edr.crowdstrike: Table structure (Part 4)
- 1 edr.crowdstrike.cannon.associatetreeidwithroot
- 2 edr.crowdstrike.cannon.asepvalueupdate
- 3 edr.crowdstrike.cannon.channelversionrequired
- 4 edr.crowdstrike.cannon.detectionexcluded
- 5 edr.crowdstrike.cannon.detectionexcluded
- 6 edr.crowdstrike.cannon.dnsrequest
- 7 edr.crowdstrike.cannon.endofprocess
- 8 edr.crowdstrike.cannon.neighborlistip4
- 9 edr.crowdstrike.cannon.detectionexcluded
- 10 edr.crowdstrike.cannon.networkconnectip4
edr.crowdstrike.cannon.associatetreeidwithroot
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
hostname |
| - |
event_simpleName |
| - |
ContextTimeStamp |
| - |
ConfigStateHash |
| - |
aip |
| - |
SessionProcessId |
| - |
ConfigBuild |
| - |
PatternDisposition |
| - |
event_platform |
| - |
TargetProcessId |
| - |
TreeId |
| - |
PatternId |
| - |
Entitlements |
| - |
name |
| - |
TreeRoot |
| - |
id |
| - |
EffectiveTransmissionClass |
| - |
aid |
| - |
timestamp |
| - |
cid |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.cannon.asepvalueupdate
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
AsepClass |
| - |
AsepFlags |
| - |
AsepIndex |
| - |
AsepValueType |
| - |
AuthenticationId |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ContextProcessId |
| - |
ContextThreadId |
| - |
ContextTimeStamp |
| - |
Data1 |
| - |
EffectiveTransmissionClass |
| - |
RegStringValue |
| - |
Entitlements |
| - |
RegNumericValue |
| - |
RegObjectName |
| - |
RegOperationType |
| - |
RegType |
| - |
RegValueName |
| - |
TokenType |
| - |
RegBinaryValue |
| - |
TargetFileName |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.channelversionrequired
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ChannelId |
| - |
ChannelVersion |
| - |
ChannelVersionRequired |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.detectionexcluded
edr.crowdstrike.cannon.detectionexcluded
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
hostname |
| - |
event_simpleName |
| - |
ContextTimeStamp |
| - |
ConfigStateHash |
| - |
aip |
| - |
SessionProcessId |
| - |
BoundingLimitCount |
| - |
ConfigBuild |
| - |
event_platform |
| - |
CommandLine |
| - |
TargetProcessId |
| - |
PatternId |
| - |
ImageFileName |
| - |
ExclusionType |
| - |
Entitlements |
| - |
name |
| - |
ExclusionSource |
| - |
id |
| - |
EffectiveTransmissionClass |
| - |
aid |
| - |
timestamp |
| - |
cid |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.cannon.dnsrequest
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ContextProcessId |
| - |
ContextThreadId |
| - |
ContextTimeStamp |
| - |
DomainName |
| - |
Entitlements |
| - |
RequestType |
| - |
DnsResponseType |
| - |
IP4Records |
| - |
FirstIP4Record |
| - |
CNAMERecords |
| - |
IP6Records |
| - |
FirstIP6Record |
| - |
QueryStatus |
| - |
DualRequest |
| - |
RespondingDnsServer |
| - |
DnsRequestCount |
| - |
InterfaceIndex |
| - |
EffectiveTransmissionClass |
| - |
BoundingLimitCount |
| - |
BoundingLimitDuration |
| - |
TreeId |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.endofprocess
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ActivePrivilegeEscalationCount |
| - |
AsepWrittenCount |
| - |
BinaryExecutableWrittenCount |
| - |
CLICreationCount |
| - |
ConHostId |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ContextProcessId |
| - |
ContextThreadId |
| - |
ContextTimeStamp |
| - |
CycleTime |
| - |
DirectoryCreatedCount |
| - |
DirectoryEnumeratedCount |
| - |
DnsRequestCount |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
ExeAndServiceCount |
| - |
ExecutableDeletedCount |
| - |
ExitCode |
| - |
FileDeletedCount |
| - |
InjectedDllCount |
| - |
InjectedThreadCount |
| - |
KernelTime |
| - |
MaxThreadCount |
| - |
NamedObjectCount |
| - |
NetworkBindCount |
| - |
NetworkCapableAsepWriteCount |
| - |
NetworkCloseCount |
| - |
NetworkConnectCount |
| - |
NetworkConnectCountUdp |
| - |
NetworkListenCount |
| - |
NetworkRecvAcceptCount |
| - |
NewExecutableWrittenCount |
| - |
PrivilegedProcessHandleCount |
| - |
RawProcessId |
| - |
RegKeySecurityDecreasedCount |
| - |
RunDllInvocationCount |
| - |
ScriptEngineInvocationCount |
| - |
ServiceEventCount |
| - |
SHA256HashData |
| - |
SnapshotFileOpenCount |
| - |
SuspectStackCount |
| - |
SuspiciousCredentialModuleLoadCount |
| - |
SuspiciousDnsRequestCount |
| - |
SuspiciousRawDiskReadCount |
| - |
TargetProcessId |
| - |
UnsignedModuleLoadCount |
| - |
UserMemoryAllocateExecutableCount |
| - |
UserMemoryAllocateExecutableRemoteCount |
| - |
UserMemoryProtectExecutableCount |
| - |
UserMemoryProtectExecutableRemoteCount |
| - |
UserSid |
| - |
UserTime |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.neighborlistip4
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
InterfaceIndex |
| - |
NeighborList |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.detectionexcluded
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
hostname |
| - |
event_simpleName |
| - |
ContextTimeStamp |
| - |
ConfigStateHash |
| - |
aip |
| - |
SessionProcessId |
| - |
BoundingLimitCount |
| - |
ConfigBuild |
| - |
event_platform |
| - |
CommandLine |
| - |
TargetProcessId |
| - |
PatternId |
| - |
ImageFileName |
| - |
ExclusionType |
| - |
Entitlements |
| - |
name |
| - |
ExclusionSource |
| - |
id |
| - |
EffectiveTransmissionClass |
| - |
aid |
| - |
timestamp |
| - |
cid |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.cannon.networkconnectip4
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ConnectionDirection |
| - |
ConnectionFlags |
| - |
ContextProcessId |
| - |
ContextTimeStamp |
| - |
Entitlements |
| - |
InContext |
| - |
LocalAddressIP4 |
| - |
LocalPort |
| - |
Protocol |
| - |
EffectiveTransmissionClass |
| - |
RemoteAddressIP4 |
| - |
RemotePort |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |