Skip to content

Parse SRUM Network Usage

Evidence: Parse SRUM Network Usage
Description: Parse System Resource Usage Monitor (SRUM) Network Data Usage.
Category:
Platform: windows
Short Name: srumnetparse
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): No

This collector gathers structured data about parse srum network usage.

FieldDescriptionExample
AutoIncIdAuto-increment ID from SRUM database123
TimestampTimestamp2023-10-15 14:30:25
ApplicationNameApplication NameExample Name
UserSidWindows SID in S-1-5-… format (from SRUM IdMapTable)S-1-5-21-…
UserNameResolved username via Windows API (LookupAccountSidW)Example Name
InterfaceLuidLUID identifier123
L2ProfileIdL2 Profile Id123
L2ProfileFlagsL2 Profile Flags123
BytesSentBytes Sent1024
BytesRecvdBytes Recvd1024