Table of Contents | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
|
edr.crowdstrike.cannon.other
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ConnectionDirection |
| - |
ConnectionFlags |
| - |
ContextProcessId |
| - |
ContextTimeStamp |
| - |
Entitlements |
| - |
InContext |
| - |
LocalAddressIP4 |
| - |
LocalPort |
| - |
Protocol |
| - |
EffectiveTransmissionClass |
| - |
RemoteAddressIP4 |
| - |
RemotePort |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
LinkName |
| - |
AuthenticationId |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
FullFilePath |
| - |
FilePath |
| - |
ComputerName |
| - |
UserName |
| - |
FileName |
| - |
ImageFileName |
| - |
ImageSubsystem |
| - |
IntegrityLevel |
| - |
MD5HashData |
| - |
ParentAuthenticationId |
| - |
ParentProcessId |
| - |
ProcessCreateFlags |
| - |
ProcessEndTime |
| - |
ProcessParameterFlags |
| - |
ProcessStartTime |
| - |
ProcessSxsFlags |
| - |
RawProcessId |
| - |
SHA1HashData |
| - |
SHA256HashData |
| - |
SourceProcessId |
| - |
SourceThreadId |
| - |
TargetProcessId |
| - |
TokenType |
| - |
UserSid |
| - |
ParentBaseFileName |
| - |
GrandParentBaseFileName |
| - |
UID |
| - |
RGID |
| - |
RUID |
| - |
GID |
| - |
MachOSubType |
| - |
ProcessGroupId |
| - |
SessionProcessId |
| - |
SVGID |
| - |
SVUID |
| - |
Tags |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
Entitlements |
| - |
ProcessCount |
| - |
SHA256HashData |
| - |
Timeout |
| - |
UID |
| - |
EffectiveTransmissionClass |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ConfigBuild |
| - |
ConfigIDBase |
| - |
ConfigIDBuild |
| - |
ConfigIDPlatform |
| - |
ConfigStateHash |
| - |
ConfigurationVersion |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
NetworkContainmentState |
| - |
ProvisionState |
| - |
SensorStateBitMap |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
Anchor | ||||
---|---|---|---|---|
|
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
AuthenticationId |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ContextTimeStamp |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
ImageFileName |
| - |
IntegrityLevel |
| - |
ParentProcessId |
| - |
ProcessStartTime |
| - |
RawProcessId |
| - |
SHA256HashData |
| - |
SyntheticPR2Flags |
| - |
TargetProcessId |
| - |
UserSid |
| - |
MD5HashData |
| - |
UID |
| - |
RGID |
| - |
RUID |
| - |
GID |
| - |
ProcessGroupId |
| - |
SessionProcessId |
| - |
SHA1HashData |
| - |
SourceProcessId |
| - |
SVGID |
| - |
SVUID |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
Anchor | ||||
---|---|---|---|---|
|
...