Skip to content

Commit 3892237

Browse files
authored
Update getting-started-linux-tutorial.rst : Rearrange linux.pstree plugin description
Moved plugin output example above the feature explanation for better flow and clarity. Simplified the description while retaining key points about process hierarchy and anomaly detection.
1 parent 0f33734 commit 3892237

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

doc/source/getting-started-linux-tutorial.rst

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -133,9 +133,7 @@ This detailed view allows investigators to correlate user privileges, startup ti
133133

134134
linux.pstree
135135
~~~~~~~~~~~~
136-
137-
This plugin presents the process hierarchy as a tree, clearly showing parent-child relationships between processes.
138-
It is especially useful for identifying unusual or suspicious process structures, such as orphaned child processes, injected children under legitimate parents, or long chains of shell execution.
136+
This plugin presents the process hierarchy as a tree, clearly showing parent-child relationships between processes.
139137

140138
.. code-block:: shell-session
141139
@@ -155,7 +153,10 @@ It is especially useful for identifying unusual or suspicious process structures
155153
**** 0x8ca671210000 1608 1608 1507 gnome-session-b
156154
***** 0x8ca66fba42c0 1765 1765 1608 ssh-agent
157155
158-
The tree view can help identify anomalies in process launch sequences or privilege escalations by inspecting unexpected parent-child relationships.
156+
157+
It helps identify unusual or suspicious process structures such as orphaned child processes, injected children under legitimate parents, or long chains of shell execution.
158+
The tree view is particularly useful for spotting anomalies in process launch sequences or privilege escalations by inspecting unexpected parent-child relationships.
159+
159160

160161

161162
linux.bash

0 commit comments

Comments
 (0)