Table of Contents | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
|
...
Field | Type | Extra field |
---|---|---|
eventdate |
| - |
machine |
| - |
activity_id |
| - |
agent_id |
| - |
aggregate_id |
| - |
cid |
| - |
composite_id |
| - |
confidence |
| - |
context_timestamp |
| - |
crawl_edge_ids_sensor |
| - |
crawl_vertex_ids_sensor |
| - |
crawled_timestamp |
| - |
created_timestamp |
| - |
data_domains |
| - |
description |
| - |
display_name |
| - |
end_time |
| - |
falcon_host_link |
| - |
id |
| - |
ldap_search_query_attack |
| - |
name |
| - |
objective |
| - |
pattern_id |
| - |
poly_id |
| - |
product |
| - |
scenario |
| - |
seconds_to_resolved |
| - |
seconds_to_triaged |
| - |
severity |
| - |
severity_name |
| - |
show_in_ui |
| - |
source_account_domain |
| - |
source_account_name |
| - |
source_account_object_guid |
| - |
source_account_object_sid |
| - |
source_account_upn |
| - |
source_endpoint_account_object_guid |
| - |
source_endpoint_account_object_sid |
| - |
source_endpoint_address_ipv4 |
| - |
source_endpoint_host_name |
| - |
source_endpoint_address_ip |
| - |
source_endpoint_sensor_id |
| - |
source_products |
| - |
source_vendors |
| - |
start_time |
| - |
status |
| - |
tactic |
| - |
tactic_id |
| - |
target_account_name |
| - |
target_domain_controller_host_name |
| - |
target_domain_controller_object_guid |
| - |
target_domain_controller_object_sid |
| - |
target_endpoint_account_object_guid |
| - |
target_endpoint_account_object_sid |
| - |
target_endpoint_host_name |
| - |
target_endpoint_sensor_id |
| - |
technique |
| - |
technique_id |
| - |
timestamp |
| - |
type |
| - |
updated_timestamp |
| - |
username |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
...
edr.crowdstrike.falconstreaming.auth_
...
activity
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
target_name |
| - |
target_user_uuid |
| - |
target_cid |
| - |
roles |
| - |
scope |
| - |
actor_user |
| - |
actor_user_uuid |
| - |
actor_cid |
| - |
subscriptions |
| - |
APIClientID |
| - |
appId |
| - |
eventType2 |
| - |
partition |
| - |
offset2 |
| - |
id |
| - |
name |
| - |
trace_id |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
...
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ProcessStartTime |
| - |
ProcessEndTime |
| - |
ProcessId |
| - |
ParentProcessId |
| - |
ComputerName |
| - |
UserName |
| - |
DetectName |
| - |
DetectDescription |
| - |
Severity |
| - |
SeverityName |
| - |
FileName |
| - |
FilePath |
| - |
CommandLine |
| - |
SHA256String |
| - |
MD5String |
| - |
SHA1String |
| - |
MachineDomain |
| - |
ExecutablesWritten |
| - |
FalconHostLink |
| - |
SensorId |
| - |
IOCType |
| - |
IOCValue |
| - |
DetectId |
| - |
new_state |
| - |
quarantined_file_id |
| - |
action_taken |
| - |
LocalIP |
| - |
MACAddress |
| - |
Tactic |
| - |
Technique |
| - |
Objective |
| - |
UserId |
| - |
UserIp |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
ScanResults_Engine_str |
| - |
ScanResults_ResultName_str |
| - |
ScanResults_Version_str |
| - |
ScanResults_Detected_str |
| - |
PatternDispositionDescription |
| - |
PatternDispositionValue |
| - |
PatternDispositionFlags_Indicator |
| - |
PatternDispositionFlags_Detect |
| - |
PatternDispositionFlags_InddetMask |
| - |
PatternDispositionFlags_SensorOnly |
| - |
PatternDispositionFlags_Rooting |
| - |
PatternDispositionFlags_KillProcess |
| - |
PatternDispositionFlags_KillSubProcess |
| - |
PatternDispositionFlags_QuarantineMachine |
| - |
PatternDispositionFlags_QuarantineFile |
| - |
PatternDispositionFlags_PolicyDisabled |
| - |
PatternDispositionFlags_KillParent |
| - |
PatternDispositionFlags_OperationBlocked |
| - |
PatternDispositionFlags_ProcessBlocked |
| - |
PatternDispositionFlags_SuspendParent |
| - |
PatternDispositionFlags_KillActionFailed |
| - |
PatternDispositionFlags_HandleOperationDowngraded |
| - |
PatternDispositionFlags_SuspendProcess |
| - |
PatternDispositionFlags_CriticalProcessDisabled |
| - |
PatternDispositionFlags_BootupSafeguardEnabled |
| - |
PatternDispositionFlags_RegistryOperationBlocked |
| - |
PatternDispositionFlags_BlockingUnsupportedOrDisabled |
| - |
PatternDispositionFlags_FsOperationBlocked |
| - |
ParentImageFileName |
| - |
ParentCommandLine |
| - |
GrandparentImageFileName |
| - |
GrandparentCommandLine |
| - |
QuarantineFiles_ImageFileName_str |
| - |
QuarantineFiles_SHA256HashData_str |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.epp_detection_summary
Field | Type | Extra fields |
---|---|---|
eventdate |
| |
machine |
| |
pattern_disposition_value |
| |
pattern_disposition_description |
| |
severity_name |
| |
type |
| |
process_id |
| |
tactic |
| |
file_path |
| |
severity |
| |
user_name |
| |
event_sh_a1_string |
| |
composite_id |
| |
source_products |
| |
local_ipv6 |
| |
event_sh_a256_string |
| |
agent_id |
| |
local_ip |
| |
source_vendors |
| |
event_ioa_rule_group_name |
| |
aggregate_id |
| |
host_groups |
| |
hostname |
| |
falcon_host_link |
| |
quarantine_machine |
| |
process_blocked |
| |
bootup_safeguard_enabled |
| |
fs_operation_blocked |
| |
quarantine_file |
| |
kill_process |
| |
kill_parent |
| |
registry_operation_blocked |
| |
indicator |
| |
detect |
| |
handle_operation_downgraded |
| |
sensor_only |
| |
rooting |
| |
policy_disabled |
| |
critical_process_disabled |
| |
suspend_parent |
| |
inddet_mask |
| |
kill_sub_process |
| |
suspend_process |
| |
operation_blocked |
| |
kill_action_failed |
| |
blocking_unsupported_or_disabled |
| |
process_end_time |
| |
technique |
| |
event_md5_string |
| |
logon_domain |
| |
event_mac_address |
| |
command_line |
| |
pattern_id |
| |
name |
| |
file_name |
| |
event_ioa_rule_name |
| |
objective |
| |
event_ioa_rule_instance_version |
| |
description |
| |
process_start_time |
| |
data_domains |
| |
event_ioa_rule_instance_id |
| |
parent_process_id |
| |
at_devo_pulling_id |
| |
metadata_offset |
| |
metadata_event_type |
| |
metadata_event_creation_time |
| |
metadata_customer_id_string |
| |
metadata_version |
| |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.external_api
...