The behavior lab is on the process pages.
Every process record now carries what the EchoTrail lab observes when it installs and runs the software on current Windows builds: command lines, DLL loads, network and DNS, registry and file writes, persistence, signer, and hashes, merged into the same tables as the endpoint telemetry with a source on every row. The lab runs continuously and every API miss is queued for it. Free pages and the free API tier carry the lab summary; the full lab record is on Team and above. The published page count and the size figures across the site are now rounded floors that move up as the lab adds records.
Read more →