_index | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
proc_key | \n\n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n | \n |
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xcd82019-02-09 20:52:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 20:52:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xcd8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/8 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x8dc2019-02-09 21:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x8dc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/10 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xbd02019-02-09 21:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 21:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xbd0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/15 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xe342019-02-09 22:02:56.263000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:02:56.263 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xe34 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/67 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x53c2019-02-09 22:32:56.247000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.247 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x53c | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/76 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xef42019-02-09 22:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 22:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xef4 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/78 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0xd742019-02-09 23:22:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:22:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd74 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/107 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x6f82019-02-09 23:32:56.260000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-09 23:32:56.260 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x6f8 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/120 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0x1fc02019-02-10 00:02:56.257000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:02:56.257 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1fc0 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/127 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf-64\\desiredstateconfiguration\\dscrun.exe0x10bc2019-02-10 00:12:56.253000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:12:56.253 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x10bc | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/129 | \n1004 | \n
c:\\program files\\microsoft monitoring agent\\agent\\health service state\\ict 2\\cmf\\desiredstateconfiguration\\dscrun.exe0xb482019-02-10 00:32:56.270000 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 00:32:56.270 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xb48 | \n... | \nNaN | \nNaN | \nNaN | \n1970-01-01 | \nc:\\program files\\microsoft monitoring agent\\ag... | \nFalse | \nFalse | \nTrue | \n1004/139 | \n1004 | \n
11 rows × 35 columns
\n\n | SubjectUserName | \nSubjectLogonId | \nRarity | \nProcessCount | \n
---|---|---|---|---|
0 | \n- | \n0x3e7 | \n0.350000 | \n20 | \n
1 | \nLOCAL SERVICE | \n0x3e5 | \n0.038462 | \n26 | \n
2 | \nMSTICAdmin | \n0x109c408 | \n0.432549 | \n10 | \n
3 | \nMSTICAdmin | \n0x1e821b5 | \n0.239992 | \n8 | \n
4 | \nMSTICAdmin | \n0x1f388a3 | \n0.202848 | \n7 | \n
\n | TenantId | \nAccount | \nEventID | \nTimeGenerated | \nComputer | \nSubjectUserSid | \nSubjectUserName | \nSubjectDomainName | \nSubjectLogonId | \nNewProcessId | \n... | \npathHash | \ncommandlineLen | \ncommandlineLogLen | \ncommandlineTokensFull | \ncommandlineScore | \ncommandlineTokensHash | \nisSystemSession | \naccountNum | \nClusterSize | \nRarity | \n
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
0 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 15:21:06.890 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd78 | \n... | \n4163782718 | \n119 | \n2.075547 | \n18 | \n10142 | \n2764818190 | \nTrue | \n2202 | \n129 | \n0.007752 | \n
1 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 13:12:52.733 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x6f8 | \n... | \n4163782718 | \n119 | \n2.075547 | \n18 | \n10142 | \n2764818190 | \nTrue | \n2202 | \n129 | \n0.007752 | \n
2 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 12:08:46.173 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0xd68 | \n... | \n4163782718 | \n119 | \n2.075547 | \n18 | \n10142 | \n2764818190 | \nTrue | \n2202 | \n129 | \n0.007752 | \n
3 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 14:16:59.427 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x16d4 | \n... | \n4163782718 | \n119 | \n2.075547 | \n18 | \n10142 | \n2764818190 | \nTrue | \n2202 | \n129 | \n0.007752 | \n
4 | \n52b1ab41-869e-4138-9e40-2a4457f09bf0 | \nWORKGROUP\\MSTICAlertsWin1$ | \n4688 | \n2019-02-10 08:56:16.593 | \nMSTICAlertsWin1 | \nS-1-5-18 | \nMSTICAlertsWin1$ | \nWORKGROUP | \n0x3e7 | \n0x1070 | \n... | \n4163782718 | \n119 | \n2.075547 | \n18 | \n10142 | \n2764818190 | \nTrue | \n2202 | \n129 | \n0.007752 | \n
5 rows × 31 columns
\n\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"BokehJS does not appear to have successfully loaded. If loading BokehJS from CDN, this \\n\"+\n \"may be due to a slow or bad network connection. Possible fixes:\\n\"+\n \"
\\n\"+\n \"\\n\"+\n \"from bokeh.resources import INLINE\\n\"+\n \"output_notebook(resources=INLINE)\\n\"+\n \"
\\n\"+\n \"