System Process Hashes in OCSF Evidence
New Release
AlphaSOC now adds running process file hashes to OCSF evidence, including MD5 and SHA-256 values where available. These fields can be accessed through AlphaSOC for Splunk and other means to perform investigation and threat hunting.