ipv4-addr:value |
networkConnections.sourceAddress, networkConnections.destinationAddress, networkConnections.natSourceAddress, networkConnections.natDestinationAddress |
ipv6-addr:value |
networkConnections.sourceAddress, networkConnections.destinationAddress |
network-traffic:src_port |
networkConnections.sourcePort, networkConnections.natSourcePort |
network-traffic:dst_port |
networkConnections.destinationPort, networkConnections.natDestinationPort |
network-traffic:protocols[*] |
networkConnections.protocol |
network-traffic:src_ref.value |
networkConnections.sourceAddress |
network-traffic:dst_ref.value |
networkConnections.destinationAddress |
directory:path |
fileStates.path, process.path |
file:parent_directory_ref.path |
fileStates.path |
file:name |
fileStates.name |
file:hashes.'SHA-256' |
fileStates.fileHash.hashValue |
file:hashes.'SHA-1' |
fileStates.fileHash.hashValue |
file:hashes.MD5 |
fileStates.fileHash.hashValue |
file:hashes.authenticodeHash256 |
fileStates.fileHash.hashValue |
file:hashes.lsHash |
fileStates.fileHash.hashValue |
file:hashes.ctph |
fileStates.fileHash.hashValue |
file:hashes.peSha1 |
fileStates.fileHash.hashValue |
file:hashes.peSha256 |
fileStates.fileHash.hashValue |
file:hashes.unknown |
fileStates.fileHash.hashValue |
process:name |
processes.name, processes.parentProcessName |
process:parent_ref.name |
processes.parentProcessName |
process:command_line |
processes.commandLine |
process:pid |
processes.processId, processes.parentProcessId, registryKeyStates.processId |
process:created |
processes.createdDateTime |
process:parent_ref.pid |
processes.parentProcessId |
process:binary_ref.parent_directory_ref.path |
processes.path |
domain-name:value |
hostStates.fqdn, hostStates.netBiosName, networkConnections.destinationDomain, userStates.domainName |
user-account:user_id |
userStates.accountName, processes.accountName, userStates.aadUserId |
user-account:account_login |
userStates.logonId |
user-account:account_type |
userStates.userAccountType |
user-account:account_last_login |
userStates.logonDateTime |
software:name |
vendorInformation.provider |
software:vendor |
vendorInformation.vendor |
software:version |
vendorInformation.providerVersion |
url:value |
networkConnections.destinationUrl |
windows-registry-key:key |
registryKeyStates.key |
windows-registry-key:values[*].data |
registryKeyStates.valueData |
windows-registry-key:values[*].name |
registryKeyStates.valueName |
windows-registry-key:values[*].data_type |
registryKeyStates.valueType |
x-msazure-sentinel:tenant_id |
azureTenantId |
x-msazure-sentinel:subscription_id |
azureSubscriptionId |
x-msazure-sentinel-alert:activityGroupName |
activityGroupName |
x-msazure-sentinel-alert:assignedTo |
assignedTo |
x-msazure-sentinel-alert:comments |
comments |
x-msazure-sentinel-alert:confidence |
confidence |
x-msazure-sentinel-alert:detectionIds |
detectionIds |
x-msazure-sentinel-alert:feedback |
feedback |
x-msazure-sentinel-alert:id |
id |
x-msazure-sentinel-alert:incidentIds |
incidentIds |
x-msazure-sentinel-alert:recommendedActions |
recommendedActions |
x-msazure-sentinel-alert:sourceMaterials |
sourceMaterials |
x-msazure-sentinel-alert:status |
status |
x-msazure-sentinel-alert:tags |
tags |
x-msazure-sentinel-alert:cloudAppStates.destinationServiceName |
cloudAppStates.destinationServiceName |
x-msazure-sentinel-alert:cloudAppStates.destinationServiceIp |
cloudAppStates.destinationServiceIp |
x-msazure-sentinel-alert:cloudAppStates.riskScore |
cloudAppStates.riskScore |
x-msazure-sentinel-alert:hostStates.isAzureAadJoined |
hostStates.isAzureAadJoined |
x-msazure-sentinel-alert:hostStates.isAzureAadRegistered |
hostStates.isAzureAadRegistered |
x-msazure-sentinel-alert:hostStates.isHybridAzureDomainJoined |
hostStates.isHybridAzureDomainJoined |
x-msazure-sentinel-alert:hostStates.os |
hostStates.os |
x-msazure-sentinel-alert:hostStates.publicIpAddress |
hostStates.publicIpAddress |
x-msazure-sentinel-alert:hostStates.privateIpAddress |
hostStates.privateIpAddress |
x-msazure-sentinel-alert:hostStates.riskScore |
hostStates.riskScore |
x-msazure-sentinel-alert:malwareStates.category |
malwareStates.category |
x-msazure-sentinel-alert:malwareStates.family |
malwareStates.family |
x-msazure-sentinel-alert:malwareStates.name |
malwareStates.family |
x-msazure-sentinel-alert:malwareStates.severity |
malwareStates.family |
x-msazure-sentinel-alert:malwareStates.wasRunning |
malwareStates.family |
x-msazure-sentinel-alert:networkConnections.applicationName |
networkConnections.applicationName |
x-msazure-sentinel-alert:networkConnections.direction |
networkConnections.direction |
x-msazure-sentinel-alert:networkConnections.domainRegisteredDateTime |
networkConnections.domainRegisteredDateTime |
x-msazure-sentinel-alert:networkConnections.localDnsName |
networkConnections.localDnsName |
x-msazure-sentinel-alert:networkConnections.natDestinationPort |
networkConnections.natDestinationPort |
x-msazure-sentinel-alert:networkConnections.natSourcePort |
networkConnections.natSourcePort |
x-msazure-sentinel-alert:networkConnections.riskScore |
networkConnections.riskScore |
x-msazure-sentinel-alert:networkConnections.status |
networkConnections.status |
x-msazure-sentinel-alert:processes.integrityLevel |
processes.integrityLevel |
x-msazure-sentinel-alert:processes.isElevated |
processes.isElevated |
x-msazure-sentinel-alert:securityResources.resource |
securityResources.resource |
x-msazure-sentinel-alert:securityResources.resourceType |
securityResources.resourceType |
x-msazure-sentinel-alert:triggers.name |
triggers.name |
x-msazure-sentinel-alert:triggers.type |
triggers.type |
x-msazure-sentinel-alert:triggers.value |
triggers.value |
x-msazure-sentinel-alert:userStates.logonIp |
userStates.logonIp |
x-msazure-sentinel-alert:userStates.aadUserId |
userStates.aadUserId |
x-msazure-sentinel-alert:userStates.emailRole |
userStates.emailRole |
x-msazure-sentinel-alert:userStates.isVpn |
userStates.isVpn |
x-msazure-sentinel-alert:userStates.logonLocation |
userStates.logonLocation |
x-msazure-sentinel-alert:userStates.logonType |
userStates.logonType |
x-msazure-sentinel-alert:userStates.onPremisesSecurityIdentifier |
userStates.onPremisesSecurityIdentifier |
x-msazure-sentinel-alert:userStates.riskScore |
userStates.riskScore |
x-msazure-sentinel-alert:userStates.userAccountType |
userStates.userAccountType |
x-msazure-sentinel-alert:userStates.userPrincipalName |
userStates.userPrincipalName |
x-msazure-sentinel-alert:vulnerabilityStates.cve |
vulnerabilityStates.cve |
x-msazure-sentinel-alert:vulnerabilityStates.severity |
vulnerabilityStates.severity |
x-msazure-sentinel-alert:vulnerabilityStates.wasRunning |
vulnerabilityStates.wasRunning |
x-ibm-finding:name |
title |
x-ibm-finding:description |
description |
x-ibm-finding:severity |
severity |
x-ibm-finding:start |
createdDateTime |
x-ibm-finding:end |
closedDateTime |
x-ibm-finding:finding_type |
category |
x-ibm-finding:src_ip_ref.value |
networkConnections.natSourceAddress |
x-ibm-finding:dst_ip_ref.value |
networkConnections.natDestinationAddress |
x-ibm-finding:src_os_ref.name |
hostStates.os |
x-ibm-finding:dst_application_ref.name |
cloudAppStates.destinationServiceName |
x-ibm-finding:src_geolocation |
networkConnections.sourceLocation |
x-ibm-finding:dst_geolocation |
networkConnections.destinationLocation |
x-ibm-finding:src_application_user_ref.user_id |
userStates.aadUserId |
x-ibm-finding:src_application_user_ref.type |
userStates.logonType |
x-ibm-finding:time_observed |
lastModifiedDateTime |
x-oca-event:action |
title |
x-oca-event:code |
id |
x-oca-event:category |
category |
x-oca-event:created |
createdDateTime |
x-oca-event:provider |
vendorInformation.subProvider |
x-oca-event:domain_ref.value |
networkConnections.urlParameters |
x-oca-event:url_ref.value |
networkConnections.urlParameters |
|
|