Layer: Endpoint
This documentation provides detailed information about all fields available for Trend Micro Apex One On-Premises.
Field Name | Type | Searchable | General Field | Description | Example | Products |
---|---|---|---|---|---|---|
detectionMeta | dynamic | true | - | The descriptions of the detected techniques | ['T1204 some description about this technique', 'T1573.001_AES another description about this technique'] |
|
detectionNames | dynamic | true | - | The rules that triggered the event | ['HS_EMOTET.SMAA', 'HM_AVEDOWN.SMZTIG-A', 'HE_DOCQRPHISH.SM'] |
|
objectSignerFlagsAdhoc | dynamic | true | - | The list of object process signature adhoc flags | - |
|
objectSignerFlagsLibValid | dynamic | true | - | The list of object process signature library validation flags | - |
|
objectSignerFlagsRuntime | dynamic | true | - | The list of object process signature runtime flags | - |
|
parentSignerFlagsAdhoc | dynamic | true | - | The list of parent process signature adhoc flags | - |
|
parentSignerFlagsLibValid | dynamic | true | - | The list of parent process signature library validation flags | - |
|
parentSignerFlagsRuntime | dynamic | true | - | The list of parent process signature runtime flags | - |
|
processSignerFlagsAdhoc | dynamic | true | - | The list of process signature adhoc flags | - |
|
processSignerFlagsLibValid | dynamic | true | - | The list of process signature library validation flags | - |
|
processSignerFlagsRuntime | dynamic | true | - | The list of process signature runtime flags | - |
|
quarantineFileId | string | true | - | The unique identifier of the quarantined object | ASLUMVS0.4FC |
|
quarantineFilePath | string | true | FileFullPath | The file path of the quarantined object | C:\ProgramData\Trend Micro\AMSP\quarantine\ASLUMVS0.4FC |
|
quarantineFileSha256 | string | true | FileSHA2 | The SHA-256 of the quarantined object | 84B2FA19B05EA88D6E785B4ADB528120485AA3F72F3E5E114DE6D3696B0D151F |
|
Generated by XDR Common Schema Public Doc Generator V2