\n", " | TimeCreated | \n", "host | \n", "EventID | \n", "EventDescription | \n", "User | \n", "process | \n", "Image | \n", "dest | \n", "cmdline | \n", "parent_process | \n", "ParentCommandLine | \n", "Hashes | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|
0 | \n", "2017-08-25T04:57:45.512440700Z | \n", "venus | \n", "3 | \n", "Network Connect | \n", "NT AUTHORITY\\SYSTEM | \n", "powershell.exe | \n", "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pow... | \n", "45.77.65.211.vultr.com | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
1 | \n", "2017-08-25T04:57:45.213738500Z | \n", "wrk-aturing | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "conhost.exe | \n", "C:\\Windows\\System32\\conhost.exe | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
2 | \n", "2017-08-25T04:57:45.213738500Z | \n", "wrk-aturing | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "cscript.exe | \n", "C:\\Windows\\System32\\cscript.exe | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
3 | \n", "2017-08-25T04:57:45.088941700Z | \n", "wrk-aturing | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "conhost.exe | \n", "C:\\Windows\\System32\\conhost.exe | \n", "wrk-aturing.frothly.local | \n", "\\??\\C:\\Windows\\system32\\conhost.exe | \n", "C:\\Windows\\System32\\csrss.exe | \n", "%SystemRoot%\\system32\\csrss.exe ObjectDirector... | \n", "SHA1=680DEC0F8907F4B8911FBE2AA5F2FD25425BE0B0 | \n", "
4 | \n", "2017-08-25T04:57:45.088941700Z | \n", "wrk-aturing | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "cscript.exe | \n", "C:\\Windows\\System32\\cscript.exe | \n", "wrk-aturing.frothly.local | \n", "C:\\Windows\\system32\\cscript.exe //Job:AgentHI... | \n", "C:\\Program Files (x86)\\Symantec\\Symantec Endpo... | \n", "\"C:\\Program Files (x86)\\Symantec\\Symantec Endp... | \n", "SHA1=70096A77E202CF9F30C064956F36D14BCBD8F7BB | \n", "
... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "
95 | \n", "2017-08-25T04:57:02.003800000Z | \n", "wrk-ghoppy | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "splunk-powershell.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "wrk-ghoppy.frothly.local | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "SHA1=50A428905F5BA8808464F8A8183DD3662D8157F6 | \n", "
96 | \n", "2017-08-25T04:57:01.170335100Z | \n", "venus | \n", "3 | \n", "Network Connect | \n", "NT AUTHORITY\\SYSTEM | \n", "powershell.exe | \n", "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pow... | \n", "45.77.65.211.vultr.com | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
97 | \n", "2017-08-25T04:57:01.941402000Z | \n", "wrk-ghoppy | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "splunk-winprintmon.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
98 | \n", "2017-08-25T04:57:01.863404500Z | \n", "wrk-ghoppy | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "splunk-netmon.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "wrk-ghoppy.frothly.local | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "SHA1=0644F98A9874414C738A0B8841BB997FB9BFC274 | \n", "
99 | \n", "2017-08-25T04:57:01.754208000Z | \n", "wrk-ghoppy | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "splunk-powershell.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
100 rows × 12 columns
\n", "\n", " | TimeCreated | \n", "host | \n", "EventID | \n", "EventDescription | \n", "User | \n", "process | \n", "Image | \n", "dest | \n", "cmdline | \n", "parent_process | \n", "ParentCommandLine | \n", "Hashes | \n", "
---|---|---|---|---|---|---|---|---|---|---|---|---|
0 | \n", "2017-08-25T04:57:45.512440700Z | \n", "venus | \n", "3 | \n", "Network Connect | \n", "NT AUTHORITY\\SYSTEM | \n", "powershell.exe | \n", "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\pow... | \n", "45.77.65.211.vultr.com | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
1 | \n", "2017-08-25T04:57:45.213738500Z | \n", "wrk-aturing | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "conhost.exe | \n", "C:\\Windows\\System32\\conhost.exe | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
2 | \n", "2017-08-25T04:57:45.213738500Z | \n", "wrk-aturing | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "cscript.exe | \n", "C:\\Windows\\System32\\cscript.exe | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
3 | \n", "2017-08-25T04:57:45.088941700Z | \n", "wrk-aturing | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "conhost.exe | \n", "C:\\Windows\\System32\\conhost.exe | \n", "wrk-aturing.frothly.local | \n", "\\??\\C:\\Windows\\system32\\conhost.exe | \n", "C:\\Windows\\System32\\csrss.exe | \n", "%SystemRoot%\\system32\\csrss.exe ObjectDirector... | \n", "SHA1=680DEC0F8907F4B8911FBE2AA5F2FD25425BE0B0 | \n", "
4 | \n", "2017-08-25T04:57:45.088941700Z | \n", "wrk-aturing | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "cscript.exe | \n", "C:\\Windows\\System32\\cscript.exe | \n", "wrk-aturing.frothly.local | \n", "C:\\Windows\\system32\\cscript.exe //Job:AgentHI... | \n", "C:\\Program Files (x86)\\Symantec\\Symantec Endpo... | \n", "\"C:\\Program Files (x86)\\Symantec\\Symantec Endp... | \n", "SHA1=70096A77E202CF9F30C064956F36D14BCBD8F7BB | \n", "
... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "... | \n", "
7923 | \n", "2017-08-25T04:57:46.758125600Z | \n", "wrk-klagerf | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "splunk-admon.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "wrk-klagerf.frothly.local | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "SHA1=1C0C7368C8B7B688CCF77D1062708E60D581B0AF | \n", "
7924 | \n", "2017-08-25T04:57:46.695728800Z | \n", "wrk-klagerf | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "splunk-MonitorNoHandle.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
7925 | \n", "2017-08-25T04:57:46.570935200Z | \n", "wrk-klagerf | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "splunk-MonitorNoHandle.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "wrk-klagerf.frothly.local | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "SHA1=F48EDD0FE4D013D690196572EA96A4FA6EB04E77 | \n", "
7926 | \n", "2017-08-25T04:57:46.539736800Z | \n", "wrk-klagerf | \n", "5 | \n", "Process Terminate | \n", "NaN | \n", "splunk-powershell.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "NaN | \n", "
7927 | \n", "2017-08-25T04:57:46.430542400Z | \n", "wrk-klagerf | \n", "1 | \n", "Process Create | \n", "NT AUTHORITY\\SYSTEM | \n", "splunk-powershell.exe | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "wrk-klagerf.frothly.local | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "C:\\Program Files\\SplunkUniversalForwarder\\bin\\... | \n", "\"C:\\Program Files\\SplunkUniversalForwarder\\bin... | \n", "SHA1=50A428905F5BA8808464F8A8183DD3662D8157F6 | \n", "
7928 rows × 12 columns
\n", "\n", " | TimeGenerated | \n", "TotalBytesSent | \n", "
---|---|---|
0 | \n", "2020-07-02T10:00:00Z | \n", "27055 | \n", "
1 | \n", "2020-07-02T09:00:00Z | \n", "33777 | \n", "
2 | \n", "2020-07-02T08:00:00Z | \n", "27355 | \n", "
3 | \n", "2020-07-02T07:00:00Z | \n", "25544 | \n", "
4 | \n", "2020-07-02T06:00:00Z | \n", "11771 | \n", "