edr.crowdstrike: Table structure (Part 5)
edr.crowdstrike.cannon.other
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ConnectionDirection |
| - |
ConnectionFlags |
| - |
ContextProcessId |
| - |
ContextTimeStamp |
| - |
Entitlements |
| - |
InContext |
| - |
LocalAddressIP4 |
| - |
LocalPort |
| - |
Protocol |
| - |
EffectiveTransmissionClass |
| - |
RemoteAddressIP4 |
| - |
RemotePort |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.processrollup2
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
LinkName |
| - |
AuthenticationId |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
FullFilePath |
| - |
FilePath |
| - |
ComputerName |
| - |
UserName |
| - |
FileName |
| - |
ImageFileName |
| - |
ImageSubsystem |
| - |
IntegrityLevel |
| - |
MD5HashData |
| - |
ParentAuthenticationId |
| - |
ParentProcessId |
| - |
ProcessCreateFlags |
| - |
ProcessEndTime |
| - |
ProcessParameterFlags |
| - |
ProcessStartTime |
| - |
ProcessSxsFlags |
| - |
RawProcessId |
| - |
SHA1HashData |
| - |
SHA256HashData |
| - |
SourceProcessId |
| - |
SourceThreadId |
| - |
TargetProcessId |
| - |
TokenType |
| - |
UserSid |
| - |
ParentBaseFileName |
| - |
GrandParentBaseFileName |
| - |
UID |
| - |
RGID |
| - |
RUID |
| - |
GID |
| - |
MachOSubType |
| - |
ProcessGroupId |
| - |
SessionProcessId |
| - |
SVGID |
| - |
SVUID |
| - |
Tags |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.processrollup2stats
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
Entitlements |
| - |
ProcessCount |
| - |
SHA256HashData |
| - |
Timeout |
| - |
UID |
| - |
EffectiveTransmissionClass |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.sensorheartbeat
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
ConfigBuild |
| - |
ConfigIDBase |
| - |
ConfigIDBuild |
| - |
ConfigIDPlatform |
| - |
ConfigStateHash |
| - |
ConfigurationVersion |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
NetworkContainmentState |
| - |
ProvisionState |
| - |
SensorStateBitMap |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.cannon.syntheticprocessrollup2
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
AuthenticationId |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
ContextTimeStamp |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
ImageFileName |
| - |
IntegrityLevel |
| - |
ParentProcessId |
| - |
ProcessStartTime |
| - |
RawProcessId |
| - |
SHA256HashData |
| - |
SyntheticPR2Flags |
| - |
TargetProcessId |
| - |
UserSid |
| - |
MD5HashData |
| - |
UID |
| - |
RGID |
| - |
RUID |
| - |
GID |
| - |
ProcessGroupId |
| - |
SessionProcessId |
| - |
SHA1HashData |
| - |
SourceProcessId |
| - |
SVGID |
| - |
SVUID |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| - |
edr.crowdstrike.falcon_spotlight.vulnerabilities
Field | Type | Extra field |
---|---|---|
eventdate |
| Â |
hostname |
| Â |
id |
| Â |
cid |
| Â |
aid |
| Â |
created_timestamp |
| Â |
closed_timestamp |
| Â |
updated_timestamp |
| Â |
status |
| Â |
cve__id |
| Â |
cve__base_score |
| Â |
cve__severity |
| Â |
cve__exploit_status |
| Â |
app__product_name_version |
| Â |
apps |
| Â |
host_info__hostname |
| Â |
host_info__local_ip |
| Â |
host_info__machine_domain |
| Â |
host_info__os_version |
| Â |
host_info__ou |
| Â |
host_info__site_name |
| Â |
host_info__system_manufacturer |
| Â |
host_info__groups |
| Â |
host_info__tags |
| Â |
host_info__platform |
| Â |
remediation__ids |
| Â |
hostchain |
| ✓ |
tag |
| ✓ |