JSON Definitions for Endpoint Security

Prev Next

The following table describes the JSON fields and values used for Endpoint Security servers.

Field

Description

Event Type

Release

msg

Only the normal format is supported.

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

product

Product name

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

_id

Identifier

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

hostname

Hostname of the infected machine

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

ip

IP address of the infected machine

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

containment_state

Whether the infected machine has been contained

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

os

Name of the target OS

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

agent_id

Agent identifier

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

agent_version

Agent version

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

resolution

Valid values are active_threat (resolution=alert and resolution=partial_block), alert, block, and partial_block.

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

event_id

Event identifier

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

enabled

True for active; false for false-positive

indicator-presence

indicator-executed

3.5

operator

A mapping between a field and a value

indicator-presence

indicator-executed

3.5

token

Name of test

indicator-presence

indicator-executed

3.5

type

Data type

indicator-presence

indicator-executed

3.5

value

Data value

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

negate

The negate operation that negates the condition.

indicator-presence

3.5

event_at

Time an event occurred

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

matched_at

Match detection time

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

reported_at

Match reported time

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

source

Source of alert. Valid values are "IOC" (indicator of compromise), "EXD" (exploit detection), and "MAL" (malware alert).

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

matched_source_alerts

Number of source alerts found

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

event_type

Primary event type for this condition (based on the first test)

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

fileWriteEvent/timestamp

Time when a file write event occurred

indicator-presence

3.5

fileWriteEvent/drive

The drive where a file write event occurred

indicator-presence

3.5

fileWriteEvent/id

File write event identifier

indicator-presence

3.5

fileWriteEvent/closed

Time when the file was closed

indicator-presence

3.5

fileWriteEvent/pid

Process identifier

indicator-presence

3.5

fileWriteEvent/filePath

Path of file that was written to

indicator-presence

3.5

fileWriteEvent/fileName

Name of file that was written to

indicator-presence

3.5

fileWriteEvent/lowestFileOffsetSeen

The beginning position, in bytes, observed during the write operation. The raw data is in decimal. Redline shows the data in hexadecimal. The lowest offset of a file from its beginning is 0.

indicator-presence

3.5

fileWriteEvent/textAtLowestOffset

Up to 64 bytes of plaintext observed starting at the lowest offset seen during a write operation.

indicator-presence

3.5

fileWriteEvent/dataAtLowestOffset

Up to 64 bytes of base64-encoded data observed starting at the lowest seen during a write operation.

indicator-presence

3.5

fileWriteEvent/process

Process name of the file write event.

indicator-presence

3.5

fileWriteEvent/md5

MD5 hash value of file

indicator-presence

3.5

fileWriteEvent/writes

Number of times the file was written to

indicator-presence

3.5

fileWriteEvent/size

Size of the file written to

indicator-presence

3.5

fileWriteEvent/fileExtension

Extension of file written to

indicator-presence

3.5

fileWriteEvent/fullPath

Full path of file written to

indicator-presence

3.5

fileWriteEvent/numBytesSeenWritten

Number of bytes that were written

indicator-presence

3.5

uuid

Unique identifier

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

version

Version

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

appliance-id

Appliance identifier

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

appliance

Appliance name

indicator-presence

indicator-executed

exploit-blocked

exploit-detected

3.5

regKeyEvent/path

Path of registry key event

indicator-executed

3.5

regKeyEvent/value

Value of registry key event

indicator-executed

3.5

regKeyEvent/hive

Hive of the registry event

indicator-executed

3.5

regKeyEvent/KeyPath

Path of registry key

indicator-executed

3.5

regKeyEvent/eventType

Event type

indicator-executed

3.5

regKeyEvent/timestamp

Time stamp of registry key event

indicator-executed

3.5

regKeyEvent/valueType

Type of value

indicator-executed

3.5

regKeyEvent/valueName

Name of value

indicator-executed

3.5

regKeyEvent/id

Identifier of the registry key event

indicator-executed

3.5

regKeyEvent/text

Text of the registry key event

indicator-executed

3.5

regKeyEvent/process

Process name of the registry key event

indicator-executed

3.5

regKeyEvent/pid

Process identifier

indicator-executed

3.5

condition

Condition

exploit-blocked

exploit-detected

3.5

event_values

Description of event

exploit-blocked

3.5

detail_type

Type of analysis

exploit-blocked

exploit-detected

3.5

rules_version

Rules version

exploit-blocked

exploit-detected

3.5

engine_version

Engine version

exploit-blocked

exploit-detected

3.5

whitelist_version

Whitelist version

exploit-blocked

exploit-detected

3.5

name

Operating system name

exploit-blocked

exploit-detected

3.5

sp

Service pack

exploit-blocked

exploit-detected

3.5

pid

Process identifier

exploit-blocked

exploit-detected

3.5

imagepath

Location

exploit-blocked

exploit-detected

3.5

md5sum

MD5 hash value

exploit-blocked

exploit-detected

3.5

detail_time

Event time

exploit-blocked

exploit-detected

3.5

timestamp

Event time

exploit-blocked

exploit-detected

3.5

MESSAGE

Message reported

exploit-blocked

exploit-detected

3.5

analysis-id

Analysis identifier

exploit-blocked

exploit-detected

3.5

result

Result of action

exploit-blocked

3.5

ppid

Parent process identifier

exploit-blocked

exploit-detected

3.5

eventid

Event identfier

exploit-blocked

exploit-detected

3.5

parentname

Parent process name

exploit-blocked

exploit-detected

3.5

cmdline

Command line

exploit-blocked

exploit-detected

3.5

is_malicious

Whether the exploit is malicious

exploit-blocked

exploit-detected

3.5

is_blocked

Whether the exploit is blocked

exploit-blocked

exploit-detected

3.5

earliest_detection_time

Earliest detection time of exploit

exploit-detected

3.5

process_id

Process identifier

exploit-detected

3.5

messages

Messages displayed

exploit-detected

3.5

process_name

Name of process

exploit-detected

3.5