Galatea007 commited on
Commit
0bf70b9
·
verified ·
1 Parent(s): 146eb8d

Upload udm_field_list.csv

Browse files
Files changed (1) hide show
  1. udm_field_list.csv +989 -0
udm_field_list.csv ADDED
@@ -0,0 +1,989 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ Field Name,Type,Description
2
+ metadata,EntityMetadata,"Entity metadata such as timestamp, product, etc."
3
+ entity,Noun,Noun in the UDM event that this entity represents.
4
+ relations,Relation,"One or more relationships between the entity (a) and other entities, including the relationship type and related entity."
5
+ additional,google.protobuf.Struct,"Important entity data that cannot be adequately represented within
6
+ the formal sections of the Entity."
7
+ risk_score,EntityRisk,Stores information related to the entity's risk score.
8
+ metric,Metric,"Stores statistical metrics about the entity. Used if metadata.entity_type
9
+ is METRIC."
10
+ product_entity_id,string,"A vendor-specific identifier that uniquely identifies the entity
11
+ (e.g. a GUID, LDAP, OID, or similar)."
12
+ collected_timestamp,google.protobuf.Timestamp,"GMT timestamp when the entity information was collected by the vendor's
13
+ local collection infrastructure."
14
+ creation_timestamp,google.protobuf.Timestamp,"GMT timestamp when the entity described by the product_entity_id was
15
+ created on the system where data was collected."
16
+ interval,google.type.Interval,"Valid existence time range for the version of the entity represented by
17
+ this entity data."
18
+ vendor_name,string,Vendor name of the product that produced the entity information.
19
+ product_name,string,Product name that produced the entity information.
20
+ feed,string,Vendor feed name for a threat indicator feed.
21
+ product_version,string,Version of the product that produced the entity information.
22
+ entity_type,EntityMetadata.EntityType (Enumerated list),"Entity type.
23
+ If an entity has multiple possible types, this specifies the most specific
24
+ type."
25
+ description,string,Human-readable description of the entity.
26
+ threat,SecurityResult,"Metadata provided by a threat intelligence feed that identified the
27
+ entity as malicious."
28
+ source_type,EntityMetadata.SourceType (Enumerated list),The source of the entity.
29
+ source_labels,Label,Entity source metadata labels.
30
+ event_metadata,Metadata,Metadata field from the event.
31
+ risk_version,string,Version of the risk score calculation algorithm.
32
+ risk_window,google.type.Interval,"Time window used when computing the risk score for an entity, for
33
+ example 24 hours or 7 days."
34
+ DEPRECATED_risk_score,int32,Deprecated risk score.
35
+ risk_delta,RiskDelta,"Represents the change in risk score for an entity between the end of the
36
+ previous time window and the end of the current time window."
37
+ detections_count,int32,Number of detections that make up the risk score within the time window.
38
+ first_detection_time,google.protobuf.Timestamp,"Timestamp of the first detection within the specified time window.
39
+ This field is empty when there are no detections."
40
+ last_detection_time,google.protobuf.Timestamp,"Timestamp of the last detection within the specified time window.
41
+ This field is empty when there are no detections."
42
+ risk_score,float,Raw risk score for the entity.
43
+ normalized_risk_score,int32,Normalized risk score for the entity. This value is between 0-1000.
44
+ risk_window_size,Int64,Risk window duration for the Entity.
45
+ raw_risk_delta,RiskDelta,"Represents the change in raw risk score for an entity between the end of
46
+ the previous time window and the end of the current time window."
47
+ first_seen,google.protobuf.Timestamp,Timestamp of the first time the entity was seen in the environment.
48
+ last_seen,google.protobuf.Timestamp,Timestamp of the last time the entity was seen in the environment.
49
+ sum_measure,Metric.Measure,Sum of all precomputed measures for the given metric.
50
+ total_events,int64,Total number of events used to calculate the given precomputed metric.
51
+ metric_name,Metric.MetricName (Enumerated list),Name of the analytic.
52
+ dimensions,Metric.Dimension (Enumerated list),All group by clauses used to calculate the metric.
53
+ export_window,int64,Export window for which the metric was exported.
54
+ value,double,Value of the aggregated measure.
55
+ aggregate_function,Metric.AggregateFunction (Enumerated list),Function used to calculate the aggregated measure.
56
+ entity,Noun,Entity (b) that the primary entity (a) is related to.
57
+ entity_type,EntityMetadata.EntityType (Enumerated list),Type of the related entity (b) in this relationship.
58
+ relationship,Relation.Relationship (Enumerated list),Type of relationship.
59
+ direction,Relation.Directionality (Enumerated list),"Directionality of relationship between primary entity (a) and the
60
+ related entity (b)."
61
+ uid,bytes,UID of the relationship.
62
+ entity_label,Relation.EntityLabel (Enumerated list),Label to identify the Noun of the relation.
63
+ previous_range_end_time,google.protobuf.Timestamp,End time of the previous time window.
64
+ risk_score_delta,int32,Difference in the normalized risk score from the previous recorded value.
65
+ previous_risk_score,int32,Risk score from previous risk window
66
+ risk_score_numeric_delta,int32,Numeric change between current and previous risk score
67
+ metadata,Metadata,"Event metadata such as timestamp, source product, etc."
68
+ additional,google.protobuf.Struct,"Any important vendor-specific event data that cannot be adequately
69
+ represented within the formal sections of the UDM model."
70
+ principal,Noun,"Represents the acting entity that originates the activity
71
+ described in the event. The principal must include at least one machine
72
+ detail (hostname, MACs, IPs, port, product-specific identifiers like an
73
+ EDR asset ID) or user detail (for example, username), and optionally
74
+ include process details. It must NOT include any of the following fields:
75
+ email, files, registry keys, or values."
76
+ src,Noun,"Represents a source entity being acted upon by the participant along with
77
+ the device or process context for the source object (the machine where the
78
+
79
+ source object resides). For example, if user U copies file A on machine X
80
+ to file B on machine Y, both file A and machine X would be specified in the
81
+
82
+ src portion of the UDM event."
83
+ target,Noun,"Represents a target entity being referenced by the event or an object on
84
+ the target entity. For example, in a firewall connection from device A to
85
+ device B, A is described as the principal and B is described as the target.
86
+ For a process injection by process C into target process D, process C is
87
+ described as the principal and process D is described as the target."
88
+ intermediary,Noun,"Represents details on one or more intermediate entities processing activity
89
+ described in the event. This includes device details about a proxy server
90
+ or SMTP relay server. If an active event (that has a principal and
91
+ possibly target) passes through any intermediaries, they're added here.
92
+ Intermediaries can impact the overall action, for example blocking or
93
+ modifying an ongoing request. A rule of thumb here is that 'principal',
94
+ 'target', and description of the initial action should be the same
95
+ regardless of the intermediary or its action. A successful network
96
+ connection from A->B should look the same in principal/target/intermediary
97
+ as one blocked by firewall C: principal: A, target: B (intermediary: C)."
98
+ observer,Noun,"Represents an observer entity (for example, a packet sniffer or
99
+ network-based vulnerability scanner), which is not a direct intermediary,
100
+ but which observes and reports on the event in question."
101
+ about,Noun,"Represents entities referenced by the event that are not otherwise
102
+ described in principal, src, target, intermediary or observer. For example,
103
+ it could be used to track email file attachments, domains/URLs/IPs embedded
104
+ within an email body, and DLLs that are loaded during a PROCESS_LAUNCH
105
+ event."
106
+ security_result,SecurityResult,A list of security results.
107
+ network,Network,"All network details go here, including sub-messages with details on each
108
+ protocol (for example, DHCP, DNS, or HTTP)."
109
+ extensions,Extensions,"All other first-class, event-specific metadata goes in this message.
110
+ Don't place protocol metadata in Extensions; put it in Network."
111
+ auth,Authentication,An authentication extension.
112
+ vulns,Vulnerabilities,A vulnerability extension.
113
+ id,bytes,ID of the UDM event. Can be used for raw and normalized event retrieval.
114
+ product_log_id,string,"A vendor-specific event identifier to uniquely identify the event (for example: a
115
+ GUID)."
116
+ event_timestamp,google.protobuf.Timestamp,The GMT timestamp when the event was generated.
117
+ collected_timestamp,google.protobuf.Timestamp,"The GMT timestamp when the event was collected by the vendor's local
118
+ collection infrastructure."
119
+ ingested_timestamp,google.protobuf.Timestamp,The GMT timestamp when the event was ingested (received) by Google Security Operations.
120
+ event_type,Metadata.EventType,"The event type.
121
+ If an event has multiple possible types, this specifies the most specific
122
+ type."
123
+ vendor_name,string,The name of the product vendor.
124
+ product_name,string,The name of the product.
125
+ product_version,string,The version of the product.
126
+ product_event_type,string,"A short, descriptive, human-readable, product-specific event name or type
127
+ (for example: ""Scanned X"", ""User account created"", ""process_start"")."
128
+ product_deployment_id,string,The deployment identifier assigned by the vendor for a product deployment.
129
+ description,string,A human-readable unparsable description of the event.
130
+ url_back_to_product,string,A URL that takes the user to the source product console for this event.
131
+ ingestion_labels,Label,User-configured ingestion metadata labels.
132
+ tags,Tags,"Tags added by Google Security Operations after an event is parsed. It is an error to
133
+ populate this field from within a parser."
134
+ enrichment_state,Metadata.EnrichmentState,The enrichment state.
135
+ log_type,string,The string value of log type.
136
+ base_labels,DataAccessLabels,Data access labels on the base event.
137
+ enrichment_labels,DataAccessLabels,"Data access labels from all the contextual events used to enrich the base
138
+ event."
139
+ sent_bytes,uint64,The number of bytes sent.
140
+ received_bytes,uint64,The number of bytes received.
141
+ sent_packets,int64,The number of packets sent.
142
+ received_packets,int64,The number of packets received.
143
+ session_duration,Int64,"The duration of the session as the number of seconds and nanoseconds.
144
+ For seconds, network.session_duration.seconds, the type is a 64-bit
145
+ integer. For nanoseconds, network.session_duration.nanos, the type is a
146
+ 32-bit integer."
147
+ session_id,string,The ID of the network session.
148
+ parent_session_id,string,The ID of the parent network session.
149
+ application_protocol_version,string,"The version of the application protocol. e.g. ""1.1, 2.0"""
150
+ community_id,string,Community ID network flow value.
151
+ direction,Network.Direction,The direction of network traffic.
152
+ ip_protocol,Network.IpProtocol,The IP protocol.
153
+ application_protocol,Network.ApplicationProtocol,The application protocol.
154
+ ftp,Ftp,FTP info.
155
+ email,Email,Email info for the sender/recipient.
156
+ dns,Dns,DNS info.
157
+ dhcp,Dhcp,DHCP info.
158
+ http,Http,HTTP info.
159
+ tls,Tls,TLS info.
160
+ smtp,Smtp,"SMTP info.
161
+ Store fields specific to SMTP not covered by Email."
162
+ asn,string,Autonomous system number.
163
+ dns_domain,string,DNS domain name.
164
+ carrier_name,string,Carrier identification.
165
+ organization_name,string,Organization name (e.g Google).
166
+ ip_subnet_range,string,Associated human-readable IP subnet range (e.g. 10.1.2.0/24).
167
+ hostname,string,"Client hostname or domain name field.
168
+ Hostname also doubles as the domain for remote entities."
169
+ domain,Domain,Information about the domain.
170
+ artifact,Artifact,Information about an artifact.
171
+ url_metadata,URL,Information about the URL.
172
+ asset_id,string,The asset ID.
173
+ user,User,Information about the user.
174
+ user_management_chain,User,"Information about the user's management chain (reporting hierarchy).
175
+ Note: user_management_chain is only populated when data is exported to
176
+ BigQuery since recursive fields (e.g. user.managers) are not supported by
177
+ BigQuery."
178
+ group,Group,Information about the group.
179
+ process,Process,Information about the process.
180
+ process_ancestors,Process,"Information about the process's ancestors ordered from immediate ancestor
181
+ (parent process) to root.
182
+ Note: process_ancestors is only populated when data is exported to BigQuery
183
+
184
+ since recursive fields (e.g. process.parent_process) are not supported by
185
+ BigQuery."
186
+ asset,Asset,Information about the asset.
187
+ ip,string,A list of IP addresses associated with a network connection.
188
+ nat_ip,string,A list of NAT translated IP addresses associated with a network connection.
189
+ port,int32,"Source or destination network port number when a specific network
190
+ connection is described within an event."
191
+ nat_port,int32,"NAT external network port number when a specific network connection is
192
+ described within an event."
193
+ mac,string,List of MAC addresses associated with a device.
194
+ administrative_domain,string,"Domain which the device belongs to (for example, the Microsoft Windows
195
+ domain)."
196
+ namespace,string,"Namespace which the device belongs to, such as ""AD forest"".
197
+ Uses for this field include Microsoft Windows AD forest, the name of
198
+
199
+ subsidiary, or the name of acquisition."
200
+ URL,string,The URL.
201
+ file,File,Information about the file.
202
+ email,string,"Email address.
203
+ Only filled in for security_result.about"
204
+ registry,Registry,Registry information.
205
+ application,string,"The name of an application or service.
206
+ Some SSO solutions only capture the name of a target application
207
+ such as ""Atlassian"" or ""Google""."
208
+ platform,Noun.Platform,Platform.
209
+ platform_version,string,"Platform version. For example,
210
+ ""Microsoft Windows 1803""."
211
+ platform_patch_level,string,"Platform patch level.
212
+ For example, ""Build 17134.48"""
213
+ cloud,Cloud,"Cloud metadata.
214
+ Deprecated: cloud should be populated in entity Attribute as generic
215
+ metadata (e.g. asset.attribute.cloud)."
216
+ location,Location,"Physical location. For cloud environments, set the region in
217
+ location.name."
218
+ ip_location,Location,Deprecated: use ip_geo_artifact.location instead.
219
+ ip_geo_artifact,Artifact,"Enriched geographic information corresponding to an IP address.
220
+ Specifically, location and network data."
221
+ resource,Resource,"Information about the resource (e.g. scheduled task, calendar entry).
222
+ This field should not be used for files, registry, or processes because
223
+ these objects are already part of Noun."
224
+ resource_ancestors,Resource,"Information about the resource's ancestors ordered from immediate ancestor
225
+ (starting with parent resource)."
226
+ labels,Label,"Labels are key-value pairs.
227
+ For example: key = ""env"", value = ""prod"".
228
+ Deprecated: labels should be populated in entity Attribute as generic
229
+ metadata (e.g. user.attribute.labels)."
230
+ object_reference,Id,Finding to which the Analyst updated the feedback.
231
+ investigation,Investigation,Analyst feedback/investigation for alerts.
232
+ network,Network,"Network details, including sub-messages with details on each protocol
233
+ (for example, DHCP, DNS, or HTTP)."
234
+ security_result,SecurityResult,A list of security results.
235
+ about,Noun,"If the security result is about a specific entity (Noun), add it here."
236
+ category,SecurityResult.SecurityCategory,The security category.
237
+ category_details,string,"For vendor-specific categories. For web categorization, put type in here
238
+
239
+ such as ""gambling"" or ""porn""."
240
+ threat_name,string,"A vendor-assigned classification common across multiple customers
241
+ (e.g. ""W32/File-A"", ""Slammer"")."
242
+ rule_set,string,"The result's rule set identifier.
243
+ (e.g. ""windows-threats"")"
244
+ rule_set_display_name,string,The curated detections rule set display name.
245
+ ruleset_category_display_name,string,"The curated detection rule set category display name.
246
+ (for example, if rule_set_display_name is ""CDIR SCC Enhanced Exfiltration"",
247
+ the rule_set_category is ""Cloud Threats"")."
248
+ rule_id,string,"A vendor-specific ID and name for a rule, varying by observerer type
249
+ (e.g. ""08123"", ""5d2b44d0-5ef6-40f5-a704-47d61d3babbe"")."
250
+ rule_name,string,"Name of the security rule
251
+ (e.g. ""BlockInboundToOracle"")."
252
+ rule_version,string,"Version of the security rule.
253
+ (e.g. ""v1.1"", ""00001"", ""1604709794"", ""2020-11-16T23:04:19+00:00"").
254
+ Note that rule versions are source-dependant and lexical ordering
255
+
256
+ should not be assumed."
257
+ rule_type,string,The type of security rule.
258
+ rule_author,string,Author of the security rule.
259
+ rule_labels,Label,"A list of rule labels that can't be captured by the other fields
260
+ in security result
261
+ (e.g. ""reference : AnotherRule"", ""contributor : John"")."
262
+ alert_state,SecurityResult.AlertState,The alerting types of this security result.
263
+ detection_fields,Label,"An ordered list of values, that represent fields in detections for a
264
+
265
+ security finding. This list represents mapping of names of requested
266
+ entities to their values (i.e. the security result matched variables) ."
267
+ outcomes,Label,"A list of outcomes that represent the results of this security finding.
268
+ This list represents a mapping of names of the requested outcomes,
269
+ to their values."
270
+ summary,string,"A human readable summary (e.g. ""failed login occurred"")"
271
+ description,string,"A human readable description (e.g. ""user password was wrong"")"
272
+ action,SecurityResult.Action,Actions taken for this event.
273
+ action_details,string,The detail of the action taken as provided by the vendor.
274
+ severity,SecurityResult.ProductSeverity,The severity of the result.
275
+ confidence,SecurityResult.ProductConfidence,The confidence level of the result as estimated by the product.
276
+ priority,SecurityResult.ProductPriority,The priority of the result.
277
+ risk_score,float,The risk score of the security result.
278
+ confidence_score,float,The confidence score of the security result.
279
+ analytics_metadata,AnalyticsMetadata,Stores metadata about each risk analytic metric the rule uses.
280
+ severity_details,string,Vendor-specific severity.
281
+ confidence_details,string,"Additional detail with regards to the confidence of a security event as
282
+ estimated by the product vendor."
283
+ priority_details,string,Vendor-specific information about the security result priority.
284
+ url_back_to_product,string,URL that takes the user to the source product console for this event.
285
+ threat_id,string,Vendor-specific ID for a threat.
286
+ threat_feed_name,string,Vendor feed name for a threat indicator feed.
287
+ threat_id_namespace,Id.Namespace,"The attribute threat_id_namespace qualifies threat_id with an ID namespace
288
+ to get an
289
+ unique ID. The attribute threat_id by itself is not unique across Google SecOps
290
+ as it is a vendor specific ID."
291
+ threat_status,SecurityResult.ThreatStatus,Current status of the threat
292
+ attack_details,AttackDetails,MITRE ATT&CK details.
293
+ first_discovered_time,google.protobuf.Timestamp,First time the IoC threat was discovered in the provider.
294
+ associations,SecurityResult.Association,Associations related to the threat.
295
+ campaigns,string,Campaigns using this IOC threat.
296
+ verdict,SecurityResult.Verdict,"Verdict about the IoC from the provider.
297
+ This field is now deprecated. Use VerdictInfo instead."
298
+ last_updated_time,google.protobuf.Timestamp,Last time the IoC threat was updated in the provider.
299
+ verdict_info,SecurityResult.VerdictInfo,Verdict information about the IoC from the provider.
300
+ threat_verdict,ThreatVerdict,GCTI threat verdict on the security result entity.
301
+ last_discovered_time,google.protobuf.Timestamp,Last time the IoC was seen in the provider data.
302
+ analytic,string,Name of the analytic.
303
+ ip,string,IP address of the artifact.
304
+ prevalence,Prevalence,The prevalence of the artifact within the customer's environment.
305
+ first_seen_time,google.protobuf.Timestamp,First seen timestamp of the IP in the customer's environment.
306
+ last_seen_time,google.protobuf.Timestamp,Last seen timestamp of the IP address in the customer's environment.
307
+ location,Location,Location of the Artifact's IP address.
308
+ network,Network,Network information related to the Artifact's IP address.
309
+ as_owner,string,Owner of the Autonomous System to which the IP address belongs.
310
+ asn,int64,Autonomous System Number to which the IP address belongs.
311
+ jarm,string,"The JARM hash for the IP address.
312
+ (https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a)."
313
+ last_https_certificate,SSLCertificate,SSL certificate information about the IP address.
314
+ last_https_certificate_date,google.protobuf.Timestamp,Most recent date for the certificate in VirusTotal.
315
+ regional_internet_registry,string,"RIR (one of the current RIRs: AFRINIC, ARIN, APNIC, LACNIC or RIPE NCC)."
316
+ tags,string,Identification attributes
317
+ whois,string,WHOIS information as returned from the pertinent WHOIS server.
318
+ whois_date,google.protobuf.Timestamp,Date of the last update of the WHOIS record in VirusTotal.
319
+ product_object_id,string,"A vendor-specific identifier to uniquely identify the entity (a GUID or
320
+
321
+ similar)."
322
+ hostname,string,Asset hostname or domain name field.
323
+ asset_id,string,"The asset ID. Value must contain the ':' character. For example,
324
+ cs:abcdd23434."
325
+ ip,string,A list of IP addresses associated with an asset.
326
+ mac,string,List of MAC addresses associated with an asset.
327
+ nat_ip,string,List of NAT IP addresses associated with an asset.
328
+ first_seen_time,google.protobuf.Timestamp,"The first observed time for an asset.
329
+ The value is calculated on the basis of the
330
+ first time the identifier was observed."
331
+ hardware,Hardware,The asset hardware specifications.
332
+ platform_software,PlatformSoftware,The asset operating system platform software.
333
+ software,Software,The asset software details.
334
+ location,Location,Location of the asset.
335
+ category,string,"The category of the asset (e.g. ""End User Asset"", ""Workstation"", ""Server"")."
336
+ type,Asset.AssetType,The type of the asset (e.g. workstation or laptop or server).
337
+ network_domain,string,"The network domain of the asset (e.g. ""corp.acme.com"")"
338
+ creation_time,google.protobuf.Timestamp,"Time the asset was created or provisioned.
339
+ Deprecate: creation_time should be populated in Attribute as generic
340
+ metadata."
341
+ first_discover_time,google.protobuf.Timestamp,"Time the asset was first discovered (by asset management/discoverability
342
+
343
+ software)."
344
+ last_discover_time,google.protobuf.Timestamp,"Time the asset was last discovered (by asset management/discoverability
345
+
346
+ software)."
347
+ system_last_update_time,google.protobuf.Timestamp,"Time the asset system or OS was last updated.
348
+ For all other operations that are not system updates (such as resizing a
349
+ VM), use Attribute.last_update_time."
350
+ last_boot_time,google.protobuf.Timestamp,Time the asset was last boot started.
351
+ labels,Label,"Metadata labels for the asset.
352
+ Deprecated: labels should be populated in Attribute as generic metadata."
353
+ deployment_status,Asset.DeploymentStatus,The deployment status of the asset for device lifecycle purposes.
354
+ vulnerabilities,Vulnerability,Vulnerabilities discovered on asset.
355
+ attribute,Attribute,Generic entity metadata attributes of the asset.
356
+ version,string,ATT&CK version (e.g. 12.1).
357
+ tactics,AttackDetails.Tactic,Tactics employed.
358
+ techniques,AttackDetails.Technique,Techniques employed.
359
+ id,string,"Tactic ID (e.g. ""TA0043"")."
360
+ name,string,"Tactic Name (e.g. ""Reconnaissance"")"
361
+ id,string,"Technique ID (e.g. ""T1595"")."
362
+ name,string,"Technique Name (e.g. ""Active Scanning"")."
363
+ subtechnique_id,string,"Subtechnique ID (e.g. ""T1595.001"")."
364
+ subtechnique_name,string,"Subtechnique Name (e.g. ""Scanning IP Blocks"")."
365
+ cloud,Cloud,"Cloud metadata attributes such as project ID, account ID, or organizational
366
+ hierarchy."
367
+ labels,Label,"Set of labels for the entity. Should only be used for product labels (for
368
+ example, Google Cloud resource labels or Azure AD sensitivity labels.
369
+ Should not be used for arbitrary key-value mappings."
370
+ permissions,Permission,"System permissions for IAM entity
371
+ (human principal, service account, group)."
372
+ roles,Role,"System IAM roles to be assumed by resources to use the role's permissions
373
+ for access control."
374
+ creation_time,google.protobuf.Timestamp,Time the resource or entity was created or provisioned.
375
+ last_update_time,google.protobuf.Timestamp,Time the resource or entity was last updated.
376
+ type,Authentication.AuthType,The type of authentication.
377
+ mechanism,Authentication.Mechanism,The authentication mechanism.
378
+ auth_details,string,The vendor defined details of the authentication.
379
+ version,string,Certificate version.
380
+ serial,string,Certificate serial number.
381
+ subject,string,Subject of the certificate.
382
+ issuer,string,Issuer of the certificate.
383
+ md5,string,"The MD5 hash of the certificate, as a hex-encoded string."
384
+ sha1,string,"The SHA1 hash of the certificate, as a hex-encoded string."
385
+ sha256,string,"The SHA256 hash of the certificate, as a hex-encoded string."
386
+ not_before,google.protobuf.Timestamp,Indicates when the certificate is first valid.
387
+ not_after,google.protobuf.Timestamp,Indicates when the certificate is no longer valid.
388
+ environment,Cloud.CloudEnvironment,The Cloud environment.
389
+ vpc,Resource,"The cloud environment VPC.
390
+ Deprecated."
391
+ project,Resource,"The cloud environment project information.
392
+ Deprecated: Use Resource.resource_ancestors"
393
+ availability_zone,string,"The cloud environment availability zone (different from region which is
394
+ location.name)."
395
+ type,string,Type.
396
+ value,string,Value.
397
+ ttl,Int64,Time to live.
398
+ priority,int64,Priority.
399
+ retry,int64,Retry.
400
+ refresh,Int64,Refresh.
401
+ minimum,Int64,Minimum.
402
+ expire,Int64,Expire.
403
+ serial,int64,Serial.
404
+ rname,string,Rname.
405
+ opcode,Dhcp.OpCode,The BOOTP op code.
406
+ htype,uint32,Hardware address type.
407
+ hlen,uint32,Hardware address length.
408
+ hops,uint32,Hardware ops.
409
+ transaction_id,uint32,Transaction ID.
410
+ seconds,uint32,Seconds elapsed since client began address acquisition/renewal process.
411
+ flags,uint32,Flags.
412
+ ciaddr,string,Client IP address (ciaddr).
413
+ yiaddr,string,Your IP address (yiaddr).
414
+ siaddr,string,IP address of the next bootstrap server.
415
+ giaddr,string,Relay agent IP address (giaddr).
416
+ chaddr,string,Client hardware address (chaddr).
417
+ sname,string,Server name that the client wishes to boot from.
418
+ file,string,Boot image filename.
419
+ options,Dhcp.Option,List of DHCP options.
420
+ type,Dhcp.MessageType,DHCP message type.
421
+ lease_time_seconds,uint32,"Lease time in seconds. See RFC2132, section 9.2."
422
+ client_hostname,string,"Client hostname. See RFC2132, section 3.14."
423
+ client_identifier,bytes,"Client identifier. See RFC2132, section 9.14."
424
+ requested_address,string,"Requested IP address. See RFC2132, section 9.1."
425
+ code,uint32,Code. See RFC1533.
426
+ data,bytes,Data.
427
+ id,uint32,DNS query id.
428
+ response,bool,Set to true if the event is a DNS response. See QR field from RFC1035.
429
+ opcode,uint32,"The DNS OpCode used to specify the type of DNS query
430
+ (for example, QUERY, IQUERY, or STATUS)."
431
+ authoritative,bool,"Other DNS header flags. See RFC1035, section 4.1.1."
432
+ truncated,bool,Whether the DNS response was truncated.
433
+ recursion_desired,bool,Whether a recursive DNS lookup is desired.
434
+ recursion_available,bool,Whether a recursive DNS lookup is available.
435
+ response_code,uint32,Response code. See RCODE from RFC1035.
436
+ questions,Dns.Question,A list of domain protocol message questions.
437
+ answers,Dns.ResourceRecord,A list of answers to the domain name query.
438
+ authority,Dns.ResourceRecord,"A list of domain name servers which verified the answers to the domain name
439
+ queries."
440
+ additional,Dns.ResourceRecord,"A list of additional domain name servers that can be used to verify the
441
+ answer to the domain."
442
+ name,string,The domain name.
443
+ type,uint32,The code specifying the type of the query.
444
+ class,uint32,The code specifying the class of the query.
445
+ prevalence,Prevalence,The prevalence of the domain within the customer's environment.
446
+ name,string,The name of the owner of the resource record.
447
+ type,uint32,The code specifying the type of the resource record.
448
+ class,uint32,The code specifying the class of the resource record.
449
+ ttl,uint32,"The time interval for which the resource record can be cached before the
450
+
451
+ source of the information should again be queried."
452
+ data,string,"The payload or response to the DNS question for all responses encoded in
453
+ UTF-8 format"
454
+ binary_data,bytes,"The raw bytes of any non-UTF8 strings that might be included as part of a
455
+ DNS response."
456
+ name,string,The domain name.
457
+ prevalence,Prevalence,The prevalence of the domain within the customer's environment.
458
+ first_seen_time,google.protobuf.Timestamp,First seen timestamp of the domain in the customer's environment.
459
+ last_seen_time,google.protobuf.Timestamp,Last seen timestamp of the domain in the customer's environment.
460
+ registrar,string,"Registrar name . FOr example, ""Wild West Domains, Inc. (R120-LROR)"",
461
+ ""GoDaddy.com, LLC"", or ""PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM""."
462
+ contact_email,string,Contact email address.
463
+ whois_server,string,Whois server name.
464
+ name_server,string,Repeated list of name servers.
465
+ creation_time,google.protobuf.Timestamp,Domain creation time.
466
+ update_time,google.protobuf.Timestamp,Last updated time.
467
+ expiration_time,google.protobuf.Timestamp,Expiration time.
468
+ audit_update_time,google.protobuf.Timestamp,Audit updated time.
469
+ status,string,"Domain status. See
470
+ https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en
471
+ for meanings of possible values"
472
+ registrant,User,Parsed contact information for the registrant of the domain.
473
+ admin,User,Parsed contact information for the administrative contact for the domain.
474
+ tech,User,Parsed contact information for the technical contact for the domain
475
+ billing,User,Parsed contact information for the billing contact of the domain.
476
+ zone,User,Parsed contact information for the zone.
477
+ whois_record_raw_text,bytes,WHOIS raw text.
478
+ registry_data_raw_text,bytes,Registry Data raw text.
479
+ iana_registrar_id,int32,"IANA Registrar ID. See
480
+ https://www.iana.org/assignments/registrar-ids/registrar-ids.xhtml"
481
+ private_registration,bool,"Indicates whether the domain appears to be using a private registration
482
+
483
+ service to mask the owner's contact information."
484
+ categories,string,Categories assign to the domain as retrieved from VirusTotal.
485
+ favicon,Favicon,Includes difference hash and MD5 hash of the domain's favicon.
486
+ jarm,string,Domain's JARM hash.
487
+ last_dns_records,DNSRecord,Domain's DNS records from the last scan.
488
+ last_dns_records_time,google.protobuf.Timestamp,Date when the DNS records list was retrieved by VirusTotal.
489
+ last_https_certificate,SSLCertificate,SSL certificate object retrieved last time the domain was analyzed.
490
+ last_https_certificate_time,google.protobuf.Timestamp,When the certificate was retrieved by VirusTotal.
491
+ popularity_ranks,PopularityRank,"Domain's position in popularity ranks such as Alexa, Quantcast, Statvoo,
492
+ etc"
493
+ tags,string,List of representative attributes.
494
+ whois_time,google.protobuf.Timestamp,Date of the last update of the WHOIS record.
495
+ from,string,The 'from' address.
496
+ reply_to,string,The 'reply to' address.
497
+ to,string,A list of 'to' addresses.
498
+ cc,string,A list of 'cc' addresses.
499
+ bcc,string,A list of 'bcc' addresses.
500
+ mail_id,string,The mail (or message) ID.
501
+ subject,string,The subject line(s) of the email.
502
+ bounce_address,string,"The envelope from address.
503
+ https://en.wikipedia.org/wiki/Bounce_address"
504
+ raw_md5,string,Favicon's MD5 hash.
505
+ dhash,string,Difference hash.
506
+ sha256,string,"The SHA256 hash of the file, as a hex-encoded string."
507
+ md5,string,"The MD5 hash of the file, as a hex-encoded string."
508
+ sha1,string,"The SHA1 hash of the file, as a hex-encoded string."
509
+ size,uint64,The size of the file in bytes.
510
+ full_path,string,The full path identifying the location of the file on the system.
511
+ mime_type,string,"The MIME (Multipurpose Internet Mail Extensions) type of the file,
512
+ for example ""PE"", ""PDF"", or ""powershell script""."
513
+ file_metadata,FileMetadata,"Metadata associated with the file.
514
+ Deprecate FileMetadata in favor of using fields in File."
515
+ security_result,SecurityResult,"Google Cloud Threat Intelligence (GCTI) security result for the file
516
+ including threat context and detection metadata."
517
+ pe_file,FileMetadataPE,Metadata about the Portable Executable (PE) file.
518
+ ssdeep,string,Ssdeep of the file
519
+ vhash,string,Vhash of the file.
520
+ ahash,string,Deprecated. Use authentihash instead.
521
+ authentihash,string,Authentihash of the file.
522
+ file_type,File.FileType,FileType field.
523
+ capabilities_tags,string,Capabilities tags.
524
+ names,string,Names fields.
525
+ tags,string,Tags for the file.
526
+ last_modification_time,google.protobuf.Timestamp,Timestamp when the file was last updated.
527
+ prevalence,Prevalence,Prevalence of the file hash in the customer's environment.
528
+ first_seen_time,google.protobuf.Timestamp,Timestamp the file was first seen in the customer's environment.
529
+ last_seen_time,google.protobuf.Timestamp,Timestamp the file was last seen in the customer's environment.
530
+ stat_mode,uint64,"The mode of the file. A bit string indicating the permissions and
531
+ privileges of the file."
532
+ stat_inode,uint64,The file identifier. Unique identifier of object within a file system.
533
+ stat_dev,uint64,The file system identifier to which the object belongs.
534
+ stat_nlink,uint64,Number of links to file.
535
+ stat_flags,uint32,User defined flags for file.
536
+ last_analysis_time,google.protobuf.Timestamp,Timestamp the file was last analysed.
537
+ embedded_urls,string,Embedded URLs found in the file.
538
+ embedded_domains,string,Embedded domains found in the file.
539
+ embedded_ips,string,Embedded IP addresses found in the file.
540
+ exif_info,ExifInfo,Exif metadata from different file formats extracted by exiftool.
541
+ signature_info,SignatureInfo,File signature information extracted from different tools.
542
+ pdf_info,PDFInfo,Information about the PDF file structure.
543
+ first_submission_time,google.protobuf.Timestamp,First submission time of the file.
544
+ last_submission_time,google.protobuf.Timestamp,Last submission time of the file.
545
+ main_icon,Favicon,Icon's relevant hashes.
546
+ id,string,Code sign identifier.
547
+ format,string,Code sign format.
548
+ compilation_time,google.protobuf.Timestamp,Code sign timestamp
549
+ imphash,string,Imphash of the file.
550
+ entry_point,int64,info.pe-entry-point.
551
+ entry_point_exiftool,int64,info.exiftool.EntryPoint.
552
+ compilation_time,google.protobuf.Timestamp,info.pe-timestamp.
553
+ compilation_exiftool_time,google.protobuf.Timestamp,info.exiftool.TimeStamp.
554
+ section,FileMetadataSection,FilemetadataSection fields.
555
+ imports,FileMetadataImports,FilemetadataImports fields.
556
+ resource,FileMetadataPeResourceInfo,FilemetadataPeResourceInfo fields.
557
+ resources_type_count,StringToInt64MapEntry,Deprecated: use resources_type_count_str.
558
+ resources_language_count,StringToInt64MapEntry,Deprecated: use resources_language_count_str.
559
+ resources_type_count_str,Label,"Number of resources by resource type.
560
+ Example: RT_ICON: 10, RT_DIALOG: 5"
561
+ resources_language_count_str,Label,"Number of resources by language.
562
+ Example: NEUTRAL: 20, ENGLISH US: 10"
563
+ signature_info,FileMetadataSignatureInfo,"FilemetadataSignatureInfo field.
564
+ deprecated, user File.signature_info instead."
565
+ verification_message,string,"Status of the certificate.
566
+ Valid values are ""Signed"", ""Unsigned"" or a description of the certificate
567
+ anomaly, if found."
568
+ verified,bool,"True if verification_message == ""Signed"""
569
+ signer,string,Deprecated: use signers field.
570
+ signers,SignerInfo,"File metadata signer information.
571
+ The order of the signers matters. Each element is a higher level
572
+ authority, being the last the root authority."
573
+ x509,X509,List of certificates.
574
+ command,string,The FTP command.
575
+ product_object_id,string,"Product globally unique user object identifier, such as an LDAP Object
576
+ Identifier."
577
+ creation_time,google.protobuf.Timestamp,"Group creation time.
578
+ Deprecated: creation_time should be populated in Attribute as generic
579
+ metadata."
580
+ group_display_name,string,"Group display name. e.g. ""Finance""."
581
+ attribute,Attribute,Generic entity metadata attributes of the group.
582
+ email_addresses,string,Email addresses of the group.
583
+ windows_sid,string,Microsoft Windows SID of the group.
584
+ serial_number,string,Hardware serial number.
585
+ manufacturer,string,Hardware manufacturer.
586
+ model,string,Hardware model.
587
+ cpu_platform,string,"Platform of the hardware CPU (e.g. ""Intel Broadwell"")."
588
+ cpu_model,string,"Model description of the hardware CPU
589
+ (e.g. ""2.8 GHz Quad-Core Intel Core i5"")."
590
+ cpu_clock_speed,uint64,Clock speed of the hardware CPU in MHz.
591
+ cpu_max_clock_speed,uint64,Maximum possible clock speed of the hardware CPU in MHz.
592
+ cpu_number_cores,uint64,Number of CPU cores.
593
+ ram,uint64,Amount of the hardware ramdom access memory (RAM) in Mb.
594
+ method,string,"The HTTP request method
595
+ (e.g. ""GET"", ""POST"", ""PATCH"", ""DELETE"")."
596
+ referral_url,string,The URL for the HTTP referer.
597
+ user_agent,string,"The User-Agent request header which includes the application type,
598
+ operating system, software vendor or software version of the requesting
599
+
600
+ software user agent."
601
+ response_code,int32,"The response status code, for example
602
+ 200, 302, 404, or 500."
603
+ parsed_user_agent,,The parsed user_agent string.
604
+ verdict,Verdict,Describes reason a finding investigation was resolved.
605
+ reputation,Reputation,Describes whether a finding was useful or not-useful.
606
+ severity_score,uint32,Severity score for a finding set by an analyst.
607
+ status,Status,Describes the workflow status of a finding.
608
+ comments,string,Comment added by the Analyst.
609
+ priority,Priority,Priority of the Alert or Finding set by analyst.
610
+ root_cause,string,Root cause of the Alert or Finding set by analyst.
611
+ reason,Reason,Reason for closing the Case or Alert.
612
+ risk_score,uint32,Risk score for a finding set by an analyst.
613
+ key,string,The key.
614
+ value,string,The value.
615
+ rbac_enabled,bool,Indicates whether this label can be used for Data RBAC
616
+ city,string,The city.
617
+ state,string,The state.
618
+ country_or_region,string,The country or region.
619
+ name,string,"Custom location name (e.g. building or site name like ""London Office"").
620
+ For cloud environments, this is the region (e.g. ""us-west2"")."
621
+ desk_name,string,"Desk name or individual location, typically for an employee in an
622
+ office.
623
+ (e.g. ""IN-BLR-BCPC-11-1121D"")."
624
+ floor_name,string,"Floor name, number or a combination of the two for a building.
625
+ (e.g. ""1-A"")."
626
+ region_latitude,float,Deprecated: use region_coordinates.
627
+ region_longitude,float,Deprecated: use region_coordinates.
628
+ region_coordinates,google.type.LatLng,"Coordinates for the associated region.
629
+ See https://cloud.google.com/vision/docs/reference/rest/v1/LatLng
630
+ for a description of the fields."
631
+ js,int64,"Number of /JS tags found in the PDF file. Should be the same as
632
+ javascript field in normal scenarios."
633
+ javascript,int64,"Number of /JavaScript tags found in the PDF file. Should be the same as
634
+ the js field in normal scenarios."
635
+ launch_action_count,int64,Number of /Launch tags found in the PDF file.
636
+ object_stream_count,int64,Number of object streams.
637
+ endobj_count,int64,Number of object definitions (endobj keyword).
638
+ header,string,PDF version.
639
+ acroform,int64,Number of /AcroForm tags found in the PDF.
640
+ autoaction,int64,Number of /AA tags found in the PDF.
641
+ embedded_file,int64,Number of /EmbeddedFile tags found in the PDF.
642
+ encrypted,int64,"Whether the document is encrypted or not. This is defined by the /Encrypt
643
+ tag."
644
+ flash,int64,Number of /RichMedia tags found in the PDF.
645
+ jbig2_compression,int64,Number of /JBIG2Decode tags found in the PDF.
646
+ obj_count,int64,Number of objects definitions (obj keyword).
647
+ endstream_count,int64,Number of defined stream objects (stream keyword).
648
+ page_count,int64,Number of pages in the PDF.
649
+ stream_count,int64,Number of defined stream objects (stream keyword).
650
+ openaction,int64,Number of /OpenAction tags found in the PDF.
651
+ startxref,int64,Number of startxref keywords in the PDF.
652
+ suspicious_colors,int64,Number of colors expressed with more than 3 bytes (CVE-2009-3459).
653
+ trailer,int64,Number of trailer keywords in the PDF.
654
+ xfa,int64,Number of \XFA tags found in the PDF.
655
+ xref,int64,Number of xref keywords in the PDF.
656
+ import_hash,string,Hash of PE imports.
657
+ name,string,Name of the permission (e.g. chronicle.analyst.updateRule).
658
+ description,string,Description of the permission (e.g. 'Ability to update detect rules').
659
+ type,Permission.PermissionType,Type of the permission.
660
+ platform,Noun.Platform,The platform operating system.
661
+ platform_version,string,"The platform software version (
662
+ e.g. ""Microsoft Windows 1803"")."
663
+ platform_patch_level,string,"The platform software patch level (
664
+ e.g. ""Build 17134.48"", ""SP1"")."
665
+ giver,string,Name of the rank serial number hexdump.
666
+ rank,int64,Rank position.
667
+ ingestion_time,google.protobuf.Timestamp,Timestamp when the rank was ingested.
668
+ rolling_max,int32,"The maximum number of assets per day accessing the resource over the
669
+ trailing day_count days."
670
+ day_count,int32,The number of days over which rolling_max is calculated.
671
+ rolling_max_sub_domains,int32,"The maximum number of assets per day accessing the domain along with
672
+
673
+ sub-domains over the trailing day_count days. This field is only valid for
674
+ domains."
675
+ day_max,int32,The max prevalence score in a day interval window.
676
+ day_max_sub_domains,int32,"The max prevalence score in a day interval window across sub-domains. This
677
+ field is only valid for domains."
678
+ pid,string,The process ID.
679
+ parent_pid,string,"The ID of the parent process.
680
+ Deprecated: use parent_process.pid instead."
681
+ parent_process,Process,Information about the parent process.
682
+ file,File,Information about the file in use by the process.
683
+ command_line,string,The command line command that created the process.
684
+ command_line_history,string,The command line history of the process.
685
+ product_specific_process_id,string,A product specific process id.
686
+ access_mask,uint64,A bit mask representing the level of access.
687
+ integrity_level_rid,uint64,The Microsoft Windows integrity level relative ID (RID) of the process.
688
+ token_elevation_type,Process.TokenElevationType,"The elevation type of the process on Microsoft Windows. This determines if
689
+ any privileges are removed when UAC is enabled."
690
+ product_specific_parent_process_id,string,"A product specific id for the parent process.
691
+ Please use parent_process.product_specific_process_id instead."
692
+ registry_key,string,"Registry key associated with an application or system component
693
+ (e.g., HKEY_, HKCU\Environment...)."
694
+ registry_value_name,string,"Name of the registry value associated with an application or system
695
+ component (e.g. TEMP)."
696
+ registry_value_data,string,"Data associated with a registry value
697
+ (e.g. %USERPROFILE%\Local Settings\Temp)."
698
+ type,string,Deprecated: use resource_type instead.
699
+ resource_type,Resource.ResourceType,Resource type.
700
+ resource_subtype,string,"Resource sub-type (e.g. ""BigQuery"", ""Bigtable"")."
701
+ id,string,Deprecated: Use resource.name or resource.product_object_id.
702
+ name,string,"The full name of the resource. For example,
703
+ Google Cloud: //cloudresourcemanager.googleapis.com/projects/wombat-123,
704
+ and AWS: arn:aws:iam::123456789012:user/johndoe."
705
+ parent,string,"The parent of the resource.
706
+ For a database table, the parent is the database. For a storage object,
707
+ the bucket name. Deprecated: use resource_ancestors.name."
708
+ product_object_id,string,"A vendor-specific identifier to uniquely identify the entity (a GUID,
709
+ OID, or similar)"
710
+ attribute,Attribute,Generic entity metadata attributes of the resource.
711
+ name,string,System role name for user.
712
+ description,string,System role description for user.
713
+ type,Role.Type,System role type for well known roles.
714
+ cert_signature,SSLCertificate.CertSignature,Certificate's signature and algorithm.
715
+ extension,SSLCertificate.Extension,(DEPRECATED) certificate's extension.
716
+ cert_extensions,google.protobuf.Struct,Certificate's extensions.
717
+ first_seen_time,google.protobuf.Timestamp,Date the certificate was first retrieved by VirusTotal.
718
+ issuer,SSLCertificate.Subject,Certificate's issuer data.
719
+ ec,SSLCertificate.EC,EC public key information.
720
+ serial_number,string,Certificate's serial number hexdump.
721
+ signature_algorithm,string,"Algorithm used for the signature (for example, ""sha1RSA"")."
722
+ size,int64,Certificate content length.
723
+ subject,SSLCertificate.Subject,Certificate's subject data.
724
+ thumbprint,string,Certificate's content SHA1 hash.
725
+ thumbprint_sha256,string,Certificate's content SHA256 hash.
726
+ validity,SSLCertificate.Validity,Certificate's validity period.
727
+ version,string,"Certificate version (typically ""V1"", ""V2"" or ""V3"")."
728
+ keyid,string,Key hexdump.
729
+ serial_number,string,Serial number hexdump.
730
+ signature,string,Signature.
731
+ signature_algorithm,string,Algorithm.
732
+ p,string,p component hexdump.
733
+ q,string,q component hexdump.
734
+ g,string,g component hexdump.
735
+ pub,string,Public key hexdump.
736
+ oid,string,Curve name.
737
+ pub,string,Public key hexdump.
738
+ ca,bool,Whether the subject acts as a certificate authority (CA) or not.
739
+ subject_key_id,string,Identifies the public key being certified.
740
+ authority_key_id,SSLCertificate.AuthorityKeyId,"Identifies the public key to be used to verify the signature on this
741
+ certificate or CRL."
742
+ key_usage,string,The purpose for which the certified public key is used.
743
+ ca_info_access,string,"Authority information access locations are URLs that are added to a
744
+ certificate in its authority information access extension."
745
+ crl_distribution_points,string,"CRL distribution points to which a certificate user should refer to
746
+ ascertain if the certificate has been revoked."
747
+ extended_key_usage,string,"One or more purposes for which the certified public key may be used, in
748
+ addition to or in place of the basic purposes indicated in the key usage
749
+ extension field."
750
+ subject_alternative_name,string,"Contains one or more alternative names, using any of a variety of name
751
+ forms, for the entity that is bound by the CA to the certified public
752
+ key."
753
+ certificate_policies,string,"Different certificate policies will relate to different applications
754
+ which may use the certified key."
755
+ netscape_cert_comment,string,Used to include free-form text comments inside certificates.
756
+ cert_template_name_dc,string,"BMP data value ""DomainController"". See MS Q291010."
757
+ netscape_certificate,bool,"Identify whether the certificate subject is an SSL client, an SSL server,
758
+ or a CA."
759
+ pe_logotype,bool,Whether the certificate includes a logotype.
760
+ old_authority_key_id,bool,Whether the certificate has an old authority key identifier extension.
761
+ algorithm,string,"Any of ""RSA"", ""DSA"" or ""EC"". Indicates the algorithm used to generate the
762
+ certificate."
763
+ rsa,SSLCertificate.RSA,RSA public key information.
764
+ key_size,int64,Key size.
765
+ modulus,string,Key modulus hexdump.
766
+ exponent,string,Key exponent hexdump.
767
+ country_name,string,C: Country name.
768
+ common_name,string,CN: CommonName.
769
+ locality,string,L: Locality.
770
+ organization,string,O: Organization.
771
+ organizational_unit,string,OU: OrganizationalUnit.
772
+ state_or_province_name,string,ST: StateOrProvinceName.
773
+ expiry_time,google.protobuf.Timestamp,Expiry date.
774
+ issue_time,google.protobuf.Timestamp,Issue date.
775
+ confidence_score,int32,Confidence score of the verdict.
776
+ verdict_time,google.protobuf.Timestamp,Timestamp at which the verdict was generated.
777
+ verdict_response,SecurityResult.VerdictResponse,Details of the verdict.
778
+ id,string,Unique association id generated by mandiant.
779
+ country_code,string,Country from which the threat actor/ malware is originated.
780
+ type,SecurityResult.Association.AssociationType,Signifies the type of association.
781
+ name,string,Name of the threat actor/malware.
782
+ description,string,Human readable description about the association.
783
+ role,string,Role of the malware. Not applicable for threat actor.
784
+ source_country,string,Name of the country the threat originated from.
785
+ alias,SecurityResult.Association.AssociationAlias,Different aliases of the threat actor given by different sources.
786
+ first_reference_time,google.protobuf.Timestamp,First time the threat actor was referenced or seen.
787
+ last_reference_time,google.protobuf.Timestamp,Last time the threat actor was referenced or seen.
788
+ industries_affected,string,List of industries the threat actor affects.
789
+ associated_actors,SecurityResult.Association,"List of associated threat actors for a malware. Not applicable for threat
790
+ actors."
791
+ region_code,Location,"Name of the country, the threat is originating from."
792
+ sponsor_region,Location,Sponsor region of the threat actor.
793
+ targeted_regions,Location,Targeted regions.
794
+ tags,string,Tags.
795
+ name,string,Name of the alias.
796
+ company,string,Name of the provider who gave the association's name.
797
+ ioc_stats_type,SecurityResult.IoCStatsType,Describes the source of the IoCStat.
798
+ first_level_source,string,"Name of first level IoC source, for example Mandiant or a third-party."
799
+ second_level_source,string,"Name of the second-level IoC source, for example Crowdsourced Threat
800
+ Analysis or Knowledge Graph."
801
+ benign_count,int32,Count of responses where the IoC was identified as benign.
802
+ quality,SecurityResult.ProductConfidence,Level of confidence in the IoC mapping extracted from the source.
803
+ malicious_count,int32,Count of responses where the IoC was identified as malicious.
804
+ response_count,int32,Total number of response from the source.
805
+ source_count,int32,Number of sources from which information was extracted.
806
+ source_provider,string,Source provider giving the ML verdict.
807
+ benign_count,int32,Count of responses where this IoC was marked benign.
808
+ malicious_count,int32,Count of responses where this IoC was marked malicious.
809
+ confidence_score,int32,Confidence score of the verdict.
810
+ mandiant_sources,SecurityResult.Source,List of mandiant sources from which the verdict was generated.
811
+ third_party_sources,SecurityResult.Source,List of third-party sources from which the verdict was generated.
812
+ name,string,Name of the IoC source.
813
+ benign_count,int32,Count of responses where this IoC was marked benign.
814
+ malicious_count,int32,Count of responses where this IoC was marked malicious.
815
+ quality,SecurityResult.ProductConfidence,Quality of the IoC mapping extracted from the source.
816
+ response_count,int32,Total response count from this source.
817
+ source_count,int32,Number of sources from which intelligence was extracted.
818
+ threat_intelligence_sources,SecurityResult.Source,Different threat intelligence sources from which IoC info was extracted.
819
+ source_count,int32,Number of sources from which intelligence was extracted.
820
+ response_count,int32,Total response count across all sources.
821
+ neighbour_influence,string,Describes the neighbour influence of the verdict.
822
+ verdict,SecurityResult.ProviderMLVerdict,ML Verdict provided by sources like Mandiant.
823
+ analyst_verdict,SecurityResult.AnalystVerdict,Human analyst verdict provided by sources like Mandiant.
824
+ source_count,int32,Number of sources from which intelligence was extracted.
825
+ response_count,int32,Total response count across all sources.
826
+ neighbour_influence,string,Describes the near neighbor influence of the verdict.
827
+ verdict_type,SecurityResult.VerdictType,Type of verdict.
828
+ source_provider,string,Source provider giving the machine learning verdict.
829
+ benign_count,int32,Count of responses where this IoC was marked as benign.
830
+ malicious_count,int32,Count of responses where this IoC was marked as malicious.
831
+ confidence_score,int32,Confidence score of the verdict.
832
+ ioc_stats,SecurityResult.IoCStats,List of IoCStats from which the verdict was generated.
833
+ verdict_time,google.protobuf.Timestamp,Timestamp when the verdict was generated.
834
+ verdict_response,SecurityResult.VerdictResponse,Details about the verdict.
835
+ global_customer_count,int32,Global customer count over the last 30 days
836
+ global_hits_count,int32,Global hit count over the last 30 days.
837
+ pwn,bool,"Whether one or more Mandiant incident response customers had this
838
+ indicator in their environment."
839
+ category_details,string,Tags related to the verdict.
840
+ pwn_first_tagged_time,google.protobuf.Timestamp,The timestamp of the first time a pwn was associated to this entity.
841
+ sigcheck,FileMetadataSignatureInfo,Signature information extracted from the sigcheck tool.
842
+ codesign,FileMetadataCodesign,Signature information extracted from the codesign utility.
843
+ name,string,"Common name of the signers/certificate.
844
+ The order of the signers matters. Each element is a higher level
845
+ authority, the last being the root authority."
846
+ status,string,"It can say ""Valid"" or state the problem with the certificate if any (e.g.
847
+ ""This certificate or one of the certificates in the certificate chain is
848
+ not time valid."")."
849
+ valid_usage,string,"Indicates which situations the certificate is valid for (e.g. ""Code
850
+ Signing"")."
851
+ cert_issuer,string,Company that issued the certificate.
852
+ helo,string,The client's 'HELO'/'EHLO' string.
853
+ mail_from,string,The client's 'MAIL FROM' string.
854
+ rcpt_to,string,The client's 'RCPT TO' string(s).
855
+ server_response,string,The server's response(s) to the client.
856
+ message_path,string,The message's path (extracted from the headers).
857
+ is_webmail,bool,If the message was sent via a webmail client.
858
+ is_tls,bool,If the connection switched to TLS.
859
+ name,string,The name of the software.
860
+ version,string,The version of the software.
861
+ permissions,Permission,"System permissions granted to the software.
862
+ For example, ""android.permission.WRITE_EXTERNAL_STORAGE"""
863
+ description,string,The description of the software.
864
+ vendor_name,string,The name of the software vendor.
865
+ tenant_id,bytes,A list of subtenant ids that this event belongs to.
866
+ data_tap_config_name,string,A list of sink name values defined in DataTap configurations.
867
+ interval,google.type.Interval,Interval duration of the leave.
868
+ description,string,Description of the leave if available (e.g. 'Vacation').
869
+ client,Tls.Client,Certificate information for the client certificate.
870
+ server,Tls.Server,Certificate information for the server certificate.
871
+ cipher,string,Cipher used during the connection.
872
+ curve,string,Elliptical curve used for a given cipher.
873
+ version,string,TLS version.
874
+ version_protocol,string,Protocol.
875
+ established,bool,Indicates whether the TLS negotiation was successful.
876
+ next_protocol,string,Protocol to be used for tunnel.
877
+ resumed,bool,"Indicates whether the TLS connection was resumed from a previous
878
+ TLS negotiation."
879
+ certificate,Certificate,Client certificate.
880
+ ja3,string,"JA3 hash from the TLS ClientHello, as a hex-encoded string."
881
+ server_name,string,"Host name of the server, that the client is connecting to."
882
+ supported_ciphers,string,Ciphers supported by the client during client hello.
883
+ certificate,Certificate,Server certificate.
884
+ ja3s,string,"JA3 hash from the TLS ServerHello, as a hex-encoded string."
885
+ tracker,string,Tracker name.
886
+ id,string,"Tracker ID, if available."
887
+ timestamp,google.protobuf.Timestamp,Tracker ingestion date.
888
+ URL,string,Tracker script URL.
889
+ URL,string,URL.
890
+ categories,string,Categorisation done by VirusTotal partners.
891
+ favicon,Favicon,Difference hash and MD5 hash of the URL's.
892
+ html_meta,google.protobuf.Struct,Meta tags (only for URLs downloading HTML).
893
+ last_final_url,string,"If the original URL redirects, where does it end."
894
+ last_http_response_code,int32,HTTP response code of the last response.
895
+ last_http_response_content_length,int64,Length in bytes of the content received.
896
+ last_http_response_content_sha256,string,URL response body's SHA256 hash.
897
+ last_http_response_cookies,google.protobuf.Struct,Website's cookies.
898
+ last_http_response_headers,google.protobuf.Struct,Headers and values of the last HTTP response.
899
+ tags,string,Tags.
900
+ title,string,Webpage title.
901
+ trackers,Tracker,Trackers found in the URL in a historical manner.
902
+ product_object_id,string,"A vendor-specific identifier to uniquely identify the entity (e.g. a GUID,
903
+ LDAP, OID, or similar)."
904
+ userid,string,The ID of the user.
905
+ user_display_name,string,"The display name of the user
906
+ (e.g. ""John Locke"")."
907
+ first_name,string,"First name of the user (e.g. ""John"")."
908
+ middle_name,string,Middle name of the user.
909
+ last_name,string,"Last name of the user (e.g. ""Locke"")."
910
+ phone_numbers,string,Phone numbers for the user.
911
+ personal_address,Location,Personal address of the user.
912
+ attribute,Attribute,Generic entity metadata attributes of the user.
913
+ first_seen_time,google.protobuf.Timestamp,"The first observed time for a user.
914
+ The value is calculated on the basis of the
915
+ first time the identifier was observed."
916
+ account_type,User.AccountType,"Type of user account (for example, service, domain, or cloud). This is
917
+
918
+ somewhat aligned to: https://attack.mitre.org/techniques/T1078/"
919
+ groupid,string,"The ID of the group that the user belongs to.
920
+ Deprecated in favor of the repeated group_identifiers field."
921
+ group_identifiers,string,"Product object identifiers of the group(s) the user belongs to
922
+ A vendor-specific identifier to uniquely identify the group(s) the user
923
+ belongs to (a GUID, LDAP OID, or similar)."
924
+ windows_sid,string,The Microsoft Windows SID of the user.
925
+ email_addresses,string,Email addresses of the user.
926
+ employee_id,string,Human capital management identifier.
927
+ title,string,User job title.
928
+ company_name,string,User job company name.
929
+ department,string,User job department
930
+ office_address,Location,User job office location.
931
+ managers,User,User job manager(s).
932
+ hire_date,google.protobuf.Timestamp,User job employment hire date.
933
+ termination_date,google.protobuf.Timestamp,User job employment termination date.
934
+ time_off,TimeOff,User time off leaves from active work.
935
+ last_login_time,google.protobuf.Timestamp,User last login timestamp.
936
+ last_password_change_time,google.protobuf.Timestamp,User last password change timestamp.
937
+ password_expiration_time,google.protobuf.Timestamp,User password expiration timestamp.
938
+ account_expiration_time,google.protobuf.Timestamp,User account expiration timestamp.
939
+ account_lockout_time,google.protobuf.Timestamp,User account lockout timestamp.
940
+ last_bad_password_attempt_time,google.protobuf.Timestamp,User last bad password attempt timestamp.
941
+ user_authentication_status,Authentication.AuthenticationStatus,System authentication status for user.
942
+ role_name,string,"System role name for user.
943
+ Deprecated: use attribute.roles."
944
+ role_description,string,"System role description for user.
945
+ Deprecated: use attribute.roles."
946
+ user_role,User.Role,"System role for user.
947
+ Deprecated: use attribute.roles."
948
+ vulnerabilities,Vulnerability,A list of vulnerabilities.
949
+ about,Noun,"If the vulnerability is about a specific noun (e.g. executable),
950
+ then add it here."
951
+ name,string,"Name of the vulnerability (e.g. ""Unsupported OS Version detected"")."
952
+ description,string,Description of the vulnerability.
953
+ vendor,string,Vendor of scan that discovered vulnerability.
954
+ scan_start_time,google.protobuf.Timestamp,"If the vulnerability was discovered during an asset scan, then this
955
+ field should be populated with the time the scan started.
956
+ This field can be left unset if the start time is not available or not
957
+ applicable."
958
+ scan_end_time,google.protobuf.Timestamp,"If the vulnerability was discovered during an asset scan, then this field
959
+
960
+ should be populated with the time the scan ended.
961
+ This field can be left unset if the end time is not available or not
962
+ applicable."
963
+ first_found,google.protobuf.Timestamp,"Products that maintain a history of vuln scans should populate first_found
964
+ with the time that a scan first detected the vulnerability on this asset."
965
+ last_found,google.protobuf.Timestamp,"Products that maintain a history of vuln scans should populate last_found
966
+ with the time that a scan last detected the vulnerability on this asset."
967
+ severity,Vulnerability.Severity,The severity of the vulnerability.
968
+ severity_details,string,Vendor-specific severity
969
+ cvss_base_score,float,"CVSS Base Score in the range of 0.0 to 10.0.
970
+ Useful for sorting."
971
+ cvss_vector,string,"Vector of CVSS properties (e.g. ""AV:L/AC:H/Au:N/C:N/I:P/A:C"")
972
+ Can be linked to via:
973
+
974
+ https://nvd.nist.gov/vuln-metrics/cvss/v2-calculator"
975
+ cvss_version,string,Version of CVSS Vector/Score.
976
+ cve_id,string,"Common Vulnerabilities and Exposures Id.
977
+ https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures
978
+ https://cve.mitre.org/about/faqs.html#what_is_cve_id"
979
+ cve_description,string,"Common Vulnerabilities and Exposures Description.
980
+ https://cve.mitre.org/about/faqs.html#what_is_cve_record"
981
+ vendor_vulnerability_id,string,Vendor specific vulnerability id (e.g. Microsoft security bulletin id).
982
+ vendor_knowledge_base_article_id,string,"Vendor specific knowledge base article (e.g. ""KBXXXXXX"" from Microsoft).
983
+ https://en.wikipedia.org/wiki/Microsoft_Knowledge_Base
984
+ https://access.redhat.com/knowledgebase"
985
+ name,string,Certificate name.
986
+ algorithm,string,Certificate algorithm.
987
+ thumbprint,string,Certificate thumbprint.
988
+ cert_issuer,string,Issuer of the certificate.
989
+ serial_number,string,Certificate serial number.