What is stacking?
Stacking is just another name for grouping like objects together and counting the amount of each like object. Very useful for finding anomalies. Also the larger the environment the more useful it is. One process that is only running on 1 machine out of 10,000 is weird.
Here is how to do it in a Velociraptor notebook.
Click column header and double triangle button.
Click hamburger stack.
Sort count column and look for weirdness.
Find process you want to analyze. I chose cmd.exe.
Hope this was useful!
Consider subscribing or becoming a paid subscriber if you would like more educational posts like this!
Happy hunting,
Marcus