Skip to content

Collect SRUM Database Files

Evidence: Collect SRUM Database Files
Description: Collect System Resource Usage Monitor (SRUM) database files.
Category:
Platform: windows
Short Name: srumcol
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): No

This collector gathers structured data about collect srum database files.

FieldDescriptionExample
PathFull path to SRUM fileC:\Windows\System32\file.ext
CreationTimeFile creation timestamp2023-10-15 14:30:25
AccessTimeFile last access timestamp2023-10-15 14:30:25
WriteTimeFile last write timestamp2023-10-15 14:30:25
SizeFile size in bytes1024
CollectionMethodFile access method used (OS/NTFS)Example value
CollectionTimeWhen this file was collected2023-10-15 14:30:25