ipv4-addr:value |
DeviceNetworkEvents.LocalIP, DeviceNetworkEvents.RemoteIP, DeviceEvents.RemoteIP, DeviceEvents.LocalIP |
ipv6-addr:value |
DeviceNetworkEvents.LocalIP, DeviceNetworkEvents.RemoteIP, DeviceEvents.RemoteIP, DeviceEvents.LocalIP |
network-traffic:src_port |
DeviceNetworkEvents.LocalPort, DeviceEvents.LocalPort |
network-traffic:dst_port |
DeviceNetworkEvents.RemotePort, DeviceEvents.RemotePort |
network-traffic:protocols[*] |
DeviceNetworkEvents.Protocol |
network-traffic:src_ref.value |
DeviceNetworkEvents.LocalIP, DeviceNetworkInfo.MacAddress, DeviceEvents.LocalIP |
network-traffic:dst_ref.value |
DeviceNetworkEvents.RemoteIP, DeviceEvents.RemoteIP |
url:value |
DeviceNetworkEvents.RemoteUrl, DeviceEvents.RemoteUrl, DeviceFileEvents.FileOriginUrl, DeviceFileEvents.FileOriginReferrerUrl |
domain-name:value |
DeviceNetworkEvents.RemoteUrl, DeviceEvents.RemoteUrl |
file:name |
DeviceFileEvents.FileName, DeviceFileEvents.InitiatingProcessFileName, DeviceFileEvents.InitiatingProcessParentFileName, DeviceProcessEvents.FileName, DeviceProcessEvents.InitiatingProcessFileName, DeviceProcessEvents.InitiatingProcessParentFileName, DeviceNetworkEvents.InitiatingProcessFileName, DeviceNetworkEvents.InitiatingProcessParentFileName, DeviceRegistryEvents.InitiatingProcessFileName, DeviceRegistryEvents.InitiatingProcessParentFileName, DeviceEvents.FileName, DeviceEvents.InitiatingProcessFileName, DeviceEvents.InitiatingProcessParentFileName, DeviceImageLoadEvents.FileName, DeviceImageLoadEvents.InitiatingProcessFileName, DeviceImageLoadEvents.InitiatingProcessParentFileName |
file:hashes.'SHA-1' |
DeviceFileEvents.SHA1, DeviceFileEvents.InitiatingProcessSHA1, DeviceProcessEvents.SHA1, DeviceProcessEvents.InitiatingProcessSHA1, DeviceNetworkEvents.InitiatingProcessSHA1, DeviceRegistryEvents.InitiatingProcessSHA1, DeviceEvents.SHA1, DeviceEvents.InitiatingProcessSHA1, DeviceImageLoadEvents.SHA1, DeviceImageLoadEvents.InitiatingProcessSHA1 |
file:hashes.'SHA-256' |
DeviceFileEvents.SHA256, DeviceFileEvents.InitiatingProcessSHA256, DeviceProcessEvents.SHA256, DeviceProcessEvents.InitiatingProcessSHA256, DeviceNetworkEvents.InitiatingProcessSHA256, DeviceRegistryEvents.InitiatingProcessSHA256, DeviceEvents.SHA256, DeviceEvents.InitiatingProcessSHA256, DeviceImageLoadEvents.SHA256, DeviceImageLoadEvents.InitiatingProcessSHA256 |
file:hashes.MD5 |
DeviceFileEvents.MD5, DeviceFileEvents.InitiatingProcessMD5, DeviceProcessEvents.MD5, DeviceProcessEvents.InitiatingProcessMD5, DeviceNetworkEvents.InitiatingProcessMD5, DeviceRegistryEvents.InitiatingProcessMD5, DeviceEvents.MD5, DeviceEvents.InitiatingProcessMD5, DeviceImageLoadEvents.MD5, DeviceImageLoadEvents.InitiatingProcessMD5 |
file:parent_directory_ref.path |
DeviceFileEvents.FolderPath, DeviceFileEvents.InitiatingProcessFolderPath, DeviceProcessEvents.FolderPath, DeviceProcessEvents.InitiatingProcessFolderPath, DeviceNetworkEvents.InitiatingProcessFolderPath, DeviceRegistryEvents.InitiatingProcessFolderPath, DeviceEvents.FolderPath, DeviceEvents.InitiatingProcessFolderPath, DeviceImageLoadEvents.FolderPath, DeviceImageLoadEvents.InitiatingProcessFolderPath |
process:name |
DeviceProcessEvents.FileName, DeviceEvents.FileName, DeviceProcessEvents.InitiatingProcessFileName, DeviceEvents.InitiatingProcessFileName, DeviceFileEvents.InitiatingProcessFileName, DeviceNetworkEvents.InitiatingProcessFileName, DeviceRegistryEvents.InitiatingProcessFileName, DeviceImageLoadEvents.InitiatingProcessFileName |
process:command_line |
DeviceProcessEvents.ProcessCommandLine, DeviceProcessEvents.InitiatingProcessCommandLine, DeviceEvents.ProcessCommandLine, DeviceEvents.InitiatingProcessCommandLine, DeviceFileEvents.InitiatingProcessCommandLine, DeviceNetworkEvents.InitiatingProcessCommandLine, DeviceRegistryEvents.InitiatingProcessCommandLine, DeviceImageLoadEvents.InitiatingProcessCommandLine |
process:pid |
DeviceProcessEvents.ProcessId, DeviceEvents.ProcessId, DeviceProcessEvents.InitiatingProcessId, DeviceEvents.InitiatingProcessId, DeviceProcessEvents.InitiatingProcessId, DeviceNetworkEvents.InitiatingProcessId, DeviceRegistryEvents.InitiatingProcessId, DeviceFileEvents.InitiatingProcessId, DeviceImageLoadEvents.InitiatingProcessId |
process:created |
DeviceProcessEvents.ProcessCreationTime, DeviceEvents.ProcessCreationTime, DeviceNetworkEvents.InitiatingProcessCreationTime, DeviceRegistryEvents.InitiatingProcessCreationTime, DeviceFileEvents.InitiatingProcessCreationTime, DeviceImageLoadEvents.InitiatingProcessCreationTime |
process:parent_ref.name |
DeviceProcessEvents.InitiatingProcessFileName, DeviceEvents.InitiatingProcessFileName, DeviceFileEvents.InitiatingProcessParentFileName, DeviceNetworkEvents.InitiatingProcessParentFileName, DeviceRegistryEvents.InitiatingProcessParentFileName, DeviceImageLoadEvents.InitiatingProcessParentFileName |
process:parent_ref.pid |
DeviceProcessEvents.InitiatingProcessId, DeviceNetworkEvents.InitiatingProcessId, DeviceRegistryEvents.InitiatingProcessParentId, DeviceFileEvents.InitiatingProcessParentId, DeviceEvents.InitiatingProcessParentId, DeviceImageLoadEvents.InitiatingProcessParentId |
process:parent_ref.created |
DeviceProcessEvents.InitiatingProcessCreationTime, DeviceEvents.InitiatingProcessCreationTime, DeviceNetworkEvents.InitiatingProcessParentCreationTime, DeviceRegistryEvents.InitiatingProcessParentCreationTime, DeviceFileEvents.InitiatingProcessParentCreationTime, DeviceImageLoadEvents.InitiatingProcessParentCreationTime |
process:parent_ref.parent_ref.name |
DeviceProcessEvents.InitiatingProcessParentFileName, DeviceEvents.InitiatingProcessParentFileName |
process:parent_ref.parent_ref.pid |
DeviceProcessEvents.InitiatingProcessParentId, DeviceNetworkEvents.InitiatingProcessParentId |
process:parent_ref.parent_ref.created |
DeviceProcessEvents.InitiatingProcessParentCreationTime, DeviceEvents.InitiatingProcessParentCreationTime |
process:creator_user_ref.user_id |
DeviceProcessEvents.AccountName, DeviceEvents.AccountName, DeviceNetworkEvents.InitiatingProcessAccountName, DeviceRegistryEvents.InitiatingProcessAccountName, DeviceFileEvents.InitiatingProcessAccountName, DeviceImageLoadEvents.InitiatingProcessAccountName |
process:creator_user_ref.account_login |
DeviceProcessEvents.AccountUpn, DeviceEvents.AccountUpn, DeviceNetworkEvents.InitiatingProcessAccountUpn, DeviceRegistryEvents.InitiatingProcessAccountUpn, DeviceFileEvents.InitiatingProcessAccountUpn, DeviceImageLoadEvents.InitiatingProcessAccountUpn |
process:parent_ref.creator_user_ref.user_id |
DeviceProcessEvents.InitiatingProcessAccountName, DeviceEvents.InitiatingProcessAccountName |
process:parent_ref.creator_user_ref.account_login |
DeviceProcessEvents.InitiatingProcessAccountUpn, DeviceEvents.InitiatingProcessAccountUpn |
process:binary_ref.hashes.'SHA-1' |
DeviceProcessEvents.SHA1, DeviceEvents.SHA1, DeviceFileEvents.InitiatingProcessSHA1, DeviceNetworkEvents.InitiatingProcessSHA1, DeviceRegistryEvents.InitiatingProcessSHA1, DeviceImageLoadEvents.InitiatingProcessSHA1 |
process:binary_ref.hashes.'SHA-256' |
DeviceProcessEvents.SHA256, DeviceEvents.SHA256, DeviceFileEvents.InitiatingProcessSHA256, DeviceNetworkEvents.InitiatingProcessSHA256, DeviceRegistryEvents.InitiatingProcessSHA256, DeviceImageLoadEvents.InitiatingProcessSHA256 |
process:binary_ref.hashes.MD5 |
DeviceProcessEvents.MD5, DeviceEvents.MD5, DeviceFileEvents.InitiatingProcessMD5, DeviceNetworkEvents.InitiatingProcessMD5, DeviceRegistryEvents.InitiatingProcessMD5, DeviceImageLoadEvents.InitiatingProcessMD5 |
process:binary_ref.parent_directory_ref.path |
DeviceProcessEvents.FolderPath, DeviceEvents.FolderPath, DeviceNetworkEvents.InitiatingProcessFolderPath, DeviceRegistryEvents.InitiatingProcessFolderPath, DeviceFileEvents.InitiatingProcessFolderPath, DeviceImageLoadEvents.InitiatingProcessFolderPath |
process:parent_ref.binary_ref.hashes.'SHA-1' |
DeviceProcessEvents.InitiatingProcessSHA1, DeviceEvents.InitiatingProcessSHA1 |
process:parent_ref.binary_ref.hashes.'SHA-256' |
DeviceProcessEvents.InitiatingProcessSHA256, DeviceEvents.InitiatingProcessSHA256 |
process:parent_ref.binary_ref.hashes.MD5 |
DeviceProcessEvents.InitiatingProcessMD5, DeviceEvents.InitiatingProcessMD5 |
process:parent_ref.binary_ref.parent_directory_ref.path |
DeviceProcessEvents.InitiatingProcessFolderPath, DeviceEvents.InitiatingProcessFolderPath |
process:child_refs.binary_ref.hashes.MD5 |
DeviceProcessEvents.MD5 |
process:child_refs.binary_ref.hashes.'SHA-256' |
DeviceProcessEvents.SHA256 |
process:child_refs.binary_ref.hashes.'SHA-1' |
DeviceProcessEvents.SHA1 |
process:child_refs.binary_ref.parent_directory_ref.path |
DeviceProcessEvents.FolderPath |
process:child_refs.creator_user_ref.account_login |
DeviceProcessEvents.AccountName |
process:child_refs.pid |
DeviceProcessEvents.ProcessId |
user-account:user_id |
DeviceProcessEvents.AccountName, DeviceFileEvents.RequestAccountName, DeviceEvents.AccountName, DeviceProcessEvents.InitiatingProcessAccountName, DeviceNetworkEvents.InitiatingProcessAccountName, DeviceRegistryEvents.InitiatingProcessAccountName, DeviceFileEvents.InitiatingProcessAccountName, DeviceEvents.InitiatingProcessAccountName, DeviceImageLoadEvents.InitiatingProcessAccountName |
user-account:account_login |
DeviceProcessEvents.AccountUpn, DeviceEvents.AccountUpn, DeviceProcessEvents.InitiatingProcessAccountUpn, DeviceNetworkEvents.InitiatingProcessAccountUpn, DeviceRegistryEvents.InitiatingProcessAccountUpn, DeviceFileEvents.InitiatingProcessAccountUpn, DeviceEvents.InitiatingProcessAccountUpn, DeviceImageLoadEvents.InitiatingProcessAccountUpn |
windows-registry-key:key |
DeviceRegistryEvents.RegistryKey, DeviceEvents.RegistryKey |
windows-registry-key:values[*] |
DeviceRegistryEvents.RegistryValueName, DeviceEvents.RegistryValueName |
mac-addr:value |
DeviceNetworkInfo.MacAddress |
directory:path |
DeviceFileEvents.FolderPath, DeviceFileEvents.InitiatingProcessFolderPath, DeviceProcessEvents.FolderPath, DeviceProcessEvents.InitiatingProcessFolderPath, DeviceEvents.FolderPath, DeviceEvents.InitiatingProcessFolderPath, DeviceNetworkEvents.InitiatingProcessFolderPath, DeviceRegistryEvents.InitiatingProcessFolderPath, DeviceImageLoadEvents.FolderPath, DeviceImageLoadEvents.InitiatingProcessFolderPath |
x-oca-asset:device_id |
DeviceFileEvents.DeviceId, DeviceProcessEvents.DeviceId, DeviceNetworkEvents.DeviceId, DeviceRegistryEvents.DeviceId, DeviceEvents.DeviceId, DeviceImageLoadEvents.DeviceId, DeviceLogonEvents.DeviceId |
x-oca-asset:hostname |
DeviceFileEvents.DeviceName, DeviceProcessEvents.DeviceName, DeviceNetworkEvents.DeviceName, DeviceRegistryEvents.DeviceName, DeviceEvents.DeviceName, DeviceImageLoadEvents.DeviceName, DeviceLogonEvents.DeviceName |
x-oca-asset:ip_refs[*].value |
DeviceNetworkEvents.LocalIP |
x-oca-asset:os.name |
DeviceInfo.OSPlatform |
x-oca-asset:os.platform |
DeviceInfo.OSPlatform |
x-oca-event:action |
DeviceProcessEvents.ActionType, DeviceEvents.ActionType, DeviceNetworkEvents.ActionType, DeviceRegistryEvents.ActionType, DeviceFileEvents.ActionType, DeviceImageLoadEvents.ActionType |
x-oca-event:process_ref.pid |
DeviceProcessEvents.ProcessId, DeviceEvents.ProcessId, DeviceNetworkEvents.InitiatingProcessId, DeviceRegistryEvents.InitiatingProcessId, DeviceFileEvents.InitiatingProcessId, DeviceImageLoadEvents.InitiatingProcessId |
x-oca-event:process_ref.name |
DeviceProcessEvents.FileName, DeviceEvents.FileName, DeviceNetworkEvents.InitiatingProcessFileName, DeviceRegistryEvents.InitiatingProcessFileName, DeviceFileEvents.InitiatingProcessFileName, DeviceImageLoadEvents.InitiatingProcessFileName |
x-oca-event:process_ref.binary_ref.name |
DeviceProcessEvents.FileName, DeviceEvents.FileName, DeviceNetworkEvents.InitiatingProcessFileName, DeviceRegistryEvents.InitiatingProcessFileName, DeviceFileEvents.InitiatingProcessFileName, DeviceImageLoadEvents.InitiatingProcessFileName |
x-oca-event:process_ref.creator_user_ref.account_login |
DeviceProcessEvents.AccountUpn, DeviceEvents.AccountUpn, DeviceNetworkEvents.InitiatingProcessAccountUpn, DeviceRegistryEvents.InitiatingProcessAccountUpn, DeviceFileEvents.InitiatingProcessAccountUpn, DeviceImageLoadEvents.InitiatingProcessAccountUpn |
x-oca-event:process_ref.creator_user_ref.user_id |
DeviceProcessEvents.AccountName, DeviceEvents.AccountName, DeviceNetworkEvents.InitiatingProcessAccountName, DeviceRegistryEvents.InitiatingProcessAccountName, DeviceFileEvents.InitiatingProcessAccountName, DeviceImageLoadEvents.InitiatingProcessAccountName |
x-oca-event:process_ref.command_line |
DeviceProcessEvents.ProcessCommandLine, DeviceEvents.ProcessCommandLine, DeviceNetworkEvents.InitiatingProcessCommandLine, DeviceRegistryEvents.InitiatingProcessCommandLine, DeviceFileEvents.InitiatingProcessCommandLine, DeviceImageLoadEvents.InitiatingProcessCommandLine |
x-oca-event:process_ref.parent_ref.name |
DeviceProcessEvents.InitiatingProcessFileName, DeviceEvents.InitiatingProcessFileName, DeviceNetworkEvents.InitiatingProcessParentFileName, DeviceRegistryEvents.InitiatingProcessParentFileName, DeviceFileEvents.InitiatingProcessParentFileName, DeviceImageLoadEvents.InitiatingProcessParentFileName |
x-oca-event:process_ref.parent_ref.pid |
DeviceProcessEvents.InitiatingProcessId, DeviceEvents.InitiatingProcessId, DeviceNetworkEvents.InitiatingProcessParentId, DeviceRegistryEvents.InitiatingProcessParentId, DeviceFileEvents.InitiatingProcessParentId, DeviceImageLoadEvents.InitiatingProcessParentId |
x-oca-event:process_ref.parent_ref.command_line |
DeviceProcessEvents.InitiatingProcessCommandLine, DeviceEvents.InitiatingProcessCommandLine |
x-oca-event:process_ref.binary_ref.hashes.'SHA-256' |
DeviceProcessEvents.SHA256, DeviceEvents.SHA256, DeviceNetworkEvents.InitiatingProcessSHA256, DeviceRegistryEvents.InitiatingProcessSHA256, DeviceFileEvents.InitiatingProcessSHA256, DeviceImageLoadEvents.InitiatingProcessSHA256 |
x-oca-event:process_ref.binary_ref.hashes.MD5 |
DeviceProcessEvents.MD5, DeviceEvents.MD5, DeviceNetworkEvents.InitiatingProcessMD5, DeviceRegistryEvents.InitiatingProcessMD5, DeviceFileEvents.InitiatingProcessMD5, DeviceImageLoadEvents.InitiatingProcessMD5 |
x-oca-event:process_ref.binary_ref.hashes.'SHA-1' |
DeviceProcessEvents.SHA1, DeviceEvents.SHA1, DeviceNetworkEvents.InitiatingProcessSHA1, DeviceRegistryEvents.InitiatingProcessSHA1, DeviceFileEvents.InitiatingProcessSHA1, DeviceImageLoadEvents.InitiatingProcessSHA1 |
x-oca-event:parent_process_ref.name |
DeviceProcessEvents.InitiatingProcessFileName, DeviceEvents.InitiatingProcessFileName, DeviceNetworkEvents.InitiatingProcessParentFileName, DeviceRegistryEvents.InitiatingProcessParentFileName, DeviceFileEvents.InitiatingProcessParentFileName, DeviceImageLoadEvents.InitiatingProcessParentFileName |
x-oca-event:parent_process_ref.pid |
DeviceProcessEvents.InitiatingProcessId, DeviceEvents.InitiatingProcessId, DeviceNetworkEvents.InitiatingProcessParentId, DeviceRegistryEvents.InitiatingProcessParentId, DeviceFileEvents.InitiatingProcessParentId, DeviceImageLoadEvents.InitiatingProcessParentId |
x-oca-event:domain_ref.value |
DeviceNetworkEvents.RemoteUrl, DeviceEvents.RemoteUrl |
x-oca-event:url_ref.value |
DeviceNetworkEvents.RemoteUrl, DeviceEvents.RemoteUrl, DeviceEvents.FileOriginUrl, DeviceFileEvents.FileOriginUrl, DeviceFileEvents.FileOriginReferrerUrl |
x-oca-event:file_ref.name |
DeviceFileEvents.FileName, DeviceImageLoadEvents.FileName |
x-oca-event:registry_ref.key |
DeviceRegistryEvents.RegistryKey |
x-oca-event:host_ref.hostname |
DeviceFileEvents.DeviceName, DeviceProcessEvents.DeviceName, DeviceNetworkEvents.DeviceName, DeviceRegistryEvents.DeviceName, DeviceEvents.DeviceName, DeviceImageLoadEvents.DeviceName, DeviceLogonEvents.DeviceName |
x-oca-event:host_ref.device_id |
DeviceFileEvents.DeviceId, DeviceProcessEvents.DeviceId, DeviceNetworkEvents.DeviceId, DeviceRegistryEvents.DeviceId, DeviceEvents.DeviceId, DeviceImageLoadEvents.DeviceId, DeviceLogonEvents.DeviceId |
x-ibm-finding:alert_id |
DeviceAlertEvents.AlertId |
x-ibm-finding:name |
DeviceAlertEvents.Title |
x-ibm-finding:time_observed |
DeviceAlertEvents.Timestamp |
|
|