Event Buffer Attribute | Helix Field Destination | Notes |
|---|---|---|
|
| True if a file close was observed during the write. |
|
| Up to 64 bytes of data written at the lowest offset. |
|
| |
|
| The raw device path of the file being written |
|
| The drive of the file being written |
|
| |
|
| The file extension being written |
|
| The filename being written |
|
| The relative path of the file being written |
|
| The full path of the file being written |
|
| The lowest offset in the file that was observed during the write |
|
| The md5 of the file |
|
| The number of bytes written during this write event |
|
| The file open duration |
|
| The file open time |
|
| |
|
| The ID of the parent of the process writing the file |
|
| The path for the PE of the parent process |
|
| The process ID writing the file |
|
| The path for the PE of the process writing the file |
|
| The name of the process writing the file |
|
| The path for the PE of the process writing the file |
|
| The size of the file being written |
|
| Raw text representation of |
|
| The owner of the process writing the file |
|
| The number of file write operations that were observed during the write. |
File Write Event
- Published on Sep 11, 2026
- 1 minute(s) read
Was this article helpful?