The Get Running Processes capability retrieves a list of running processes on a configuration item (CI) from a host or endpoint. This capability is used for incident enrichment during investigations.

Note: If no implementations are available, capability actions are not displayed in product menus.

Activities specific to this workflow are described here. For more information on other activities, see Common Security Operations integration flows and orchestration Flow Actions.