Environment
Question
Why do queries and watchlists using child negation still showing hits with parents and with the negated child processes?
Answer
The watchlist only searches within a one-hour time window for the child process search condition to be met. This can result in what looks to be inaccurate hits when long-lived processes are searched on. The one-hour window and these search results also applies to long-lived processes and searching with multiple conditions.
Additional Notes