| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| AgentId |
Unique identifier for the CrowdStrike agent that generated the alert. |
String |
| AggregateId |
Identifier for aggregated alerts from the same source. |
String |
| AlertType |
The type or category of the CrowdStrike alert. |
String |
| AllegedFiletype |
The suspected file type of the malicious file associated with the alert. |
String |
| AssignedToName |
Name of the user assigned to handle the alert. |
String |
| AssignedToUid |
User ID of the assigned user. |
String |
| AssignedToUuid |
UUID of the assigned user. |
String |
| Categorization |
Categorization of the alert. |
String |
| ChildProcessIds |
List of child process IDs spawned by the detected process. |
Object |
| Cid |
Customer ID in the CrowdStrike platform. |
String |
| CloudIndicator |
Indicates if the alert involves cloud-based indicators. |
Boolean |
| Cmdline |
Command line used to execute the detected process. |
String |
| CompositeId |
Composite identifier combining multiple alert attributes. |
String |
| Confidence |
Confidence score of the alert (0-100). |
Int32 |
| ContextTimestamp |
Timestamp providing additional context for the alert. |
String |
| CorrelationRuleCreateCase |
Indicates if the correlation rule is configured to create a case. |
Boolean |
| CorrelationRuleExecutionId |
Execution ID of the correlation rule that triggered the alert. |
String |
| CorrelationRuleId |
Identifier of the correlation rule that triggered the alert. |
String |
| CorrelationRuleUserId |
User ID associated with the correlation rule. |
String |
| CorrelationRuleUserUuid |
UUID of the user associated with the correlation rule. |
String |
| CrawledTimestamp |
Timestamp when the alert data was last crawled. |
DateTime |
| CreatedTimestamp |
Timestamp when the alert was first created. |
DateTime |
| CrowdStrikeDomain |
CrowdStrike host/domain configured for this connection; hard-coded on every record so hosts can be differentiated. |
String |
| DataDomains |
Domains associated with the alert. |
Object |
| Description |
Detailed description of the alert. |
String |
| DetectionId |
Unique identifier for the detection associated with the alert. |
String |
| Device |
Information about the device where the alert was detected. |
Object |
| DisplayName |
Human-readable name for the alert. |
String |
| EmailSent |
Indicates if an email notification was sent for this alert. |
Boolean |
| EndTime |
Timestamp when the alert activity ended. |
String |
| EnrichedEntities |
Enriched entity information associated with the alert. |
Object |
| EventCorrelationId |
Correlation ID linking related events. |
String |
| EventIds |
Event IDs associated with the alert. |
String |
| External |
Indicates if the alert originated from an external source. |
Boolean |
| FalconHostLink |
Link to the alert details in the CrowdStrike Falcon console. |
String |
| Filename |
Name of the file associated with the alert. |
String |
| Filepath |
Full path to the file associated with the alert. |
String |
| GlobalPrevalence |
Global prevalence rating of the detected file. |
String |
| GrandparentDetails |
Details about the grandparent process in the process tree. |
Object |
| HasTruncatedEntities |
Indicates if the alert entities have been truncated. |
Boolean |
| Id |
Unique identifier for the alert. |
String |
| IndicatorId |
Identifier for the indicator of compromise that triggered the alert. |
String |
| IocContext |
Context information about the indicator of compromise. |
Object |
| IsClosed |
Indicates if the alert has been closed. |
Boolean |
| LeadId |
Identifier for the lead associated with the alert. |
String |
| LeadType |
Type of the lead associated with the alert. |
String |
| LocalAddressIp4 |
IPv4 address of the local endpoint. |
String |
| LocalAddressIp6 |
IPv6 address of the local endpoint. |
String |
| LocalPrevalence |
Local prevalence rating within the organization. |
String |
| LocalProcessId |
Local process ID on the system where the alert occurred. |
String |
| LogonDomain |
Domain used for user logon associated with the alert. |
String |
| Md5 |
MD5 hash of the file associated with the alert. |
String |
| MitreAttack |
MITRE ATT&CK tactics and techniques associated with the alert. |
Object |
| Name |
Name of the alert. |
String |
| Objective |
The attacker’s presumed objective. |
String |
| OriginalCorrelationRulesEntitiesCount |
Original count of correlation rule entities. |
Int32 |
| OriginalIndicatorEntitiesCount |
Original count of indicator entities. |
Int32 |
| OriginCid |
Customer ID of the originating tenant. |
String |
| ParentDetails |
Details about the parent process in the process tree. |
Object |
| ParentProcessId |
Process ID of the parent process. |
String |
| PatternDisposition |
Numerical identifier for the action taken by the detection pattern. |
Int32 |
| PatternDispositionDescription |
Text description of the pattern disposition action. |
String |
| PatternDispositionDetails |
Detailed information about the pattern disposition. |
Object |
| PatternId |
Identifier for the detection pattern that triggered the alert. |
Int32 |
| Platform |
Operating system or platform where the alert was detected. |
String |
| PolyId |
Poly ID associated with the alert. |
String |
| PriorityDetails |
Priority details associated with the alert. |
Object |
| ProcessEndTime |
Timestamp when the detected process ended. |
String |
| ProcessId |
Process ID of the detected process. |
String |
| ProcessStartTime |
Timestamp when the detected process started. |
String |
| Product |
CrowdStrike product that generated the alert. |
String |
| Scenario |
Security scenario that triggered the alert. |
String |
| Score |
Score associated with the alert. |
Int32 |
| SecondsToResolved |
Time in seconds from alert creation to resolution. |
Int32 |
| SecondsToTriaged |
Time in seconds from alert creation to triage. |
Int32 |
| Severity |
Severity level of the alert. |
Int32 |
| SeverityName |
Text representation of the severity level. |
String |
| Sha1 |
SHA1 hash of the file associated with the alert. |
String |
| Sha256 |
SHA256 hash of the file associated with the alert. |
String |
| ShowInUi |
Indicates if the alert should be displayed in the user interface. |
Boolean |
| SignalEndTimestamp |
Timestamp when the signal ended. |
String |
| SignalStartTimestamp |
Timestamp when the signal started. |
String |
| SignalUpdatedTimestamp |
Timestamp when the signal was last updated. |
String |
| SourceEndpointAddressIp4 |
IPv4 address of the source endpoint. |
String |
| SourceEndpointAddressIp6 |
IPv6 address of the source endpoint. |
String |
| SourceIps |
List of source IP addresses associated with the alert. |
Object |
| SourceProducts |
List of products that contributed to this alert. |
Object |
| SourceSystem |
|
String |
| SourceVendors |
List of vendors associated with the alert sources. |
Object |
| StartTime |
Timestamp when the alert activity started. |
String |
| Status |
Current status of the alert. |
String |
| Tactic |
MITRE ATT&CK tactic associated with the alert. |
String |
| TacticId |
Identifier of the MITRE ATT&CK tactic. |
String |
| Tags |
Custom tags associated with the alert. |
Object |
| Technique |
MITRE ATT&CK technique associated with the alert. |
String |
| TechniqueId |
Identifier of the MITRE ATT&CK technique. |
String |
| TemplateInstanceId |
Instance ID of the detection template used. |
Int32 |
| TenantId |
Unique identifier of the tenant into which the data connector ingests data. |
String |
| ThreatgraphIndicators |
Threat graph indicators associated with the alert. |
Object |
| TimeGenerated |
The timestamp (UTC) when the alert was generated. |
DateTime |
| Timestamp |
Time when the alert event occurred. |
DateTime |
| TriggeringProcessGraphId |
Graph ID of the process that triggered the alert. |
String |
| Type |
The name of the table |
String |
| UpdatedTimestamp |
Time when the alert was last updated. |
DateTime |
| UserId |
User ID associated with the alert. |
String |
| UserName |
Username associated with the alert. |
String |
| Users |
List of users associated with the alert. |
Object |
| VendorPatternId |
Vendor-specific pattern identifier. |
String |
| XdrEventId |
XDR event ID associated with the alert. |
String |