Layer: Endpoint
This documentation provides detailed information about all fields available for Endpoint Sensor.
| Field Name | Type | Searchable | General Field | Description | Example | Products |
|---|---|---|---|---|---|---|
| act | dynamic | true | - | The actions taken to mitigate the event |
|
|
| additionalInfo | string | true | - | The filter rule info | Default |
|
| app | string | true | - | The layer-7 network protocol being exploited protocol | SMB | Endpoint Sensor |
| authId | string | true | - | The authorization ID |
|
|
| azId | string | true | - | The Avaliability Zone ID of the virtual machine that made the request |
|
Endpoint Sensor |
| behaviorCat | string | true | - | The matched policy category |
|
|
| channel | string | true | - | The Windows event channel |
|
|
| cloudIdentityAccountId | string | true | - | The Cloud Identity account ID used for authorization | 111111111111 | Endpoint Sensor |
| cloudIdentityId | string | true | - | The Cloud Identity ID used for authorization | arn:aws:sts::111111111111:assumed-role/eksctl-aws-test-nodegroup-ng-21d38-NodeInstanceRole-3wPxVEo4zHlK/i-01234567890abcdef | Endpoint Sensor |
| cloudIdentityName | string | true | - | The Cloud Identity name used for authorization | AWSsampleToken | Endpoint Sensor |
| cloudProvider | string | true | - | The service provider of the cloud asset |
|
|
| cloudServiceApiName | string | true | - | The cloud service API |
|
Endpoint Sensor |
| cloudServiceName | string | true | - | The cloud service |
|
Endpoint Sensor |
| codeIntegrityOptionEnabled | bool | true | - | Whether the system enforced signed kernel loading according to DSE(driver signature enforcement) |
|
Endpoint Sensor |
| codeIntegrityOptionTestsign | bool | true | - | Whether the system bypassed DSE(driver signature enforcement) checks and permitted loading of test-signed drivers |
|
Endpoint Sensor |
| correlationData | dynamic | true | - | The data for correlation | - |
|
| customAssetTags | dynamic | true | - | The list of custom asset tags | {"os":["linux", "windows"], "org":["bu1"]} |
|
| customAssetTags | dynamic | true | - | The list of custom asset tags | {"os":["linux", "windows"], "org":["bu1"]} |
|
| detectedBackupFolder | string | true | - | The folder path for detected backup folders | C:\\Program Files (x86)\\Trend Micro\\artifact\\DCE |
|
| detectionAggregationId | string | true | - | The correlation key for detection logs and artifacts |
|
Endpoint Sensor |
| detectionAggressivenessLevel | int | false | - | The detection aggressiveness level |
|
|
| deviceGUID | string | true | - | The GUID of the agent which reported the detection |
|
|
| deviceType | int | true | - | The disk drive type |
|
Endpoint Sensor |
| dpt | int | true | Port | The destination port |
|
|
| dpt | int | true | Port | The destination port number | - |
|
| dst | dynamic | true |
|
The destination IP | 10.10.10.10 |
|
| dst | string | true |
|
The destination IP address |
|
|
| endpointGUID | string | true | EndpointID | The GUID of the agent which reported the detection |
|
|
| endpointGuid | string | true | EndpointID | Host GUID of the endpoint on which the event was detected | 11111111-1111-1111-1111-111111111111 |
|
| endpointHostName | string | true | EndpointName | The endpoint hostname or node where the event was detected |
|
|
| endpointHostName | string | true | EndpointName | The host name of the endpoint on which the event was detected |
|
|
| endpointIp | dynamic | true |
|
IP address of the endpoint on which the event was detected |
|
|
| endpointMacAddress | dynamic | true | - | The host MAC address |
|
|
| engineOperation | string | true | - | The operation of the engine event |
|
|
| engVer | string | true | - | The engine version |
|
|
| eventDataAccessList | string | true | - | The list of requested access rights |
|
|
| eventDataAccessMask | string | true | - | The hexadecimal value of the requested or used permissions during an access attempt |
|
|
| eventDataActionName | string | true | - | The action performed |
|
|
| eventDataAuthenticationPackageName | string | true | - | The authentication package name of the Windows event data |
|
|
| eventDataConsumer | string | true | - | The recipient of the reported event |
|
Endpoint Sensor |
| eventDataElevatedToken | string | true | - | Whether the session is elevated and has administrator privileges |
|
|
| eventDataFullyQualifiedAssemblyName | string | true | - | The fully qualified .NET assembly name |
|
|
| eventDataImpersonationLevel | string | true | - | The sign-in session impersonation level |
|
|
| eventDataIpAddress | string | true | - | The IP address for Windows event 4624 which is "An account was successfully logged on" |
|
|
| eventDataLogonProcessName | string | true | - | The name of the Windows event sign in process name |
|
|
| eventDataLogonType | string | true | - | The logon type for Windows event 4624 which is "An account was successfully logged on" |
|
|
| eventDataModuleILPath | string | true | - | The CIL image path of the module or the dynamic module name |
|
|
| eventDataObjectName | string | true | - | The identifying information about the object for which access was requested |
|
|
| eventDataObjectType | string | true | - | The object type |
|
|
| eventDataOperation | string | true | - | Windows event 11 |
|
|
| eventDataPath | string | true | - | The path of the Windows event data |
|
|
| eventDataProviderName | string | true | - | The name of the Windows event data provider |
|
Endpoint Sensor |
| eventDataProviderPath | string | true | - | The file path of the Windows event data provider |
|
Endpoint Sensor |
| eventDataServiceFileName | string | true | - | The full file path of the service executable file |
|
Endpoint Sensor |
| eventDataServiceName | string | true | - | The service name |
|
Endpoint Sensor |
| eventDataStatus | string | true | - | The Windows event data status |
|
|
| eventDataSubjectUserName | string | true | - | The account name |
|
|
| eventDataSubStatus | string | true | - | The Windows event data sub status |
|
|
| eventDataTargetDomainName | string | true | - | The target sign-in account domain or computer name |
|
|
| eventDataTargetName | string | true | - | The service, application, or network resource name |
|
|
| eventDataTaskName | string | true | - | The task name logged by the Windows event |
|
|
| eventDataTicketEncryptionType | string | true | - | The cryptographic suite used for the Kerberos TGS |
|
|
| eventDataTicketOptions | string | true | - | The authentication request Kerberos ticket behavior and permissions flags |
|
|
| eventDataUserContext | string | true | - | The user context of the Windows event data |
|
|
| eventDataWorkstationName | string | true | - | The name of the computer used in the sign-in attempt |
|
|
| eventHashId | string | true | - | The event hash ID |
|
|
| eventId | string | true | - | The event ID from the logs of each product |
|
|
| eventId | int | true | - | Event type | - |
|
| eventMessage | string | true | - | The event message | [0x13bb4e2a0] activating connection: mach=true listener=false peer=false name=com.apple.airportd |
|
| eventName | string | true | - | The event type |
|
|
| eventSubId | int | true | - | The access type |
|
|
| eventSubName | string | true | - | The event type sub-name |
|
|
| eventTime | real | true | - | The time the agent detected the event | 1657781088000 |
|
| firstSeen | real | false | - | The first time the event was seen | 1656355418449 |
|
| hostName | string | true |
|
The domain name |
|
|
| httpReferer | string | true | URL | The HTTP header referer |
|
|
| importTable | dynamic | true | - | The imported table information | - | Endpoint Sensor |
| importTableFileName | dynamic | true | - | The library file name which has imported functions |
|
Endpoint Sensor |
| importTableFunctionName | dynamic | true | - | The imported function file name |
|
Endpoint Sensor |
| instanceAccountId | string | true | - | The cloud account ID of the virtual machine that made the request | 111111111111 | Endpoint Sensor |
| instanceId | string | true | - | The ID of the instance that indicates the meta-cloud or data center VM |
|
|
| instanceId | string | true | - | The virtual machine instance ID on the cloud platform | i-01234567890abcdef |
|
| instanceName | string | true | - | The virtual machine that made the request | ec2-123-124-0-12.us-west-2.compute.amazonaws.com | Endpoint Sensor |
| integrityLevel | int | true | - | The integrity level of a process | 16384 | Endpoint Sensor |
| integrityLevel | int | true | - | The integrity level of a process | - |
|
| lastSeen | real | false | - | The last time the event was seen | 1656355418449 |
|
| logKey | string | true | - | The unique key of the event |
|
|
| logonUser | dynamic | true | UserAccount | The logon user name |
|
|
| messageType | string | true | - | The message type | Default |
|
| mpname | string | true | - | The management product name |
|
|
| mpver | string | true | - | The product version |
|
|
| nativeDeviceCharacteristics | int | false | - | Additional driver device information |
|
Endpoint Sensor |
| nativeDeviceType | int | false | - | The underlying hardware type of the driver |
|
Endpoint Sensor |
| nativeStorageDeviceBusType | int | false | - | The bus type to which the device is connected |
|
Endpoint Sensor |
| networkInterfaceId | string | true | - | The network interface of the virtual machine that made the request | eni-01234567890abcdef | Endpoint Sensor |
| objectActionResults | dynamic | true | - | The object process action results |
|
Endpoint Sensor |
| objectActionReturnCodes | dynamic | true | - | The object process action return codes |
|
Endpoint Sensor |
| objectActions | dynamic | true | - | The object process actions |
|
Endpoint Sensor |
| objectApiHookNum | int | false | - | The API hook number of the object | 1 | Endpoint Sensor |
| objectApiName | string | true | - | The API name | GetIpNetTable | Endpoint Sensor |
| objectApiName | string | true | - | The name of the executed API | GetIpNetTable | Endpoint Sensor |
| objectApiRvInNum | string | true | - | The API telemetry return value | 0 | Endpoint Sensor |
| objectAppName | string | true | - | Name of the app involved in the AMSI event |
|
|
| objectArtifactIds | dynamic | true | - | The artifact IDs generated by objectAction |
|
|
| objectAuthId | string | true | - | The object authorization ID |
|
|
| objectBmData | string | true | - | The data of BM event |
|
|
| objectCmd | dynamic | true | CLICommand | The object process command line |
|
|
| objectCmd | string | true | CLICommand | Command line entry of target process |
|
|
| objectContentName | string | true | - | The AMSI object content name |
|
|
| objectCreateDispositions | int | false | - | The disposition of CreateFile | - | Endpoint Sensor |
| objectCurrentFileSize | long | true | - | Previous size of modified object file |
|
|
| objectDesiredAccess | int | false | - | The desired access of the event | - | Endpoint Sensor |
| objectFileAttributes | int | false | - | The new file attributes |
|
Endpoint Sensor |
| objectFileAttributesHashId | string | true | - | The hash ID of the file attribute meta information |
|
Endpoint Sensor |
| objectFileCreation | string | true | - | The time the object file was created |
|
|
| objectFileCurrentAttributes | int | false | - | The original file attributes |
|
Endpoint Sensor |
| objectFileCurrentOwnerName | string | true | - | The current owner name of the object file |
|
|
| objectFileCurrentOwnerSid | string | true | - | The current security identifier owner of the object file |
|
|
| objectFileDaclString | string | true | - | The discretionary access control list of the object file |
|
|
| objectFileExtendedAttribute | string | true | - | The extended attributes of the file |
|
|
| objectFileGroupName | string | true | - | The object file user group name |
|
|
| objectFileGroupSid | string | true | - | The security identifier of the object file group |
|
|
| objectFileHashId | string | true | - | The object file hash ID |
|
|
| objectFileHashMd5 | string | true | FileMD5 | The MD5 of the object |
|
|
| objectFileHashMd5 | string | true | FileMD5 | The md5 hash of target process image or target file |
|
|
| objectFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the objectFilePath object |
|
|
| objectFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of target process image or target file |
|
|
| objectFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the object (objectFilePath) |
|
|
| objectFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of target process image or target file |
|
|
| objectFileIsRemoteAccess | bool | true | - | The remote access to the object file | - |
|
| objectFileModifiedTime | string | true | - | The time the object file was modified |
|
|
| objectFileOriginalName | string | true | FileName | The original file name of the object image |
|
|
| objectFileOwnerName | string | true | - | The object file owner name |
|
|
| objectFileOwnerSid | string | true | - | The security identifier of the object file owner |
|
|
| objectFilePath | string | true | FileFullPath | The file path of the target process image or target file |
|
|
| objectFilePath | string | true |
|
The file path of the target process image or target file |
|
|
| objectFileRemoteAccess | bool | true | - | The remote access for the object file | - |
|
| objectFileSaclString | string | true | - | The system access control list of the object file |
|
|
| objectFileSize | string | true | - | The file size of the object file |
|
|
| objectFirstSeen | string | true | - | The first time the object was seen |
|
|
| objectHashId | long | false | - | The object hash ID |
|
|
| objectHostName | string | true | DomainName | Server name where Internet event was detected |
|
|
| objectIntegrityLevel | int | true | - | Integrity level of target process | - |
|
| objectIp | string | true |
|
IP address of internet event | 10.10.10.10 |
|
| objectIps | dynamic | true |
|
IP address list of internet event |
|
|
| objectLastSeen | string | true | - | The last time the object was seen |
|
|
| objectLaunchTime | string | true | - | The object launch time of the Windows event |
|
|
| objectLoginOutFailureMessage | string | true | - | The sign-in/sign-out error message | Login incorrect |
|
| objectLoginOutFirstSeen | long | true | - | The first time the object sign-in/sign-out was seen | 1713903612 |
|
| objectLoginOutHashId | long | true | - | The FNV of the object sign-in/sign-out meta | -8981232070268295229 |
|
| objectLoginOutLastSeen | long | true | - | The last time the object sign-in/sign-out was seen | 1713903612 |
|
| objectLoginOutMetaType | int | true | - | The sign-in/sign-out meta | 1 - LOGIN_OUT_META_TYPE_OPENSSH |
|
| objectLoginOutSessionId | long | true | - | The sign-in/sign-out session ID | 260 |
|
| objectLoginOutSourceAddress | string | true | - | The sign-in/sign-out source IP | 10.10.10.10 |
|
| objectLoginOutStatus | int | true | - | The sign-in/sign-out status | -1 |
|
| objectName | string | true | - | The base name of the object file or process | net.exe |
|
| objectName | string | true | - | The object name |
|
|
| objectPid | int | false | - | The object process PID |
|
|
| objectPid | int | true | - | The PID of target process | - |
|
| objectPipeName | string | true | - | The object pipe name | \\.\pipe\F451F406BD | Endpoint Sensor |
| objectPipeName | string | true | - | The named pipe of the event |
|
Endpoint Sensor |
| objectPort | int | true | Port | The port number used by internet event | - |
|
| objectProcessHashId | long | true | - | FNV of target process |
|
|
| objectRawDataSize | dynamic | true | - | The raw data size of the Windows event object |
|
|
| objectRawDataStr | dynamic | true | - | The data contents of the AMSI event |
|
|
| objectRegistryData | string | true | RegistryValueData | The registry data contents | C:\Program Files\AlertMedia\AlertMedia Desktop Notifications\AlertMedia.exe |
|
| objectRegistryData | string | true | RegistryValueData | The registry value data |
|
|
| objectRegistryKeyHandle | string | true | RegistryKey | The registry key path |
|
|
| objectRegistryKeyHandle | string | true | RegistryKey | The registry key |
|
|
| objectRegistryRoot | string | true | - | The name of the object registry root key |
|
|
| objectRegistryRoot | int | false | - | The Windows Registry Root ID |
|
|
| objectRegistryValue | string | true | RegistryValue | The registry value name |
|
|
| objectRegistryValue | string | true | RegistryValue | Registry value name |
|
|
| objectRegType | int | false | - | The registry value type | - | Endpoint Sensor |
| objectRegType | int | false | - | The Windows Registry Type ID |
|
|
| objectRunAsLocalAccount | bool | true | - | The "runas" command uses a local account |
|
|
| objectSessionId | string | true | - | The object session ID |
|
|
| objectSigner | dynamic | true | - | The list of object process signers |
|
|
| objectSigner | dynamic | true | - | Certificate signer of object process or file |
|
|
| objectSignerFlagsAdhoc | dynamic | true | - | The list of object process signature adhoc flags | - |
|
| objectSignerFlagsAdhoc | dynamic | true | - | The list of object process or file signature adhoc flags | - |
|
| objectSignerFlagsLibValid | dynamic | true | - | The list of object process signature library validation flags | - |
|
| objectSignerFlagsLibValid | dynamic | true | - | The list of object process or file signature library validation flags | - |
|
| objectSignerFlagsRuntime | dynamic | true | - | The list of object process signature runtime flags | - |
|
| objectSignerFlagsRuntime | dynamic | true | - | The list of object process or file signature runtime flags | - |
|
| objectSignerValid | dynamic | true | - | Whether each signer of the object process is valid | - | Endpoint Sensor |
| objectSignerValid | dynamic | true | - | Validity of certificate signer |
|
|
| objectSubTrueType | int | true | - | File object's true sub-type |
|
|
| objectTrueType | int | true | - | File object's true major type |
|
|
| objectType | string | true | - | The object type |
|
|
| objectUser | string | true | UserAccount | The owner name of the target process or the login user name |
|
|
| objectUserDomain | string | false | - | The object user domain |
|
|
| objectUserGroup | string | true | - | The user group name |
|
|
| objectUserGroupSids | dynamic | true | - | The user group SIDs of the object |
|
Endpoint Sensor |
| osDescription | string | true | - | The OS version |
|
|
| osName | string | true | - | The host operating system name |
|
|
| osType | string | true | - | The host operating system type |
|
|
| osVer | string | true | - | The version of the host operating system |
|
|
| parentAuthId | string | true | - | The parent authorization ID |
|
|
| parentCmd | string | true | CLICommand | The command line of the subject parent process |
|
|
| parentCmd | string | true | CLICommand | The command line entry of the parent process |
|
|
| parentFileCreation | string | true | - | The time the parent file was created |
|
|
| parentFileCurrentOwnerName | string | true | - | The current owner name of the parent file |
|
|
| parentFileCurrentOwnerSid | string | true | - | The current security identifier owner of the parent file |
|
|
| parentFileDaclString | string | true | - | The discretionary access control list of the parent file |
|
|
| parentFileGroupName | string | true | - | The name of the parent file user group |
|
|
| parentFileGroupSid | string | true | - | The security identifier of the parent process file group |
|
|
| parentFileHashId | long | true | - | The parent file hash ID |
|
|
| parentFileHashMd5 | string | true | FileMD5 | The MD5 of the subject parent process |
|
Endpoint Sensor |
| parentFileHashMd5 | string | true | FileMD5 | The md5 hash of parent process |
|
|
| parentFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the subject parent process |
|
Endpoint Sensor |
| parentFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of parent process |
|
|
| parentFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the subject parent process |
|
|
| parentFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of parent process |
|
|
| parentFileModifiedTime | string | true | - | The time the parent file was modified |
|
|
| parentFileOriginalName | string | true | FileName | The original file name of the parent image |
|
|
| parentFileOwnerName | string | true | - | The owner name of the parent file |
|
|
| parentFileOwnerSid | string | true | - | The security identifier of the parent file owner |
|
|
| parentFilePath | string | true | FileFullPath | The full file path of the parent process |
|
Endpoint Sensor |
| parentFilePath | string | true |
|
The file path of the parent process |
|
|
| parentFileRemoteAccess | bool | true | - | The remote access to the parent file | - |
|
| parentFileSaclString | string | true | - | The system access control list of the parent file |
|
|
| parentFileSize | string | true | - | The file size of the parent file |
|
|
| parentHashId | string | true | - | The FNV of the parent process |
|
Endpoint Sensor |
| parentHashId | long | true | - | The parent hash ID |
|
|
| parentIntegrityLevel | int | true | - | The integrity level of a parent | 16384 | Endpoint Sensor |
| parentIntegrityLevel | int | true | - | The integrity level of a parent | - |
|
| parentLaunchTime | real | true | - | The time when the parent process was launched |
|
|
| parentName | string | true | - | The image name of the parent process |
|
|
| parentName | string | true | - | The image name of the parent process |
|
|
| parentPayloadSigner | dynamic | true | - | The signer name list of the parent process payload |
|
Endpoint Sensor |
| parentPayloadSignerFlagsAdhoc | dynamic | true | - | The list of parent process payload signature adhoc flags | - | Endpoint Sensor |
| parentPayloadSignerFlagsLibValid | dynamic | true | - | The list of parent process payload signature library validation flags | - | Endpoint Sensor |
| parentPayloadSignerFlagsRuntime | dynamic | true | - | The list of parent process payload signature runtime flags | - | Endpoint Sensor |
| parentPayloadSignerValid | dynamic | true | - | Whether each signer of the parent process payload is valid | - | Endpoint Sensor |
| parentPid | int | true | - | The PID of the parent process | - |
|
| parentPid | int | true | - | The PID of the parent process |
|
|
| parentSessionId | int | false | - | The parent session ID | - |
|
| parentSigner | dynamic | true | - | The signers of the parent process |
|
Endpoint Sensor |
| parentSigner | dynamic | true | - | The signer of the parent file |
|
|
| parentSignerFlagsAdhoc | dynamic | true | - | The list of parent process signature adhoc flags | - |
|
| parentSignerFlagsAdhoc | dynamic | true | - | The list of parent process signature adhoc flags | - |
|
| parentSignerFlagsLibValid | dynamic | true | - | The list of parent process signature library validation flags | - |
|
| parentSignerFlagsLibValid | dynamic | true | - | The list of parent process signature library validation flags | - |
|
| parentSignerFlagsRuntime | dynamic | true | - | The list of parent process signature runtime flags | - |
|
| parentSignerFlagsRuntime | dynamic | true | - | The list of parent process signature runtime flags | - |
|
| parentSignerValid | dynamic | true | - | Whether each signer of the parent process is valid | - | Endpoint Sensor |
| parentSignerValid | dynamic | true | - | The validity of the parent signer | - |
|
| parentSubTrueType | int | true | - | The true file subtype of the parent file | - |
|
| parentTrueType | int | true | - | The true file type of the parent file | - |
|
| parentUser | string | true | - | The type of user that executed the parent process |
|
|
| parentUserDomain | string | true | - | The user domain of the parent process |
|
|
| parentUserGroupSids | dynamic | true | - | The SIDs of the parent user group |
|
Endpoint Sensor |
| patVer | string | true | - | The version of the behavior pattern |
|
|
| plang | int | false | - | The product language |
|
|
| platformAssetTags | dynamic | true | - | The list of platform custom asset tags | {"Asset group":["finance"], "some.ip": ["10.1.0.1"]} |
|
| platformAssetTags | dynamic | true | - | The list of platform custom asset tags | {"Asset group":["finance"], "some.ip": ["10.1.0.1"]} |
|
| pname | string | true | - | The internal product ID |
|
|
| pname | string | true | - | Internal product ID (Deprecated, use productCode) |
|
|
| policyId | string | true | - | The policy ID of which the event was detected |
|
|
| pplat | int | false | - | The product platform |
|
|
| processActionResults | dynamic | true | - | The process action results |
|
Endpoint Sensor |
| processActionReturnCodes | dynamic | true | - | The process action return codes |
|
Endpoint Sensor |
| processActions | dynamic | true | - | The process actions |
|
Endpoint Sensor |
| processArtifactIds | dynamic | true | - | The artifact IDs generated by processAction |
|
|
| processCmd | string | true | CLICommand | The subject process command line |
|
|
| processCmd | string | true | CLICommand | The command line entry of the subject process |
|
|
| processFileCreation | string | true | - | The time the process file was created |
|
|
| processFileCurrentOwnerName | string | true | - | The current owner name of the process file |
|
|
| processFileCurrentOwnerSid | string | true | - | The owner of the process file current security identifier |
|
|
| processFileDaclString | string | true | - | The discretionary access control list of the process file |
|
|
| processFileGroupName | string | true | - | The name of the process file user group |
|
|
| processFileGroupSid | string | true | - | The security identifier of the process file group |
|
|
| processFileHashId | long | true | - | The file hash of the process |
|
|
| processFileHashMd5 | string | true | FileMD5 | The MD5 of the subject process |
|
|
| processFileHashMd5 | string | true | FileMD5 | The MD5 hash of the subject process image |
|
|
| processFileHashSha1 | string | true | FileSHA1 | The SHA-1 of the subject process |
|
|
| processFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of subject process image |
|
|
| processFileHashSha256 | string | true | FileSHA2 | The SHA-256 of the subject process |
|
|
| processFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of subject process image |
|
|
| processFileModifiedTime | string | true | - | The time the process file was modified |
|
|
| processFileOriginalName | string | true | FileName | The original file name of the process image |
|
|
| processFileOwnerName | string | true | - | The process file owner name |
|
|
| processFileOwnerSid | string | true | - | The security identifier of the process file owner |
|
|
| processFilePath | string | true |
|
The file path of the subject process |
|
|
| processFilePath | string | true |
|
The file path of the subject process |
|
|
| processFileRemoteAccess | bool | true | - | The remote access to the process file | - |
|
| processFileSaclString | string | true | - | The system access control list of the process file |
|
|
| processFileSize | string | true | - | The file size of the process file |
|
|
| processHashId | string | true | - | The FNV of the subject process |
|
Endpoint Sensor |
| processHashId | long | true | - | The FNV of subject process |
|
|
| processImagePath | string | true | - | The process triggered by the file event |
|
|
| processLaunchTime | real | true | - | The time the subject process was launched |
|
|
| processName | string | true | ProcessName | The image name of the process that triggered the event |
|
|
| processName | string | true | ProcessName | The image name of the process that triggered the event |
|
|
| processPayloadSigner | dynamic | true | - | The signer name list of the process payload |
|
Endpoint Sensor |
| processPayloadSignerFlagsAdhoc | dynamic | true | - | The list of process payload signature adhoc flags | - | Endpoint Sensor |
| processPayloadSignerFlagsLibValid | dynamic | true | - | The list of process payload signature library validation flags | - | Endpoint Sensor |
| processPayloadSignerFlagsRuntime | dynamic | true | - | The list of process payload signature runtime flags | - | Endpoint Sensor |
| processPayloadSignerValid | dynamic | true | - | Whether each signer of the process payload is valid | - | Endpoint Sensor |
| processPid | int | true | - | The PID of the subject process | - |
|
| processPid | int | true | - | The PID of the subject process |
|
|
| processPkgName | string | true | - | The process package name |
|
Endpoint Sensor |
| processSigner | dynamic | true | - | The signer name list of the subject process |
|
|
| processSigner | dynamic | true | - | The process file signer |
|
|
| processSignerFlagsAdhoc | dynamic | true | - | The list of process signature adhoc flags | - |
|
| processSignerFlagsAdhoc | dynamic | true | - | The list of process signature adhoc flags | - |
|
| processSignerFlagsLibValid | dynamic | true | - | The list of process signature library validation flags | - |
|
| processSignerFlagsLibValid | dynamic | true | - | The list of process signature library validation flags | - |
|
| processSignerFlagsRuntime | dynamic | true | - | The list of process signature runtime flags | - |
|
| processSignerFlagsRuntime | dynamic | true | - | The list of process signature runtime flags | - |
|
| processSignerValid | dynamic | true | - | The validity of the process signer |
|
|
| processStackTrace | string | true | - | The process stack trace of the telemetry event | C:\Windows\System32\ntdll.dll?NtCreateUserProcess|ZwCreateUserProcess, C:\Windows\System32\kernelbase.dll!CreateProcessInternalW | Endpoint Sensor |
| processSubTrueType | int | true | - | The true file subtype of the process | - |
|
| processTrueType | int | true | - | The true file type of the process | - |
|
| processUser | string | true | UserAccount | The owner name of subject process image |
|
|
| processUserDomain | string | true | - | The process user domain |
|
|
| processUserGroupSids | dynamic | true | - | The user group SIDs of the process |
|
Endpoint Sensor |
| proto | int | false | - | The protocol type |
|
|
| providerGUID | string | true | - | The GUID of the Windows event provider | {11111111-1111-1111-1111-111111111111} |
|
| providerName | string | true | - | The name of the Windows event provider |
|
|
| proxy | string | true | - | The proxy address |
|
|
| publicSpt | int | true | Port | The public port of the endpoint making the request | 57163 | Endpoint Sensor |
| publicSrc | string | true |
|
The public ip of the endpoint making the request | 10.10.10.10 | Endpoint Sensor |
| pver | string | true | - | The product version |
|
|
| rawDataSize | string | true | - | The size of the Windows event log |
|
|
| rawDataStr | string | true | - | Windows event raw contents |
|
|
| regionId | string | true | - | The cloud asset region |
|
|
| request | string | true | URL | Request URL |
|
|
| requestMethod | string | true | - | The network protocol request method |
|
|
| riskLevel | string | true | - | The risk level |
|
|
| rt | string | false | - | The Unix time of the log generation | 1656324260000 |
|
| rt | string | false | - | The event time | 1657781088000 |
|
| ruleId | int | true | - | The rule ID | 1005566 |
|
| ruleName | string | true | - | The name of the rule that triggered the event |
|
|
| sessionId | int | false | - | The session ID |
|
|
| smbSharedName | string | true | - | The shared folder name for the server that contains the files to be opened | C:\sharedfolder | Endpoint Sensor |
| smbSharedName | string | true | - | The shared folder name for the server that contains the files | sharedfolder | Endpoint Sensor |
| sourceType | string | true | - | The source type |
|
|
| spt | int | true | Port | The source port |
|
|
| spt | int | true | Port | The source port number |
|
|
| src | dynamic | true |
|
The source IP | 10.10.10.10 |
|
| src | string | true |
|
The source address |
|
|
| srcFileCreation | string | true | - | The time the source file was created |
|
|
| srcFileCurrentOwnerName | string | true | - | The current owner name of the source file |
|
|
| srcFileCurrentOwnerSid | string | true | - | The current security identifier owner of the source file |
|
|
| srcFileDaclString | string | true | - | The discretionary access control list of the source file |
|
|
| srcFileGroupName | string | true | - | The source file user group name |
|
|
| srcFileGroupSid | string | true | - | The security identifier of the source file group |
|
|
| srcFileHashId | long | false | - | The source file hash ID |
|
|
| srcFileHashMd5 | string | true | FileMD5 | The md5 hash of source file |
|
|
| srcFileHashSha1 | string | true | FileSHA1 | The SHA1 hash of source file |
|
|
| srcFileHashSha256 | string | true | FileSHA2 | The SHA256 hash of source file |
|
|
| srcFileIsRemoteAccess | bool | true | - | The remote access of the source file | - |
|
| srcFileModifiedTime | string | true | - | The time the source file was modified |
|
|
| srcFileOwnerName | string | true | - | The source file owner name |
|
|
| srcFileOwnerSid | string | true | - | The security identifier of the source file owner |
|
|
| srcFilePath | string | true |
|
The source file path |
|
|
| srcFileSaclString | string | true | - | The system access control list of the source file |
|
|
| srcFileSize | string | true | - | The file size of the source file |
|
|
| srcFirstSeen | string | true | - | The first time the source file was seen |
|
|
| srcHashId | long | false | - | The source hash ID |
|
|
| srcLastSeen | string | true | - | The last time the source file was seen |
|
|
| srcSigner | dynamic | true | - | The signer of the source file |
|
|
| srcSignerFlagsAdhoc | dynamic | true | - | The list of source file signature adhoc flags | - |
|
| srcSignerFlagsLibValid | dynamic | true | - | The list of source file signature library validation flags | - |
|
| srcSignerFlagsRuntime | dynamic | true | - | The list of source file signature runtime flags | - |
|
| srcSignerValid | dynamic | true | - | The validity of the source file signer | - |
|
| srcSubTrueType | int | false | - | The true file subtype of the source file | - |
|
| srcTrueType | int | false | - | The true file type of the source file | - |
|
| status | string | true | - | The HTTP response status code |
|
|
| subnetId | string | true | - | The subnet ID of the virtual machine that made the request | subnet-01234567890abcdef | Endpoint Sensor |
| subSystem | string | true | - | The sub system information | com.apple.xpc |
|
| suspiciousObject | string | true | - | The matched suspicious object | 36ba9de3da9e6f8abfffdda7787ab0ecc16724bb | Endpoint Sensor |
| suspiciousObjectType | string | true | - | The matched suspicious object type | sha1 | Endpoint Sensor |
| tacticId | dynamic | true | Tactic | The list of MITRE tactic IDs |
|
|
| timezone | string | true | - | The host time zone |
|
|
| triggerReason | string | true | - | The cause of the triggered action |
|
|
| userDomain | dynamic | true | - | The user domain name |
|
|
| vpcId | string | true | - | The virtual private cloud that contains the cloud asset | vpc-01234567890abcdef |
|
| winEventId | int | true | - | Event ID of Windows event |
|
|
Generated by XDR Common Schema Public Doc Generator V2