Layer: Endpoint
This documentation provides detailed information about all fields available for Endpoint Sensor.
Field Name | Type | Searchable | General Field | Description | Example | Products |
---|---|---|---|---|---|---|
act | dynamic | true | - | The actions taken to mitigate the event |
|
|
additionalInfo | string | true | - | The filter rule info | Default |
|
app | string | true | - | The layer-7 network protocol being exploited protocol | SMB | Endpoint Sensor |
authId | string | true | - | The authorization ID |
|
|
azId | string | true | - | The Avaliability Zone ID of the virtual machine that made the request |
|
Endpoint Sensor |
behaviorCat | string | true | - | The matched policy category |
|
|
channel | string | true | - | The Windows event channel |
|
|
cloudIdentityAccountId | string | true | - | The Cloud Identity account ID used for authorization | 111111111111 | Endpoint Sensor |
cloudIdentityId | string | true | - | The Cloud Identity ID used for authorization | arn:aws:sts::111111111111:assumed-role/eksctl-aws-test-nodegroup-ng-21d38-NodeInstanceRole-3wPxVEo4zHlK/i-01234567890abcdef | Endpoint Sensor |
cloudIdentityName | string | true | - | The Cloud Identity name used for authorization | AWSsampleToken | Endpoint Sensor |
cloudProvider | string | true | - | The service provider of the cloud asset |
|
|
cloudServiceApiName | string | true | - | The cloud service API |
|
Endpoint Sensor |
cloudServiceName | string | true | - | The cloud service |
|
Endpoint Sensor |
codeIntegrityOptionEnabled | bool | true | - | Whether the system enforced signed kernel loading according to DSE(driver signature enforcement) |
|
Endpoint Sensor |
codeIntegrityOptionTestsign | bool | true | - | Whether the system bypassed DSE(driver signature enforcement) checks and permitted loading of test-signed drivers |
|
Endpoint Sensor |
correlationData | dynamic | true | - | The data for correlation | - |
|
customAssetTags | dynamic | true | - | The list of custom asset tags | {"os":["linux", "windows"], "org":["bu1"]} |
|
customAssetTags | dynamic | true | - | The list of custom asset tags | {"os":["linux", "windows"], "org":["bu1"]} |
|
detectedBackupFolder | string | true | - | The folder path for detected backup folders | C:\\Program Files (x86)\\Trend Micro\\artifact\\DCE |
|
detectionAggregationId | string | true | - | The correlation key for detection logs and artifacts |
|
Endpoint Sensor |
detectionAggressivenessLevel | int | false | - | The detection aggressiveness level |
|
|
deviceGUID | string | true | - | The GUID of the agent which reported the detection |
|
|
deviceType | int | true | - | The disk drive type |
|
Endpoint Sensor |
dpt | int | true | Port | The destination port |
|
|
dpt | int | true | Port | The destination port number | - |
|
dst | dynamic | true |
|
The destination IP | 10.10.10.10 |
|
dst | string | true |
|
The destination IP address |
|
|
endpointGUID | string | true | EndpointID | The GUID of the agent which reported the detection |
|
|
endpointGuid | string | true | EndpointID | Host GUID of the endpoint on which the event was detected | 11111111-1111-1111-1111-111111111111 |
|
endpointHostName | string | true | EndpointName | The endpoint hostname or node where the event was detected |
|
|
endpointHostName | string | true | EndpointName | The host name of the endpoint on which the event was detected |
|
|
endpointIp | dynamic | true |
|
IP address of the endpoint on which the event was detected |
|
|
endpointMacAddress | dynamic | true | - | The host MAC address |
|
|
engineOperation | string | true | - | The operation of the engine event |
|
|
engVer | string | true | - | The engine version |
|
|
eventDataAccessList | string | true | - | The list of requested access rights |
|
|
eventDataAccessMask | string | true | - | The hexadecimal value of the requested or used permissions during an access attempt |
|
|
eventDataActionName | string | true | - | The action performed |
|
|
eventDataAuthenticationPackageName | string | true | - | The authentication package name of the Windows event data |
|
|
eventDataConsumer | string | true | - | The recipient of the reported event |
|
Endpoint Sensor |
eventDataElevatedToken | string | true | - | Whether the session is elevated and has administrator privileges |
|
|
eventDataFullyQualifiedAssemblyName | string | true | - | The fully qualified .NET assembly name |
|
|
eventDataImpersonationLevel | string | true | - | The sign-in session impersonation level |
|
|
eventDataIpAddress | string | true | - | The IP address for Windows event 4624 which is "An account was successfully logged on" |
|
|
eventDataLogonProcessName | string | true | - | The name of the Windows event sign in process name |
|
|
eventDataLogonType | string | true | - | The logon type for Windows event 4624 which is "An account was successfully logged on" |
|
|
eventDataModuleILPath | string | true | - | The CIL image path of the module or the dynamic module name |
|
|
eventDataObjectName | string | true | - | The identifying information about the object for which access was requested |
|
|
eventDataObjectType | string | true | - | The object type |
|
|
eventDataOperation | string | true | - | Windows event 11 |
|
|
eventDataPath | string | true | - | The path of the Windows event data |
|
|
eventDataProviderName | string | true | - | The name of the Windows event data provider |
|
Endpoint Sensor |
eventDataProviderPath | string | true | - | The file path of the Windows event data provider |
|
Endpoint Sensor |
eventDataServiceFileName | string | true | - | The full file path of the service executable file |
|
Endpoint Sensor |
eventDataServiceName | string | true | - | The service name |
|
Endpoint Sensor |
eventDataStatus | string | true | - | The Windows event data status |
|
|
eventDataSubjectUserName | string | true | - | The account name |
|
|
eventDataSubStatus | string | true | - | The Windows event data sub status |
|
|
eventDataTargetDomainName | string | true | - | The target sign-in account domain or computer name |
|
|
eventDataTargetName | string | true | - | The service, application, or network resource name |
|
|
eventDataTaskName | string | true | - | The task name logged by the Windows event |
|
|
eventDataTicketEncryptionType | string | true | - | The cryptographic suite used for the Kerberos TGS |
|
|
eventDataTicketOptions | string | true | - | The authentication request Kerberos ticket behavior and permissions flags |
|
|
eventDataUserContext | string | true | - | The user context of the Windows event data |
|
|
eventDataWorkstationName | string | true | - | The name of the computer used in the sign-in attempt |
|
|
eventHashId | string | true | - | The event hash ID |
|
|
eventId | string | true | - | The event ID from the logs of each product |
|
|
eventId | int | true | - | Event type | - |
|
eventMessage | string | true | - | The event message | [0x13bb4e2a0] activating connection: mach=true listener=false peer=false name=com.apple.airportd |
|
eventName | string | true | - | The event type |
|
|
eventSubId | int | true | - | The access type |
|
|
eventSubName | string | true | - | The event type sub-name |
|
|
eventTime | real | true | - | The time the agent detected the event | 1657781088000 |
|
firstSeen | real | false | - | The first time the event was seen | 1656355418449 |
|
hostName | string | true |
|
The domain name |
|
|
httpReferer | string | true | URL | The HTTP header referer |
|
|
importTable | dynamic | true | - | The imported table information | - | Endpoint Sensor |
importTableFileName | dynamic | true | - | The library file name which has imported functions |
|
Endpoint Sensor |
importTableFunctionName | dynamic | true | - | The imported function file name |
|
Endpoint Sensor |
instanceAccountId | string | true | - | The cloud account ID of the virtual machine that made the request | 111111111111 | Endpoint Sensor |
instanceId | string | true | - | The ID of the instance that indicates the meta-cloud or data center VM |
|
|
instanceId | string | true | - | The virtual machine instance ID on the cloud platform | i-01234567890abcdef |
|
instanceName | string | true | - | The virtual machine that made the request | ec2-123-124-0-12.us-west-2.compute.amazonaws.com | Endpoint Sensor |
integrityLevel | int | true | - | The integrity level of a process | 16384 | Endpoint Sensor |
integrityLevel | int | true | - | The integrity level of a process | - |
|
lastSeen | real | false | - | The last time the event was seen | 1656355418449 |
|
logKey | string | true | - | The unique key of the event |
|
|
logonUser | dynamic | true | UserAccount | The logon user name |
|
|
messageType | string | true | - | The message type | Default |
|
mpname | string | true | - | The management product name |
|
|
mpver | string | true | - | The product version |
|
|
nativeDeviceCharacteristics | int | false | - | Additional driver device information |
|
Endpoint Sensor |
nativeDeviceType | int | false | - | The underlying hardware type of the driver |
|
Endpoint Sensor |
nativeStorageDeviceBusType | int | false | - | The bus type to which the device is connected |
|
Endpoint Sensor |
networkInterfaceId | string | true | - | The network interface of the virtual machine that made the request | eni-01234567890abcdef | Endpoint Sensor |
objectActionResults | dynamic | true | - | The object process action results |
|
Endpoint Sensor |
objectActionReturnCodes | dynamic | true | - | The object process action return codes |
|
Endpoint Sensor |
objectActions | dynamic | true | - | The object process actions |
|
Endpoint Sensor |
objectApiHookNum | int | false | - | The API hook number of the object | 1 | Endpoint Sensor |
objectApiName | string | true | - | The API name | GetIpNetTable | Endpoint Sensor |
objectApiName | string | true | - | The name of the executed API | GetIpNetTable | Endpoint Sensor |
objectApiRvInNum | string | true | - | The API telemetry return value | 0 | Endpoint Sensor |
objectAppName | string | true | - | Name of the app involved in the AMSI event |
|
|
objectArtifactIds | dynamic | true | - | The artifact IDs generated by objectAction |
|
|
objectAuthId | string | true | - | The object authorization ID |
|
|
objectBmData | string | true | - | The data of BM event |
|
|
objectCmd | dynamic | true | CLICommand | The object process command line |
|
|
objectCmd | string | true | CLICommand | Command line entry of target process |
|
|
objectContentName | string | true | - | The AMSI object content name |
|
|
objectCreateDispositions | int | false | - | The disposition of CreateFile | - | Endpoint Sensor |
objectCurrentFileSize | long | true | - | Previous size of modified object file |
|
|
objectDesiredAccess | int | false | - | The desired access of the event | - | Endpoint Sensor |
objectFileAttributes | int | false | - | The new file attributes |
|
Endpoint Sensor |
objectFileAttributesHashId | string | true | - | The hash ID of the file attribute meta information |
|
Endpoint Sensor |
objectFileCreation | string | true | - | The time the object file was created |
|
|
objectFileCurrentAttributes | int | false | - | The original file attributes |
|
Endpoint Sensor |
objectFileCurrentOwnerName | string | true | - | The current owner name of the object file |
|
|
objectFileCurrentOwnerSid | string | true | - | The current security identifier owner of the object file |
|
|
objectFileDaclString | string | true | - | The discretionary access control list of the object file |
|
|
objectFileExtendedAttribute | string | true | - | The extended attributes of the file |
|
|
objectFileGroupName | string | true | - | The object file user group name |
|
|
objectFileGroupSid | string | true | - | The security identifier of the object file group |
|
|
objectFileHashId | string | true | - | The object file hash ID |
|
|
objectFileHashMd5 | string | true | FileMD5 | The MD5 of the object |
|
|
objectFileHashMd5 | string | true | FileMD5 | The md5 hash of target process image or target file |
|
|
objectFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the objectFilePath object |
|
|
objectFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of target process image or target file |
|
|
objectFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the object (objectFilePath) |
|
|
objectFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of target process image or target file |
|
|
objectFileIsRemoteAccess | bool | true | - | The remote access to the object file | - |
|
objectFileModifiedTime | string | true | - | The time the object file was modified |
|
|
objectFileOriginalName | string | true | FileName | The original file name of the object image |
|
|
objectFileOwnerName | string | true | - | The object file owner name |
|
|
objectFileOwnerSid | string | true | - | The security identifier of the object file owner |
|
|
objectFilePath | string | true | FileFullPath | The file path of the target process image or target file |
|
|
objectFilePath | string | true |
|
The file path of the target process image or target file |
|
|
objectFileRemoteAccess | bool | true | - | The remote access for the object file | - |
|
objectFileSaclString | string | true | - | The system access control list of the object file |
|
|
objectFileSize | string | true | - | The file size of the object file |
|
|
objectFirstSeen | string | true | - | The first time the object was seen |
|
|
objectHashId | long | false | - | The object hash ID |
|
|
objectHostName | string | true | DomainName | Server name where Internet event was detected |
|
|
objectIntegrityLevel | int | true | - | Integrity level of target process | - |
|
objectIp | string | true |
|
IP address of internet event | 10.10.10.10 |
|
objectIps | dynamic | true |
|
IP address list of internet event |
|
|
objectLastSeen | string | true | - | The last time the object was seen |
|
|
objectLaunchTime | string | true | - | The object launch time of the Windows event |
|
|
objectLoginOutFailureMessage | string | true | - | The sign-in/sign-out error message | Login incorrect |
|
objectLoginOutFirstSeen | long | true | - | The first time the object sign-in/sign-out was seen | 1713903612 |
|
objectLoginOutHashId | long | true | - | The FNV of the object sign-in/sign-out meta | -8981232070268295229 |
|
objectLoginOutLastSeen | long | true | - | The last time the object sign-in/sign-out was seen | 1713903612 |
|
objectLoginOutMetaType | int | true | - | The sign-in/sign-out meta | 1 - LOGIN_OUT_META_TYPE_OPENSSH |
|
objectLoginOutSessionId | long | true | - | The sign-in/sign-out session ID | 260 |
|
objectLoginOutSourceAddress | string | true | - | The sign-in/sign-out source IP | 10.10.10.10 |
|
objectLoginOutStatus | int | true | - | The sign-in/sign-out status | -1 |
|
objectName | string | true | - | The base name of the object file or process | net.exe |
|
objectName | string | true | - | The object name |
|
|
objectPid | int | false | - | The object process PID |
|
|
objectPid | int | true | - | The PID of target process | - |
|
objectPipeName | string | true | - | The object pipe name | \\.\pipe\F451F406BD | Endpoint Sensor |
objectPipeName | string | true | - | The named pipe of the event |
|
Endpoint Sensor |
objectPort | int | true | Port | The port number used by internet event | - |
|
objectProcessHashId | long | true | - | FNV of target process |
|
|
objectRawDataSize | dynamic | true | - | The raw data size of the Windows event object |
|
|
objectRawDataStr | dynamic | true | - | The data contents of the AMSI event |
|
|
objectRegistryData | string | true | RegistryValueData | The registry data contents | C:\Program Files\AlertMedia\AlertMedia Desktop Notifications\AlertMedia.exe |
|
objectRegistryData | string | true | RegistryValueData | The registry value data |
|
|
objectRegistryKeyHandle | string | true | RegistryKey | The registry key path |
|
|
objectRegistryKeyHandle | string | true | RegistryKey | The registry key |
|
|
objectRegistryRoot | string | true | - | The name of the object registry root key |
|
|
objectRegistryRoot | int | false | - | The Windows Registry Root ID |
|
|
objectRegistryValue | string | true | RegistryValue | The registry value name |
|
|
objectRegistryValue | string | true | RegistryValue | Registry value name |
|
|
objectRegType | int | false | - | The registry value type | - | Endpoint Sensor |
objectRegType | int | false | - | The Windows Registry Type ID |
|
|
objectRunAsLocalAccount | bool | true | - | The "runas" command uses a local account |
|
|
objectSessionId | string | true | - | The object session ID |
|
|
objectSigner | dynamic | true | - | The list of object process signers |
|
|
objectSigner | dynamic | true | - | Certificate signer of object process or file |
|
|
objectSignerFlagsAdhoc | dynamic | true | - | The list of object process signature adhoc flags | - |
|
objectSignerFlagsAdhoc | dynamic | true | - | The list of object process or file signature adhoc flags | - |
|
objectSignerFlagsLibValid | dynamic | true | - | The list of object process signature library validation flags | - |
|
objectSignerFlagsLibValid | dynamic | true | - | The list of object process or file signature library validation flags | - |
|
objectSignerFlagsRuntime | dynamic | true | - | The list of object process signature runtime flags | - |
|
objectSignerFlagsRuntime | dynamic | true | - | The list of object process or file signature runtime flags | - |
|
objectSignerValid | dynamic | true | - | Whether each signer of the object process is valid | - | Endpoint Sensor |
objectSignerValid | dynamic | true | - | Validity of certificate signer |
|
|
objectSubTrueType | int | true | - | File object's true sub-type |
|
|
objectTrueType | int | true | - | File object's true major type |
|
|
objectType | string | true | - | The object type |
|
|
objectUser | string | true | UserAccount | The owner name of the target process or the login user name |
|
|
objectUserDomain | string | false | - | The object user domain |
|
|
objectUserGroup | string | true | - | The user group name |
|
|
objectUserGroupSids | dynamic | true | - | The user group SIDs of the object |
|
Endpoint Sensor |
osDescription | string | true | - | The OS version |
|
|
osName | string | true | - | The host operating system name |
|
|
osType | string | true | - | The host operating system type |
|
|
osVer | string | true | - | The version of the host operating system |
|
|
parentAuthId | string | true | - | The parent authorization ID |
|
|
parentCmd | string | true | CLICommand | The command line of the subject parent process |
|
|
parentCmd | string | true | CLICommand | The command line entry of the parent process |
|
|
parentFileCreation | string | true | - | The time the parent file was created |
|
|
parentFileCurrentOwnerName | string | true | - | The current owner name of the parent file |
|
|
parentFileCurrentOwnerSid | string | true | - | The current security identifier owner of the parent file |
|
|
parentFileDaclString | string | true | - | The discretionary access control list of the parent file |
|
|
parentFileGroupName | string | true | - | The name of the parent file user group |
|
|
parentFileGroupSid | string | true | - | The security identifier of the parent process file group |
|
|
parentFileHashId | long | true | - | The parent file hash ID |
|
|
parentFileHashMd5 | string | true | FileMD5 | The MD5 of the subject parent process |
|
Endpoint Sensor |
parentFileHashMd5 | string | true | FileMD5 | The md5 hash of parent process |
|
|
parentFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the subject parent process |
|
Endpoint Sensor |
parentFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of parent process |
|
|
parentFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the subject parent process |
|
|
parentFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of parent process |
|
|
parentFileModifiedTime | string | true | - | The time the parent file was modified |
|
|
parentFileOriginalName | string | true | FileName | The original file name of the parent image |
|
|
parentFileOwnerName | string | true | - | The owner name of the parent file |
|
|
parentFileOwnerSid | string | true | - | The security identifier of the parent file owner |
|
|
parentFilePath | string | true | FileFullPath | The full file path of the parent process |
|
Endpoint Sensor |
parentFilePath | string | true |
|
The file path of the parent process |
|
|
parentFileRemoteAccess | bool | true | - | The remote access to the parent file | - |
|
parentFileSaclString | string | true | - | The system access control list of the parent file |
|
|
parentFileSize | string | true | - | The file size of the parent file |
|
|
parentHashId | string | true | - | The FNV of the parent process |
|
Endpoint Sensor |
parentHashId | long | true | - | The parent hash ID |
|
|
parentIntegrityLevel | int | true | - | The integrity level of a parent | 16384 | Endpoint Sensor |
parentIntegrityLevel | int | true | - | The integrity level of a parent | - |
|
parentLaunchTime | real | true | - | The time when the parent process was launched |
|
|
parentName | string | true | - | The image name of the parent process |
|
|
parentName | string | true | - | The image name of the parent process |
|
|
parentPayloadSigner | dynamic | true | - | The signer name list of the parent process payload |
|
Endpoint Sensor |
parentPayloadSignerFlagsAdhoc | dynamic | true | - | The list of parent process payload signature adhoc flags | - | Endpoint Sensor |
parentPayloadSignerFlagsLibValid | dynamic | true | - | The list of parent process payload signature library validation flags | - | Endpoint Sensor |
parentPayloadSignerFlagsRuntime | dynamic | true | - | The list of parent process payload signature runtime flags | - | Endpoint Sensor |
parentPayloadSignerValid | dynamic | true | - | Whether each signer of the parent process payload is valid | - | Endpoint Sensor |
parentPid | int | true | - | The PID of the parent process | - |
|
parentPid | int | true | - | The PID of the parent process |
|
|
parentSessionId | int | false | - | The parent session ID | - |
|
parentSigner | dynamic | true | - | The signers of the parent process |
|
Endpoint Sensor |
parentSigner | dynamic | true | - | The signer of the parent file |
|
|
parentSignerFlagsAdhoc | dynamic | true | - | The list of parent process signature adhoc flags | - |
|
parentSignerFlagsAdhoc | dynamic | true | - | The list of parent process signature adhoc flags | - |
|
parentSignerFlagsLibValid | dynamic | true | - | The list of parent process signature library validation flags | - |
|
parentSignerFlagsLibValid | dynamic | true | - | The list of parent process signature library validation flags | - |
|
parentSignerFlagsRuntime | dynamic | true | - | The list of parent process signature runtime flags | - |
|
parentSignerFlagsRuntime | dynamic | true | - | The list of parent process signature runtime flags | - |
|
parentSignerValid | dynamic | true | - | Whether each signer of the parent process is valid | - | Endpoint Sensor |
parentSignerValid | dynamic | true | - | The validity of the parent signer | - |
|
parentSubTrueType | int | true | - | The true file subtype of the parent file | - |
|
parentTrueType | int | true | - | The true file type of the parent file | - |
|
parentUser | string | true | - | The type of user that executed the parent process |
|
|
parentUserDomain | string | true | - | The user domain of the parent process |
|
|
parentUserGroupSids | dynamic | true | - | The SIDs of the parent user group |
|
Endpoint Sensor |
patVer | string | true | - | The version of the behavior pattern |
|
|
plang | int | false | - | The product language |
|
|
platformAssetTags | dynamic | true | - | The list of platform custom asset tags | {"Asset group":["finance"], "some.ip": ["10.1.0.1"]} |
|
platformAssetTags | dynamic | true | - | The list of platform custom asset tags | {"Asset group":["finance"], "some.ip": ["10.1.0.1"]} |
|
pname | string | true | - | The internal product ID |
|
|
pname | string | true | - | Internal product ID (Deprecated, use productCode) |
|
|
policyId | string | true | - | The policy ID of which the event was detected |
|
|
pplat | int | false | - | The product platform |
|
|
processActionResults | dynamic | true | - | The process action results |
|
Endpoint Sensor |
processActionReturnCodes | dynamic | true | - | The process action return codes |
|
Endpoint Sensor |
processActions | dynamic | true | - | The process actions |
|
Endpoint Sensor |
processArtifactIds | dynamic | true | - | The artifact IDs generated by processAction |
|
|
processCmd | string | true | CLICommand | The subject process command line |
|
|
processCmd | string | true | CLICommand | The command line entry of the subject process |
|
|
processFileCreation | string | true | - | The time the process file was created |
|
|
processFileCurrentOwnerName | string | true | - | The current owner name of the process file |
|
|
processFileCurrentOwnerSid | string | true | - | The owner of the process file current security identifier |
|
|
processFileDaclString | string | true | - | The discretionary access control list of the process file |
|
|
processFileGroupName | string | true | - | The name of the process file user group |
|
|
processFileGroupSid | string | true | - | The security identifier of the process file group |
|
|
processFileHashId | long | true | - | The file hash of the process |
|
|
processFileHashMd5 | string | true | FileMD5 | The MD5 of the subject process |
|
|
processFileHashMd5 | string | true | FileMD5 | The MD5 hash of the subject process image |
|
|
processFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the subject process |
|
|
processFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of subject process image |
|
|
processFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the subject process |
|
|
processFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of subject process image |
|
|
processFileModifiedTime | string | true | - | The time the process file was modified |
|
|
processFileOriginalName | string | true | FileName | The original file name of the process image |
|
|
processFileOwnerName | string | true | - | The process file owner name |
|
|
processFileOwnerSid | string | true | - | The security identifier of the process file owner |
|
|
processFilePath | string | true |
|
The file path of the subject process |
|
|
processFilePath | string | true |
|
The file path of the subject process |
|
|
processFileRemoteAccess | bool | true | - | The remote access to the process file | - |
|
processFileSaclString | string | true | - | The system access control list of the process file |
|
|
processFileSize | string | true | - | The file size of the process file |
|
|
processHashId | string | true | - | The FNV of the subject process |
|
Endpoint Sensor |
processHashId | long | true | - | The FNV of subject process |
|
|
processImagePath | string | true | - | The process triggered by the file event |
|
|
processLaunchTime | real | true | - | The time the subject process was launched |
|
|
processName | string | true | ProcessName | The image name of the process that triggered the event |
|
|
processName | string | true | ProcessName | The image name of the process that triggered the event |
|
|
processPayloadSigner | dynamic | true | - | The signer name list of the process payload |
|
Endpoint Sensor |
processPayloadSignerFlagsAdhoc | dynamic | true | - | The list of process payload signature adhoc flags | - | Endpoint Sensor |
processPayloadSignerFlagsLibValid | dynamic | true | - | The list of process payload signature library validation flags | - | Endpoint Sensor |
processPayloadSignerFlagsRuntime | dynamic | true | - | The list of process payload signature runtime flags | - | Endpoint Sensor |
processPayloadSignerValid | dynamic | true | - | Whether each signer of the process payload is valid | - | Endpoint Sensor |
processPid | int | true | - | The PID of the subject process | - |
|
processPid | int | true | - | The PID of the subject process |
|
|
processPkgName | string | true | - | The process package name |
|
Endpoint Sensor |
processSigner | dynamic | true | - | The signer name list of the subject process |
|
|
processSigner | dynamic | true | - | The process file signer |
|
|
processSignerFlagsAdhoc | dynamic | true | - | The list of process signature adhoc flags | - |
|
processSignerFlagsAdhoc | dynamic | true | - | The list of process signature adhoc flags | - |
|
processSignerFlagsLibValid | dynamic | true | - | The list of process signature library validation flags | - |
|
processSignerFlagsLibValid | dynamic | true | - | The list of process signature library validation flags | - |
|
processSignerFlagsRuntime | dynamic | true | - | The list of process signature runtime flags | - |
|
processSignerFlagsRuntime | dynamic | true | - | The list of process signature runtime flags | - |
|
processSignerValid | dynamic | true | - | The validity of the process signer |
|
|
processStackTrace | string | true | - | The process stack trace of the telemetry event | C:\Windows\System32\ntdll.dll?NtCreateUserProcess|ZwCreateUserProcess, C:\Windows\System32\kernelbase.dll!CreateProcessInternalW | Endpoint Sensor |
processSubTrueType | int | true | - | The true file subtype of the process | - |
|
processTrueType | int | true | - | The true file type of the process | - |
|
processUser | string | true | UserAccount | The owner name of subject process image |
|
|
processUserDomain | string | true | - | The process user domain |
|
|
processUserGroupSids | dynamic | true | - | The user group SIDs of the process |
|
Endpoint Sensor |
proto | int | false | - | The protocol type |
|
|
providerGUID | string | true | - | The GUID of the Windows event provider | {11111111-1111-1111-1111-111111111111} |
|
providerName | string | true | - | The name of the Windows event provider |
|
|
proxy | string | true | - | The proxy address |
|
|
publicSpt | int | true | Port | The public port of the endpoint making the request | 57163 | Endpoint Sensor |
publicSrc | string | true |
|
The public ip of the endpoint making the request | 10.10.10.10 | Endpoint Sensor |
pver | string | true | - | The product version |
|
|
rawDataSize | string | true | - | The size of the Windows event log |
|
|
rawDataStr | string | true | - | Windows event raw contents |
|
|
regionId | string | true | - | The cloud asset region |
|
|
request | string | true | URL | Request URL |
|
|
requestMethod | string | true | - | The network protocol request method |
|
|
riskLevel | string | true | - | The risk level |
|
|
rt | string | false | - | The Unix time of the log generation | 1656324260000 |
|
rt | string | false | - | The event time | 1657781088000 |
|
ruleId | int | true | - | The rule ID | 1005566 |
|
ruleName | string | true | - | The name of the rule that triggered the event |
|
|
sessionId | int | false | - | The session ID |
|
|
smbSharedName | string | true | - | The shared folder name for the server that contains the files to be opened | C:\sharedfolder | Endpoint Sensor |
smbSharedName | string | true | - | The shared folder name for the server that contains the files | sharedfolder | Endpoint Sensor |
sourceType | string | true | - | The source type |
|
|
spt | int | true | Port | The source port |
|
|
spt | int | true | Port | The source port number |
|
|
src | dynamic | true |
|
The source IP | 10.10.10.10 |
|
src | string | true |
|
The source address |
|
|
srcFileCreation | string | true | - | The time the source file was created |
|
|
srcFileCurrentOwnerName | string | true | - | The current owner name of the source file |
|
|
srcFileCurrentOwnerSid | string | true | - | The current security identifier owner of the source file |
|
|
srcFileDaclString | string | true | - | The discretionary access control list of the source file |
|
|
srcFileGroupName | string | true | - | The source file user group name |
|
|
srcFileGroupSid | string | true | - | The security identifier of the source file group |
|
|
srcFileHashId | long | false | - | The source file hash ID |
|
|
srcFileHashMd5 | string | true | FileMD5 | The md5 hash of source file |
|
|
srcFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of source file |
|
|
srcFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of source file |
|
|
srcFileIsRemoteAccess | bool | true | - | The remote access of the source file | - |
|
srcFileModifiedTime | string | true | - | The time the source file was modified |
|
|
srcFileOwnerName | string | true | - | The source file owner name |
|
|
srcFileOwnerSid | string | true | - | The security identifier of the source file owner |
|
|
srcFilePath | string | true |
|
The source file path |
|
|
srcFileSaclString | string | true | - | The system access control list of the source file |
|
|
srcFileSize | string | true | - | The file size of the source file |
|
|
srcFirstSeen | string | true | - | The first time the source file was seen |
|
|
srcHashId | long | false | - | The source hash ID |
|
|
srcLastSeen | string | true | - | The last time the source file was seen |
|
|
srcSigner | dynamic | true | - | The signer of the source file |
|
|
srcSignerFlagsAdhoc | dynamic | true | - | The list of source file signature adhoc flags | - |
|
srcSignerFlagsLibValid | dynamic | true | - | The list of source file signature library validation flags | - |
|
srcSignerFlagsRuntime | dynamic | true | - | The list of source file signature runtime flags | - |
|
srcSignerValid | dynamic | true | - | The validity of the source file signer | - |
|
srcSubTrueType | int | false | - | The true file subtype of the source file | - |
|
srcTrueType | int | false | - | The true file type of the source file | - |
|
status | string | true | - | The HTTP response status code |
|
|
subnetId | string | true | - | The subnet ID of the virtual machine that made the request | subnet-01234567890abcdef | Endpoint Sensor |
subSystem | string | true | - | The sub system information | com.apple.xpc |
|
suspiciousObject | string | true | - | The matched suspicious object | 36ba9de3da9e6f8abfffdda7787ab0ecc16724bb | Endpoint Sensor |
suspiciousObjectType | string | true | - | The matched suspicious object type | sha1 | Endpoint Sensor |
tacticId | dynamic | true | Tactic | The list of MITRE tactic IDs |
|
|
timezone | string | true | - | The host time zone |
|
|
triggerReason | string | true | - | The cause of the triggered action |
|
|
userDomain | dynamic | true | - | The user domain name |
|
|
vpcId | string | true | - | The virtual private cloud that contains the cloud asset | vpc-01234567890abcdef |
|
winEventId | int | true | - | Event ID of Windows event |
|
|
Generated by XDR Common Schema Public Doc Generator V2