OpenIOC search terms supported by the xAgent

Prev Next

The following table lists the descriptions, types, and OpenIOC search terms supported by Endpoint Security (HX) xAgent release . These terms can be used with the /hx/api/v3/searches endpoint. See the Endpoint Security REST API Guide for more information.

  • Agent App Creation Date— date

    AgentInfo/appCreated

  • Agent App Start Date— date

    AgentInfo/appStarted

  • Agent App Version— string

    AgentInfo/appVersion

  • Agent Config Channel— string

    AgentInfo/configChannel

  • Agent Config ETag— string

    AgentInfo/configETag

  • Agent Config ID— string

    AgentInfo/configId

  • Agent Containment State— string

    AgentInfo/containmentState

  • Agent Containment Whitelist IP— IP

    AgentInfo/containmentWhitelistArray/ip/ip

  • Agent ExD Status— string

    AgentInfo/exdStatus

  • Agent Intel ETag— string

    AgentInfo/intelETag

  • Agent Intel Hash— md5

    AgentInfo/intelHash

  • State Agent Status— string

    AgentInfo/stateAgentStatus

  • ARP Cache Type— string

    ArpEntryItem/CacheType

  • ARP IPv4 Address— IP

    ArpEntryItem/IPv4Address

  • ARP IPv6 Address— IP

    ArpEntryItem/IPv6Address

  • ARP Interface— IP

    ArpEntryItem/Interface

  • ARP Interface Type— IP

    ArpEntryItem/InterfaceType

  • ARP Is Router— bool

    ArpEntryItem/IsRouter

  • ARP Last Reachable— date

    ArpEntryItem/LastReachable

  • ARP Last Unreachable— date

    ArpEntryItem/LastUnreachable

  • ARP Physical Address— string

    ArpEntryItem/PhysicalAddress

  • ARP State— string

    ArpEntryItem/State

  • Config Key— string

    ConfigItem/key

  • Config Value— string

    ConfigItem/val

  • CookieHistory Browser Name— string

    CookieHistoryItem/BrowserName

  • CookieHistory Browser Version— string

    CookieHistoryItem/BrowserVersion

  • CookieHistory Cookie Flags— string

    CookieHistoryItem/CookieFlags

  • CookieHistory Cookie Name— string

    CookieHistoryItem/CookieName

  • CookieHistory Cookie Path— string

    CookieHistoryItem/CookiePath

  • CookieHistory Cookie Value— string

    CookieHistoryItem/CookieValue

  • CookieHistory Creation Date— date

    CookieHistoryItem/CreationDate

  • CookieHistory Expiration Date— date

    CookieHistoryItem/ExpirationDate

  • CookieHistory File Name— string

    CookieHistoryItem/FileName

  • CookieHistory File Path— string

    CookieHistoryItem/FilePath

  • CookieHistory Host Name— string

    CookieHistoryItem/HostName

  • CookieHistory IsHttpOnly— string

    CookieHistoryItem/IsHttpOnly

  • CookieHistory IsSecure— bool

    CookieHistoryItem/IsSecure

  • CookieHistory Last Accessed Date— date

    CookieHistoryItem/LastAccessedDate

  • CookieHistory Last Modified Date— date

    CookieHistoryItem/LastModifiedDate

  • CookieHistory Profile— string

    CookieHistoryItem/Profile

  • CookieHistory Username— string

    CookieHistoryItem/Username

  • Disk Name— string

    DiskItem/DiskName

  • Disk Size— int

    DiskItem/DiskSize

  • Disk Partition Length— int

    DiskItem/PartitionList/Partition/PartitionLength

  • Disk Partition Number— int

    DiskItem/PartitionList/Partition/PartitionNumber

  • Disk Partition Offset— int

    DiskItem/PartitionList/Partition/PartitionOffset

  • Disk Partition Type— string

    DiskItem/PartitionList/Partition/PartitionType

  • DNS Data Length— int

    DnsEntryItem/DataLength

  • DNS Flags— string

    DnsEntryItem/Flags

  • DNS Host— string

    DnsEntryItem/Host

  • DNS Record Data ATM Address— string

    DnsEntryItem/RecordData/ATMAddress

  • DNS Record Data Address Type— string

    DnsEntryItem/RecordData/AddressType

  • DNS Record Data Administrator Name— string

    DnsEntryItem/RecordData/AdministratorName

  • DNS Record Data Algorithm— string

    DnsEntryItem/RecordData/Algorithm

  • DNS Record Data Bitmask— int

    DnsEntryItem/RecordData/Bitmask

  • DNS Record Data Blob— string

    DnsEntryItem/RecordData/Blob

  • DNS Record Data Cache Timeout— date

    DnsEntryItem/RecordData/CacheTimeout

  • DNS Record Data Creation Date— date

    DnsEntryItem/RecordData/CreationDate

  • DNS Record Data Date Signed— date

    DnsEntryItem/RecordData/DateSigned

  • DNS Record Data Default Time To Live— date

    DnsEntryItem/RecordData/DefaultTimeToLive

  • DNS Record Data Digest— string

    DnsEntryItem/RecordData/Digest

  • DNS Record Data Digest Length— int

    DnsEntryItem/RecordData/DigestLength

  • DNS Record Data Digest Type— string

    DnsEntryItem/RecordData/DigestType

  • DNS Record Data Error— string

    DnsEntryItem/RecordData/Error

  • DNS Record Data Expiration Date— date

    DnsEntryItem/RecordData/ExpirationDate

  • DNS Record Data Expire— date

    DnsEntryItem/RecordData/Expire

  • DNS Record Data Fudge Time— int

    DnsEntryItem/RecordData/FudgeTime

  • DNS Record Data Host— string

    DnsEntryItem/RecordData/Host

  • DNS Record Data IPv4 Address— IP

    DnsEntryItem/RecordData/IPv4Address

  • DNS Record Data IPv6 Address— IP

    DnsEntryItem/RecordData/IPv6Address

  • DNS Record Data Key— string

    DnsEntryItem/RecordData/Key

  • DNS Record Data Key Flags— int

    DnsEntryItem/RecordData/KeyFlags

  • DNS Record Data Key Length— int

    DnsEntryItem/RecordData/KeyLength

  • DNS Record Data Key Name— string

    DnsEntryItem/RecordData/KeyName

  • DNS Record Data Key Tag— int

    DnsEntryItem/RecordData/KeyTag

  • DNS Record Data Label Count— int

    DnsEntryItem/RecordData/LabelCount

  • DNS Record Data Lookup Timeout— date

    DnsEntryItem/RecordData/LookupTimeout

  • DNS Record Data Mailbox Errors Name— string

    DnsEntryItem/RecordData/MailboxErrorsName

  • DNS Record Data Mailbox Name— string

    DnsEntryItem/RecordData/MailboxName

  • DNS Record Data Mapping Flag— string

    DnsEntryItem/RecordData/MappingFlag

  • DNS Record Data Mode— string

    DnsEntryItem/RecordData/Mode

  • DNS Record Data MX Host— string

    DnsEntryItem/RecordData/MxHost

  • DNS Record Data Next Host— string

    DnsEntryItem/RecordData/NextHost

  • DNS Record Data Order— int

    DnsEntryItem/RecordData/Order

  • DNS Record Data Original Time To Live— date

    DnsEntryItem/RecordData/OriginalTimeToLive

  • DNS Record Data Original Xid— int

    DnsEntryItem/RecordData/OriginalXid

  • DNS Record Data Port— int

    DnsEntryItem/RecordData/Port

  • DNS Record Data Preference— int

    DnsEntryItem/RecordData/Preference

  • DNS Record Data Primary Server Name— string

    DnsEntryItem/RecordData/PrimaryServerName

  • DNS Record Data Priority— int

    DnsEntryItem/RecordData/Priority

  • DNS Record Data Protocol— string

    DnsEntryItem/RecordData/Protocol

  • DNS Record Data Public Key— string

    DnsEntryItem/RecordData/PublicKey

  • DNS Record Data Refresh— date

    DnsEntryItem/RecordData/Refresh

  • DNS Record Data Regular Expression— string

    DnsEntryItem/RecordData/RegularExpression

  • DNS Record Data Replacement — string

    DnsEntryItem/RecordData/Replacement

  • DNS Record Data Retry— date

    DnsEntryItem/RecordData/Retry

  • DNS Record Data Serial Number— int

    DnsEntryItem/RecordData/SerialNumber

  • DNS Record Data Services— string

    DnsEntryItem/RecordData/Services

  • DNS Record Data Signature— string

    DnsEntryItem/RecordData/Signature

  • DNS Record Data Signature Length— int

    DnsEntryItem/RecordData/SignatureLength

  • DNS Record Data Signer— string

    DnsEntryItem/RecordData/Signer

  • DNS Record Data String— string

    DnsEntryItem/RecordData/String

  • DNS Record Data Target Host — string

    DnsEntryItem/RecordData/TargetHost

  • DNS Record Data Type— string

    DnsEntryItem/RecordData/Type

  • DNS Record Data Type Covered— string

    DnsEntryItem/RecordData/TypeCovered

  • DNS Record Data Weight— int

    DnsEntryItem/RecordData/Weight

  • DNS Record Data WINS Server IPv4 Address— IP

    DnsEntryItem/RecordData/WinsServerIPv4Address

  • DNS Record Name— string

    DnsEntryItem/RecordName

  • DNS Record Type— string

    DnsEntryItem/RecordType

  • DNS Time To Live— string

    DnsEntryItem/TimeToLive

  • Driver Certificate Issuer— string

    DriverItem/CertificateIssuer

  • Driver Certificate Subject— string

    DriverItem/CertificateSubject

  • Driver Attached Device Name— string

    DriverItem/DeviceItem/AttachedDeviceName

  • Driver Attached Device Object— int

    DriverItem/DeviceItem/AttachedDeviceObject

  • Driver Attached Driver Name — string

    DriverItem/DeviceItem/AttachedDriverName

  • Driver Attached Driver Object— int

    DriverItem/DeviceItem/AttachedDriverObject

  • Driver Attached To Device Name— string

    DriverItem/DeviceItem/AttachedToDeviceName

  • Driver Attached To Device Object— int

    DriverItem/DeviceItem/AttachedToDeviceObject

  • Driver Attached To Driver Name— string

    DriverItem/DeviceItem/AttachedToDriverName

  • Driver Attached To Driver Object— int

    DriverItem/DeviceItem/AttachedToDriverObject

  • Driver Device Name— string

    DriverItem/DeviceItem/DeviceName

  • Driver Device Object— int

    DriverItem/DeviceItem/DeviceObject

  • Driver Device Driver Name— string

    DriverItem/DeviceItem/DriverName

  • Driver Init— int

    DriverItem/DriverInit

  • Driver Name— string

    DriverItem/DriverName

  • Driver Object Address— int

    DriverItem/DriverObjectAddress

  • Driver StartIo— int

    DriverItem/DriverStartIo

  • Driver Unload— int

    DriverItem/DriverUnload

  • DriverItem IRP_MJ_CLEANUP— int

    DriverItem/IRP_MJ_CLEANUP

  • DriverItem IRP_MJ_CLOSE— int

    DriverItem/IRP_MJ_CLOSE

  • DriverItem IRP_MJ_CREATE— int

    DriverItem/IRP_MJ_CREATE

  • DriverItem IRP_MJ_CREATE_MAILSLOT— int

    DriverItem/IRP_MJ_CREATE_MAILSLOT

  • DriverItem IRP_MJ_CREATE_NAMED_PIPE— int

    DriverItem/IRP_MJ_CREATE_NAMED_PIPE

  • DriverItem IRP_MJ_DEVICE_CHANGE— int

    DriverItem/IRP_MJ_DEVICE_CHANGE

  • DriverItem IRP_MJ_DEVICE_CONTROL— int

    DriverItem/IRP_MJ_DEVICE_CONTROL

  • DriverItem IRP_MJ_DIRECTORY_CONTROL— int

    DriverItem/IRP_MJ_DIRECTORY_CONTROL

  • DriverItem IRP_MJ_FILE_SYSTEM_CONTROL— int

    DriverItem/IRP_MJ_FILE_SYSTEM_CONTROL

  • DriverItem IRP_MJ_FLUSH_BUFFERS— int

    DriverItem/IRP_MJ_FLUSH_BUFFERS

  • DriverItem IRP_MJ_INTERNAL_DEVICE_CONTROL— int

    DriverItem/IRP_MJ_INTERNAL_DEVICE_CONTROL

  • DriverItem IRP_MJ_LOCK_CONTROL— int

    DriverItem/IRP_MJ_LOCK_CONTROL

  • DriverItem IRP_MJ_PNP— int

    DriverItem/IRP_MJ_PNP

  • DriverItem IRP_MJ_POWER— int

    DriverItem/IRP_MJ_POWER

  • DriverItem IRP_MJ_QUERY_EA— int

    DriverItem/IRP_MJ_QUERY_EA

  • DriverItem IRP_MJ_QUERY_INFORMATION— int

    DriverItem/IRP_MJ_QUERY_INFORMATION

  • DriverItem IRP_MJ_QUERY_QUOTA— int

    DriverItem/IRP_MJ_QUERY_QUOTA

  • DriverItem IRP_MJ_QUERY_SECURITY— int

    DriverItem/IRP_MJ_QUERY_SECURITY

  • DriverItem IRP_MJ_QUERY_VOLUME_INFORMATION— int

    DriverItem/IRP_MJ_QUERY_VOLUME_INFORMATION

  • DriverItem IRP_MJ_READ— int

    DriverItem/IRP_MJ_READ

  • DriverItem IRP_MJ_SET_EA— int

    DriverItem/IRP_MJ_SET_EA

  • DriverItem IRP_MJ_SET_INFORMATION— int

    DriverItem/IRP_MJ_SET_INFORMATION

  • DriverItem IRP_MJ_SET_QUOTA— int

    DriverItem/IRP_MJ_SET_QUOTA

  • DriverItem IRP_MJ_SET_SECURITY— int

    DriverItem/IRP_MJ_SET_SECURITY

  • DriverItem IRP_MJ_SET_VOLUME_INFORMATION— int

    DriverItem/IRP_MJ_SET_VOLUME_INFORMATION

  • DriverItem IRP_MJ_SHUTDOWN— int

    DriverItem/IRP_MJ_SHUTDOWN

  • DriverItem IRP_MJ_SYSTEM_CONTROL— int

    DriverItem/IRP_MJ_SYSTEM_CONTROL

  • DriverItem IRP_MJ_WRITE— int

    DriverItem/IRP_MJ_WRITE

  • Driver Image Base— int

    DriverItem/ImageBase

  • Driver Image Size— int

    DriverItem/ImageSize

  • Driver Md5sum— md5

    DriverItem/Md5sum

  • int Driver PEInfo Base Address— int

    DriverItem/PEInfo/BaseAddress

  • Driver PEInfo Detected Anomalies— string

    DriverItem/PEInfo/DetectedAnomalies/string

  • Driver PEInfo Detected Entry Point Signature Name— string

    DriverItem/PEInfo/DetectedEntryPointSignature/Name

  • Driver PEInfo Detected Entry Point Signature Type— string

    DriverItem/PEInfo/DetectedEntryPointSignature/Type

  • Driver Certificate Issuer— string

    DriverItem/PEInfo/DigitalSignature/CertificateIssuer

  • Driver Certificate Subject— string

    DriverItem/PEInfo/DigitalSignature/CertificateSubject

  • Driver Signature Description— string

    DriverItem/PEInfo/DigitalSignature/Description

  • Driver Signature Exists— bool

    DriverItem/PEInfo/DigitalSignature/SignatureExists

  • Driver Signature Verified— bool

    DriverItem/PEInfo/DigitalSignature/SignatureVerified

  • Driver PEInfo EpJumpCodes Depth— int

    DriverItem/PEInfo/EpJumpCodes/Depth

  • Driver PEInfo EpJumpCodes Opcodes— string

    DriverItem/PEInfo/EpJumpCodes/Opcodes

  • Driver Exported Function— string

    DriverItem/PEInfo/Exports/ExportedFunctions/string

  • Driver Exports Time Stamp— date

    DriverItem/PEInfo/Exports/ExportsTimeStamp

  • Driver Exports Dll Name— string

    DriverItem/PEInfo/Exports/DllName

  • Driver Number Of Functions— int

    DriverItem/PEInfo/Exports/NumberOfFunctions

  • Driver Number Of Names— int

    DriverItem/PEInfo/Exports/NumberOfNames

  • Driver PEInfo Extraneous Bytes— string

    DriverItem/PEInfo/ExtraneousBytes

  • Driver Imported Function— string

    DriverItem/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • Driver Imported Module Name— string

    DriverItem/PEInfo/ImportedModules/Module/Name

  • Driver PEInfo PEChecksum PEComputedAPI— int

    DriverItem/PEInfo/PEChecksum/PEComputedAPI

  • Driver PEInfo PEChecksum PEFileAPI — int

    DriverItem/PEInfo/PEChecksum/PEFileAPI

  • Driver PEInfo PEChecksum PEFileRaw— int

    DriverItem/PEInfo/PEChecksum/PEFileRaw

  • Driver PEInfo PETimeStamp— date

    DriverItem/PEInfo/PETimeStamp

  • Driver PEInfo Sections Section Detected Characteristics— string

    DriverItem/PEInfo/Sections/Section/DetectedCharacteristics

  • Driver PEInfo Sections Section Detected Signature Keys— string

    DriverItem/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • Driver PEInfo Sections Section Entropy CurveData float— float

    DriverItem/PEInfo/Sections/Section/Entropy/CurveData/float

  • Driver PEInfo Sections Section Name— string

    DriverItem/PEInfo/Sections/Section/Name

  • Driver PEInfo Sections Section Size— int

    DriverItem/PEInfo/Sections/Section/SizeInBytes

  • Driver PEInfo Sections Section Type — string

    DriverItem/PEInfo/Sections/Section/Type

  • Driver PEInfo Subsystem— string

    DriverItem/PEInfo/Subsystem

  • Driver PEInfo Type— string

    DriverItem/PEInfo/Type

  • Driver Sha1sum— sha1

    DriverItem/Sha1sum

  • Driver Sha256sum— sha256

    DriverItem/Sha256sum

  • Driver Signature Description— string

    DriverItem/SignatureDescription

  • Driver Signature Exists— bool

    DriverItem/SignatureExists

  • Driver Signature Verified— bool

    DriverItem/SignatureVerified

  • Driver String— string

    DriverItem/StringList/string

  • Email attachment content— string

    Email/Attachment/Content

  • Email Attachment MIME Type— string

    Email/Attachment/MIMEType

  • Email Attachment Name— string

    Email/Attachment/Name

  • Email Attachment Size— int

    Email/Attachment/SizeInBytes

  • Email Attachment Count— int

    Email/AttachmentCount

  • Email BCC Recipient(s)— string

    Email/BCC

  • Email Body Text— string

    Email/Body

  • Email CC Recipients(s)— string

    Email/CC

  • Email Content-Type— string

    Email/Content-Type

  • Email Date (Sent)— date

    Email/Date

  • Email Sender— string

    Email/From

  • Email In-Reply-To— string

    Email/In-Reply-To

  • Email MIME-Version— string

    Email/MIME-Version

  • Email Received Date— string

    Email/Received

  • Email Received From Host— string

    Email/ReceivedFromHost

  • Email Received From IP— IP

    Email/ReceivedFromIP

  • Email References— string

    Email/References

  • Email Return Path— string

    Email/Return-Path

  • Email Subject— string

    Email/Subject

  • Email Thread-Index— string

    Email/Thread-Index

  • Email Thread-Topic— string

    Email/Thread-Topic

  • Email Recipients— string

    Email/To

  • Email X-MS-Has-Attach— string

    Email/X-MS-Has-Attach

  • Email X-filenames— string

    Email/X-filenames

  • Email X-filesizes— int

    Email/X-filesizes

  • Email X-filetypes— string

    Email/X-filetypes

  • EventLog Correlation Activity Id— string

    EventLogItem/CorrelationActivityId

  • EventLog Correlation Related Activity Id— string

    EventLogItem/CorrelationRelatedActivityId

  • EventLog ID— int

    EventLogItem/EID

  • EventLog Execution Process Id— int

    EventLogItem/ExecutionProcessId

  • EventLog Execution Thread Id— int

    EventLogItem/ExecutionThreadId

  • EventLog blob— string

    EventLogItem/blob

  • EventLog category— string

    EventLogItem/category

  • EventLog categoryNum— string

    EventLogItem/categoryNum

  • EventLog GenTime— date

    EventLogItem/genTime

  • EventLog index— int

    EventLogItem/index

  • EventLog log— string

    EventLogItem/log

  • EventLog machine— string

    EventLogItem/machine

  • EventLog Message— string

    EventLogItem/message

  • EventLog reserved— string

    EventLogItem/reserved

  • EventLog source— string

    EventLogItem/source

  • EventLog type— string

    EventLogItem/type

  • EventLog unformatted Message— string

    EventLogItem/unformattedMessage/string

  • EventLog user— string

    EventLogItem/user

  • EventLog writeTime— date

    EventLogItem/writeTime

  • FileDownloadHistory AutoResume— string

    FileDownloadHistoryItem/AutoResume

  • FileDownloadHistory Browser Name— string

    FileDownloadHistoryItem/BrowserName

  • FileDownloadHistory Browser Version— string

    FileDownloadHistoryItem/BrowserVersion

  • FileDownloadHistory Bytes Downloaded— int

    FileDownloadHistoryItem/BytesDownloaded

  • FileDownloadHistory Cache Flags— string

    FileDownloadHistoryItem/CacheFlags

  • FileDownloadHistory Cache Hit Coun— int

    FileDownloadHistoryItem/CacheHitCount

  • FileDownloadHistory Download Type— string

    FileDownloadHistoryItem/DownloadType

  • FileDownloadHistory End Date— date

    FileDownloadHistoryItem/EndDate

  • FileDownloadHistory File Name— string

    FileDownloadHistoryItem/FileName

  • FileDownloadHistory Full Http Header— string

    FileDownloadHistoryItem/FullHttpHeader

  • FileDownloadHistory Last Accessed Date— date

    FileDownloadHistoryItem/LastAccessedDate

  • FileDownloadHistory Last Cache Synch Date— date

    FileDownloadHistoryItem/LastCacheSynchDate

  • FileDownloadHistory Last Checked Date— date

    FileDownloadHistoryItem/LastCheckedDate

  • FileDownloadHistory Last Modified Date— date

    FileDownloadHistoryItem/LastModifiedDate

  • FileDownloadHistory Max Bytes— int

    FileDownloadHistoryItem/MaxBytes

  • FileDownloadHistory MimeType— string

    FileDownloadHistoryItem/MimeType

  • FileDownloadHistory Profile— string

    FileDownloadHistoryItem/Profile

  • FileDownloadHistory Referrer— string

    FileDownloadHistoryItem/Referrer

  • FileDownloadHistory Source URL— string

    FileDownloadHistoryItem/SourceURL

  • FileDownloadHistory Start Date— date

    FileDownloadHistoryItem/StartDate

  • FileDownloadHistory State— string

    FileDownloadHistoryItem/State

  • FileDownloadHistory Target Directory— string

    FileDownloadHistoryItem/TargetDirectory

  • FileDownloadHistory Temporary Path— string

    FileDownloadHistoryItem/TemporaryPath

  • FileDownloadHistory Username— string

    FileDownloadHistoryItem/Username

  • File Accessed Time— date

    FileItem/Accessed

  • File Changed Time— date

    FileItem/Changed

  • File Created Time— date

    FileItem/Created

  • File DevicePath— string

    FileItem/DevicePath

  • File Drive— string

    FileItem/Drive

  • File Attribute— string

    FileItem/FileAttributes

  • File Extension— string

    FileItem/FileExtension

  • File Name— string

    FileItem/FileName

  • File Path— string

    FileItem/FilePath

  • File Filename Accessed— date

    FileItem/FilenameAccessed

  • File Filename Changed— date

    FileItem/FilenameChanged

  • File Filename Created— date

    FileItem/FilenameCreated

  • File Filename Modified— date

    FileItem/FilenameModified

  • File Full Path— string

    FileItem/FullPath

  • File INode— int

    FileItem/INode

  • File MD5— md5

    FileItem/Md5sum

  • File Modified Time— date

    FileItem/Modified

  • detectedAnomaly— string

    FileItem/detectedAnomaly

  • File Base Address— int

    FileItem/PEInfo/BaseAddress

  • File PE Detected Anomalies— string

    FileItem/PEInfo/DetectedAnomalies/string

  • File EntryPoint Sig Name— string

    FileItem/PEInfo/DetectedEntryPointSignature/Name

  • File EntryPoint Sig Type— string

    FileItem/PEInfo/DetectedEntryPointSignature/Type

  • File Certificate Issuer— string

    FileItem/PEInfo/DigitalSignature/CertificateIssuer

  • File Certificate Subject— string

    FileItem/PEInfo/DigitalSignature/CertificateSubject

  • File Digital Signature Description— string

    FileItem/PEInfo/DigitalSignature/Description

  • File Digital Signature Exists— bool

    FileItem/PEInfo/DigitalSignature/SignatureExists

  • File Digital Signature Verified— bool

    FileItem/PEInfo/DigitalSignature/SignatureVerified

  • File Double Jump— int

    FileItem/PEInfo/EpJumpCodes/Depth

  • File PEInfo EpJumpCodes Opcodes— string

    FileItem/PEInfo/EpJumpCodes/Opcodes

  • File Dll Export Name— string

    FileItem/PEInfo/Exports/DllName

  • File Export Function— string

    FileItem/PEInfo/Exports/ExportedFunctions/string

  • File Exports Time Stamp— date

    FileItem/PEInfo/Exports/ExportsTimeStamp

  • File Export Count— int

    FileItem/PEInfo/Exports/NumberOfFunctions

  • File Export Number Of Names— int

    FileItem/PEInfo/Exports/NumberOfNames

  • File Extraneous Bytes— string

    FileItem/PEInfo/ExtraneousBytes

  • File Import Function— string

    FileItem/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • File Import Name— string

    FileItem/PEInfo/ImportedModules/Module/Name

  • File Number of Imported Functions— int

    FileItem/PEInfo/ImportedModules/Module/NumberOfFunctions

  • File PE ComputedAPI— int

    FileItem/PEInfo/PEChecksum/PEComputedAPI

  • File PE Checksum API— int

    FileItem/PEInfo/PEChecksum/PEFileAPI

  • File PEFileRaw— int

    FileItem/PEInfo/PEChecksum/PEFileRaw

  • File Compile Time— date

    FileItem/PEInfo/PETimeStamp

  • File PEInfo Resource Info Data— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Data

  • File PEInfo Resource Info Language— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Language

  • File PEInfo Resource Info Name— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Name

  • File PEInfo Resource Info Size— int

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Size

  • File PEInfo Resource Info Type— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Type

  • File PEInfo Number of Sections— int

    FileItem/PEInfo/Sections/NumberOfSections

  • File PEInfo Actual Number of Sections— int

    FileItem/PEInfo/Sections/ActualNumberOfSections

  • File Detected Characteristics— string

    FileItem/PEInfo/Sections/Section/DetectedCharacteristics

  • File Detected Signatures— string

    FileItem/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • File PEInfo Sections Section Entropy CurveData— float

    FileItem/PEInfo/Sections/Section/Entropy/CurveData/float

  • File Section Name— string

    FileItem/PEInfo/Sections/Section/Name

  • File PE Section Size— int

    FileItem/PEInfo/Sections/Section/SizeInBytes

  • File PE Section Type— string

    FileItem/PEInfo/Sections/Section/Type

  • File PE Subsystem— string

    FileItem/PEInfo/Subsystem

  • File PE Type— string

    FileItem/PEInfo/Type

  • File PEInfo Version Info Comments— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/Comments

  • File PEInfo Version Info CompanyName— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/CompanyName

  • File PEInfo Version Info FileDescription— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileDescription

  • File PEInfo Version Info FileVersion— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileVersion

  • File PEInfo Version Info InternalName— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/InternalName

  • File PEInfo Version Info Language— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/Language

  • File PEInfo Version Info LegalCopyright— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalCopyright

  • File PEInfo Version Info LegalTrademarks— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalTrademarks

  • File PEInfo Version Info OriginalFilename— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/OriginalFilename

  • File PEInfo Version Info PrivateBuild— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/PrivateBuild

  • File PEInfo Version Info ProductName— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductName

  • File PEInfo Version Info ProductVersion— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductVersion

  • File PEInfo Version Info SpecialBuild— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/SpecialBuild

  • File Peak Code Entropy— float

    FileItem/PeakCodeEntropy

  • File Peak Entropy— float

    FileItem/PeakEntropy

  • File Security ID— string

    FileItem/SecurityID

  • File Security Type— string

    FileItem/SecurityType

  • File Sha1sum— sha1

    FileItem/Sha1sum

  • File Sha256sum— sha256

    FileItem/Sha256sum

  • File Size— int

    FileItem/SizeInBytes

  • File ADS MD5— md5

    FileItem/StreamList/Stream/Md5sum

  • File ADS Name— string

    FileItem/StreamList/Stream/Name

  • File Stream Sha1sum— sha1

    FileItem/StreamList/Stream/Sha1sum

  • File Stream Sha256sum— sha256

    FileItem/StreamList/Stream/Sha256sum

  • File ADS Size— int

    FileItem/StreamList/Stream/SizeInBytes

  • File Strings— string

    FileItem/StringList/string

  • File Owner— string

    FileItem/Username

  • FormHistory Browser Name— string

    FormHistoryItem/BrowserName

  • FormHistory Browser Version— string

    FormHistoryItem/BrowserVersion

  • FormHistory Creation Date— date

    FormHistoryItem/CreationDate

  • FormHistory Encrypted Password— string

    FormHistoryItem/EncryptedPassword

  • FormHistory Encryption Type— string

    FormHistoryItem/EncryptionType

  • FormHistory First Used Date— date

    FormHistoryItem/FirstUsedDate

  • FormHistory Form Field Name— string

    FormHistoryItem/FormFieldName

  • FormHistory Form Field Value— string

    FormHistoryItem/FormFieldValue

  • FormHistory Form Submit URL— string

    FormHistoryItem/FormSubmitURL

  • FormHistory Form Type— string

    FormHistoryItem/FormType

  • FormHistory Guid— string

    FormHistoryItem/Guid

  • FormHistory Host Name— string

    FormHistoryItem/HostName

  • FormHistory Http Realm— string

    FormHistoryItem/HttpRealm

  • FormHistory Last Used Date— date

    FormHistoryItem/LastUsedDate

  • FormHistory Password Field Name— string

    FormHistoryItem/PasswordFieldName

  • FormHistory Profile— string

    FormHistoryItem/Profile

  • FormHistory Times Used— int

    FormHistoryItem/TimesUsed

  • FormHistory Username— string

    FormHistoryItem/Username

  • FormHistory Username Field Name— string

    FormHistoryItem/UsernameFieldName

  • FormHistory Username Field Value— string

    FormHistoryItem/UsernameFieldValue

  • Hive Name— string

    HiveItem/Name

  • Hive Path— string

    HiveItem/Path

  • Hook Digital Signature Hooked Certificate Issuer— string

    HookItem/DigitalSignatureHooked/CertificateIssuer

  • Hook Digital Signature Hooked Certificate Subject— string

    HookItem/DigitalSignatureHooked/CertificateSubject

  • Hook Digital Signature Hooked Description— string

    HookItem/DigitalSignatureHooked/Description

  • Hook Digital Signature Hooked Signature Exists— bool

    HookItem/DigitalSignatureHooked/SignatureExists

  • Hook Digital Signature Hooked Signature Verified— bool

    HookItem/DigitalSignatureHooked/SignatureVerified

  • Hook Digital Signature Hooking Certificate Issuer— string

    HookItem/DigitalSignatureHooking/CertificateIssuer

  • Hook Digital Signature Hooking Certificate Subject— string

    HookItem/DigitalSignatureHooking/CertificateSubject

  • Hook Digital Signature Hooking Description— string

    HookItem/DigitalSignatureHooking/Description

  • Hook Digital Signature Hooking Signature Exists— bool

    HookItem/DigitalSignatureHooking/SignatureExists

  • Hook Digital Signature Hooking Signature Verified— bool

    HookItem/DigitalSignatureHooking/SignatureVerified

  • Hook Description— string

    HookItem/HookDescription

  • Hook Hooked Function— string

    HookItem/HookedFunction

  • Hook Hooked Module— string

    HookItem/HookedModule

  • Hook Hooking Address— int

    HookItem/HookingAddress

  • Hook Hooking Module— string

    HookItem/HookingModule

  • Log Line Argument— string

    Log/args/arg

  • Log Line Flags— int

    Log/flags

  • Log Line Function— string

    Log/fn

  • Log Line High-Resolution Time— int

    Log/hr

  • Log Line LID— int

    Log/lid

  • Log Line Function Line Number— int

    Log/ln

  • Log Line Level— string

    Log/lvl

  • Log Line Message— string

    Log/msg

  • Log Line PID— int

    Log/pid

  • Log Line TID— int

    Log/tid

  • Log Line Date— date

    Log/time

  • Log Line UID— int

    Log/uid

  • Module Address— int

    ModuleItem/ModuleAddress

  • Module Base— int

    ModuleItem/ModuleBase

  • Module Init— int

    ModuleItem/ModuleInit

  • Module Name— string

    ModuleItem/ModuleName

  • Module Path— string

    ModuleItem/ModulePath

  • Module Size— int

    ModuleItem/ModuleSize

  • Network DNS— string

    Network/DNS

  • Network String HTTP Referr— string

    Network/HTTP_Referr

  • Network String General— string

    Network/String

  • Network String URI— string

    Network/URI

  • Network String User Agent— string

    Network/UserAgent

  • Persistence FileItem Accessed— date

    PersistenceItem/FileItem/Accessed

  • Persistence FileItem Changed— date

    PersistenceItem/FileItem/Changed

  • Persistence FileItem Created— date

    PersistenceItem/FileItem/Created

  • Persistence FileItem Device Path— string

    PersistenceItem/FileItem/DevicePath

  • Persistence FileItem Drive— string

    PersistenceItem/FileItem/Drive

  • Persistence FileItem File Attributes— string

    PersistenceItem/FileItem/FileAttributes

  • Persistence FileItem File Extension— string

    PersistenceItem/FileItem/FileExtension

  • Persistence FileItem File Name— string

    PersistenceItem/FileItem/FileName

  • Persistence FileItem File Path— string

    PersistenceItem/FileItem/FilePath

  • Persistence FileItem Filename Accessed— date

    PersistenceItem/FileItem/FilenameAccessed

  • Persistence FileItem Filename Changed— date

    PersistenceItem/FileItem/FilenameChanged

  • Persistence FileItem Filename Created— date

    PersistenceItem/FileItem/FilenameCreated

  • Persistence FileItem Filename Modified— date

    PersistenceItem/FileItem/FilenameModified

  • Persistence FileItem Full Path— string

    PersistenceItem/FileItem/FullPath

  • Persistence FileItem INode— int

    PersistenceItem/FileItem/INode

  • Persistence FileItem Md5sum— md5

    PersistenceItem/FileItem/Md5sum

  • Persistence FileItem Modified— date

    PersistenceItem/FileItem/Modified

  • Persistence FileItem Size In Bytes— int

    PersistenceItem/FileItem/SizeInBytes

  • Persistence FileItem PEInfo Base Address— int

    PersistenceItem/FileItem/PEInfo/BaseAddress

  • Persistence FileItem PEInfo Detected Anomalies string— string

    PersistenceItem/FileItem/PEInfo/DetectedAnomalies/string

  • Persistence FileItem PEInfo Detected Entry Point Signature Name— string

    PersistenceItem/FileItem/PEInfo/DetectedEntryPointSignature/Name

  • Persistence FileItem PEInfo Detected Entry Point Signature Type— string

    PersistenceItem/FileItem/PEInfo/DetectedEntryPointSignature/Type

  • Persistence FileItem PEInfo DigitalSignature Certificate Issuer — string

    PersistenceItem/FileItem/PEInfo/DigitalSignature/CertificateIssuer

  • Persistence FileItem PEInfo DigitalSignature Certificate Subject— string

    PersistenceItem/FileItem/PEInfo/DigitalSignature/CertificateSubject

  • Persistence FileItem PEInfo DigitalSignature Description— string

    PersistenceItem/FileItem/PEInfo/DigitalSignature/Description

  • Persistence FileItem PEInfo DigitalSignature Signature Exists— bool

    PersistenceItem/FileItem/PEInfo/DigitalSignature/SignatureExists

  • Persistence FileItem PEInfo DigitalSignature Signature Verified — bool

    PersistenceItem/FileItem/PEInfo/DigitalSignature/SignatureVerified

  • Persistence FileItem PEInfo EpJumpCodes Depth— int

    PersistenceItem/FileItem/PEInfo/EpJumpCodes/Depth

  • Persistence FileItem PEInfo EpJumpCodes Opcodes— string

    PersistenceItem/FileItem/PEInfo/EpJumpCodes/OpCodes

  • Persistence FileItem PEInfo Exports Exported Functions string— string

    PersistenceItem/FileItem/PEInfo/Exports/ExportedFunctions/string

  • Persistence FileItem PEInfo Exports Exports Time Stamp— date

    PersistenceItem/FileItem/PEInfo/Exports/ExportsTimeStamp

  • Persistence FileItem PEInfo Exports Number Of Functions— int

    PersistenceItem/FileItem/PEInfo/Exports/NumberOfFunctions

  • Persistence FileItem PEInfo Exports Number Of Names— int

    PersistenceItem/FileItem/PEInfo/Exports/NumberOfNames

  • Persistence FileItem PEInfo Extraneous Bytes— int

    PersistenceItem/FileItem/PEInfo/ExtraneousBytes

  • Persistence FileItem PEInfo Imported Modules Module Imported Functions string— string

    PersistenceItem/FileItem/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • Persistence FileItem PEInfo Imported Modules Module Name— string

    PersistenceItem/FileItem/PEInfo/ImportedModules/Module/Name

  • Persistence FileItem PEInfo PEChecksum PE Computed API— int

    PersistenceItem/FileItem/PEInfo/PEChecksum/PEComputedAPI

  • Persistence FileItem PEInfo PEChecksum PE File API— int

    PersistenceItem/FileItem/PEInfo/PEChecksum/PEFileAPI

  • Persistence FileItem PEInfo PEChecksum PE File Raw— int

    PersistenceItem/FileItem/PEInfo/PEChecksum/PEFileRaw

  • Persistence FileItem PEInfo PE Time Stamp— date

    PersistenceItem/FileItem/PEInfo/PETimeStamp

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Language— string

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Language

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Name— string

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Name

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Size— int

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Size

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Type— string

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Type

  • Persistence FileItem PEInfo Sections Section Detected Characteristics— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/DetectedCharacteristics

  • Persistence FileItem PEInfo Sections Section Detected Signature Keys string— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • Persistence FileItem PEInfo Sections Section Entropy Curve Data float— float

    PersistenceItem/FileItem/PEInfo/Sections/Section/Entropy/CurveData/float

  • Persistence FileItem PEInfo Sections Section Name— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/Name

  • Persistence FileItem PEInfo Sections Section SizeInBytes— int

    PersistenceItem/FileItem/PEInfo/Sections/Section/SizeInBytes

  • Persistence FileItem PEInfo Sections Section Type— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/Type

  • Persistence FileItem PEInfo Subsystem— string

    PersistenceItem/FileItem/PEInfo/Subsystem

  • Persistence FileItem PEInfo Type— string

    PersistenceItem/FileItem/PEInfo/Type

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Comments— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/Comments

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Company Name— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/CompanyName

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem File Description— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileDescription

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem File Version— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileVersion

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Internal Name— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/InternalName

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Language— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/Language

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Legal Copyright— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalCopyright

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Legal Trademarks— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalTrademarks

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Original Filename— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/OriginalFilename

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Private Build— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/PrivateBuild

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Product Name— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductName

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Product Version — string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductVersion

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Special Build— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/SpecialBuild

  • Persistence FileItem Peak Code Entropy— int

    PersistenceItem/FileItem/PeakCodeEntropy

  • Persistence FileItem Peak Entropy— int

    PersistenceItem/FileItem/PeakEntropy

  • Persistence FileItem Security ID— string

    PersistenceItem/FileItem/SecurityID

  • Persistence FileItem Security Type— string

    PersistenceItem/FileItem/SecurityType

  • Persistence FileItem Sha1sum— sha1

    PersistenceItem/FileItem/Sha1sum

  • Persistence FileItem Sha256sum— sha256

    PersistenceItem/FileItem/Sha256sum

  • Persistence FileItem Stream List Stream Md5sum— int

    PersistenceItem/FileItem/StreamList/Stream/Md5sum

  • Persistence FileItem Stream List Stream Name— string

    PersistenceItem/FileItem/StreamList/Stream/Name

  • Persistence FileItem Stream List Stream Sha1sum— sha1

    PersistenceItem/FileItem/StreamList/Stream/Sha1sum

  • Persistence FileItem Stream List Stream Sha256sum— sha256

    PersistenceItem/FileItem/StreamList/Stream/Sha256sum

  • Persistence FileItem Stream List Stream Size In Bytes— int

    PersistenceItem/FileItem/StreamList/Stream/SizeInBytes

  • Persistence FileItem Username— string

    PersistenceItem/FileItem/Username

  • Persistence Link File Path — string

    PersistenceItem/LinkFilePath

  • Persistence Type— string

    PersistenceItem/PersistenceType

  • Persistence Reg Context— string

    PersistenceItem/RegContext

  • Persistence RegistryItem Hive— string

    PersistenceItem/RegistryItem/Hive

  • Persistence RegistryItem Key Path— string

    PersistenceItem/RegistryItem/KeyPath

  • Persistence RegistryItem NumSubKeys— int

    PersistenceItem/RegistryItem/NumSubKeys

  • Persistence RegistryItem NumValues— string

    PersistenceItem/RegistryItem/NumValues

  • Persistence RegistryItem Modified— date

    PersistenceItem/RegistryItem/Modified

  • Persistence RegistryItem Path— string

    PersistenceItem/RegistryItem/Path

  • Persistence RegistryItem Reported Length In Bytes— int

    PersistenceItem/RegistryItem/ReportedLengthInBytes

  • Persistence RegistryItem Security ID— string

    PersistenceItem/RegistryItem/SecurityID

  • Persistence RegistryItem Text— string

    PersistenceItem/RegistryItem/Text

  • Persistence RegistryItem Type— string

    PersistenceItem/RegistryItem/Type

  • Persistence RegistryItem Username— string

    PersistenceItem/RegistryItem/Username

  • Persistence RegistryItem Value— string

    PersistenceItem/RegistryItem/Value

  • Persistence RegistryItem Value Name— string

    PersistenceItem/RegistryItem/ValueName

  • Persistence ServiceItem Arguments— string

    PersistenceItem/ServiceItem/arguments

  • Persistence ServiceItem Description— string

    PersistenceItem/ServiceItem/description

  • Persistence ServiceItem Descriptive Name— string

    PersistenceItem/ServiceItem/descriptiveName

  • Persistence ServiceItem Mode— string

    PersistenceItem/ServiceItem/mode

  • Persistence ServiceItem Name— string

    PersistenceItem/ServiceItem/name

  • Persistence ServiceItem Path— string

    PersistenceItem/ServiceItem/path

  • Persistence ServiceItem Path Certificate Issuer— string

    PersistenceItem/ServiceItem/pathCertificateIssuer

  • Persistence ServiceItem Path Certificate Subject— string

    PersistenceItem/ServiceItem/pathCertificateSubject

  • Persistence ServiceItem Path Signature Description— string

    PersistenceItem/ServiceItem/pathSignatureDescription

  • Persistence ServiceItem Path Signature Exists— bool

    PersistenceItem/ServiceItem/pathSignatureExists

  • Persistence ServiceItem Path Signature Verified— bool

    PersistenceItem/ServiceItem/pathSignatureVerified

  • Persistence ServiceItem Path Md5sum— md5

    PersistenceItem/ServiceItem/pathmd5sum

  • Persistence ServiceItem Path Sha1sum— sha1

    PersistenceItem/ServiceItem/pathsha1sum

  • Persistence ServiceItem Path Sha256sum— sha256

    PersistenceItem/ServiceItem/pathsha256sum

  • Persistence ServiceItem PID— int

    PersistenceItem/ServiceItem/pid

  • Persistence ServiceItem Service DLL— string

    PersistenceItem/ServiceItem/serviceDLL

  • Persistence ServiceItem Service DLL Certificate Issuer— string

    PersistenceItem/ServiceItem/serviceDLLCertificateIssuer

  • Persistence ServiceItem Service DLL Certificate Subject— string

    PersistenceItem/ServiceItem/serviceDLLCertificateSubject

  • Persistence ServiceItem Service DLL Signature Description— string

    PersistenceItem/ServiceItem/serviceDLLSignatureDescription

  • Persistence ServiceItem Service DLL Signature Exists— bool

    PersistenceItem/ServiceItem/serviceDLLSignatureExists

  • Persistence ServiceItem Service DLL Signature Verified— bool

    PersistenceItem/ServiceItem/serviceDLLSignatureVerified

  • Persistence ServiceItem Service DLL Md5sum— md5

    PersistenceItem/ServiceItem/serviceDLLmd5sum

  • Persistence ServiceItem Service DLL Sha1sum— sha1

    PersistenceItem/ServiceItem/serviceDLLsha1sum

  • Persistence ServiceItem Service DLL Sha256sum— sha256

    PersistenceItem/ServiceItem/serviceDLLsha256sum

  • Persistence ServiceItem Started As— string

    PersistenceItem/ServiceItem/startedAs

  • Persistence ServiceItem Status— string

    PersistenceItem/ServiceItem/status

  • Persistence ServiceItem Type— string

    PersistenceItem/ServiceItem/type

  • Port Creation Time— date

    PortItem/CreationTime

  • Port Local IP— IP

    PortItem/localIP

  • Port Local Port— int

    PortItem/localPort

  • Port Path— string

    PortItem/path

  • Port PID— int

    PortItem/pid

  • Port Process— string

    PortItem/process

  • Port Protocol— string

    PortItem/protocol

  • Port Remote IP— IP

    PortItem/remoteIP

  • Port Remote Port— int

    PortItem/remotePort

  • Port State— string

    PortItem/state

  • Prefetch Accessed File— string

    PrefetchItem/AccessedFileList/AccessedFile

  • Prefetch File Executed— string

    PrefetchItem/ApplicationFileName

  • Prefetch Application Full Path— string

    PrefetchItem/ApplicationFullPath

  • Prefetch File Created— date

    PrefetchItem/Created

  • Prefetch Full Path— string

    PrefetchItem/FullPath

  • Prefetch Last Run— date

    PrefetchItem/LastRun

  • Prefetch Hash— string

    PrefetchItem/PrefetchHash

  • Prefetch Volume Device Path— string

    PrefetchItem/VolumeList/VolumeItem/DevicePath

  • Prefetch Volume Creation Time— date

    PrefetchItem/VolumeList/VolumeItem/CreationTime

  • Prefetch Volume Serial Number— string

    PrefetchItem/VolumeList/VolumeItem/SerialNumber

  • Prefetch Reported Size— int

    PrefetchItem/ReportedSizeInBytes

  • Prefetch Size— int

    PrefetchItem/SizeInBytes

  • Prefetch Times Executed— int

    PrefetchItem/TimesExecuted

  • Process Handle Access Mask— string

    ProcessItem/HandleList/Handle/AccessMask

  • Process Handle Count— int

    ProcessItem/HandleList/Handle/HandleCount

  • Process Handle Index— int

    ProcessItem/HandleList/Handle/Index

  • Process Handle Name— string

    ProcessItem/HandleList/Handle/Name

  • Process Handle Object Address— string

    ProcessItem/HandleList/Handle/ObjectAddress

  • Process Handle Pointer Count— string

    ProcessItem/HandleList/Handle/PointerCount

  • Process Handle Type— string

    ProcessItem/HandleList/Handle/Type

  • Process Port Creation Time— date

    ProcessItem/PortList/PortItem/CreationTime

  • Process Port Local IP— IP

    ProcessItem/PortList/PortItem/localIP

  • Process Local Port— int

    ProcessItem/PortList/PortItem/localPort

  • Process Port Path— string

    ProcessItem/PortList/PortItem/path

  • Process Port PID— int

    ProcessItem/PortList/PortItem/pid

  • Process Port Process— string

    ProcessItem/PortList/PortItem/process

  • Process Port Protocol— string

    ProcessItem/PortList/PortItem/protocol

  • Process Port Remote IP— IP

    ProcessItem/PortList/PortItem/remoteIP

  • Process Remote Port— int

    ProcessItem/PortList/PortItem/remotePort

  • Process State— string

    ProcessItem/PortList/PortItem/state

  • Process Section Certificate Issuer— string

    ProcessItem/SectionList/MemorySection/DigitalSignature/CertificateIssuer

  • Process Section Certificate Subject— string

    ProcessItem/SectionList/MemorySection/DigitalSignature/CertificateSubject

  • Process Section Signature Description— string

    ProcessItem/SectionList/MemorySection/DigitalSignature/Description

  • Process Section Signature Exists— bool

    ProcessItem/SectionList/MemorySection/DigitalSignature/SignatureExists

  • Process Section Signature Verified— bool

    ProcessItem/SectionList/MemorySection/DigitalSignature/SignatureVerified

  • Process Section Injected— bool

    ProcessItem/SectionList/MemorySection/Injected

  • Process Mapped— string

    ProcessItem/SectionList/MemorySection/Mapped

  • Process Section MD5— md5

    ProcessItem/SectionList/MemorySection/Md5sum

  • Process Section MemD5— md5

    ProcessItem/SectionList/MemorySection/MemD5

  • Process Section Name— string

    ProcessItem/SectionList/MemorySection/Name

  • Process SectionList MemorySection PEInfo Base Address— int

    ProcessItem/SectionList/MemorySection/PEInfo/BaseAddress

  • Process SectionList MemorySection PEInfo Detected Anomalies— string

    ProcessItem/SectionList/MemorySection/PEInfo/DetectedAnomalies/string

  • Process SectionList MemorySection PEInfo Detected EntryPoint Signature Name— string

    ProcessItem/SectionList/MemorySection/PEInfo/DetectedEntryPointSignature/Name

  • Process SectionList MemorySection PEInfo Detected EntryPoint Signature Type— string

    ProcessItem/SectionList/MemorySection/PEInfo/DetectedEntryPointSignature/Type

  • Process SectionList MemorySection PEInfo Digital Signature Certificate Issuer— string

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/CertificateIssuer

  • Process SectionList MemorySection PEInfo Digital Signature Certificate Subject— string

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/CertificateSubject

  • Process SectionList MemorySection PEInfo Digital Signature Description— string

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/Description

  • Process SectionList MemorySection PEInfo Digital Signature Signature Exists— bool

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/SignatureExists

  • Process SectionList MemorySection PEInfo Digital Signature Signature Verified— bool

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/SignatureVerified

  • Process SectionList MemorySection PEInfo EpJumpCodes Depth— int

    ProcessItem/SectionList/MemorySection/PEInfo/EpJumpCodes/Depth

  • Process SectionList MemorySection PEInfo EpJumpCodes Opcodes— string

    ProcessItem/SectionList/MemorySection/PEInfo/EpJumpCodes/Opcodes

  • Process Section Exported Function— string

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/ExportedFunctions/string

  • Process Section Exports Time Stamp— date

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/ExportsTimeStamp

  • Process Section Number Of Functions— int

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/NumberOfFunctions

  • Process Section Export Number Of Names— int

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/NumberOfNames

  • Process SectionList MemorySection PEInfo Extraneous Bytes— string

    ProcessItem/SectionList/MemorySection/PEInfo/ExtraneousBytes

  • Process Section Imported Function— string

    ProcessItem/SectionList/MemorySection/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • Process Section Imported Module— string

    ProcessItem/SectionList/MemorySection/PEInfo/ImportedModules/Module/Name

  • Process SectionList MemorySection PEInfo PEChecksum PEComputedAPI— int

    ProcessItem/SectionList/MemorySection/PEInfo/PEChecksum/PEComputedAPI

  • Process SectionList MemorySection PEInfo PEChecksum PEFileAPI— int

    ProcessItem/SectionList/MemorySection/PEInfo/PEChecksum/PEFileAPI

  • Process SectionList MemorySection PEInfo PEChecksum PEFileRaw— int

    ProcessItem/SectionList/MemorySection/PEInfo/PEChecksum/PEFileRaw

  • Process SectionList MemorySection PEInfo PETimeStamp— date

    ProcessItem/SectionList/MemorySection/PEInfo/PETimeStamp

  • Process SectionList MemorySection PEInfo Sections Section Detected Characteristics— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/DetectedCharacteristics

  • Process SectionList MemorySection PEInfo Sections Section Detected Signature Keys— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • Process SectionList MemorySection PEInfo Sections Section Entropy Curve Data float— float

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/Entropy/CurveData/float

  • Process SectionList MemorySection PEInfo Sections Section Name— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/Name

  • Process SectionList MemorySection PEInfo Sections Section Size— int

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/SizeInBytes

  • Process SectionList MemorySection PEInfo Sections Section Type— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/Type

  • Process SectionList MemorySection PEInfo Subsystem— string

    ProcessItem/SectionList/MemorySection/PEInfo/Subsystem

  • Process SectionList MemorySection PEInfo Type— string

    ProcessItem/SectionList/MemorySection/PEInfo/Type

  • Process Section Dll Export Name— string

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/DllName

  • Process Protection— string

    ProcessItem/SectionList/MemorySection/Protection

  • Process Raw Flags— string

    ProcessItem/SectionList/MemorySection/RawFlags

  • Process Region Size— int

    ProcessItem/SectionList/MemorySection/RegionSize

  • Process Region Start— int

    ProcessItem/SectionList/MemorySection/RegionStart

  • Process Section Sha1sum— sha1

    ProcessItem/SectionList/MemorySection/Sha1sum

  • Process Section Sha256sum— sha256

    ProcessItem/SectionList/MemorySection/Sha256sum

  • Process Security ID— string

    ProcessItem/SecurityID

  • Process Security Type— string

    ProcessItem/SecurityType

  • Process String— string

    ProcessItem/StringList/string

  • Process Username— string

    ProcessItem/Username

  • Process Arguments— string

    ProcessItem/arguments

  • Detected Anomaly— string

    ProcessItem/detectedAnomaly

  • Process Hidden— string

    ProcessItem/hidden

  • Process Kernel Time— string

    ProcessItem/kernelTime

  • Process Name— string

    ProcessItem/name

  • Process Parent PID— int

    ProcessItem/parentpid

  • Process Path— string

    ProcessItem/path

  • Process PID— int

    ProcessItem/pid

  • Process Start Time— date

    ProcessItem/startTime

  • Process User Time— string

    ProcessItem/userTime

  • Registry Hive— string

    RegistryItem/Hive

  • Registry Key Path— string

    RegistryItem/KeyPath

  • Registry Key Modified Date— date

    RegistryItem/Modified

  • Registry NumSubKeys— int

    RegistryItem/NumSubKeys

  • Registry NumValues— int

    RegistryItem/NumValues

  • Registry Path— string

    RegistryItem/Path

  • Registry Reported Length In Bytes— int

    RegistryItem/ReportedLengthInBytes

  • Registry Security ID— string

    RegistryItem/SecurityID

  • Registry Text— string

    RegistryItem/Text

  • Registry Type— string

    RegistryItem/Type

  • Registry Username— string

    RegistryItem/Username

  • Registry Value— string

    RegistryItem/Value

  • Registry Value Name— string

    RegistryItem/ValueName

  • Detected Anomaly— string

    RegistryItem/detectedAnomaly

  • Route Destination— IP

    RouteEntryItem/Destination

  • Route Gateway— IP

    RouteEntryItem/Gateway

  • Route Interface— string

    RouteEntryItem/Interface

  • Route Is Autoconfigure Address— bool

    RouteEntryItem/IsAutoconfigureAddress

  • Route Is IPv6— bool

    RouteEntryItem/IsIPv6

  • Route Is Immortal— bool

    RouteEntryItem/IsImmortal

  • Route Is Loopback— bool

    RouteEntryItem/IsLoopback

  • Route Is Publish— bool

    RouteEntryItem/IsPublish

  • Route Metric— int

    RouteEntryItem/Metric

  • Route Netmask— IP

    RouteEntryItem/Netmask

  • Route Origin— string

    RouteEntryItem/Origin

  • Route Preferred Lifetime— date

    RouteEntryItem/PreferredLifetime

  • Route Protocol— string

    RouteEntryItem/Protocol

  • Route Age— string

    RouteEntryItem/RouteAge

  • Route Type— string

    RouteEntryItem/RouteType

  • Route Valid Lifetime— date

    RouteEntryItem/ValidLifetime

  • Service arguments— string

    ServiceItem/arguments

  • Service Description— string

    ServiceItem/description

  • Service Descriptive Name— string

    ServiceItem/descriptiveName

  • Service mode— string

    ServiceItem/mode

  • Service Name— string

    ServiceItem/name

  • Service Path— string

    ServiceItem/path

  • Service Path Certificate Issuer— string

    ServiceItem/pathCertificateIssuer

  • Service Path Certificate Subject— string

    ServiceItem/pathCertificateSubject

  • Service Path Signature Description— string

    ServiceItem/pathSignatureDescription

  • Service Path Signature Exists— bool

    ServiceItem/pathSignatureExists

  • Service Path Signature Verified— bool

    ServiceItem/pathSignatureVerified

  • Service Path MD5— md5

    ServiceItem/pathmd5sum

  • Service Path Sha1sum— sha1

    ServiceItem/pathsha1sum

  • Service Path Sha256sum— sha256

    ServiceItem/pathsha256sum

  • Service PID— int

    ServiceItem/pid

  • Service DLL— string

    ServiceItem/serviceDLL

  • Service DLL Certificate Issuer— string

    ServiceItem/serviceDLLCertificateIssuer

  • Service DLL Certificate Subject — string

    ServiceItem/serviceDLLCertificateSubject

  • Service DLL Signature Description— string

    ServiceItem/serviceDLLSignatureDescription

  • Service DLLSignature Exists— bool

    ServiceItem/serviceDLLSignatureExists

  • Service DLL Signature Verified— bool

    ServiceItem/serviceDLLSignatureVerified

  • Service DLL MD5— md5

    ServiceItem/serviceDLLmd5sum

  • Service DLL Sha1sum— sha1

    ServiceItem/serviceDLLsha1sum

  • Service DLL Sha256sum— sha256

    ServiceItem/serviceDLLsha256sum

  • Service Started As— string

    ServiceItem/startedAs

  • Service Status— string

    ServiceItem/status

  • Service Type— string

    ServiceItem/type

  • Snort Signature— string

    Snort/Snort

  • SystemInfo MAC— string

    SystemInfoItem/MAC

  • SystemInfo Operating System— string

    SystemInfoItem/OS

  • SystemInfo Operating System Bitness— string

    SystemInfoItem/OSBitness

  • SystemInfo App Created— date

    SystemInfoItem/appCreated

  • SystemInfo App Version— string

    SystemInfoItem/appVersion

  • SystemInfo Available Physical Memory— int

    SystemInfoItem/availphysical

  • SystemInfo BIOS Date— string

    SystemInfoItem/biosInfo/biosDate

  • SystemInfo BIOS Type— string

    SystemInfoItem/biosInfo/biosType

  • SystemInfo BIOS Version— string

    SystemInfoItem/biosInfo/biosVersion

  • SystemInfo Build Number— string

    SystemInfoItem/buildNumber

  • SystemInfo Clock Skew— date

    SystemInfoItem/clockSkew

  • SystemInfo Containment State— string

    SystemInfoItem/containmentState

  • SystemInfo Containment Whitelist IP— IP

    SystemInfoItem/containmentWhitelistArray/ip/ip

  • SystemInfo Date— date

    SystemInfoItem/date

  • SystemInfo Directory— string

    SystemInfoItem/directory

  • SystemInfo Domain— string

    SystemInfoItem/domain

  • SystemInfo Drives— string

    SystemInfoItem/drives

  • SystemInfo GMT Offset— date

    SystemInfoItem/gmtoffset

  • SystemInfo Hostname— string

    SystemInfoItem/hostname

  • SystemInfo Install Date— date

    SystemInfoItem/installDate

  • SystemInfo IOMMU— string

    SystemInfoItem/iommu

  • SystemInfo Logged On User— string

    SystemInfoItem/loggedOnUser

  • SystemInfo LPC Device— string

    SystemInfoItem/lpcDevice

  • SystemInfo Machine— string

    SystemInfoItem/machine

  • string SystemInfo networkArray networkInfo MAC — string

    SystemInfoItem/networkArray/networkInfo/MAC

  • SystemInfo Network Adapter— string

    SystemInfoItem/networkArray/networkInfo/adapter

  • SystemInfo Network Description— string

    SystemInfoItem/networkArray/networkInfo/description

  • SystemInfo Network DHCP Lease Expires— date

    SystemInfoItem/networkArray/networkInfo/dhcpLeaseExpires

  • SystemInfo Network DHCP Lease Obtained— date

    SystemInfoItem/networkArray/networkInfo/dhcpLeaseObtained

  • SystemInfo Network DHCP Server— IP

    SystemInfoItem/networkArray/networkInfo/dhcpServerArray/dhcpServer

  • SystemInfo Network IP Address— IP

    SystemInfoItem/networkArray/networkInfo/ipArray/ipInfo/ipAddress

  • SystemInfo Network IPv6 Address— IP

    SystemInfoItem/networkArray/networkInfo/ipArray/ipInfo/ipv6Address

  • SystemInfo Network Subnet Mask— IP

    SystemInfoItem/networkArray/networkInfo/ipArray/ipInfo/subnetMask

  • SystemInfo Network IP Gateway— IP

    SystemInfoItem/networkArray/networkInfo/ipGatewayArray/ipGateway

  • SystemInfo Patch Level— string

    SystemInfoItem/patchLevel

  • SystemInfo Primary IPv4 Address— IP

    SystemInfoItem/primaryIpv4Address

  • SystemInfo Primary IP Address— IP

    SystemInfoItem/primaryIpAddress

  • SystemInfo Virtualization— string

    SystemInfoItem/procConfigInfo/virtualization

  • SystemInfo VM Guest— string

    SystemInfoItem/procConfigInfo/vmGuest

  • SystemInfo Proc Type— string

    SystemInfoItem/procType

  • SystemInfo Processor— string

    SystemInfoItem/processor

  • SystemInfo Product ID— string

    SystemInfoItem/productID

  • SystemInfo Product Name— string

    SystemInfoItem/productName

  • SystemInfo Registered Org— string

    SystemInfoItem/regOrg

  • SystemInfo Registered Owner— string

    SystemInfoItem/regOwner

  • SystemInfo State Agent Status— string

    SystemInfoItem/stateAgentStatus

  • SystemInfo Timezone— string

    SystemInfoItem/timezone

  • SystemInfo Timezone DST— string

    SystemInfoItem/timezoneDST

  • SystemInfo Timezone Standard— string

    SystemInfoItem/timezoneStandard

  • SystemInfo Total Physical— int

    SystemInfoItem/totalphysical

  • SystemInfo Uptime— string

    SystemInfoItem/uptime

  • SystemInfo User— string

    SystemInfoItem/user

  • SystemRestore Acl Change Security ID— string

    SystemRestoreItem/AclChangeSecurityID

  • SystemRestore Acl Change Username— string

    SystemRestoreItem/AclChangeUsername

  • SystemRestore Backup Filename— string

    SystemRestoreItem/BackupFileName

  • SystemRestore Change Event— string

    SystemRestoreItem/ChangeEvent

  • SystemRestore ChangeLog Entry Flags— string

    SystemRestoreItem/ChangeLogEntryFlags

  • SystemRestore ChangeLog Seq. Number— int

    SystemRestoreItem/ChangeLogEntrySequenceNumber

  • SystemRestore ChangeLog Entry Type— string

    SystemRestoreItem/ChangeLogEntryType

  • SystemRestore ChangeLog Filename— string

    SystemRestoreItem/ChangeLogFileName

  • SystemRestore Created— date

    SystemRestoreItem/Created

  • SystemRestore Debug Info Process ID— int

    SystemRestoreItem/DebugInfoProcessId

  • SystemRestore Debug Info Process Name— string

    SystemRestoreItem/DebugInfoProcessName

  • SystemRestore Debug Info Thread ID— int

    SystemRestoreItem/DebugInfoThreadId

  • SystemRestore Debug Info Timestamp— date

    SystemRestoreItem/DebugInfoTimeStamp

  • SystemRestore File Attributes— string

    SystemRestoreItem/FileAttributes

  • SystemRestore New Filename— string

    SystemRestoreItem/NewFileName

  • SystemRestore Original Filename— string

    SystemRestoreItem/OriginalFileName

  • SystemRestore Original Short FileName— string

    SystemRestoreItem/OriginalShortFileName

  • SystemRestore Original Volume Path— string

    SystemRestoreItem/OriginalVolumePath

  • SystemRestore Process Name— string

    SystemRestoreItem/ProcessName

  • SystemRestore Registry Hives— string

    SystemRestoreItem/RegistryHives/String

  • SystemRestore Description— string

    SystemRestoreItem/RestorePointDescription

  • SystemRestore Full Path— string

    SystemRestoreItem/RestorePointFullPath

  • SystemRestore Restore Point Name— string

    SystemRestoreItem/RestorePointName

  • SystemRestore Type— string

    SystemRestoreItem/RestorePointType

  • Task Account Logon Type— string

    TaskItem/AccountLogonType

  • Task Account Name— string

    TaskItem/AccountName

  • Task Account Run Level— string

    TaskItem/AccountRunLevel

  • Task Action Type— string

    TaskItem/ActionList/Action/ActionType

  • Task Action COM Class Id— string

    TaskItem/ActionList/Action/COMClassId

  • Task Action COM Data— string

    TaskItem/ActionList/Action/COMData

  • Task Action Digital Signature Certificate Issuer— string

    TaskItem/ActionList/Action/DigitalSignature/CertificateIssuer

  • Task Action Digital Signature Certificate Subject— string

    TaskItem/ActionList/Action/DigitalSignature/CertificateSubject

  • Task Action Digital Signature Description— string

    TaskItem/ActionList/Action/DigitalSignature/Description

  • Task Action Digital Signature Signature Exists— bool

    TaskItem/ActionList/Action/DigitalSignature/SignatureExists

  • Task Action Digital Signature Signature Verified— bool

    TaskItem/ActionList/Action/DigitalSignature/SignatureVerified

  • Task Action Email Attachments— string

    TaskItem/ActionList/Action/EmailAttachments

  • Task Action Email BCC— string

    TaskItem/ActionList/Action/EmailBCC

  • Task Action Email Body— string

    TaskItem/ActionList/Action/EmailBody

  • Task Action Email CC— string

    TaskItem/ActionList/Action/EmailCC

  • Task Action Email From— string

    TaskItem/ActionList/Action/EmailFrom

  • Task Action Email ReplyTo— string

    TaskItem/ActionList/Action/EmailReplyTo

  • Task Action Email Server— string

    TaskItem/ActionList/Action/EmailServer

  • Task Action Email Subject— string

    TaskItem/ActionList/Action/EmailSubject

  • Task Action Email To— string

    TaskItem/ActionList/Action/EmailTo

  • Task Action Exec Arguments— string

    TaskItem/ActionList/Action/ExecArguments

  • Task Action Exec Program MD5— md5

    TaskItem/ActionList/Action/ExecProgramMd5sum

  • Task Action Exec Program Path— string

    TaskItem/ActionList/Action/ExecProgramPath

  • Task Action Exec Program Sha1sum— sha1

    TaskItem/ActionList/Action/ExecProgramSha1sum

  • Task Action Exec Program Sha256sum— sha256

    TaskItem/ActionList/Action/ExecProgramSha256sum

  • Task Action Exec Working Directory— string

    TaskItem/ActionList/Action/ExecWorkingDirectory

  • Task Action Show Message Body— string

    TaskItem/ActionList/Action/ShowMessageBody

  • Task Action Show Message Title— string

    TaskItem/ActionList/Action/ShowMessageTitle

  • Task Application Name— string

    TaskItem/ApplicationName

  • Task Certificate Issuer— string

    TaskItem/CertificateIssuer

  • Task Certificate Subject— string

    TaskItem/CertificateSubject

  • Task Comment— string

    TaskItem/Comment

  • Task Creation Date— date

    TaskItem/CreationDate

  • Task Creator— string

    TaskItem/Creator

  • Task Exit Code— string

    TaskItem/ExitCode

  • Task Flag— string

    TaskItem/Flag

  • Task Max Run Time— string

    TaskItem/MaxRunTime

  • Task Most Recent Run Time— date

    TaskItem/MostRecentRunTime

  • Task Name— string

    TaskItem/Name

  • Task Next Run Time— date

    TaskItem/NextRunTime

  • Task Parameters— string

    TaskItem/Parameters

  • Task Priority— string

    TaskItem/Priority

  • Task Signature Description— string

    TaskItem/SignatureDescription

  • Task Signature Exists— string

    TaskItem/SignatureExists

  • Task Signature Verified— bool

    TaskItem/SignatureVerified

  • Task Status— string

    TaskItem/Status

  • Task Trigger Begin— date

    TaskItem/TriggerList/Trigger/TriggerBegin

  • Task Trigger Delay— string

    TaskItem/TriggerList/Trigger/TriggerDelay

  • Task Trigger Enabled— bool

    TaskItem/TriggerList/Trigger/TriggerEnabled

  • Task Trigger End— string

    TaskItem/TriggerList/Trigger/TriggerEnd

  • Task Trigger Frequency— string

    TaskItem/TriggerList/Trigger/TriggerFrequency

  • Task Trigger Max Run Time — string

    TaskItem/TriggerList/Trigger/TriggerMaxRunTime

  • Task Trigger Session Change Type— string

    TaskItem/TriggerList/Trigger/TriggerSessionChangeType

  • Task Trigger Subscription— string

    TaskItem/TriggerList/Trigger/TriggerSubscription

  • Task Trigger Username— string

    TaskItem/TriggerList/Trigger/TriggerUsername

  • Task Trigger Value Queries— string

    TaskItem/TriggerList/Trigger/TriggerValueQueries

  • Task Virtual Path— string

    TaskItem/VirtualPath

  • Task Work Data— string

    TaskItem/WorkItemData

  • Task Working Directory— string

    TaskItem/WorkingDirectory

  • Task MD5— md5

    TaskItem/md5sum

  • Task Sha1sum— sha1

    TaskItem/sha1sum

  • Task Sha256sum— sha256

    TaskItem/sha256sum

  • UrlHistory Browser Name— string

    UrlHistoryItem/BrowserName

  • UrlHistory Browser Version— string

    UrlHistoryItem/BrowserVersion

  • UrlHistory First Bookmark Date— string

    UrlHistoryItem/FirstBookmarkDate

  • UrlHistory First Visit Date— date

    UrlHistoryItem/FirstVisitDate

  • UrlHistory Hidden— string

    UrlHistoryItem/Hidden

  • UrlHistory Host Name— string

    UrlHistoryItem/HostName

  • UrlHistory Indexed Content— string

    UrlHistoryItem/IndexedContent

  • UrlHistory Last Visit Date— date

    UrlHistoryItem/LastVisitDate

  • UrlHistory Last Visit Date Local— date

    UrlHistoryItem/LastVisitDateLocal

  • UrlHistory Page Title— string

    UrlHistoryItem/PageTitle

  • UrlHistory Profile— string

    UrlHistoryItem/Profile

  • UrlHistory Thumbnail— string

    UrlHistoryItem/Thumbnail

  • UrlHistory Typed— string

    UrlHistoryItem/Typed

  • UrlHistory URL— string

    UrlHistoryItem/URL

  • UrlHistory Username— string

    UrlHistoryItem/Username

  • UrlHistory Visit Count— int

    UrlHistoryItem/VisitCount

  • UrlHistory Visit From— string

    UrlHistoryItem/VisitFrom

  • UrlHistory Visit Type— string

    UrlHistoryItem/VisitType

  • User Last Login— date

    UserItem/LastLogin

  • User Security ID— string

    UserItem/SecurityID

  • User Security Type— string

    UserItem/SecurityType

  • User Name— string

    UserItem/Username

  • User Description— string

    UserItem/description

  • User Disabled— bool

    UserItem/disabled

  • User Fullname— string

    UserItem/fullname

  • string User Group Name — string

    UserItem/grouplist/groupname

  • User Home Directory— string

    UserItem/homedirectory

  • User Lockedout— bool

    UserItem/lockedout

  • User Password Required— string

    UserItem/passwordrequired

  • User Script Path— string

    UserItem/scriptpath

  • User Password Age— string

    UserItem/userpasswordage

  • Volume Actual Available Allocation Units— int

    VolumeItem/ActualAvailableAllocationUnits

  • Volume Bytes Per Sector— int

    VolumeItem/BytesPerSector

  • Volume Creation Time— date

    VolumeItem/CreationTime

  • Volume Device Path— string

    VolumeItem/DevicePath

  • Volume Drive Letter— string

    VolumeItem/DriveLetter

  • Volume File System Flags— string

    VolumeItem/FileSystemFlags

  • Volume File System Name— string

    VolumeItem/FileSystemName

  • Volume Is Mounted— bool

    VolumeItem/IsMounted

  • Volume Name— string

    VolumeItem/Name

  • Volume Sectors Per Allocation Unit— string

    VolumeItem/SectorsPerAllocationUnit

  • Volume Serial Number— string

    VolumeItem/SerialNumber

  • Volume Total Allocation Units— string

    VolumeItem/TotalAllocationUnits

  • Volume Type— string

    VolumeItem/Type

  • Volume Name— string

    VolumeItem/VolumeName

  • Yara Rule— string

    Yara/Yara

  • Event Address Notification Event Address— IP

    eventItem/addressNotificationEvent/address

  • Event Address Notification Event Timestamp— date

    eventItem/addressNotificationEvent/timestamp

  • Event Details Detail Name— string

    eventItem/details/detail/name

  • Event Details Detail Value— string

    eventItem/details/detail/value

  • Event DNS Lookup Event Hostname— string

    eventItem/dnsLookupEvent/hostname

  • Event DNS Lookup Event PID— int

    eventItem/dnsLookupEvent/pid

  • Event DNS Lookup Event Process— string

    eventItem/dnsLookupEvent/process

  • Event DNS Lookup Event Timestamp— date

    eventItem/dnsLookupEvent/timestamp

  • Event Type— string

    eventItem/eventType

  • Event File Write Event Closed— bool

    eventItem/fileWriteEvent/closed

  • Event File Write Event Data At Lowest Offset— string

    eventItem/fileWriteEvent/dataAtLowestOffset

  • Event File Write Event Device Path— string

    eventItem/fileWriteEvent/devicePath

  • Event File Write Event Drive— string

    eventItem/fileWriteEvent/drive

  • Event File Write Event File Extension— string

    eventItem/fileWriteEvent/fileExtension

  • Event File Write Event File Name— string

    eventItem/fileWriteEvent/fileName

  • Event File Write Event File Path— string

    eventItem/fileWriteEvent/filePath

  • Event File Write Event Full Path— string

    eventItem/fileWriteEvent/fullPath

  • Event File Write Event Lowest File Offset Seen— int

    eventItem/fileWriteEvent/lowestFileOffsetSeen

  • Event File Write Event MD5— md5

    eventItem/fileWriteEvent/md5

  • Event File Write Event Num Bytes Seen Written— int

    eventItem/fileWriteEvent/numBytesSeenWritten

  • Event File Write Event PID— int

    eventItem/fileWriteEvent/pid

  • Event File Write Event Process— string

    eventItem/fileWriteEvent/process

  • Event File Write Event Size— int

    eventItem/fileWriteEvent/size

  • Event File Write Event Text At Lowest Offset— string

    eventItem/fileWriteEvent/textAtLowestOffset

  • Event File Write Event Timestamp— date

    eventItem/fileWriteEvent/timestamp

  • Event File Write Event Writes— int

    eventItem/fileWriteEvent/writes

  • Event Image Load Event Device Path— string

    eventItem/imageLoadEvent/devicePath

  • Event Image Load Event Drive— string

    eventItem/imageLoadEvent/drive

  • Event Image Load Event File Extension— string

    eventItem/imageLoadEvent/fileExtension

  • Event Image Load Event File Name— string

    eventItem/imageLoadEvent/fileName

  • Event Image Load Event File Path— string

    eventItem/imageLoadEvent/filePath

  • Event Image Load Event Full Path— string

    eventItem/imageLoadEvent/fullPath

  • Event Image Load Event Parent PID— int

    eventItem/imageLoadEvent/parentPid

  • Event Image Load Event PID— int

    eventItem/imageLoadEvent/pid

  • Event Image Load Event Process— string

    eventItem/imageLoadEvent/process

  • Event Image Load Event Timestamp— date

    eventItem/imageLoadEvent/timestamp

  • Event Image Load Event Username— string

    eventItem/imageLoadEvent/username

  • Event IPv4 Network Event Local IP— IP

    eventItem/ipv4NetworkEvent/localIP

  • Event IPv4 Network Event Local Port— int

    eventItem/ipv4NetworkEvent/localPort

  • Event IPv4 Network Event PID— int

    eventItem/ipv4NetworkEvent/pid

  • Event IPv4 Network Event Process— string

    eventItem/ipv4NetworkEvent/process

  • Event IPv4 Network Event Protocol— string

    eventItem/ipv4NetworkEvent/protocol

  • Event IPv4 Network Event Remote IP— IP

    eventItem/ipv4NetworkEvent/remoteIP

  • Event IPv4 Network Event Remote Port— int

    eventItem/ipv4NetworkEvent/remotePort

  • Event IPv4 Network Event Timestamp— date

    eventItem/ipv4NetworkEvent/timestamp

  • Event Process Event Event Type— string

    eventItem/processEvent/eventType

  • Event Process Event MD5— md5

    eventItem/processEvent/md5

  • Event Process Event Parent PID— int

    eventItem/processEvent/parentPid

  • Event Process Event Parent Process— string

    eventItem/processEvent/parentProcess

  • Event Process Event Parent Process Path— string

    eventItem/processEvent/parentProcessPath

  • Event Process Event PID— int

    eventItem/processEvent/pid

  • Event Process Event Process— string

    eventItem/processEvent/process

  • Event Process Event Process Path— string

    eventItem/processEvent/processPath

  • Event Process Event Start Time— date

    eventItem/processEvent/startTime

  • Event Process Event Timestamp— date

    eventItem/processEvent/timestamp

  • Event Process Event Username— string

    eventItem/processEvent/username

  • Event Reg Key Event Event Type— string

    eventItem/regKeyEvent/eventType

  • Event Reg Key Event Hive— string

    eventItem/regKeyEvent/hive

  • Event Reg Key Event Key Path— string

    eventItem/regKeyEvent/keyPath

  • Event Reg Key Event Original Path— string

    eventItem/regKeyEvent/originalPath

  • Event Reg Key Event Path— string

    eventItem/regKeyEvent/path

  • Event Reg Key Event PID— string

    eventItem/regKeyEvent/pid

  • Event Reg Key Event Process— string

    eventItem/regKeyEvent/process

  • Event Reg Key Event Text— string

    eventItem/regKeyEvent/text

  • Event Reg Key Event Timestamp— string

    eventItem/regKeyEvent/timestamp

  • Event Reg Key Event Value— string

    eventItem/regKeyEvent/value

  • Event Reg Key Event Value Name— string

    eventItem/regKeyEvent/valueName

  • Event Reg Key Event Value Type— string

    eventItem/regKeyEvent/valueType

  • Event URL Monitor Event Hostname— string

    eventItem/urlMonitorEvent/hostname

  • Event URL Monitor Event HTTP Header— string

    eventItem/urlMonitorEvent/httpHeader

  • Event URL Monitor Event Local Port— int

    eventItem/urlMonitorEvent/localPort

  • Event URL Monitor Event PID— int

    eventItem/urlMonitorEvent/pid

  • Event URL Monitor Event Process— string

    eventItem/urlMonitorEvent/process

  • Event URL Monitor Event Process Path— string

    eventItem/urlMonitorEvent/processPath

  • Event URL Monitor Event Remote IP Address— IP

    eventItem/urlMonitorEvent/remoteIpAddress

  • Event URL Monitor Event Remote Port— int

    eventItem/urlMonitorEvent/remotePort

  • Event URL Monitor Event Request URL— string

    eventItem/urlMonitorEvent/requestUrl

  • Event URL Monitor Event Timestamp— date

    eventItem/urlMonitorEvent/timestamp

  • Event URL Monitor Event URL Method— string

    eventItem/urlMonitorEvent/urlMethod

  • Event URL Monitor Event User Agent— string

    eventItem/urlMonitorEvent/userAgent

  • Event URL Monitor Event Username— string

    eventItem/urlMonitorEvent/username

  • Event Timestamp— date

    eventItem/timestamp