edr.crowdstrike.falconstreaming.agents
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
hostname |
| - |
device_id |
| - |
cid |
| - |
agent_load_flags |
| - |
agent_local_time |
| - |
agent_version |
| - |
bios_manufacturer |
| - |
bios_version |
| - |
build_number |
| - |
config_id_base |
| - |
config_id_build |
| - |
config_id_platform |
| - |
cpu_signature |
| - |
external_ip |
| - |
mac_address |
| - |
hostname2 |
| - |
first_seen |
| - |
last_seen |
| - |
local_ip |
| - |
major_version |
| - |
minor_version |
| - |
os_version |
| - |
os_build |
| - |
platform_id |
| - |
platform_name |
| - |
policies |
| - |
reduced_functionality_mode |
| - |
device_policies__prevention__policy_type |
| - |
device_policies__prevention__policy_id |
| - |
device_policies__prevention__applied |
| - |
device_policies__prevention__settings_hash |
| - |
device_policies__prevention__assigned_date |
| - |
device_policies__prevention__applied_date |
| - |
device_policies__prevention__rule_groups |
| - |
device_policies__sensor_update__policy_type |
| - |
device_policies__sensor_update__policy_id |
| - |
device_policies__sensor_update__applied |
| - |
device_policies__sensor_update__settings_hash |
| - |
device_policies__sensor_update__assigned_date |
| - |
device_policies__sensor_update__applied_date |
| - |
device_policies__sensor_update__uninstall_protection |
| - |
device_policies__device_control__policy_type |
| - |
device_policies__device_control__policy_id |
| - |
device_policies__device_control__applied |
| - |
device_policies__device_control__assigned_date |
| - |
device_policies__device_control__applied_date |
| - |
device_policies__global_config__policy_type |
| - |
device_policies__global_config__policy_id |
| - |
device_policies__global_config__applied |
| - |
device_policies__global_config__settings_hash |
| - |
device_policies__global_config__assigned_date |
| - |
device_policies__global_config__applied_date |
| - |
device_policies__remote_response__policy_type |
| - |
device_policies__remote_response__policy_id |
| - |
device_policies__remote_response__applied |
| - |
device_policies__remote_response__settings_hash |
| - |
device_policies__remote_response__assigned_date |
| - |
device_policies__remote_response__applied_date |
| - |
device_policies__firewall__policy_type |
| - |
device_policies__firewall__policy_id |
| - |
device_policies__firewall__applied |
| - |
device_policies__firewall__assigned_date |
| - |
device_policies__firewall__applied_date |
| - |
device_policies__firewall__rule_set_id |
| - |
groups |
| - |
group_hash |
| - |
product_type |
| - |
product_type_desc |
| - |
provision_status |
| - |
serial_number |
| - |
service_pack_major |
| - |
service_pack_minor |
| - |
pointer_size |
| - |
status |
| - |
system_manufacturer |
| - |
system_product_name |
| - |
tags |
| - |
modified_timestamp |
| - |
slow_changing_modified_timestamp |
| - |
meta__version |
| - |
instance_id |
| - |
service_provider |
| - |
service_provider_account_id |
| - |
machine_domain |
| - |
ou |
| - |
site_name |
| - |
zone_group |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.alert
Field | Type | Extra field |
---|---|---|
eventdate |
| - |
machine |
| - |
activity_id |
| - |
agent_id |
| - |
aggregate_id |
| - |
cid |
| - |
composite_id |
| - |
confidence |
| - |
context_timestamp |
| - |
crawl_edge_ids_sensor |
| - |
crawl_vertex_ids_sensor |
| - |
crawled_timestamp |
| - |
created_timestamp |
| - |
data_domains |
| - |
description |
| - |
display_name |
| - |
end_time |
| - |
falcon_host_link |
| - |
id |
| - |
ldap_search_query_attack |
| - |
name |
| - |
objective |
| - |
pattern_id |
| - |
poly_id |
| - |
product |
| - |
scenario |
| - |
seconds_to_resolved |
| - |
seconds_to_triaged |
| - |
severity |
| - |
severity_name |
| - |
show_in_ui |
| - |
source_account_domain |
| - |
source_account_name |
| - |
source_account_object_guid |
| - |
source_account_object_sid |
| - |
source_account_upn |
| - |
source_endpoint_account_object_guid |
| - |
source_endpoint_account_object_sid |
| - |
source_endpoint_address_ipv4 |
| - |
source_endpoint_host_name |
| - |
source_endpoint_address_ip |
| - |
source_endpoint_sensor_id |
| - |
source_products |
| - |
source_vendors |
| - |
start_time |
| - |
status |
| - |
tactic |
| - |
tactic_id |
| - |
target_account_name |
| - |
target_domain_controller_host_name |
| - |
target_domain_controller_object_guid |
| - |
target_domain_controller_object_sid |
| - |
target_endpoint_account_object_guid |
| - |
target_endpoint_account_object_sid |
| - |
target_endpoint_host_name |
| - |
target_endpoint_sensor_id |
| - |
technique |
| - |
technique_id |
| - |
timestamp |
| - |
type |
| - |
updated_timestamp |
| - |
username |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.auth_activity
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
target_name |
| - |
target_user_uuid |
| - |
target_cid |
| - |
roles |
| - |
scope |
| - |
actor_user |
| - |
actor_user_uuid |
| - |
actor_cid |
| - |
subscriptions |
| - |
APIClientID |
| - |
appId |
| - |
eventType2 |
| - |
partition |
| - |
offset2 |
| - |
id |
| - |
name |
| - |
trace_id |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.behaviors
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
behavior_id |
| - |
detection_ids |
| - |
cid |
| - |
aid |
| - |
pattern_id |
| - |
template_instance_id |
| - |
timestamp |
| - |
cmdline |
| - |
filepath |
| - |
domain |
| - |
pattern_disposition |
| - |
pattern_disposition_details__indicator |
| - |
pattern_disposition_details__detect |
| - |
pattern_disposition_details__inddet_mask |
| - |
pattern_disposition_details__sensor_only |
| - |
pattern_disposition_details__rooting |
| - |
pattern_disposition_details__kill_process |
| - |
pattern_disposition_details__kill_subprocess |
| - |
pattern_disposition_details__quarantine_machine |
| - |
pattern_disposition_details__quarantine_file |
| - |
pattern_disposition_details__policy_disabled |
| - |
pattern_disposition_details__kill_parent |
| - |
pattern_disposition_details__operation_blocked |
| - |
pattern_disposition_details__process_blocked |
| - |
pattern_disposition_details__registry_operation_blocked |
| - |
pattern_disposition_details__critical_process_disabled |
| - |
pattern_disposition_details__bootup_safeguard_enabled |
| - |
pattern_disposition_details__fs_operation_blocked |
| - |
pattern_disposition_details__handle_operation_downgraded |
| - |
pattern_disposition_details__kill_action_failed |
| - |
pattern_disposition_details__blocking_unsupported_or_disabled |
| - |
pattern_disposition_details__suspend_process |
| - |
pattern_disposition_details__suspend_parent |
| - |
sha256 |
| - |
user_name |
| - |
tactic |
| - |
tactic_id |
| - |
technique |
| - |
technique_id |
| - |
objective |
| - |
compound_tto |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.customer_ioc
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
AgentIdString |
| - |
DeviceId |
| - |
ComputerName |
| - |
ProcessId |
| - |
ParentProcessId |
| - |
ProcessStartTime |
| - |
FileName |
| - |
FilePath |
| - |
CommandLine |
| - |
MD5String |
| - |
SHA256String |
| - |
DomainName |
| - |
IPv4 |
| - |
IPv6 |
| - |
jsonEvent |
| - |
rawMessage |
| ✓ |
hostchain |
| ✓ |
tag |
| ✓ |
edr.crowdstrike.falconstreaming.detection_summary
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ProcessStartTime |
| - |
ProcessEndTime |
| - |
ProcessId |
| - |
ParentProcessId |
| - |
ComputerName |
| - |
UserName |
| - |
DetectName |
| - |
DetectDescription |
| - |
Severity |
| - |
SeverityName |
| - |
FileName |
| - |
FilePath |
| - |
CommandLine |
| - |
SHA256String |
| - |
MD5String |
| - |
SHA1String |
| - |
MachineDomain |
| - |
ExecutablesWritten |
| - |
FalconHostLink |
| - |
SensorId |
| - |
IOCType |
| - |
IOCValue |
| - |
DetectId |
| - |
new_state |
| - |
quarantined_file_id |
| - |
action_taken |
| - |
LocalIP |
| - |
MACAddress |
| - |
Tactic |
| - |
Technique |
| - |
Objective |
| - |
UserId |
| - |
UserIp |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
ScanResults_Engine_str |
| - |
ScanResults_ResultName_str |
| - |
ScanResults_Version_str |
| - |
ScanResults_Detected_str |
| - |
PatternDispositionDescription |
| - |
PatternDispositionValue |
| - |
PatternDispositionFlags_Indicator |
| - |
PatternDispositionFlags_Detect |
| - |
PatternDispositionFlags_InddetMask |
| - |
PatternDispositionFlags_SensorOnly |
| - |
PatternDispositionFlags_Rooting |
| - |
PatternDispositionFlags_KillProcess |
| - |
PatternDispositionFlags_KillSubProcess |
| - |
PatternDispositionFlags_QuarantineMachine |
| - |
PatternDispositionFlags_QuarantineFile |
| - |
PatternDispositionFlags_PolicyDisabled |
| - |
PatternDispositionFlags_KillParent |
| - |
PatternDispositionFlags_OperationBlocked |
| - |
PatternDispositionFlags_ProcessBlocked |
| - |
PatternDispositionFlags_SuspendParent |
| - |
PatternDispositionFlags_KillActionFailed |
| - |
PatternDispositionFlags_HandleOperationDowngraded |
| - |
PatternDispositionFlags_SuspendProcess |
| - |
PatternDispositionFlags_CriticalProcessDisabled |
| - |
PatternDispositionFlags_BootupSafeguardEnabled |
| - |
PatternDispositionFlags_RegistryOperationBlocked |
| - |
PatternDispositionFlags_BlockingUnsupportedOrDisabled |
| - |
PatternDispositionFlags_FsOperationBlocked |
| - |
ParentImageFileName |
| - |
ParentCommandLine |
| - |
GrandparentImageFileName |
| - |
GrandparentCommandLine |
| - |
QuarantineFiles_ImageFileName_str |
| - |
QuarantineFiles_SHA256HashData_str |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.external_api
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ProcessStartTime |
| - |
ProcessEndTime |
| - |
ProcessId |
| - |
ParentProcessId |
| - |
ComputerName |
| - |
UserName |
| - |
DetectName |
| - |
DetectDescription |
| - |
Severity |
| - |
SeverityName |
| - |
FileName |
| - |
FilePath |
| - |
CommandLine |
| - |
SHA256String |
| - |
MD5String |
| - |
SHA1String |
| - |
MachineDomain |
| - |
ExecutablesWritten |
| - |
FalconHostLink |
| - |
SensorId |
| - |
IOCType |
| - |
IOCValue |
| - |
DetectId |
| - |
new_state |
| - |
quarantined_file_id |
| - |
action_taken |
| - |
LocalIP |
| - |
MACAddress |
| - |
Tactic |
| - |
Technique |
| - |
Objective |
| - |
UserId |
| - |
UserIp |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
ScanResults_Engine_str |
| - |
ScanResults_ResultName_str |
| - |
ScanResults_Version_str |
| - |
ScanResults_Detected_str |
| - |
PatternDispositionDescription |
| - |
PatternDispositionValue |
| - |
PatternDispositionFlags_Indicator |
| - |
PatternDispositionFlags_Detect |
| - |
PatternDispositionFlags_InddetMask |
| - |
PatternDispositionFlags_SensorOnly |
| - |
PatternDispositionFlags_Rooting |
| - |
PatternDispositionFlags_KillProcess |
| - |
PatternDispositionFlags_KillSubProcess |
| - |
PatternDispositionFlags_QuarantineMachine |
| - |
PatternDispositionFlags_QuarantineFile |
| - |
PatternDispositionFlags_PolicyDisabled |
| - |
PatternDispositionFlags_KillParent |
| - |
PatternDispositionFlags_OperationBlocked |
| - |
PatternDispositionFlags_ProcessBlocked |
| - |
PatternDispositionFlags_SuspendParent |
| - |
PatternDispositionFlags_KillActionFailed |
| - |
PatternDispositionFlags_HandleOperationDowngraded |
| - |
PatternDispositionFlags_SuspendProcess |
| - |
PatternDispositionFlags_CriticalProcessDisabled |
| - |
PatternDispositionFlags_BootupSafeguardEnabled |
| - |
PatternDispositionFlags_RegistryOperationBlocked |
| - |
PatternDispositionFlags_BlockingUnsupportedOrDisabled |
| - |
PatternDispositionFlags_FsOperationBlocked |
| - |
ParentImageFileName |
| - |
ParentCommandLine |
| - |
GrandparentImageFileName |
| - |
GrandparentCommandLine |
| - |
QuarantineFiles_ImageFileName_str |
| - |
QuarantineFiles_SHA256HashData_str |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.firewall_match
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventType |
| - |
eventCreationTime |
| - |
version |
| - |
deviceId |
| - |
customerId |
| - |
ipv |
| - |
commandLine |
| - |
connectionDirection |
| - |
evEventType |
| - |
flag_audit |
| - |
flag_log |
| - |
flag_monitor |
| - |
hostName |
| - |
icmpCode |
| - |
icmpType |
| - |
imageFileName |
| - |
localAddress |
| - |
localPort |
| - |
matchCount |
| - |
matchCountSinceLastReport |
| - |
networkProfile |
| - |
pid |
| - |
policyName |
| - |
policyID |
| - |
protocol |
| - |
remoteAddress |
| - |
remotePort |
| - |
ruleAction |
| - |
ruleDescription |
| - |
ruleFamilyID |
| - |
ruleGroupName |
| - |
ruleName |
| - |
ruleId |
| - |
status |
| - |
timestamp |
| - |
treeID |
| - |
platform |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.identity_protection
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventType |
| - |
eventCreationTime |
| - |
version |
| - |
incidentType |
| - |
incidentDescription |
| - |
severity |
| - |
severityName |
| - |
startTime |
| - |
endTime |
| - |
identityProtectionIncidentId |
| - |
userName |
| - |
endpointName |
| - |
endpointIp |
| - |
category |
| - |
numbersOfAlerts |
| - |
numberOfCompromisedEntities |
| - |
state |
| - |
falconHostLink |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.idp_detection_summary
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
|
|
| |
customerIDString |
|
|
| |
offset |
|
|
| |
eventType |
|
|
| |
eventCreationTime |
|
|
| |
version |
|
|
| |
contextTimeStamp |
|
|
| |
detectId |
| isnull(detectId_aux) or isempty(detectId_aux) ? compositeId : detectId_aux | compositeId detectId_aux | |
detectName |
| isnull(detectName_aux) or isempty(detectName_aux) ? name : detectName_aux | detectName_aux name | |
detectDescription |
| isnull(detectDescription_aux) or isempty(detectDescription_aux) ? description : detectDescription_aux | description detectDescription_aux | |
compositeId |
|
|
| |
name |
|
|
| |
description |
|
|
| |
falconHostLink |
|
|
| |
startTime |
|
|
| |
endTime |
|
|
| |
severity |
|
|
| |
tactic |
|
|
| |
technique |
|
|
| |
objective |
|
|
| |
sourceAccountDomain |
|
|
| |
sourceAccountName |
|
|
| |
sourceAccountObjectSid |
|
|
| |
sourceEndpointAccountObjectGuid |
|
|
| |
sourceEndpointAccountObjectSid |
|
|
| |
sourceEndpointHostName |
|
|
| |
sourceEndpointIpAddress |
|
|
| |
sourceEndpointSensorId |
|
|
| |
activityId |
|
|
| |
patternId |
|
|
| |
hostchain |
|
|
| ✓ |
tag |
|
|
| ✓ |
rawMessage |
|
|
| ✓ |