Struct ProcessCreateEventData

Source
pub struct ProcessCreateEventData {
Show 16 fields pub utc_time: UtcTime, pub process_guid: ProcessGuid, pub process_id: u64, pub image: Image, pub command_line: CommandLine, pub current_directory: CurrentDirectory, pub user: User, pub logon_guid: LogonGuid, pub logon_id: LogonId, pub terminal_session_id: TerminalSessionId, pub integrity_level: IntegrityLevel, pub hashes: Hashes, pub parent_process_guid: ProcessGuid, pub parent_process_id: u64, pub parent_image: Image, pub parent_command_line: CommandLine,
}

Fields§

§utc_time: UtcTime

2017-04-28 22:08:22.025

§process_guid: ProcessGuid

{A23EAE89-BD56-5903-0000-0010E9D95E00}

§process_id: u64

6228

§image: Image

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

§command_line: CommandLine

“C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” –type=utility –lang=en-US –no-sandbox –service-request-channel-token=F47498BBA884E523FA93E623C4569B94 –mojo-platform-channel-handle=3432 /prefetch:8

§current_directory: CurrentDirectory

C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81</Data>

§user: User

LAB\rsmith

§logon_guid: LogonGuid

{A23EAE89-B357-5903-0000-002005EB0700}

§logon_id: LogonId

0x7eb05

§terminal_session_id: TerminalSessionId

1

§integrity_level: IntegrityLevel

Medium

§hashes: Hashes

SHA256=6055A20CF7EC81843310AD37700FF67B2CF8CDE3DCE68D54BA42934177C10B57

§parent_process_guid: ProcessGuid

{A23EAE89-BD28-5903-0000-00102F345D00}

§parent_process_id: u64

13220

§parent_image: Image

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

§parent_command_line: CommandLine

“C:\Program Files (x86)\Google\Chrome\Application\chrome.exe”

Trait Implementations§

Source§

impl Clone for ProcessCreateEventData

Source§

fn clone(&self) -> ProcessCreateEventData

Returns a copy of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ProcessCreateEventData

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for ProcessCreateEventData

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Hash for ProcessCreateEventData

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl TryFrom<IntermediaryEventData> for ProcessCreateEventData

Source§

type Error = Error

The type returned in the event of a conversion error.
Source§

fn try_from(inter: IntermediaryEventData) -> Result<Self>

Performs the conversion.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,