OpenIOC search terms supported by the xAgent

Prev Next

The following table lists the descriptions, types, and OpenIOC search terms supported by Endpoint Security (HX) xAgent release 35.31.0. These terms can be used with the /hx/api/v3/searches endpoint. See the Endpoint Security REST API Guide for more information.

  • Agent App Creation Date— date

    AgentInfo/appCreated

  • Agent App Start Date— date

    AgentInfo/appStarted

  • Agent App Version— string

    AgentInfo/appVersion

  • Agent Config Channel— string

    AgentInfo/configChannel

  • Agent Config ETag— string

    AgentInfo/configETag

  • Agent Config ID— string

    AgentInfo/configId

  • Agent Containment State— string

    AgentInfo/containmentState

  • Agent Containment Whitelist IP— IP

    AgentInfo/containmentWhitelistArray/ip/ip

  • Agent ExD Status— string

    AgentInfo/exdStatus

  • Agent Intel ETag— string

    AgentInfo/intelETag

  • Agent Intel Hash— md5

    AgentInfo/intelHash

  • State Agent Status— string

    AgentInfo/stateAgentStatus

  • ARP Cache Type— string

    ArpEntryItem/CacheType

  • ARP IPv4 Address— IP

    ArpEntryItem/IPv4Address

  • ARP IPv6 Address— IP

    ArpEntryItem/IPv6Address

  • ARP Interface— IP

    ArpEntryItem/Interface

  • ARP Interface Type— IP

    ArpEntryItem/InterfaceType

  • ARP Is Router— bool

    ArpEntryItem/IsRouter

  • ARP Last Reachable— date

    ArpEntryItem/LastReachable

  • ARP Last Unreachable— date

    ArpEntryItem/LastUnreachable

  • ARP Physical Address— string

    ArpEntryItem/PhysicalAddress

  • ARP State— string

    ArpEntryItem/State

  • Config Key— string

    ConfigItem/key

  • Config Value— string

    ConfigItem/val

  • CookieHistory Browser Name— string

    CookieHistoryItem/BrowserName

  • CookieHistory Browser Version— string

    CookieHistoryItem/BrowserVersion

  • CookieHistory Cookie Flags— string

    CookieHistoryItem/CookieFlags

  • CookieHistory Cookie Name— string

    CookieHistoryItem/CookieName

  • CookieHistory Cookie Path— string

    CookieHistoryItem/CookiePath

  • CookieHistory Cookie Value— string

    CookieHistoryItem/CookieValue

  • CookieHistory Creation Date— date

    CookieHistoryItem/CreationDate

  • CookieHistory Expiration Date— date

    CookieHistoryItem/ExpirationDate

  • CookieHistory File Name— string

    CookieHistoryItem/FileName

  • CookieHistory File Path— string

    CookieHistoryItem/FilePath

  • CookieHistory Host Name— string

    CookieHistoryItem/HostName

  • CookieHistory IsHttpOnly— string

    CookieHistoryItem/IsHttpOnly

  • CookieHistory IsSecure— bool

    CookieHistoryItem/IsSecure

  • CookieHistory Last Accessed Date— date

    CookieHistoryItem/LastAccessedDate

  • CookieHistory Last Modified Date— date

    CookieHistoryItem/LastModifiedDate

  • CookieHistory Profile— string

    CookieHistoryItem/Profile

  • CookieHistory Username— string

    CookieHistoryItem/Username

  • Disk Name— string

    DiskItem/DiskName

  • Disk Size— int

    DiskItem/DiskSize

  • Disk Partition Length— int

    DiskItem/PartitionList/Partition/PartitionLength

  • Disk Partition Number— int

    DiskItem/PartitionList/Partition/PartitionNumber

  • Disk Partition Offset— int

    DiskItem/PartitionList/Partition/PartitionOffset

  • Disk Partition Type— string

    DiskItem/PartitionList/Partition/PartitionType

  • DNS Data Length— int

    DnsEntryItem/DataLength

  • DNS Flags— string

    DnsEntryItem/Flags

  • DNS Host— string

    DnsEntryItem/Host

  • DNS Record Data ATM Address— string

    DnsEntryItem/RecordData/ATMAddress

  • DNS Record Data Address Type— string

    DnsEntryItem/RecordData/AddressType

  • DNS Record Data Administrator Name— string

    DnsEntryItem/RecordData/AdministratorName

  • DNS Record Data Algorithm— string

    DnsEntryItem/RecordData/Algorithm

  • DNS Record Data Bitmask— int

    DnsEntryItem/RecordData/Bitmask

  • DNS Record Data Blob— string

    DnsEntryItem/RecordData/Blob

  • DNS Record Data Cache Timeout— date

    DnsEntryItem/RecordData/CacheTimeout

  • DNS Record Data Creation Date— date

    DnsEntryItem/RecordData/CreationDate

  • DNS Record Data Date Signed— date

    DnsEntryItem/RecordData/DateSigned

  • DNS Record Data Default Time To Live— date

    DnsEntryItem/RecordData/DefaultTimeToLive

  • DNS Record Data Digest— string

    DnsEntryItem/RecordData/Digest

  • DNS Record Data Digest Length— int

    DnsEntryItem/RecordData/DigestLength

  • DNS Record Data Digest Type— string

    DnsEntryItem/RecordData/DigestType

  • DNS Record Data Error— string

    DnsEntryItem/RecordData/Error

  • DNS Record Data Expiration Date— date

    DnsEntryItem/RecordData/ExpirationDate

  • DNS Record Data Expire— date

    DnsEntryItem/RecordData/Expire

  • DNS Record Data Fudge Time— int

    DnsEntryItem/RecordData/FudgeTime

  • DNS Record Data Host— string

    DnsEntryItem/RecordData/Host

  • DNS Record Data IPv4 Address— IP

    DnsEntryItem/RecordData/IPv4Address

  • DNS Record Data IPv6 Address— IP

    DnsEntryItem/RecordData/IPv6Address

  • DNS Record Data Key— string

    DnsEntryItem/RecordData/Key

  • DNS Record Data Key Flags— int

    DnsEntryItem/RecordData/KeyFlags

  • DNS Record Data Key Length— int

    DnsEntryItem/RecordData/KeyLength

  • DNS Record Data Key Name— string

    DnsEntryItem/RecordData/KeyName

  • DNS Record Data Key Tag— int

    DnsEntryItem/RecordData/KeyTag

  • DNS Record Data Label Count— int

    DnsEntryItem/RecordData/LabelCount

  • DNS Record Data Lookup Timeout— date

    DnsEntryItem/RecordData/LookupTimeout

  • DNS Record Data Mailbox Errors Name— string

    DnsEntryItem/RecordData/MailboxErrorsName

  • DNS Record Data Mailbox Name— string

    DnsEntryItem/RecordData/MailboxName

  • DNS Record Data Mapping Flag— string

    DnsEntryItem/RecordData/MappingFlag

  • DNS Record Data Mode— string

    DnsEntryItem/RecordData/Mode

  • DNS Record Data MX Host— string

    DnsEntryItem/RecordData/MxHost

  • DNS Record Data Next Host— string

    DnsEntryItem/RecordData/NextHost

  • DNS Record Data Order— int

    DnsEntryItem/RecordData/Order

  • DNS Record Data Original Time To Live— date

    DnsEntryItem/RecordData/OriginalTimeToLive

  • DNS Record Data Original Xid— int

    DnsEntryItem/RecordData/OriginalXid

  • DNS Record Data Port— int

    DnsEntryItem/RecordData/Port

  • DNS Record Data Preference— int

    DnsEntryItem/RecordData/Preference

  • DNS Record Data Primary Server Name— string

    DnsEntryItem/RecordData/PrimaryServerName

  • DNS Record Data Priority— int

    DnsEntryItem/RecordData/Priority

  • DNS Record Data Protocol— string

    DnsEntryItem/RecordData/Protocol

  • DNS Record Data Public Key— string

    DnsEntryItem/RecordData/PublicKey

  • DNS Record Data Refresh— date

    DnsEntryItem/RecordData/Refresh

  • DNS Record Data Regular Expression— string

    DnsEntryItem/RecordData/RegularExpression

  • DNS Record Data Replacement — string

    DnsEntryItem/RecordData/Replacement

  • DNS Record Data Retry— date

    DnsEntryItem/RecordData/Retry

  • DNS Record Data Serial Number— int

    DnsEntryItem/RecordData/SerialNumber

  • DNS Record Data Services— string

    DnsEntryItem/RecordData/Services

  • DNS Record Data Signature— string

    DnsEntryItem/RecordData/Signature

  • DNS Record Data Signature Length— int

    DnsEntryItem/RecordData/SignatureLength

  • DNS Record Data Signer— string

    DnsEntryItem/RecordData/Signer

  • DNS Record Data String— string

    DnsEntryItem/RecordData/String

  • DNS Record Data Target Host — string

    DnsEntryItem/RecordData/TargetHost

  • DNS Record Data Type— string

    DnsEntryItem/RecordData/Type

  • DNS Record Data Type Covered— string

    DnsEntryItem/RecordData/TypeCovered

  • DNS Record Data Weight— int

    DnsEntryItem/RecordData/Weight

  • DNS Record Data WINS Server IPv4 Address— IP

    DnsEntryItem/RecordData/WinsServerIPv4Address

  • DNS Record Name— string

    DnsEntryItem/RecordName

  • DNS Record Type— string

    DnsEntryItem/RecordType

  • DNS Time To Live— string

    DnsEntryItem/TimeToLive

  • Driver Certificate Issuer— string

    DriverItem/CertificateIssuer

  • Driver Certificate Subject— string

    DriverItem/CertificateSubject

  • Driver Attached Device Name— string

    DriverItem/DeviceItem/AttachedDeviceName

  • Driver Attached Device Object— int

    DriverItem/DeviceItem/AttachedDeviceObject

  • Driver Attached Driver Name — string

    DriverItem/DeviceItem/AttachedDriverName

  • Driver Attached Driver Object— int

    DriverItem/DeviceItem/AttachedDriverObject

  • Driver Attached To Device Name— string

    DriverItem/DeviceItem/AttachedToDeviceName

  • Driver Attached To Device Object— int

    DriverItem/DeviceItem/AttachedToDeviceObject

  • Driver Attached To Driver Name— string

    DriverItem/DeviceItem/AttachedToDriverName

  • Driver Attached To Driver Object— int

    DriverItem/DeviceItem/AttachedToDriverObject

  • Driver Device Name— string

    DriverItem/DeviceItem/DeviceName

  • Driver Device Object— int

    DriverItem/DeviceItem/DeviceObject

  • Driver Device Driver Name— string

    DriverItem/DeviceItem/DriverName

  • Driver Init— int

    DriverItem/DriverInit

  • Driver Name— string

    DriverItem/DriverName

  • Driver Object Address— int

    DriverItem/DriverObjectAddress

  • Driver StartIo— int

    DriverItem/DriverStartIo

  • Driver Unload— int

    DriverItem/DriverUnload

  • DriverItem IRP_MJ_CLEANUP— int

    DriverItem/IRP_MJ_CLEANUP

  • DriverItem IRP_MJ_CLOSE— int

    DriverItem/IRP_MJ_CLOSE

  • DriverItem IRP_MJ_CREATE— int

    DriverItem/IRP_MJ_CREATE

  • DriverItem IRP_MJ_CREATE_MAILSLOT— int

    DriverItem/IRP_MJ_CREATE_MAILSLOT

  • DriverItem IRP_MJ_CREATE_NAMED_PIPE— int

    DriverItem/IRP_MJ_CREATE_NAMED_PIPE

  • DriverItem IRP_MJ_DEVICE_CHANGE— int

    DriverItem/IRP_MJ_DEVICE_CHANGE

  • DriverItem IRP_MJ_DEVICE_CONTROL— int

    DriverItem/IRP_MJ_DEVICE_CONTROL

  • DriverItem IRP_MJ_DIRECTORY_CONTROL— int

    DriverItem/IRP_MJ_DIRECTORY_CONTROL

  • DriverItem IRP_MJ_FILE_SYSTEM_CONTROL— int

    DriverItem/IRP_MJ_FILE_SYSTEM_CONTROL

  • DriverItem IRP_MJ_FLUSH_BUFFERS— int

    DriverItem/IRP_MJ_FLUSH_BUFFERS

  • DriverItem IRP_MJ_INTERNAL_DEVICE_CONTROL— int

    DriverItem/IRP_MJ_INTERNAL_DEVICE_CONTROL

  • DriverItem IRP_MJ_LOCK_CONTROL— int

    DriverItem/IRP_MJ_LOCK_CONTROL

  • DriverItem IRP_MJ_PNP— int

    DriverItem/IRP_MJ_PNP

  • DriverItem IRP_MJ_POWER— int

    DriverItem/IRP_MJ_POWER

  • DriverItem IRP_MJ_QUERY_EA— int

    DriverItem/IRP_MJ_QUERY_EA

  • DriverItem IRP_MJ_QUERY_INFORMATION— int

    DriverItem/IRP_MJ_QUERY_INFORMATION

  • DriverItem IRP_MJ_QUERY_QUOTA— int

    DriverItem/IRP_MJ_QUERY_QUOTA

  • DriverItem IRP_MJ_QUERY_SECURITY— int

    DriverItem/IRP_MJ_QUERY_SECURITY

  • DriverItem IRP_MJ_QUERY_VOLUME_INFORMATION— int

    DriverItem/IRP_MJ_QUERY_VOLUME_INFORMATION

  • DriverItem IRP_MJ_READ— int

    DriverItem/IRP_MJ_READ

  • DriverItem IRP_MJ_SET_EA— int

    DriverItem/IRP_MJ_SET_EA

  • DriverItem IRP_MJ_SET_INFORMATION— int

    DriverItem/IRP_MJ_SET_INFORMATION

  • DriverItem IRP_MJ_SET_QUOTA— int

    DriverItem/IRP_MJ_SET_QUOTA

  • DriverItem IRP_MJ_SET_SECURITY— int

    DriverItem/IRP_MJ_SET_SECURITY

  • DriverItem IRP_MJ_SET_VOLUME_INFORMATION— int

    DriverItem/IRP_MJ_SET_VOLUME_INFORMATION

  • DriverItem IRP_MJ_SHUTDOWN— int

    DriverItem/IRP_MJ_SHUTDOWN

  • DriverItem IRP_MJ_SYSTEM_CONTROL— int

    DriverItem/IRP_MJ_SYSTEM_CONTROL

  • DriverItem IRP_MJ_WRITE— int

    DriverItem/IRP_MJ_WRITE

  • Driver Image Base— int

    DriverItem/ImageBase

  • Driver Image Size— int

    DriverItem/ImageSize

  • Driver Md5sum— md5

    DriverItem/Md5sum

  • int Driver PEInfo Base Address— int

    DriverItem/PEInfo/BaseAddress

  • Driver PEInfo Detected Anomalies— string

    DriverItem/PEInfo/DetectedAnomalies/string

  • Driver PEInfo Detected Entry Point Signature Name— string

    DriverItem/PEInfo/DetectedEntryPointSignature/Name

  • Driver PEInfo Detected Entry Point Signature Type— string

    DriverItem/PEInfo/DetectedEntryPointSignature/Type

  • Driver Certificate Issuer— string

    DriverItem/PEInfo/DigitalSignature/CertificateIssuer

  • Driver Certificate Subject— string

    DriverItem/PEInfo/DigitalSignature/CertificateSubject

  • Driver Signature Description— string

    DriverItem/PEInfo/DigitalSignature/Description

  • Driver Signature Exists— bool

    DriverItem/PEInfo/DigitalSignature/SignatureExists

  • Driver Signature Verified— bool

    DriverItem/PEInfo/DigitalSignature/SignatureVerified

  • Driver PEInfo EpJumpCodes Depth— int

    DriverItem/PEInfo/EpJumpCodes/Depth

  • Driver PEInfo EpJumpCodes Opcodes— string

    DriverItem/PEInfo/EpJumpCodes/Opcodes

  • Driver Exported Function— string

    DriverItem/PEInfo/Exports/ExportedFunctions/string

  • Driver Exports Time Stamp— date

    DriverItem/PEInfo/Exports/ExportsTimeStamp

  • Driver Exports Dll Name— string

    DriverItem/PEInfo/Exports/DllName

  • Driver Number Of Functions— int

    DriverItem/PEInfo/Exports/NumberOfFunctions

  • Driver Number Of Names— int

    DriverItem/PEInfo/Exports/NumberOfNames

  • Driver PEInfo Extraneous Bytes— string

    DriverItem/PEInfo/ExtraneousBytes

  • Driver Imported Function— string

    DriverItem/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • Driver Imported Module Name— string

    DriverItem/PEInfo/ImportedModules/Module/Name

  • Driver PEInfo PEChecksum PEComputedAPI— int

    DriverItem/PEInfo/PEChecksum/PEComputedAPI

  • Driver PEInfo PEChecksum PEFileAPI — int

    DriverItem/PEInfo/PEChecksum/PEFileAPI

  • Driver PEInfo PEChecksum PEFileRaw— int

    DriverItem/PEInfo/PEChecksum/PEFileRaw

  • Driver PEInfo PETimeStamp— date

    DriverItem/PEInfo/PETimeStamp

  • Driver PEInfo Sections Section Detected Characteristics— string

    DriverItem/PEInfo/Sections/Section/DetectedCharacteristics

  • Driver PEInfo Sections Section Detected Signature Keys— string

    DriverItem/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • Driver PEInfo Sections Section Entropy CurveData float— float

    DriverItem/PEInfo/Sections/Section/Entropy/CurveData/float

  • Driver PEInfo Sections Section Name— string

    DriverItem/PEInfo/Sections/Section/Name

  • Driver PEInfo Sections Section Size— int

    DriverItem/PEInfo/Sections/Section/SizeInBytes

  • Driver PEInfo Sections Section Type — string

    DriverItem/PEInfo/Sections/Section/Type

  • Driver PEInfo Subsystem— string

    DriverItem/PEInfo/Subsystem

  • Driver PEInfo Type— string

    DriverItem/PEInfo/Type

  • Driver Sha1sum— sha1

    DriverItem/Sha1sum

  • Driver Sha256sum— sha256

    DriverItem/Sha256sum

  • Driver Signature Description— string

    DriverItem/SignatureDescription

  • Driver Signature Exists— bool

    DriverItem/SignatureExists

  • Driver Signature Verified— bool

    DriverItem/SignatureVerified

  • Driver String— string

    DriverItem/StringList/string

  • Email attachment content— string

    Email/Attachment/Content

  • Email Attachment MIME Type— string

    Email/Attachment/MIMEType

  • Email Attachment Name— string

    Email/Attachment/Name

  • Email Attachment Size— int

    Email/Attachment/SizeInBytes

  • Email Attachment Count— int

    Email/AttachmentCount

  • Email BCC Recipient(s)— string

    Email/BCC

  • Email Body Text— string

    Email/Body

  • Email CC Recipients(s)— string

    Email/CC

  • Email Content-Type— string

    Email/Content-Type

  • Email Date (Sent)— date

    Email/Date

  • Email Sender— string

    Email/From

  • Email In-Reply-To— string

    Email/In-Reply-To

  • Email MIME-Version— string

    Email/MIME-Version

  • Email Received Date— string

    Email/Received

  • Email Received From Host— string

    Email/ReceivedFromHost

  • Email Received From IP— IP

    Email/ReceivedFromIP

  • Email References— string

    Email/References

  • Email Return Path— string

    Email/Return-Path

  • Email Subject— string

    Email/Subject

  • Email Thread-Index— string

    Email/Thread-Index

  • Email Thread-Topic— string

    Email/Thread-Topic

  • Email Recipients— string

    Email/To

  • Email X-MS-Has-Attach— string

    Email/X-MS-Has-Attach

  • Email X-filenames— string

    Email/X-filenames

  • Email X-filesizes— int

    Email/X-filesizes

  • Email X-filetypes— string

    Email/X-filetypes

  • EventLog Correlation Activity Id— string

    EventLogItem/CorrelationActivityId

  • EventLog Correlation Related Activity Id— string

    EventLogItem/CorrelationRelatedActivityId

  • EventLog ID— int

    EventLogItem/EID

  • EventLog Execution Process Id— int

    EventLogItem/ExecutionProcessId

  • EventLog Execution Thread Id— int

    EventLogItem/ExecutionThreadId

  • EventLog blob— string

    EventLogItem/blob

  • EventLog category— string

    EventLogItem/category

  • EventLog categoryNum— string

    EventLogItem/categoryNum

  • EventLog GenTime— date

    EventLogItem/genTime

  • EventLog index— int

    EventLogItem/index

  • EventLog log— string

    EventLogItem/log

  • EventLog machine— string

    EventLogItem/machine

  • EventLog Message— string

    EventLogItem/message

  • EventLog reserved— string

    EventLogItem/reserved

  • EventLog source— string

    EventLogItem/source

  • EventLog type— string

    EventLogItem/type

  • EventLog unformatted Message— string

    EventLogItem/unformattedMessage/string

  • EventLog user— string

    EventLogItem/user

  • EventLog writeTime— date

    EventLogItem/writeTime

  • FileDownloadHistory AutoResume— string

    FileDownloadHistoryItem/AutoResume

  • FileDownloadHistory Browser Name— string

    FileDownloadHistoryItem/BrowserName

  • FileDownloadHistory Browser Version— string

    FileDownloadHistoryItem/BrowserVersion

  • FileDownloadHistory Bytes Downloaded— int

    FileDownloadHistoryItem/BytesDownloaded

  • FileDownloadHistory Cache Flags— string

    FileDownloadHistoryItem/CacheFlags

  • FileDownloadHistory Cache Hit Coun— int

    FileDownloadHistoryItem/CacheHitCount

  • FileDownloadHistory Download Type— string

    FileDownloadHistoryItem/DownloadType

  • FileDownloadHistory End Date— date

    FileDownloadHistoryItem/EndDate

  • FileDownloadHistory File Name— string

    FileDownloadHistoryItem/FileName

  • FileDownloadHistory Full Http Header— string

    FileDownloadHistoryItem/FullHttpHeader

  • FileDownloadHistory Last Accessed Date— date

    FileDownloadHistoryItem/LastAccessedDate

  • FileDownloadHistory Last Cache Synch Date— date

    FileDownloadHistoryItem/LastCacheSynchDate

  • FileDownloadHistory Last Checked Date— date

    FileDownloadHistoryItem/LastCheckedDate

  • FileDownloadHistory Last Modified Date— date

    FileDownloadHistoryItem/LastModifiedDate

  • FileDownloadHistory Max Bytes— int

    FileDownloadHistoryItem/MaxBytes

  • FileDownloadHistory MimeType— string

    FileDownloadHistoryItem/MimeType

  • FileDownloadHistory Profile— string

    FileDownloadHistoryItem/Profile

  • FileDownloadHistory Referrer— string

    FileDownloadHistoryItem/Referrer

  • FileDownloadHistory Source URL— string

    FileDownloadHistoryItem/SourceURL

  • FileDownloadHistory Start Date— date

    FileDownloadHistoryItem/StartDate

  • FileDownloadHistory State— string

    FileDownloadHistoryItem/State

  • FileDownloadHistory Target Directory— string

    FileDownloadHistoryItem/TargetDirectory

  • FileDownloadHistory Temporary Path— string

    FileDownloadHistoryItem/TemporaryPath

  • FileDownloadHistory Username— string

    FileDownloadHistoryItem/Username

  • File Accessed Time— date

    FileItem/Accessed

  • File Changed Time— date

    FileItem/Changed

  • File Created Time— date

    FileItem/Created

  • File DevicePath— string

    FileItem/DevicePath

  • File Drive— string

    FileItem/Drive

  • File Attribute— string

    FileItem/FileAttributes

  • File Extension— string

    FileItem/FileExtension

  • File Name— string

    FileItem/FileName

  • File Path— string

    FileItem/FilePath

  • File Filename Accessed— date

    FileItem/FilenameAccessed

  • File Filename Changed— date

    FileItem/FilenameChanged

  • File Filename Created— date

    FileItem/FilenameCreated

  • File Filename Modified— date

    FileItem/FilenameModified

  • File Full Path— string

    FileItem/FullPath

  • File INode— int

    FileItem/INode

  • File MD5— md5

    FileItem/Md5sum

  • File Modified Time— date

    FileItem/Modified

  • detectedAnomaly— string

    FileItem/detectedAnomaly

  • File Base Address— int

    FileItem/PEInfo/BaseAddress

  • File PE Detected Anomalies— string

    FileItem/PEInfo/DetectedAnomalies/string

  • File EntryPoint Sig Name— string

    FileItem/PEInfo/DetectedEntryPointSignature/Name

  • File EntryPoint Sig Type— string

    FileItem/PEInfo/DetectedEntryPointSignature/Type

  • File Certificate Issuer— string

    FileItem/PEInfo/DigitalSignature/CertificateIssuer

  • File Certificate Subject— string

    FileItem/PEInfo/DigitalSignature/CertificateSubject

  • File Digital Signature Description— string

    FileItem/PEInfo/DigitalSignature/Description

  • File Digital Signature Exists— bool

    FileItem/PEInfo/DigitalSignature/SignatureExists

  • File Digital Signature Verified— bool

    FileItem/PEInfo/DigitalSignature/SignatureVerified

  • File Double Jump— int

    FileItem/PEInfo/EpJumpCodes/Depth

  • File PEInfo EpJumpCodes Opcodes— string

    FileItem/PEInfo/EpJumpCodes/Opcodes

  • File Dll Export Name— string

    FileItem/PEInfo/Exports/DllName

  • File Export Function— string

    FileItem/PEInfo/Exports/ExportedFunctions/string

  • File Exports Time Stamp— date

    FileItem/PEInfo/Exports/ExportsTimeStamp

  • File Export Count— int

    FileItem/PEInfo/Exports/NumberOfFunctions

  • File Export Number Of Names— int

    FileItem/PEInfo/Exports/NumberOfNames

  • File Extraneous Bytes— string

    FileItem/PEInfo/ExtraneousBytes

  • File Import Function— string

    FileItem/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • File Import Name— string

    FileItem/PEInfo/ImportedModules/Module/Name

  • File Number of Imported Functions— int

    FileItem/PEInfo/ImportedModules/Module/NumberOfFunctions

  • File PE ComputedAPI— int

    FileItem/PEInfo/PEChecksum/PEComputedAPI

  • File PE Checksum API— int

    FileItem/PEInfo/PEChecksum/PEFileAPI

  • File PEFileRaw— int

    FileItem/PEInfo/PEChecksum/PEFileRaw

  • File Compile Time— date

    FileItem/PEInfo/PETimeStamp

  • File PEInfo Resource Info Data— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Data

  • File PEInfo Resource Info Language— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Language

  • File PEInfo Resource Info Name— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Name

  • File PEInfo Resource Info Size— int

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Size

  • File PEInfo Resource Info Type— string

    FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Type

  • File PEInfo Number of Sections— int

    FileItem/PEInfo/Sections/NumberOfSections

  • File PEInfo Actual Number of Sections— int

    FileItem/PEInfo/Sections/ActualNumberOfSections

  • File Detected Characteristics— string

    FileItem/PEInfo/Sections/Section/DetectedCharacteristics

  • File Detected Signatures— string

    FileItem/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • File PEInfo Sections Section Entropy CurveData— float

    FileItem/PEInfo/Sections/Section/Entropy/CurveData/float

  • File Section Name— string

    FileItem/PEInfo/Sections/Section/Name

  • File PE Section Size— int

    FileItem/PEInfo/Sections/Section/SizeInBytes

  • File PE Section Type— string

    FileItem/PEInfo/Sections/Section/Type

  • File PE Subsystem— string

    FileItem/PEInfo/Subsystem

  • File PE Type— string

    FileItem/PEInfo/Type

  • File PEInfo Version Info Comments— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/Comments

  • File PEInfo Version Info CompanyName— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/CompanyName

  • File PEInfo Version Info FileDescription— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileDescription

  • File PEInfo Version Info FileVersion— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileVersion

  • File PEInfo Version Info InternalName— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/InternalName

  • File PEInfo Version Info Language— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/Language

  • File PEInfo Version Info LegalCopyright— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalCopyright

  • File PEInfo Version Info LegalTrademarks— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalTrademarks

  • File PEInfo Version Info OriginalFilename— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/OriginalFilename

  • File PEInfo Version Info PrivateBuild— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/PrivateBuild

  • File PEInfo Version Info ProductName— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductName

  • File PEInfo Version Info ProductVersion— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductVersion

  • File PEInfo Version Info SpecialBuild— string

    FileItem/PEInfo/VersionInfoList/VersionInfoItem/SpecialBuild

  • File Peak Code Entropy— float

    FileItem/PeakCodeEntropy

  • File Peak Entropy— float

    FileItem/PeakEntropy

  • File Security ID— string

    FileItem/SecurityID

  • File Security Type— string

    FileItem/SecurityType

  • File Sha1sum— sha1

    FileItem/Sha1sum

  • File Sha256sum— sha256

    FileItem/Sha256sum

  • File Size— int

    FileItem/SizeInBytes

  • File ADS MD5— md5

    FileItem/StreamList/Stream/Md5sum

  • File ADS Name— string

    FileItem/StreamList/Stream/Name

  • File Stream Sha1sum— sha1

    FileItem/StreamList/Stream/Sha1sum

  • File Stream Sha256sum— sha256

    FileItem/StreamList/Stream/Sha256sum

  • File ADS Size— int

    FileItem/StreamList/Stream/SizeInBytes

  • File Strings— string

    FileItem/StringList/string

  • File Owner— string

    FileItem/Username

  • FormHistory Browser Name— string

    FormHistoryItem/BrowserName

  • FormHistory Browser Version— string

    FormHistoryItem/BrowserVersion

  • FormHistory Creation Date— date

    FormHistoryItem/CreationDate

  • FormHistory Encrypted Password— string

    FormHistoryItem/EncryptedPassword

  • FormHistory Encryption Type— string

    FormHistoryItem/EncryptionType

  • FormHistory First Used Date— date

    FormHistoryItem/FirstUsedDate

  • FormHistory Form Field Name— string

    FormHistoryItem/FormFieldName

  • FormHistory Form Field Value— string

    FormHistoryItem/FormFieldValue

  • FormHistory Form Submit URL— string

    FormHistoryItem/FormSubmitURL

  • FormHistory Form Type— string

    FormHistoryItem/FormType

  • FormHistory Guid— string

    FormHistoryItem/Guid

  • FormHistory Host Name— string

    FormHistoryItem/HostName

  • FormHistory Http Realm— string

    FormHistoryItem/HttpRealm

  • FormHistory Last Used Date— date

    FormHistoryItem/LastUsedDate

  • FormHistory Password Field Name— string

    FormHistoryItem/PasswordFieldName

  • FormHistory Profile— string

    FormHistoryItem/Profile

  • FormHistory Times Used— int

    FormHistoryItem/TimesUsed

  • FormHistory Username— string

    FormHistoryItem/Username

  • FormHistory Username Field Name— string

    FormHistoryItem/UsernameFieldName

  • FormHistory Username Field Value— string

    FormHistoryItem/UsernameFieldValue

  • Hive Name— string

    HiveItem/Name

  • Hive Path— string

    HiveItem/Path

  • Hook Digital Signature Hooked Certificate Issuer— string

    HookItem/DigitalSignatureHooked/CertificateIssuer

  • Hook Digital Signature Hooked Certificate Subject— string

    HookItem/DigitalSignatureHooked/CertificateSubject

  • Hook Digital Signature Hooked Description— string

    HookItem/DigitalSignatureHooked/Description

  • Hook Digital Signature Hooked Signature Exists— bool

    HookItem/DigitalSignatureHooked/SignatureExists

  • Hook Digital Signature Hooked Signature Verified— bool

    HookItem/DigitalSignatureHooked/SignatureVerified

  • Hook Digital Signature Hooking Certificate Issuer— string

    HookItem/DigitalSignatureHooking/CertificateIssuer

  • Hook Digital Signature Hooking Certificate Subject— string

    HookItem/DigitalSignatureHooking/CertificateSubject

  • Hook Digital Signature Hooking Description— string

    HookItem/DigitalSignatureHooking/Description

  • Hook Digital Signature Hooking Signature Exists— bool

    HookItem/DigitalSignatureHooking/SignatureExists

  • Hook Digital Signature Hooking Signature Verified— bool

    HookItem/DigitalSignatureHooking/SignatureVerified

  • Hook Description— string

    HookItem/HookDescription

  • Hook Hooked Function— string

    HookItem/HookedFunction

  • Hook Hooked Module— string

    HookItem/HookedModule

  • Hook Hooking Address— int

    HookItem/HookingAddress

  • Hook Hooking Module— string

    HookItem/HookingModule

  • Log Line Argument— string

    Log/args/arg

  • Log Line Flags— int

    Log/flags

  • Log Line Function— string

    Log/fn

  • Log Line High-Resolution Time— int

    Log/hr

  • Log Line LID— int

    Log/lid

  • Log Line Function Line Number— int

    Log/ln

  • Log Line Level— string

    Log/lvl

  • Log Line Message— string

    Log/msg

  • Log Line PID— int

    Log/pid

  • Log Line TID— int

    Log/tid

  • Log Line Date— date

    Log/time

  • Log Line UID— int

    Log/uid

  • Module Address— int

    ModuleItem/ModuleAddress

  • Module Base— int

    ModuleItem/ModuleBase

  • Module Init— int

    ModuleItem/ModuleInit

  • Module Name— string

    ModuleItem/ModuleName

  • Module Path— string

    ModuleItem/ModulePath

  • Module Size— int

    ModuleItem/ModuleSize

  • Network DNS— string

    Network/DNS

  • Network String HTTP Referr— string

    Network/HTTP_Referr

  • Network String General— string

    Network/String

  • Network String URI— string

    Network/URI

  • Network String User Agent— string

    Network/UserAgent

  • Persistence FileItem Accessed— date

    PersistenceItem/FileItem/Accessed

  • Persistence FileItem Changed— date

    PersistenceItem/FileItem/Changed

  • Persistence FileItem Created— date

    PersistenceItem/FileItem/Created

  • Persistence FileItem Device Path— string

    PersistenceItem/FileItem/DevicePath

  • Persistence FileItem Drive— string

    PersistenceItem/FileItem/Drive

  • Persistence FileItem File Attributes— string

    PersistenceItem/FileItem/FileAttributes

  • Persistence FileItem File Extension— string

    PersistenceItem/FileItem/FileExtension

  • Persistence FileItem File Name— string

    PersistenceItem/FileItem/FileName

  • Persistence FileItem File Path— string

    PersistenceItem/FileItem/FilePath

  • Persistence FileItem Filename Accessed— date

    PersistenceItem/FileItem/FilenameAccessed

  • Persistence FileItem Filename Changed— date

    PersistenceItem/FileItem/FilenameChanged

  • Persistence FileItem Filename Created— date

    PersistenceItem/FileItem/FilenameCreated

  • Persistence FileItem Filename Modified— date

    PersistenceItem/FileItem/FilenameModified

  • Persistence FileItem Full Path— string

    PersistenceItem/FileItem/FullPath

  • Persistence FileItem INode— int

    PersistenceItem/FileItem/INode

  • Persistence FileItem Md5sum— md5

    PersistenceItem/FileItem/Md5sum

  • Persistence FileItem Modified— date

    PersistenceItem/FileItem/Modified

  • Persistence FileItem Size In Bytes— int

    PersistenceItem/FileItem/SizeInBytes

  • Persistence FileItem PEInfo Base Address— int

    PersistenceItem/FileItem/PEInfo/BaseAddress

  • Persistence FileItem PEInfo Detected Anomalies string— string

    PersistenceItem/FileItem/PEInfo/DetectedAnomalies/string

  • Persistence FileItem PEInfo Detected Entry Point Signature Name— string

    PersistenceItem/FileItem/PEInfo/DetectedEntryPointSignature/Name

  • Persistence FileItem PEInfo Detected Entry Point Signature Type— string

    PersistenceItem/FileItem/PEInfo/DetectedEntryPointSignature/Type

  • Persistence FileItem PEInfo DigitalSignature Certificate Issuer — string

    PersistenceItem/FileItem/PEInfo/DigitalSignature/CertificateIssuer

  • Persistence FileItem PEInfo DigitalSignature Certificate Subject— string

    PersistenceItem/FileItem/PEInfo/DigitalSignature/CertificateSubject

  • Persistence FileItem PEInfo DigitalSignature Description— string

    PersistenceItem/FileItem/PEInfo/DigitalSignature/Description

  • Persistence FileItem PEInfo DigitalSignature Signature Exists— bool

    PersistenceItem/FileItem/PEInfo/DigitalSignature/SignatureExists

  • Persistence FileItem PEInfo DigitalSignature Signature Verified — bool

    PersistenceItem/FileItem/PEInfo/DigitalSignature/SignatureVerified

  • Persistence FileItem PEInfo EpJumpCodes Depth— int

    PersistenceItem/FileItem/PEInfo/EpJumpCodes/Depth

  • Persistence FileItem PEInfo EpJumpCodes Opcodes— string

    PersistenceItem/FileItem/PEInfo/EpJumpCodes/OpCodes

  • Persistence FileItem PEInfo Exports Exported Functions string— string

    PersistenceItem/FileItem/PEInfo/Exports/ExportedFunctions/string

  • Persistence FileItem PEInfo Exports Exports Time Stamp— date

    PersistenceItem/FileItem/PEInfo/Exports/ExportsTimeStamp

  • Persistence FileItem PEInfo Exports Number Of Functions— int

    PersistenceItem/FileItem/PEInfo/Exports/NumberOfFunctions

  • Persistence FileItem PEInfo Exports Number Of Names— int

    PersistenceItem/FileItem/PEInfo/Exports/NumberOfNames

  • Persistence FileItem PEInfo Extraneous Bytes— int

    PersistenceItem/FileItem/PEInfo/ExtraneousBytes

  • Persistence FileItem PEInfo Imported Modules Module Imported Functions string— string

    PersistenceItem/FileItem/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • Persistence FileItem PEInfo Imported Modules Module Name— string

    PersistenceItem/FileItem/PEInfo/ImportedModules/Module/Name

  • Persistence FileItem PEInfo PEChecksum PE Computed API— int

    PersistenceItem/FileItem/PEInfo/PEChecksum/PEComputedAPI

  • Persistence FileItem PEInfo PEChecksum PE File API— int

    PersistenceItem/FileItem/PEInfo/PEChecksum/PEFileAPI

  • Persistence FileItem PEInfo PEChecksum PE File Raw— int

    PersistenceItem/FileItem/PEInfo/PEChecksum/PEFileRaw

  • Persistence FileItem PEInfo PE Time Stamp— date

    PersistenceItem/FileItem/PEInfo/PETimeStamp

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Language— string

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Language

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Name— string

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Name

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Size— int

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Size

  • Persistence FileItem PEInfo ResourceInfoList ResourceInfoItem Type— string

    PersistenceItem/FileItem/PEInfo/ResourceInfoList/ResourceInfoItem/Type

  • Persistence FileItem PEInfo Sections Section Detected Characteristics— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/DetectedCharacteristics

  • Persistence FileItem PEInfo Sections Section Detected Signature Keys string— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • Persistence FileItem PEInfo Sections Section Entropy Curve Data float— float

    PersistenceItem/FileItem/PEInfo/Sections/Section/Entropy/CurveData/float

  • Persistence FileItem PEInfo Sections Section Name— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/Name

  • Persistence FileItem PEInfo Sections Section SizeInBytes— int

    PersistenceItem/FileItem/PEInfo/Sections/Section/SizeInBytes

  • Persistence FileItem PEInfo Sections Section Type— string

    PersistenceItem/FileItem/PEInfo/Sections/Section/Type

  • Persistence FileItem PEInfo Subsystem— string

    PersistenceItem/FileItem/PEInfo/Subsystem

  • Persistence FileItem PEInfo Type— string

    PersistenceItem/FileItem/PEInfo/Type

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Comments— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/Comments

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Company Name— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/CompanyName

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem File Description— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileDescription

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem File Version— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/FileVersion

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Internal Name— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/InternalName

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Language— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/Language

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Legal Copyright— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalCopyright

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Legal Trademarks— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/LegalTrademarks

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Original Filename— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/OriginalFilename

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Private Build— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/PrivateBuild

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Product Name— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductName

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Product Version — string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/ProductVersion

  • Persistence FileItem PEInfo VersionInfoList VersionInfoItem Special Build— string

    PersistenceItem/FileItem/PEInfo/VersionInfoList/VersionInfoItem/SpecialBuild

  • Persistence FileItem Peak Code Entropy— int

    PersistenceItem/FileItem/PeakCodeEntropy

  • Persistence FileItem Peak Entropy— int

    PersistenceItem/FileItem/PeakEntropy

  • Persistence FileItem Security ID— string

    PersistenceItem/FileItem/SecurityID

  • Persistence FileItem Security Type— string

    PersistenceItem/FileItem/SecurityType

  • Persistence FileItem Sha1sum— sha1

    PersistenceItem/FileItem/Sha1sum

  • Persistence FileItem Sha256sum— sha256

    PersistenceItem/FileItem/Sha256sum

  • Persistence FileItem Stream List Stream Md5sum— int

    PersistenceItem/FileItem/StreamList/Stream/Md5sum

  • Persistence FileItem Stream List Stream Name— string

    PersistenceItem/FileItem/StreamList/Stream/Name

  • Persistence FileItem Stream List Stream Sha1sum— sha1

    PersistenceItem/FileItem/StreamList/Stream/Sha1sum

  • Persistence FileItem Stream List Stream Sha256sum— sha256

    PersistenceItem/FileItem/StreamList/Stream/Sha256sum

  • Persistence FileItem Stream List Stream Size In Bytes— int

    PersistenceItem/FileItem/StreamList/Stream/SizeInBytes

  • Persistence FileItem Username— string

    PersistenceItem/FileItem/Username

  • Persistence Link File Path — string

    PersistenceItem/LinkFilePath

  • Persistence Type— string

    PersistenceItem/PersistenceType

  • Persistence Reg Context— string

    PersistenceItem/RegContext

  • Persistence RegistryItem Hive— string

    PersistenceItem/RegistryItem/Hive

  • Persistence RegistryItem Key Path— string

    PersistenceItem/RegistryItem/KeyPath

  • Persistence RegistryItem NumSubKeys— int

    PersistenceItem/RegistryItem/NumSubKeys

  • Persistence RegistryItem NumValues— string

    PersistenceItem/RegistryItem/NumValues

  • Persistence RegistryItem Modified— date

    PersistenceItem/RegistryItem/Modified

  • Persistence RegistryItem Path— string

    PersistenceItem/RegistryItem/Path

  • Persistence RegistryItem Reported Length In Bytes— int

    PersistenceItem/RegistryItem/ReportedLengthInBytes

  • Persistence RegistryItem Security ID— string

    PersistenceItem/RegistryItem/SecurityID

  • Persistence RegistryItem Text— string

    PersistenceItem/RegistryItem/Text

  • Persistence RegistryItem Type— string

    PersistenceItem/RegistryItem/Type

  • Persistence RegistryItem Username— string

    PersistenceItem/RegistryItem/Username

  • Persistence RegistryItem Value— string

    PersistenceItem/RegistryItem/Value

  • Persistence RegistryItem Value Name— string

    PersistenceItem/RegistryItem/ValueName

  • Persistence ServiceItem Arguments— string

    PersistenceItem/ServiceItem/arguments

  • Persistence ServiceItem Description— string

    PersistenceItem/ServiceItem/description

  • Persistence ServiceItem Descriptive Name— string

    PersistenceItem/ServiceItem/descriptiveName

  • Persistence ServiceItem Mode— string

    PersistenceItem/ServiceItem/mode

  • Persistence ServiceItem Name— string

    PersistenceItem/ServiceItem/name

  • Persistence ServiceItem Path— string

    PersistenceItem/ServiceItem/path

  • Persistence ServiceItem Path Certificate Issuer— string

    PersistenceItem/ServiceItem/pathCertificateIssuer

  • Persistence ServiceItem Path Certificate Subject— string

    PersistenceItem/ServiceItem/pathCertificateSubject

  • Persistence ServiceItem Path Signature Description— string

    PersistenceItem/ServiceItem/pathSignatureDescription

  • Persistence ServiceItem Path Signature Exists— bool

    PersistenceItem/ServiceItem/pathSignatureExists

  • Persistence ServiceItem Path Signature Verified— bool

    PersistenceItem/ServiceItem/pathSignatureVerified

  • Persistence ServiceItem Path Md5sum— md5

    PersistenceItem/ServiceItem/pathmd5sum

  • Persistence ServiceItem Path Sha1sum— sha1

    PersistenceItem/ServiceItem/pathsha1sum

  • Persistence ServiceItem Path Sha256sum— sha256

    PersistenceItem/ServiceItem/pathsha256sum

  • Persistence ServiceItem PID— int

    PersistenceItem/ServiceItem/pid

  • Persistence ServiceItem Service DLL— string

    PersistenceItem/ServiceItem/serviceDLL

  • Persistence ServiceItem Service DLL Certificate Issuer— string

    PersistenceItem/ServiceItem/serviceDLLCertificateIssuer

  • Persistence ServiceItem Service DLL Certificate Subject— string

    PersistenceItem/ServiceItem/serviceDLLCertificateSubject

  • Persistence ServiceItem Service DLL Signature Description— string

    PersistenceItem/ServiceItem/serviceDLLSignatureDescription

  • Persistence ServiceItem Service DLL Signature Exists— bool

    PersistenceItem/ServiceItem/serviceDLLSignatureExists

  • Persistence ServiceItem Service DLL Signature Verified— bool

    PersistenceItem/ServiceItem/serviceDLLSignatureVerified

  • Persistence ServiceItem Service DLL Md5sum— md5

    PersistenceItem/ServiceItem/serviceDLLmd5sum

  • Persistence ServiceItem Service DLL Sha1sum— sha1

    PersistenceItem/ServiceItem/serviceDLLsha1sum

  • Persistence ServiceItem Service DLL Sha256sum— sha256

    PersistenceItem/ServiceItem/serviceDLLsha256sum

  • Persistence ServiceItem Started As— string

    PersistenceItem/ServiceItem/startedAs

  • Persistence ServiceItem Status— string

    PersistenceItem/ServiceItem/status

  • Persistence ServiceItem Type— string

    PersistenceItem/ServiceItem/type

  • Port Creation Time— date

    PortItem/CreationTime

  • Port Local IP— IP

    PortItem/localIP

  • Port Local Port— int

    PortItem/localPort

  • Port Path— string

    PortItem/path

  • Port PID— int

    PortItem/pid

  • Port Process— string

    PortItem/process

  • Port Protocol— string

    PortItem/protocol

  • Port Remote IP— IP

    PortItem/remoteIP

  • Port Remote Port— int

    PortItem/remotePort

  • Port State— string

    PortItem/state

  • Prefetch Accessed File— string

    PrefetchItem/AccessedFileList/AccessedFile

  • Prefetch File Executed— string

    PrefetchItem/ApplicationFileName

  • Prefetch Application Full Path— string

    PrefetchItem/ApplicationFullPath

  • Prefetch File Created— date

    PrefetchItem/Created

  • Prefetch Full Path— string

    PrefetchItem/FullPath

  • Prefetch Last Run— date

    PrefetchItem/LastRun

  • Prefetch Hash— string

    PrefetchItem/PrefetchHash

  • Prefetch Volume Device Path— string

    PrefetchItem/VolumeList/VolumeItem/DevicePath

  • Prefetch Volume Creation Time— date

    PrefetchItem/VolumeList/VolumeItem/CreationTime

  • Prefetch Volume Serial Number— string

    PrefetchItem/VolumeList/VolumeItem/SerialNumber

  • Prefetch Reported Size— int

    PrefetchItem/ReportedSizeInBytes

  • Prefetch Size— int

    PrefetchItem/SizeInBytes

  • Prefetch Times Executed— int

    PrefetchItem/TimesExecuted

  • Process Handle Access Mask— string

    ProcessItem/HandleList/Handle/AccessMask

  • Process Handle Count— int

    ProcessItem/HandleList/Handle/HandleCount

  • Process Handle Index— int

    ProcessItem/HandleList/Handle/Index

  • Process Handle Name— string

    ProcessItem/HandleList/Handle/Name

  • Process Handle Object Address— string

    ProcessItem/HandleList/Handle/ObjectAddress

  • Process Handle Pointer Count— string

    ProcessItem/HandleList/Handle/PointerCount

  • Process Handle Type— string

    ProcessItem/HandleList/Handle/Type

  • Process Port Creation Time— date

    ProcessItem/PortList/PortItem/CreationTime

  • Process Port Local IP— IP

    ProcessItem/PortList/PortItem/localIP

  • Process Local Port— int

    ProcessItem/PortList/PortItem/localPort

  • Process Port Path— string

    ProcessItem/PortList/PortItem/path

  • Process Port PID— int

    ProcessItem/PortList/PortItem/pid

  • Process Port Process— string

    ProcessItem/PortList/PortItem/process

  • Process Port Protocol— string

    ProcessItem/PortList/PortItem/protocol

  • Process Port Remote IP— IP

    ProcessItem/PortList/PortItem/remoteIP

  • Process Remote Port— int

    ProcessItem/PortList/PortItem/remotePort

  • Process State— string

    ProcessItem/PortList/PortItem/state

  • Process Section Certificate Issuer— string

    ProcessItem/SectionList/MemorySection/DigitalSignature/CertificateIssuer

  • Process Section Certificate Subject— string

    ProcessItem/SectionList/MemorySection/DigitalSignature/CertificateSubject

  • Process Section Signature Description— string

    ProcessItem/SectionList/MemorySection/DigitalSignature/Description

  • Process Section Signature Exists— bool

    ProcessItem/SectionList/MemorySection/DigitalSignature/SignatureExists

  • Process Section Signature Verified— bool

    ProcessItem/SectionList/MemorySection/DigitalSignature/SignatureVerified

  • Process Section Injected— bool

    ProcessItem/SectionList/MemorySection/Injected

  • Process Mapped— string

    ProcessItem/SectionList/MemorySection/Mapped

  • Process Section MD5— md5

    ProcessItem/SectionList/MemorySection/Md5sum

  • Process Section MemD5— md5

    ProcessItem/SectionList/MemorySection/MemD5

  • Process Section Name— string

    ProcessItem/SectionList/MemorySection/Name

  • Process SectionList MemorySection PEInfo Base Address— int

    ProcessItem/SectionList/MemorySection/PEInfo/BaseAddress

  • Process SectionList MemorySection PEInfo Detected Anomalies— string

    ProcessItem/SectionList/MemorySection/PEInfo/DetectedAnomalies/string

  • Process SectionList MemorySection PEInfo Detected EntryPoint Signature Name— string

    ProcessItem/SectionList/MemorySection/PEInfo/DetectedEntryPointSignature/Name

  • Process SectionList MemorySection PEInfo Detected EntryPoint Signature Type— string

    ProcessItem/SectionList/MemorySection/PEInfo/DetectedEntryPointSignature/Type

  • Process SectionList MemorySection PEInfo Digital Signature Certificate Issuer— string

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/CertificateIssuer

  • Process SectionList MemorySection PEInfo Digital Signature Certificate Subject— string

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/CertificateSubject

  • Process SectionList MemorySection PEInfo Digital Signature Description— string

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/Description

  • Process SectionList MemorySection PEInfo Digital Signature Signature Exists— bool

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/SignatureExists

  • Process SectionList MemorySection PEInfo Digital Signature Signature Verified— bool

    ProcessItem/SectionList/MemorySection/PEInfo/DigitalSignature/SignatureVerified

  • Process SectionList MemorySection PEInfo EpJumpCodes Depth— int

    ProcessItem/SectionList/MemorySection/PEInfo/EpJumpCodes/Depth

  • Process SectionList MemorySection PEInfo EpJumpCodes Opcodes— string

    ProcessItem/SectionList/MemorySection/PEInfo/EpJumpCodes/Opcodes

  • Process Section Exported Function— string

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/ExportedFunctions/string

  • Process Section Exports Time Stamp— date

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/ExportsTimeStamp

  • Process Section Number Of Functions— int

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/NumberOfFunctions

  • Process Section Export Number Of Names— int

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/NumberOfNames

  • Process SectionList MemorySection PEInfo Extraneous Bytes— string

    ProcessItem/SectionList/MemorySection/PEInfo/ExtraneousBytes

  • Process Section Imported Function— string

    ProcessItem/SectionList/MemorySection/PEInfo/ImportedModules/Module/ImportedFunctions/string

  • Process Section Imported Module— string

    ProcessItem/SectionList/MemorySection/PEInfo/ImportedModules/Module/Name

  • Process SectionList MemorySection PEInfo PEChecksum PEComputedAPI— int

    ProcessItem/SectionList/MemorySection/PEInfo/PEChecksum/PEComputedAPI

  • Process SectionList MemorySection PEInfo PEChecksum PEFileAPI— int

    ProcessItem/SectionList/MemorySection/PEInfo/PEChecksum/PEFileAPI

  • Process SectionList MemorySection PEInfo PEChecksum PEFileRaw— int

    ProcessItem/SectionList/MemorySection/PEInfo/PEChecksum/PEFileRaw

  • Process SectionList MemorySection PEInfo PETimeStamp— date

    ProcessItem/SectionList/MemorySection/PEInfo/PETimeStamp

  • Process SectionList MemorySection PEInfo Sections Section Detected Characteristics— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/DetectedCharacteristics

  • Process SectionList MemorySection PEInfo Sections Section Detected Signature Keys— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/DetectedSignatureKeys/string

  • Process SectionList MemorySection PEInfo Sections Section Entropy Curve Data float— float

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/Entropy/CurveData/float

  • Process SectionList MemorySection PEInfo Sections Section Name— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/Name

  • Process SectionList MemorySection PEInfo Sections Section Size— int

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/SizeInBytes

  • Process SectionList MemorySection PEInfo Sections Section Type— string

    ProcessItem/SectionList/MemorySection/PEInfo/Sections/Section/Type

  • Process SectionList MemorySection PEInfo Subsystem— string

    ProcessItem/SectionList/MemorySection/PEInfo/Subsystem

  • Process SectionList MemorySection PEInfo Type— string

    ProcessItem/SectionList/MemorySection/PEInfo/Type

  • Process Section Dll Export Name— string

    ProcessItem/SectionList/MemorySection/PEInfo/Exports/DllName

  • Process Protection— string

    ProcessItem/SectionList/MemorySection/Protection

  • Process Raw Flags— string

    ProcessItem/SectionList/MemorySection/RawFlags

  • Process Region Size— int

    ProcessItem/SectionList/MemorySection/RegionSize

  • Process Region Start— int

    ProcessItem/SectionList/MemorySection/RegionStart

  • Process Section Sha1sum— sha1

    ProcessItem/SectionList/MemorySection/Sha1sum

  • Process Section Sha256sum— sha256

    ProcessItem/SectionList/MemorySection/Sha256sum

  • Process Security ID— string

    ProcessItem/SecurityID

  • Process Security Type— string

    ProcessItem/SecurityType

  • Process String— string

    ProcessItem/StringList/string

  • Process Username— string

    ProcessItem/Username

  • Process Arguments— string

    ProcessItem/arguments

  • Detected Anomaly— string

    ProcessItem/detectedAnomaly

  • Process Hidden— string

    ProcessItem/hidden

  • Process Kernel Time— string

    ProcessItem/kernelTime

  • Process Name— string

    ProcessItem/name

  • Process Parent PID— int

    ProcessItem/parentpid

  • Process Path— string

    ProcessItem/path

  • Process PID— int

    ProcessItem/pid

  • Process Start Time— date

    ProcessItem/startTime

  • Process User Time— string

    ProcessItem/userTime

  • Registry Hive— string

    RegistryItem/Hive

  • Registry Key Path— string

    RegistryItem/KeyPath

  • Registry Key Modified Date— date

    RegistryItem/Modified

  • Registry NumSubKeys— int

    RegistryItem/NumSubKeys

  • Registry NumValues— int

    RegistryItem/NumValues

  • Registry Path— string

    RegistryItem/Path

  • Registry Reported Length In Bytes— int

    RegistryItem/ReportedLengthInBytes

  • Registry Security ID— string

    RegistryItem/SecurityID

  • Registry Text— string

    RegistryItem/Text

  • Registry Type— string

    RegistryItem/Type

  • Registry Username— string

    RegistryItem/Username

  • Registry Value— string

    RegistryItem/Value

  • Registry Value Name— string

    RegistryItem/ValueName

  • Detected Anomaly— string

    RegistryItem/detectedAnomaly

  • Route Destination— IP

    RouteEntryItem/Destination

  • Route Gateway— IP

    RouteEntryItem/Gateway

  • Route Interface— string

    RouteEntryItem/Interface

  • Route Is Autoconfigure Address— bool

    RouteEntryItem/IsAutoconfigureAddress

  • Route Is IPv6— bool

    RouteEntryItem/IsIPv6

  • Route Is Immortal— bool

    RouteEntryItem/IsImmortal

  • Route Is Loopback— bool

    RouteEntryItem/IsLoopback

  • Route Is Publish— bool

    RouteEntryItem/IsPublish

  • Route Metric— int

    RouteEntryItem/Metric

  • Route Netmask— IP

    RouteEntryItem/Netmask

  • Route Origin— string

    RouteEntryItem/Origin

  • Route Preferred Lifetime— date

    RouteEntryItem/PreferredLifetime

  • Route Protocol— string

    RouteEntryItem/Protocol

  • Route Age— string

    RouteEntryItem/RouteAge

  • Route Type— string

    RouteEntryItem/RouteType

  • Route Valid Lifetime— date

    RouteEntryItem/ValidLifetime

  • Service arguments— string

    ServiceItem/arguments

  • Service Description— string

    ServiceItem/description

  • Service Descriptive Name— string

    ServiceItem/descriptiveName

  • Service mode— string

    ServiceItem/mode

  • Service Name— string

    ServiceItem/name

  • Service Path— string

    ServiceItem/path

  • Service Path Certificate Issuer— string

    ServiceItem/pathCertificateIssuer

  • Service Path Certificate Subject— string

    ServiceItem/pathCertificateSubject

  • Service Path Signature Description— string

    ServiceItem/pathSignatureDescription

  • Service Path Signature Exists— bool

    ServiceItem/pathSignatureExists

  • Service Path Signature Verified— bool

    ServiceItem/pathSignatureVerified

  • Service Path MD5— md5

    ServiceItem/pathmd5sum

  • Service Path Sha1sum— sha1

    ServiceItem/pathsha1sum

  • Service Path Sha256sum— sha256

    ServiceItem/pathsha256sum

  • Service PID— int

    ServiceItem/pid

  • Service DLL— string

    ServiceItem/serviceDLL

  • Service DLL Certificate Issuer— string

    ServiceItem/serviceDLLCertificateIssuer

  • Service DLL Certificate Subject — string

    ServiceItem/serviceDLLCertificateSubject

  • Service DLL Signature Description— string

    ServiceItem/serviceDLLSignatureDescription

  • Service DLLSignature Exists— bool

    ServiceItem/serviceDLLSignatureExists

  • Service DLL Signature Verified— bool

    ServiceItem/serviceDLLSignatureVerified

  • Service DLL MD5— md5

    ServiceItem/serviceDLLmd5sum

  • Service DLL Sha1sum— sha1

    ServiceItem/serviceDLLsha1sum

  • Service DLL Sha256sum— sha256

    ServiceItem/serviceDLLsha256sum

  • Service Started As— string

    ServiceItem/startedAs

  • Service Status— string

    ServiceItem/status

  • Service Type— string

    ServiceItem/type

  • Snort Signature— string

    Snort/Snort

  • SystemInfo MAC— string

    SystemInfoItem/MAC

  • SystemInfo Operating System— string

    SystemInfoItem/OS

  • SystemInfo Operating System Bitness— string

    SystemInfoItem/OSBitness

  • SystemInfo App Created— date

    SystemInfoItem/appCreated

  • SystemInfo App Version— string

    SystemInfoItem/appVersion

  • SystemInfo Available Physical Memory— int

    SystemInfoItem/availphysical

  • SystemInfo BIOS Date— string

    SystemInfoItem/biosInfo/biosDate

  • SystemInfo BIOS Type— string

    SystemInfoItem/biosInfo/biosType

  • SystemInfo BIOS Version— string

    SystemInfoItem/biosInfo/biosVersion

  • SystemInfo Build Number— string

    SystemInfoItem/buildNumber

  • SystemInfo Clock Skew— date

    SystemInfoItem/clockSkew

  • SystemInfo Containment State— string

    SystemInfoItem/containmentState

  • SystemInfo Containment Whitelist IP— IP

    SystemInfoItem/containmentWhitelistArray/ip/ip

  • SystemInfo Date— date

    SystemInfoItem/date

  • SystemInfo Directory— string

    SystemInfoItem/directory

  • SystemInfo Domain— string

    SystemInfoItem/domain

  • SystemInfo Drives— string

    SystemInfoItem/drives

  • SystemInfo GMT Offset— date

    SystemInfoItem/gmtoffset

  • SystemInfo Hostname— string

    SystemInfoItem/hostname

  • SystemInfo Install Date— date

    SystemInfoItem/installDate

  • SystemInfo IOMMU— string

    SystemInfoItem/iommu

  • SystemInfo Logged On User— string

    SystemInfoItem/loggedOnUser

  • SystemInfo LPC Device— string

    SystemInfoItem/lpcDevice

  • SystemInfo Machine— string

    SystemInfoItem/machine

  • string SystemInfo networkArray networkInfo MAC — string

    SystemInfoItem/networkArray/networkInfo/MAC

  • SystemInfo Network Adapter— string

    SystemInfoItem/networkArray/networkInfo/adapter

  • SystemInfo Network Description— string

    SystemInfoItem/networkArray/networkInfo/description

  • SystemInfo Network DHCP Lease Expires— date

    SystemInfoItem/networkArray/networkInfo/dhcpLeaseExpires

  • SystemInfo Network DHCP Lease Obtained— date

    SystemInfoItem/networkArray/networkInfo/dhcpLeaseObtained

  • SystemInfo Network DHCP Server— IP

    SystemInfoItem/networkArray/networkInfo/dhcpServerArray/dhcpServer

  • SystemInfo Network IP Address— IP

    SystemInfoItem/networkArray/networkInfo/ipArray/ipInfo/ipAddress

  • SystemInfo Network IPv6 Address— IP

    SystemInfoItem/networkArray/networkInfo/ipArray/ipInfo/ipv6Address

  • SystemInfo Network Subnet Mask— IP

    SystemInfoItem/networkArray/networkInfo/ipArray/ipInfo/subnetMask

  • SystemInfo Network IP Gateway— IP

    SystemInfoItem/networkArray/networkInfo/ipGatewayArray/ipGateway

  • SystemInfo Patch Level— string

    SystemInfoItem/patchLevel

  • SystemInfo Primary IPv4 Address— IP

    SystemInfoItem/primaryIpv4Address

  • SystemInfo Primary IP Address— IP

    SystemInfoItem/primaryIpAddress

  • SystemInfo Virtualization— string

    SystemInfoItem/procConfigInfo/virtualization

  • SystemInfo VM Guest— string

    SystemInfoItem/procConfigInfo/vmGuest

  • SystemInfo Proc Type— string

    SystemInfoItem/procType

  • SystemInfo Processor— string

    SystemInfoItem/processor

  • SystemInfo Product ID— string

    SystemInfoItem/productID

  • SystemInfo Product Name— string

    SystemInfoItem/productName

  • SystemInfo Registered Org— string

    SystemInfoItem/regOrg

  • SystemInfo Registered Owner— string

    SystemInfoItem/regOwner

  • SystemInfo State Agent Status— string

    SystemInfoItem/stateAgentStatus

  • SystemInfo Timezone— string

    SystemInfoItem/timezone

  • SystemInfo Timezone DST— string

    SystemInfoItem/timezoneDST

  • SystemInfo Timezone Standard— string

    SystemInfoItem/timezoneStandard

  • SystemInfo Total Physical— int

    SystemInfoItem/totalphysical

  • SystemInfo Uptime— string

    SystemInfoItem/uptime

  • SystemInfo User— string

    SystemInfoItem/user

  • SystemRestore Acl Change Security ID— string

    SystemRestoreItem/AclChangeSecurityID

  • SystemRestore Acl Change Username— string

    SystemRestoreItem/AclChangeUsername

  • SystemRestore Backup Filename— string

    SystemRestoreItem/BackupFileName

  • SystemRestore Change Event— string

    SystemRestoreItem/ChangeEvent

  • SystemRestore ChangeLog Entry Flags— string

    SystemRestoreItem/ChangeLogEntryFlags

  • SystemRestore ChangeLog Seq. Number— int

    SystemRestoreItem/ChangeLogEntrySequenceNumber

  • SystemRestore ChangeLog Entry Type— string

    SystemRestoreItem/ChangeLogEntryType

  • SystemRestore ChangeLog Filename— string

    SystemRestoreItem/ChangeLogFileName

  • SystemRestore Created— date

    SystemRestoreItem/Created

  • SystemRestore Debug Info Process ID— int

    SystemRestoreItem/DebugInfoProcessId

  • SystemRestore Debug Info Process Name— string

    SystemRestoreItem/DebugInfoProcessName

  • SystemRestore Debug Info Thread ID— int

    SystemRestoreItem/DebugInfoThreadId

  • SystemRestore Debug Info Timestamp— date

    SystemRestoreItem/DebugInfoTimeStamp

  • SystemRestore File Attributes— string

    SystemRestoreItem/FileAttributes

  • SystemRestore New Filename— string

    SystemRestoreItem/NewFileName

  • SystemRestore Original Filename— string

    SystemRestoreItem/OriginalFileName

  • SystemRestore Original Short FileName— string

    SystemRestoreItem/OriginalShortFileName

  • SystemRestore Original Volume Path— string

    SystemRestoreItem/OriginalVolumePath

  • SystemRestore Process Name— string

    SystemRestoreItem/ProcessName

  • SystemRestore Registry Hives— string

    SystemRestoreItem/RegistryHives/String

  • SystemRestore Description— string

    SystemRestoreItem/RestorePointDescription

  • SystemRestore Full Path— string

    SystemRestoreItem/RestorePointFullPath

  • SystemRestore Restore Point Name— string

    SystemRestoreItem/RestorePointName

  • SystemRestore Type— string

    SystemRestoreItem/RestorePointType

  • Task Account Logon Type— string

    TaskItem/AccountLogonType

  • Task Account Name— string

    TaskItem/AccountName

  • Task Account Run Level— string

    TaskItem/AccountRunLevel

  • Task Action Type— string

    TaskItem/ActionList/Action/ActionType

  • Task Action COM Class Id— string

    TaskItem/ActionList/Action/COMClassId

  • Task Action COM Data— string

    TaskItem/ActionList/Action/COMData

  • Task Action Digital Signature Certificate Issuer— string

    TaskItem/ActionList/Action/DigitalSignature/CertificateIssuer

  • Task Action Digital Signature Certificate Subject— string

    TaskItem/ActionList/Action/DigitalSignature/CertificateSubject

  • Task Action Digital Signature Description— string

    TaskItem/ActionList/Action/DigitalSignature/Description

  • Task Action Digital Signature Signature Exists— bool

    TaskItem/ActionList/Action/DigitalSignature/SignatureExists

  • Task Action Digital Signature Signature Verified— bool

    TaskItem/ActionList/Action/DigitalSignature/SignatureVerified

  • Task Action Email Attachments— string

    TaskItem/ActionList/Action/EmailAttachments

  • Task Action Email BCC— string

    TaskItem/ActionList/Action/EmailBCC

  • Task Action Email Body— string

    TaskItem/ActionList/Action/EmailBody

  • Task Action Email CC— string

    TaskItem/ActionList/Action/EmailCC

  • Task Action Email From— string

    TaskItem/ActionList/Action/EmailFrom

  • Task Action Email ReplyTo— string

    TaskItem/ActionList/Action/EmailReplyTo

  • Task Action Email Server— string

    TaskItem/ActionList/Action/EmailServer

  • Task Action Email Subject— string

    TaskItem/ActionList/Action/EmailSubject

  • Task Action Email To— string

    TaskItem/ActionList/Action/EmailTo

  • Task Action Exec Arguments— string

    TaskItem/ActionList/Action/ExecArguments

  • Task Action Exec Program MD5— md5

    TaskItem/ActionList/Action/ExecProgramMd5sum

  • Task Action Exec Program Path— string

    TaskItem/ActionList/Action/ExecProgramPath

  • Task Action Exec Program Sha1sum— sha1

    TaskItem/ActionList/Action/ExecProgramSha1sum

  • Task Action Exec Program Sha256sum— sha256

    TaskItem/ActionList/Action/ExecProgramSha256sum

  • Task Action Exec Working Directory— string

    TaskItem/ActionList/Action/ExecWorkingDirectory

  • Task Action Show Message Body— string

    TaskItem/ActionList/Action/ShowMessageBody

  • Task Action Show Message Title— string

    TaskItem/ActionList/Action/ShowMessageTitle

  • Task Application Name— string

    TaskItem/ApplicationName

  • Task Certificate Issuer— string

    TaskItem/CertificateIssuer

  • Task Certificate Subject— string

    TaskItem/CertificateSubject

  • Task Comment— string

    TaskItem/Comment

  • Task Creation Date— date

    TaskItem/CreationDate

  • Task Creator— string

    TaskItem/Creator

  • Task Exit Code— string

    TaskItem/ExitCode

  • Task Flag— string

    TaskItem/Flag

  • Task Max Run Time— string

    TaskItem/MaxRunTime

  • Task Most Recent Run Time— date

    TaskItem/MostRecentRunTime

  • Task Name— string

    TaskItem/Name

  • Task Next Run Time— date

    TaskItem/NextRunTime

  • Task Parameters— string

    TaskItem/Parameters

  • Task Priority— string

    TaskItem/Priority

  • Task Signature Description— string

    TaskItem/SignatureDescription

  • Task Signature Exists— string

    TaskItem/SignatureExists

  • Task Signature Verified— bool

    TaskItem/SignatureVerified

  • Task Status— string

    TaskItem/Status

  • Task Trigger Begin— date

    TaskItem/TriggerList/Trigger/TriggerBegin

  • Task Trigger Delay— string

    TaskItem/TriggerList/Trigger/TriggerDelay

  • Task Trigger Enabled— bool

    TaskItem/TriggerList/Trigger/TriggerEnabled

  • Task Trigger End— string

    TaskItem/TriggerList/Trigger/TriggerEnd

  • Task Trigger Frequency— string

    TaskItem/TriggerList/Trigger/TriggerFrequency

  • Task Trigger Max Run Time — string

    TaskItem/TriggerList/Trigger/TriggerMaxRunTime

  • Task Trigger Session Change Type— string

    TaskItem/TriggerList/Trigger/TriggerSessionChangeType

  • Task Trigger Subscription— string

    TaskItem/TriggerList/Trigger/TriggerSubscription

  • Task Trigger Username— string

    TaskItem/TriggerList/Trigger/TriggerUsername

  • Task Trigger Value Queries— string

    TaskItem/TriggerList/Trigger/TriggerValueQueries

  • Task Virtual Path— string

    TaskItem/VirtualPath

  • Task Work Data— string

    TaskItem/WorkItemData

  • Task Working Directory— string

    TaskItem/WorkingDirectory

  • Task MD5— md5

    TaskItem/md5sum

  • Task Sha1sum— sha1

    TaskItem/sha1sum

  • Task Sha256sum— sha256

    TaskItem/sha256sum

  • UrlHistory Browser Name— string

    UrlHistoryItem/BrowserName

  • UrlHistory Browser Version— string

    UrlHistoryItem/BrowserVersion

  • UrlHistory First Bookmark Date— string

    UrlHistoryItem/FirstBookmarkDate

  • UrlHistory First Visit Date— date

    UrlHistoryItem/FirstVisitDate

  • UrlHistory Hidden— string

    UrlHistoryItem/Hidden

  • UrlHistory Host Name— string

    UrlHistoryItem/HostName

  • UrlHistory Indexed Content— string

    UrlHistoryItem/IndexedContent

  • UrlHistory Last Visit Date— date

    UrlHistoryItem/LastVisitDate

  • UrlHistory Last Visit Date Local— date

    UrlHistoryItem/LastVisitDateLocal

  • UrlHistory Page Title— string

    UrlHistoryItem/PageTitle

  • UrlHistory Profile— string

    UrlHistoryItem/Profile

  • UrlHistory Thumbnail— string

    UrlHistoryItem/Thumbnail

  • UrlHistory Typed— string

    UrlHistoryItem/Typed

  • UrlHistory URL— string

    UrlHistoryItem/URL

  • UrlHistory Username— string

    UrlHistoryItem/Username

  • UrlHistory Visit Count— int

    UrlHistoryItem/VisitCount

  • UrlHistory Visit From— string

    UrlHistoryItem/VisitFrom

  • UrlHistory Visit Type— string

    UrlHistoryItem/VisitType

  • User Last Login— date

    UserItem/LastLogin

  • User Security ID— string

    UserItem/SecurityID

  • User Security Type— string

    UserItem/SecurityType

  • User Name— string

    UserItem/Username

  • User Description— string

    UserItem/description

  • User Disabled— bool

    UserItem/disabled

  • User Fullname— string

    UserItem/fullname

  • string User Group Name — string

    UserItem/grouplist/groupname

  • User Home Directory— string

    UserItem/homedirectory

  • User Lockedout— bool

    UserItem/lockedout

  • User Password Required— string

    UserItem/passwordrequired

  • User Script Path— string

    UserItem/scriptpath

  • User Password Age— string

    UserItem/userpasswordage

  • Volume Actual Available Allocation Units— int

    VolumeItem/ActualAvailableAllocationUnits

  • Volume Bytes Per Sector— int

    VolumeItem/BytesPerSector

  • Volume Creation Time— date

    VolumeItem/CreationTime

  • Volume Device Path— string

    VolumeItem/DevicePath

  • Volume Drive Letter— string

    VolumeItem/DriveLetter

  • Volume File System Flags— string

    VolumeItem/FileSystemFlags

  • Volume File System Name— string

    VolumeItem/FileSystemName

  • Volume Is Mounted— bool

    VolumeItem/IsMounted

  • Volume Name— string

    VolumeItem/Name

  • Volume Sectors Per Allocation Unit— string

    VolumeItem/SectorsPerAllocationUnit

  • Volume Serial Number— string

    VolumeItem/SerialNumber

  • Volume Total Allocation Units— string

    VolumeItem/TotalAllocationUnits

  • Volume Type— string

    VolumeItem/Type

  • Volume Name— string

    VolumeItem/VolumeName

  • Yara Rule— string

    Yara/Yara

  • Event Address Notification Event Address— IP

    eventItem/addressNotificationEvent/address

  • Event Address Notification Event Timestamp— date

    eventItem/addressNotificationEvent/timestamp

  • Event Details Detail Name— string

    eventItem/details/detail/name

  • Event Details Detail Value— string

    eventItem/details/detail/value

  • Event DNS Lookup Event Hostname— string

    eventItem/dnsLookupEvent/hostname

  • Event DNS Lookup Event PID— int

    eventItem/dnsLookupEvent/pid

  • Event DNS Lookup Event Process— string

    eventItem/dnsLookupEvent/process

  • Event DNS Lookup Event Timestamp— date

    eventItem/dnsLookupEvent/timestamp

  • Event Type— string

    eventItem/eventType

  • Event File Write Event Closed— bool

    eventItem/fileWriteEvent/closed

  • Event File Write Event Data At Lowest Offset— string

    eventItem/fileWriteEvent/dataAtLowestOffset

  • Event File Write Event Device Path— string

    eventItem/fileWriteEvent/devicePath

  • Event File Write Event Drive— string

    eventItem/fileWriteEvent/drive

  • Event File Write Event File Extension— string

    eventItem/fileWriteEvent/fileExtension

  • Event File Write Event File Name— string

    eventItem/fileWriteEvent/fileName

  • Event File Write Event File Path— string

    eventItem/fileWriteEvent/filePath

  • Event File Write Event Full Path— string

    eventItem/fileWriteEvent/fullPath

  • Event File Write Event Lowest File Offset Seen— int

    eventItem/fileWriteEvent/lowestFileOffsetSeen

  • Event File Write Event MD5— md5

    eventItem/fileWriteEvent/md5

  • Event File Write Event Num Bytes Seen Written— int

    eventItem/fileWriteEvent/numBytesSeenWritten

  • Event File Write Event PID— int

    eventItem/fileWriteEvent/pid

  • Event File Write Event Process— string

    eventItem/fileWriteEvent/process

  • Event File Write Event Size— int

    eventItem/fileWriteEvent/size

  • Event File Write Event Text At Lowest Offset— string

    eventItem/fileWriteEvent/textAtLowestOffset

  • Event File Write Event Timestamp— date

    eventItem/fileWriteEvent/timestamp

  • Event File Write Event Writes— int

    eventItem/fileWriteEvent/writes

  • Event Image Load Event Device Path— string

    eventItem/imageLoadEvent/devicePath

  • Event Image Load Event Drive— string

    eventItem/imageLoadEvent/drive

  • Event Image Load Event File Extension— string

    eventItem/imageLoadEvent/fileExtension

  • Event Image Load Event File Name— string

    eventItem/imageLoadEvent/fileName

  • Event Image Load Event File Path— string

    eventItem/imageLoadEvent/filePath

  • Event Image Load Event Full Path— string

    eventItem/imageLoadEvent/fullPath

  • Event Image Load Event Parent PID— int

    eventItem/imageLoadEvent/parentPid

  • Event Image Load Event PID— int

    eventItem/imageLoadEvent/pid

  • Event Image Load Event Process— string

    eventItem/imageLoadEvent/process

  • Event Image Load Event Timestamp— date

    eventItem/imageLoadEvent/timestamp

  • Event Image Load Event Username— string

    eventItem/imageLoadEvent/username

  • Event IPv4 Network Event Local IP— IP

    eventItem/ipv4NetworkEvent/localIP

  • Event IPv4 Network Event Local Port— int

    eventItem/ipv4NetworkEvent/localPort

  • Event IPv4 Network Event PID— int

    eventItem/ipv4NetworkEvent/pid

  • Event IPv4 Network Event Process— string

    eventItem/ipv4NetworkEvent/process

  • Event IPv4 Network Event Protocol— string

    eventItem/ipv4NetworkEvent/protocol

  • Event IPv4 Network Event Remote IP— IP

    eventItem/ipv4NetworkEvent/remoteIP

  • Event IPv4 Network Event Remote Port— int

    eventItem/ipv4NetworkEvent/remotePort

  • Event IPv4 Network Event Timestamp— date

    eventItem/ipv4NetworkEvent/timestamp

  • Event Process Event Event Type— string

    eventItem/processEvent/eventType

  • Event Process Event MD5— md5

    eventItem/processEvent/md5

  • Event Process Event Parent PID— int

    eventItem/processEvent/parentPid

  • Event Process Event Parent Process— string

    eventItem/processEvent/parentProcess

  • Event Process Event Parent Process Path— string

    eventItem/processEvent/parentProcessPath

  • Event Process Event PID— int

    eventItem/processEvent/pid

  • Event Process Event Process— string

    eventItem/processEvent/process

  • Event Process Event Process Path— string

    eventItem/processEvent/processPath

  • Event Process Event Start Time— date

    eventItem/processEvent/startTime

  • Event Process Event Timestamp— date

    eventItem/processEvent/timestamp

  • Event Process Event Username— string

    eventItem/processEvent/username

  • Event Reg Key Event Event Type— string

    eventItem/regKeyEvent/eventType

  • Event Reg Key Event Hive— string

    eventItem/regKeyEvent/hive

  • Event Reg Key Event Key Path— string

    eventItem/regKeyEvent/keyPath

  • Event Reg Key Event Original Path— string

    eventItem/regKeyEvent/originalPath

  • Event Reg Key Event Path— string

    eventItem/regKeyEvent/path

  • Event Reg Key Event PID— string

    eventItem/regKeyEvent/pid

  • Event Reg Key Event Process— string

    eventItem/regKeyEvent/process

  • Event Reg Key Event Text— string

    eventItem/regKeyEvent/text

  • Event Reg Key Event Timestamp— string

    eventItem/regKeyEvent/timestamp

  • Event Reg Key Event Value— string

    eventItem/regKeyEvent/value

  • Event Reg Key Event Value Name— string

    eventItem/regKeyEvent/valueName

  • Event Reg Key Event Value Type— string

    eventItem/regKeyEvent/valueType

  • Event URL Monitor Event Hostname— string

    eventItem/urlMonitorEvent/hostname

  • Event URL Monitor Event HTTP Header— string

    eventItem/urlMonitorEvent/httpHeader

  • Event URL Monitor Event Local Port— int

    eventItem/urlMonitorEvent/localPort

  • Event URL Monitor Event PID— int

    eventItem/urlMonitorEvent/pid

  • Event URL Monitor Event Process— string

    eventItem/urlMonitorEvent/process

  • Event URL Monitor Event Process Path— string

    eventItem/urlMonitorEvent/processPath

  • Event URL Monitor Event Remote IP Address— IP

    eventItem/urlMonitorEvent/remoteIpAddress

  • Event URL Monitor Event Remote Port— int

    eventItem/urlMonitorEvent/remotePort

  • Event URL Monitor Event Request URL— string

    eventItem/urlMonitorEvent/requestUrl

  • Event URL Monitor Event Timestamp— date

    eventItem/urlMonitorEvent/timestamp

  • Event URL Monitor Event URL Method— string

    eventItem/urlMonitorEvent/urlMethod

  • Event URL Monitor Event User Agent— string

    eventItem/urlMonitorEvent/userAgent

  • Event URL Monitor Event Username— string

    eventItem/urlMonitorEvent/username

  • Event Timestamp— date

    eventItem/timestamp