edr.crowdstrike: Table structure (Part 3)
- 1 edr.crowdstrike.falconstreaming.user_activity_other
- 2 edr.crowdstrike.falconstreaming.recon_notification_summary
- 3 edr.crowdstrike.falconstreaming.user_activity_detections
- 4 edr.crowdstrike.falconstreaming.user_activity_devices
- 5 edr.crowdstrike.falconstreaming.user_activity_prevention_policy
- 6 edr.crowdstrike.falconstreaming.user_activity_ip_whitelist
- 7 edr.crowdstrike.falconstreaming.vulnerabilities
- 8 edr.crowdstrike.falcon
- 9 edr.crowdstrike.cannon
- 10 edr.crowdstrike.cannon.associateindicator
edr.crowdstrike.falconstreaming.user_activity_other
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
UserId |
| - |
UserIp |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.recon_notification_summary
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventType |
| - |
eventCreationTime |
| - |
version |
| - |
notificationId |
| - |
highlights_str |
| - |
matchedTimestamp |
| - |
ruleId |
| - |
ruleName |
| - |
ruleTopic |
| - |
rulePriority |
| - |
itemId |
| - |
itemType |
| - |
itemPostedTimestamp |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.user_activity_detections
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
customerIDString |
| Â | Â | Â |
offset |
| Â | Â | Â |
eventCreationTime |
| Â | Â | Â |
version |
| Â | Â | Â |
eventType |
| Â | Â | Â |
ServiceName |
| Â | Â | Â |
OperationName |
| Â | Â | Â |
UTCTimestamp |
| Â | Â | Â |
Success |
| Â | Â | Â |
UserId |
| Â | Â | Â |
UserIp |
| Â | Â | Â |
detection_id |
| isnull(detection_id_aux) or isempty(detection_id_aux) ? composite_id : detection_id_aux | detection_id_aux composite_id | Â |
composite_id |
| Â | Â | Â |
detects |
| Â | Â | Â |
new_state |
| Â | Â | Â |
assigned_to |
| Â | Â | Â |
assigned_to_uid |
| Â | Â | Â |
show_in_ui |
| Â | Â | Â |
APIClientID |
| Â | Â | Â |
AuditKeyValues |
| Â | Â | Â |
jsonEvent |
| Â | Â | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  |  | ✓ |
edr.crowdstrike.falconstreaming.user_activity_devices
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
SensorId |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.user_activity_prevention_policy
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
policy_id |
| - |
devices_affected |
| - |
policy_priority |
| - |
old_policy_priority |
| - |
policy_name |
| - |
policy_description |
| - |
policy_platform |
| - |
policy_type |
| - |
policy_assignment_rule |
| - |
policy_enabled |
| - |
policy_settings_AdwareExecution |
| - |
old_policy_settings_AdwareExecution |
| - |
policy_settings_ApplicationExploitationActivity |
| - |
old_policy_settings_ApplicationExploitationActivity |
| - |
policy_settings_BackupDeletion |
| - |
old_policy_settings_BackupDeletion |
| - |
policy_settings_ChopperWebshell |
| - |
old_policy_settings_ChopperWebshell |
| - |
policy_settings_Cryptowall |
| - |
old_policy_settings_Cryptowall |
| - |
policy_settings_CustomBlacklisting |
| - |
old_policy_settings_CustomBlacklisting |
| - |
policy_settings_DriveByDownload |
| - |
old_policy_settings_DriveByDownload |
| - |
policy_settings_FileAnalysis |
| - |
old_policy_settings_FileAnalysis |
| - |
policy_settings_FileAttributeAnalysis |
| - |
old_policy_settings_FileAttributeAnalysis |
| - |
policy_settings_FileEncryption |
| - |
old_policy_settings_FileEncryption |
| - |
policy_settings_ForceASLR |
| - |
old_policy_settings_ForceASLR |
| - |
policy_settings_ForceDEP |
| - |
old_policy_settings_ForceDEP |
| - |
policy_settings_HeapSprayPreallocation |
| - |
old_policy_settings_HeapSprayPreallocation |
| - |
policy_settings_Locky |
| - |
old_policy_settings_Locky |
| - |
policy_settings_WindowsLogonBypassStickyKeys |
| - |
old_policy_settings_WindowsLogonBypassStickyKeys |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.user_activity_ip_whitelist
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
customerIDString |
| - |
offset |
| - |
eventCreationTime |
| - |
version |
| - |
eventType |
| - |
ServiceName |
| - |
OperationName |
| - |
UTCTimestamp |
| - |
Success |
| - |
UserId |
| - |
UserIp |
| - |
APIClientID |
| - |
AuditKeyValues |
| - |
jsonEvent |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falconstreaming.vulnerabilities
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
hostname |
| - |
id |
| - |
cid |
| - |
aid |
| - |
created_timestamp |
| - |
closed_timestamp |
| - |
updated_timestamp |
| - |
status |
| - |
cve__id |
| - |
cve__base_score |
| - |
cve__severity |
| - |
cve__exploit_status |
| - |
app__product_name_version |
| - |
apps |
| - |
host_info__hostname |
| - |
host_info__local_ip |
| - |
host_info__machine_domain |
| - |
host_info__os_version |
| - |
host_info__ou |
| - |
host_info__site_name |
| - |
host_info__system_manufacturer |
| - |
host_info__groups |
| - |
host_info__tags |
| - |
host_info__platform |
| - |
remediation__ids |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
edr.crowdstrike.falcon
Field | Type | Field transformation | Source field name | Extra fields |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
metadata_customerIDString |
| Â | Â | Â |
metadata_offset |
| Â | Â | Â |
metadata_eventType |
| Â | Â | Â |
metadata_eventCreationTime |
| Â | Â | Â |
metadata_version |
| Â | Â | Â |
event_ProcessStartTime |
| Â | Â | Â |
event_ProcessEndTime |
| Â | Â | Â |
event_ProcessId |
| Â | Â | Â |
event_ParentProcessId |
| Â | Â | Â |
event_ComputerName |
| Â | Â | Â |
event_UserName |
| Â | Â | Â |
event_DetectId |
| isnull(event_DetectId_aux) or isempty(event_DetectId_aux) ? event_CompositeId : event_DetectId_aux | event_DetectId_aux event_CompositeId | Â |
event_DetectName |
| isnull(event_DetectName_aux) or isempty(event_DetectName_aux) ? event_Name : event_DetectName_aux | event_Name event_DetectName_aux | Â |
event_DetectDescription |
| event_DetectDescription_aux event_Description | Â | |
event_CompositeId |
| Â | Â | Â |
event_Name |
| Â | Â | Â |
event_Description |
| Â | Â | Â |
event_Severity |
| Â | Â | Â |
event_SeverityName |
| Â | Â | Â |
event_FileName |
| Â | Â | Â |
event_FilePath |
| Â | Â | Â |
event_CommandLine |
| Â | Â | Â |
event_SHA256String |
| Â | Â | Â |
event_MD5String |
| Â | Â | Â |
event_SHA1String |
| Â | Â | Â |
event_MachineDomain |
| Â | Â | Â |
event_ExecutablesWritten |
| Â | Â | Â |
event_FalconHostLink |
| Â | Â | Â |
event_SensorId |
| Â | Â | Â |
event_IOCType |
| Â | Â | Â |
event_IOCValue |
| Â | Â | Â |
event_new_state |
| Â | Â | Â |
event_quarantined_file_id |
| Â | Â | Â |
event_action_taken |
| Â | Â | Â |
event_target_name |
| Â | Â | Â |
event_LocalIP |
| Â | Â | Â |
event_MACAddress |
| Â | Â | Â |
event_Tactic |
| Â | Â | Â |
event_Technique |
| Â | Â | Â |
event_Objective |
| Â | Â | Â |
event_group_id |
| Â | Â | Â |
event_group_name |
| Â | Â | Â |
event_old_group_name |
| Â | Â | Â |
event_group_description |
| Â | Â | Â |
event_old_group_description |
| Â | Â | Â |
event_group_assignment_rule |
| Â | Â | Â |
event_old_group_assignment_rule |
| Â | Â | Â |
event_policy_id |
| Â | Â | Â |
event_policy_name |
| Â | Â | Â |
event_old_policy_name |
| Â | Â | Â |
event_policy_description |
| Â | Â | Â |
event_policy_type |
| Â | Â | Â |
event_policy_enabled |
| Â | Â | Â |
event_policy_platform |
| Â | Â | Â |
event_policy_assignment_rule |
| Â | Â | Â |
event_policy_settings_ReleaseID |
| Â | Â | Â |
event_old_policy_settings_ReleaseID |
| Â | Â | Â |
event_policy_settings_UninstallProtection |
| Â | Â | Â |
event_UserId |
| Â | Â | Â |
event_UserIp |
| Â | Â | Â |
event_OperationName |
| Â | Â | Â |
event_ServiceName |
| Â | Â | Â |
event_Success |
| Â | Â | Â |
event_UTCTimestamp |
| Â | Â | Â |
event_UTCTimestamp_formatted |
| Â | Â | Â |
event_ScanResults_Engine_str |
| event_ScanResults_Engine | Â | |
event_ScanResults_ResultName_str |
| event_ScanResults_ResultName | Â | |
event_ScanResults_Version_str |
| event_ScanResults_Version | Â | |
event_ScanResults_Detected_str |
| event_ScanResults_Detected | Â | |
event_PatternDispositionDescription |
| Â | Â | Â |
event_PatternDispositionValue |
| Â | Â | Â |
event_PatternDispositionFlags_Indicator |
| Â | Â | Â |
event_PatternDispositionFlags_Detect |
| Â | Â | Â |
event_PatternDispositionFlags_InddetMask |
| Â | Â | Â |
event_PatternDispositionFlags_SensorOnly |
| Â | Â | Â |
event_PatternDispositionFlags_Rooting |
| Â | Â | Â |
event_PatternDispositionFlags_KillProcess |
| Â | Â | Â |
event_PatternDispositionFlags_KillSubProcess |
| Â | Â | Â |
event_PatternDispositionFlags_QuarantineMachine |
| Â | Â | Â |
event_PatternDispositionFlags_QuarantineFile |
| Â | Â | Â |
event_PatternDispositionFlags_PolicyDisabled |
| Â | Â | Â |
event_PatternDispositionFlags_KillParent |
| Â | Â | Â |
event_PatternDispositionFlags_OperationBlocked |
| Â | Â | Â |
event_PatternDispositionFlags_ProcessBlocked |
| Â | Â | Â |
event_ParentImageFileName |
| Â | Â | Â |
event_ParentCommandLine |
| Â | Â | Â |
event_GrandparentImageFileName |
| Â | Â | Â |
event_GrandparentCommandLine |
| Â | Â | Â |
event_QuarantineFiles_ImageFileName_str |
| event_QuarantineFiles_ImageFileName | Â | |
event_QuarantineFiles_SHA256HashData_str |
| event_QuarantineFiles_SHA256HashData | Â | |
message |
| Â | rawSource | Â |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |
rawMessage |
|  | rawSource | ✓ |
edr.crowdstrike.cannon
Field | Type | Extra Label |
---|---|---|
eventdate |
| - |
aid |
| - |
aip |
| - |
cid |
| - |
event_platform |
| - |
event_type |
| - |
event_simpleName |
| - |
id |
| - |
name |
| - |
timestamp |
| - |
AuthenticationId |
| - |
CommandLine |
| - |
ConfigBuild |
| - |
ConfigStateHash |
| - |
EffectiveTransmissionClass |
| - |
Entitlements |
| - |
FullFilePath |
| - |
FilePath |
| - |
FileName |
| - |
ImageFileName |
| - |
ImageSubsystem |
| - |
IntegrityLevel |
| - |
MD5HashData |
| - |
ParentAuthenticationId |
| - |
ParentProcessId |
| - |
ProcessCreateFlags |
| - |
ProcessEndTime |
| - |
ProcessParameterFlags |
| - |
ProcessStartTime |
| - |
ProcessSxsFlags |
| - |
RawProcessId |
| - |
SHA1HashData |
| - |
SHA256HashData |
| - |
SourceProcessId |
| - |
SourceThreadId |
| - |
TargetFileName |
| - |
TargetProcessId |
| - |
SessionProcessId |
| - |
TokenType |
| - |
UserSid |
| - |
ComputerName |
| - |
ClientComputerName |
| - |
FirstIP4Record |
| - |
PhysicalAddress |
| - |
ContextProcessId |
| - |
LocalAddressIP4 |
| - |
LocalPort |
| - |
Protocol |
| - |
RemoteAddressIP4 |
| - |
RemotePort |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
tagGroup |
| - |
rawMessage |
| - |
edr.crowdstrike.cannon.associateindicator
Field | Type | Extra Field |
---|---|---|
eventdate |
| - |
hostname |
| - |
event_simpleName |
| - |
ContextTimeStamp |
| - |
ConfigStateHash |
| - |
aip |
| - |
SessionProcessId |
| - |
ConfigBuild |
| - |
PatternDisposition |
| - |
event_platform |
| - |
TargetProcessId |
| - |
PatternId |
| - |
Entitlements |
| - |
name |
| - |
id |
| - |
EffectiveTransmissionClass |
| - |
aid |
| - |
timestamp |
| - |
cid |
| - |
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |