Type
|
Item
|
||
FQDN / IP address / Hostname
|
Specify the remote endpoint FQDN, IP address, or hostname to identify
network connections that the investigated endpoint made
Examples:
|
||
User name
|
Specify the name of the Active Directory account or local
user
Examples:
|
||
File name
|
Specify the full file name including extension
Example:
|
||
File hash value
|
Specify the hash value of a file.
Example:
|
||
File directory
|
Specify the full path excluding file name
Example:
|
||
Registry key
|
Specify the full or partial registry key, value name, or
value data
Examples:
|
||
Registry value name
|
|||
Registry value data
|
|||
CLI command
|
Specify the command line parameters.
Examples:
|
Views: