IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB ThreatHunter: Why Is the Process Tree For System Empty?

CB ThreatHunter: Why Is the Process Tree For System Empty?

Environment

  • CB ThreatHunter: All Supported Versions

Question

Why Is the Process Tree For "System" Empty?

Answer

The system ‘process’ is a special case. It’s not  the same as a normal process and is dynamically created at boot-time (so it’s not an .exe or .dll). "System" is given a process id (PID) of 4, and only runs worker threads. There are no child processes of system and therefore there’s not going to be a process tree for it, even though it could have events associated to it.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
491
Contributors