Blue Team
search
⌘Ctrlk
Blue Team
  • Model
    • Asset Inventory
    • Network Mapping
    • Operational Activity Mapping
    • System Mapping
  • Harden
    • Agent Authentication
    • Application Hardening
    • Credential Hardening
    • Message Hardening
    • Platform Hardening
    • Source Code Hardening
  • Detect
    • File Analysis
    • Identifier Analysis
    • Message Analysis
    • Network Traffic Analysis
    • Physical Access Monitoring
    • Platform Monitoring
    • Process Analysis
      • Database Query String Analysis
      • File Access Pattern Analysis
      • Indirect Branch Call Analysis
      • Process Code Segment Verification
      • Process Self-Modification Detection
      • Process Spawn Analysis
      • Script Execution Analysis
      • Shadow Stack Comparisons
      • System Call Analysis
    • User Behavior Analysis
  • Isolate
    • Access Mediation
    • Access Policy Administration
    • Content Filtering
    • Execution Isolation
    • Network Isolation
  • Deceive
    • Decoy Environment
    • Decoy Object
  • Evict
    • Credential Eviction
    • Object Eviction
    • Process Eviction
  • Restore
    • Restore Access
    • Restore Object
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Detect

Process Analysis

Database Query String Analysischevron-rightFile Access Pattern Analysischevron-rightIndirect Branch Call Analysischevron-rightProcess Code Segment Verificationchevron-rightProcess Self-Modification Detectionchevron-rightProcess Spawn Analysischevron-rightScript Execution Analysischevron-rightShadow Stack Comparisonschevron-rightSystem Call Analysischevron-right
PreviousPlatform Uptime Monitoringchevron-leftNextDatabase Query String Analysischevron-right