We have several monitoring / IPS solutions that help us keep our network safe. We had an occurrence of a user infecting a workstation and triggering several alarms. After narrowing down the infection list and researching their patterns, we had a list of running processes the infection creates.
It would be handy to enter a list of running processes and check against running hosts to verify they were not running.
EDIT: Also might be handy to have a ‘search for existing file’. Kinda of a bulky feature / function, I admit.