Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug in service name resolution #117

Open
qjerome opened this issue Jun 30, 2022 · 0 comments
Open

Bug in service name resolution #117

qjerome opened this issue Jun 30, 2022 · 0 comments
Labels
bug Something isn't working

Comments

@qjerome
Copy link
Contributor

qjerome commented Jun 30, 2022

When there is a PID re-use it may happen that service name is wrong.
This bug only occurs when events are queued too long by ETW, for instance when the EDR is not consuming events from trace.

Fix: we could partially fix this by checking the image or not resolving services for processes not tracked by the EDR

@qjerome qjerome added the bug Something isn't working label Jul 13, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant