The System
process responsible for most kernel-mode threads. Modules run
under System are primarily drivers (.sys
files), but also include several
important DLLs as well as the kernel executable, ntoskrnl.exe
Executable’s image path.
N/A for system.exe - Not generated from an executable image
A process which spawned the analyzed process.
None
Expected number of processes running which may normally run on Windows.
One
Windows account with which the process was launched. This defines what privileges given process has.
Local System
Expected time of process to be launched.
At boot time