| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| AccountId |
Cloud account ID. |
String |
| AddedPrivileges |
Privileges that were added to the account. |
String |
| AgentId |
Unique identifier for the CrowdStrike agent. |
String |
| AgentIdString |
The agent ID string. |
String |
| AggregateId |
Aggregate identifier for related detections. |
String |
| ApiClientId |
API client ID used for the request. |
String |
| AppId |
Application ID. |
String |
| AuditEventType |
Event type from the audit attributes. |
String |
| AuditKeyValues |
JSON string containing audit key-value pairs. |
String |
| AuthenticationProtocol |
Authentication protocol used (e.g., NTLM, Kerberos). |
String |
| Author |
Author of the detection rule. |
String |
| Category |
Category of the identity protection event (e.g., Incident). |
String |
| Cid |
Customer ID in the CrowdStrike platform. |
String |
| CloudIndicator |
Indicates if the detection involves cloud-based indicators. |
String |
| CloudPlatform |
Cloud platform (e.g., AWS, Azure, GCP). |
String |
| CloudProvider |
Cloud provider (e.g., aws, azure, gcp). |
String |
| CloudService |
Cloud service involved (e.g., EC2, S3). |
String |
| CommandLine |
Command line used to execute the process. |
String |
| CompositeId |
Composite identifier combining multiple detection attributes. |
String |
| ComputerName |
Name of the computer where the IOC was detected. |
String |
| ConnectionDirection |
Direction of the network connection. |
String |
| Consumes |
Content type consumed by the API. |
String |
| ContextTimeStamp |
Context timestamp of the IDP detection event (Unix epoch). |
DateTime |
| CrowdStrikeDomain |
CrowdStrike host/domain configured for this connection; hard-coded on every record so hosts can be differentiated. |
String |
| CurrentPrivileges |
Current privilege level of the account. |
String |
| CustomerId |
Customer identifier in the CrowdStrike platform. |
String |
| CustomerIdString |
The customer ID string. |
String |
| DataDomains |
Data domains associated with the event. |
String |
| Description |
Detailed description of the detection. |
String |
| DestinationEndpointIp |
IP address of the destination endpoint. |
String |
| DestinationEndpointName |
Name of the destination endpoint. |
String |
| DeviceId |
Unique identifier for the device. |
String |
| Disposition |
Assessment result (e.g., Failed, Passed). |
String |
| Eid |
Event ID. |
String |
| ElapsedMicroseconds |
Elapsed time in microseconds. |
String |
| ElapsedTime |
Elapsed time of the request. |
String |
| EndpointIp |
IP address of the endpoint involved in the incident. |
String |
| EndpointName |
Name of the endpoint involved in the incident. |
String |
| EndTime |
End time of the event. |
DateTime |
| EndTimestamp |
Unix epoch timestamp when the session ended. |
DateTime |
| EventAction |
Action that triggered the IOA (e.g., TerminateInstances). |
String |
| EventSource |
Source of the event (e.g., aws.cloudtrail). |
String |
| EventType |
The type of event, used to filter logs. |
String |
| EventUuid |
Unique UUID for the event. |
String |
| ExecutionId |
Execution identifier for the report run. |
String |
| ExternalApiType |
The external API type. |
String |
| FalconHostLink |
Link to the detection details in the CrowdStrike Falcon console. |
String |
| FileName |
Name of the file associated with the IOC. |
String |
| FilePath |
Full path to the file. |
String |
| Finding |
Details of the finding. |
String |
| FineScore |
Fine score of the incident. |
String |
| FirstSeen |
First time the hash spreading was observed. |
DateTime |
| Flags |
JSON string containing firewall rule flags (Audit, Log, Monitor). |
String |
| GrandParentCommandLine |
Command line of the grandparent process. |
String |
| GrandParentImageFileName |
Image file name of the grandparent process. |
String |
| GrandParentImageFilePath |
Full path to the grandparent process image file. |
String |
| Hash |
Credential hash observed spreading across hosts. |
String |
| Highlights |
JSON string containing highlights of the notification. |
String |
| HostGroups |
Host groups the system belongs to. |
String |
| HostId |
Identifier of the host involved in the incident. |
String |
| Hostname |
Name of the host where the event occurred. |
String |
| HostnameField |
Hostname of the target system. |
String |
| IcmpCode |
ICMP code if the protocol is ICMP. |
String |
| IcmpType |
ICMP type if the protocol is ICMP. |
String |
| IdentityProtectionIncidentId |
Unique identifier for the identity protection incident. |
String |
| ImageFileName |
Image file name of the process associated with the event. |
String |
| IncidentDescription |
Description of the hash spreading incident. |
String |
| IncidentEndTime |
End time of the incident (Unix epoch). |
DateTime |
| IncidentId |
Unique identifier for the incident. |
String |
| IncidentStartTime |
Start time of the incident (Unix epoch). |
DateTime |
| IncidentType |
Type of identity protection incident (e.g., GoldenTicketAlert). |
String |
| Ipv |
IP version (ipv4 or ipv6). |
String |
| ItemId |
Identifier of the matched item. |
String |
| ItemPostedTimestamp |
Timestamp when the item was posted. |
DateTime |
| ItemType |
Type of the matched item. |
String |
| LastSeen |
Last time the hash spreading was observed. |
DateTime |
| LateralMovement |
Lateral movement indicator for the incident. |
String |
| LocalAddress |
Local IP address involved in the firewall event. |
String |
| LocalIp |
Local IP address of the host. |
String |
| LocalIpv6 |
Local IPv6 address of the host. |
String |
| LocalPort |
Local port number involved in the firewall event. |
String |
| LogonDomain |
Logon domain associated with the detection. |
String |
| MACAddress |
MAC address of the host. |
String |
| MatchCount |
Number of times the firewall rule was matched. |
String |
| MatchCountSinceLastReport |
Number of matches since the last report. |
String |
| MatchedTimestamp |
Timestamp when the match was found. |
DateTime |
| MD5String |
MD5 hash of the file. |
String |
| Message |
Message associated with the audit event. |
String |
| MitreAttack |
JSON string containing MITRE ATT&CK framework details. |
String |
| MobileDetectionId |
Unique identifier for the mobile detection. |
String |
| Name |
Name of the detection (e.g., Attacker Methodology). |
String |
| NetworkProfile |
Network profile identifier. |
String |
| Nonce |
A unique nonce value. |
String |
| NotificationId |
Unique identifier for the recon notification. |
String |
| NumberOfCompromisedEntities |
Number of compromised entities in the incident. |
String |
| NumbersOfAlerts |
Number of alerts associated with the incident. |
String |
| Objective |
Objective of the detection (e.g., Follow Through). |
String |
| Offset |
Stream offset value. |
String |
| OperationName |
Name of the operation performed. |
String |
| ParentCommandLine |
Command line of the parent process. |
String |
| ParentImageFileName |
Image file name of the parent process. |
String |
| ParentImageFilePath |
Full path to the parent process image file. |
String |
| ParentProcessId |
Process ID of the parent process. |
String |
| Partition |
Stream partition. |
String |
| PatternDispositionDescription |
Description of the pattern disposition action. |
String |
| PatternDispositionFlags |
JSON string containing flags indicating various pattern disposition actions. |
String |
| PatternDispositionValue |
Numerical value of the pattern disposition. |
String |
| PatternId |
Identifier for the detection pattern. |
String |
| Pid |
Process ID associated with the firewall event. |
String |
| PlatformId |
Platform ID (e.g., 0=Windows, 1=Mac, 2=Linux). |
String |
| PlatformName |
Name of the platform (e.g., Windows, Linux, Mac). |
String |
| PolicyId |
Policy identifier. |
String |
| PolicyName |
Name of the firewall policy. |
String |
| PolicyStatement |
Description of the CSPM policy that was triggered. |
String |
| PreviousPrivileges |
Previous privilege level of the account. |
String |
| ProcessEndTime |
Timestamp when the detected process ended. |
DateTime |
| ProcessId |
Process ID associated with the IOC. |
String |
| ProcessStartTime |
Timestamp when the detected process started. |
DateTime |
| Produces |
Content type produced by the API. |
String |
| Protocol |
Network protocol (e.g., 1=ICMP, 6=TCP, 17=UDP). |
String |
| ReceivedTime |
Time the request was received. |
DateTime |
| Region |
Cloud region (e.g., us-west-2). |
String |
| RemoteAddress |
Remote IP address involved in the firewall event. |
String |
| RemotePort |
Remote port number involved in the firewall event. |
String |
| ReportFileReference |
File reference path for downloading the report. |
String |
| ReportId |
Unique identifier for the report. |
String |
| ReportName |
Name of the scheduled report. |
String |
| ReportType |
Type of the report (e.g., spotlight_vulnerabilities). |
String |
| ReportUrl |
URL to the CSPM assessment report. |
String |
| RequestAccept |
Accept header of the request. |
String |
| RequestContentType |
Content type of the request. |
String |
| RequestMethod |
HTTP method of the request (e.g., POST, GET). |
String |
| RequestPath |
Path of the API request. |
String |
| RequestUriLength |
Length of the request URI. |
String |
| ResourceAttributes |
JSON string containing resource attributes. |
String |
| ResourceCreateTime |
Creation time of the resource. |
DateTime |
| ResourceIdType |
Type of the resource identifier (e.g., Instance Id). |
String |
| ResourcesId |
Identifier of the cloud resource. |
String |
| ResourcesName |
Name of the cloud resource. |
String |
| ResourceUrl |
URL to the resource in the cloud console. |
String |
| RiskScore |
Risk score associated with the detection. |
String |
| RuleAction |
Action taken by the firewall rule. |
String |
| RuleDescription |
Description of the firewall rule. |
String |
| RuleFamilyId |
Family identifier of the firewall rule. |
String |
| RuleGroupName |
Name of the firewall rule group. |
String |
| RuleId |
Identifier of the recon rule. |
String |
| RuleName |
Name of the recon rule. |
String |
| RulePriority |
Priority of the recon rule. |
String |
| RuleTopic |
Topic of the recon rule (e.g., Credential Exposure). |
String |
| Scopes |
API scopes used for the request. |
String |
| SensorId |
Unique identifier for the CrowdStrike sensor on the mobile device. |
String |
| SensorIds |
Sensor IDs associated with the detection. |
String |
| ServiceName |
Name of the service (e.g., api_request). |
String |
| SessionId |
Unique identifier for the remote response session. |
String |
| Severity |
Numerical severity level. |
String |
| SeverityName |
Text representation of the severity level. |
String |
| SHA1String |
SHA1 hash of the detected file. |
String |
| SHA256Hashes |
SHA256 hashes associated with the detection. |
String |
| SHA256String |
SHA256 hash of the detected file. |
String |
| Source |
Source of the audit event. |
String |
| SourceAccountDomain |
Domain of the source account. |
String |
| SourceAccountName |
Name of the source account. |
String |
| SourceAccountObjectSid |
Object SID of the source account. |
String |
| SourceAccountUpn |
User principal name of the source account. |
String |
| SourceEndpointIp |
IP address of the source endpoint. |
String |
| SourceEndpointName |
Name of the source endpoint. |
String |
| SourceIp |
Source IP address. |
String |
| SourceProducts |
Products associated with the detection source. |
String |
| SourceSystem |
|
String |
| SourceVendors |
Vendors associated with the detection source. |
String |
| SpreadCount |
Number of hosts the hash has been observed on. |
String |
| StartTime |
Start time of the event. |
DateTime |
| StartTimestamp |
Unix epoch timestamp when the session started. |
DateTime |
| State |
Current state of the incident (e.g., IN_PROGRESS, CLOSED). |
String |
| Status |
Status of the report execution. |
String |
| StatusCode |
HTTP status code of the response. |
String |
| StatusMessage |
Status message for the report execution. |
String |
| Success |
Whether the API call was successful. |
Boolean |
| Tactic |
MITRE ATT&CK tactic. |
String |
| TacticId |
The MITRE ATT&CK tactic ID associated with the detection. |
String |
| TacticIds |
MITRE ATT&CK tactic IDs associated with the detection. |
String |
| Tactics |
MITRE ATT&CK tactics associated with the detection. |
String |
| Tags |
JSON string containing resource tags. |
String |
| Technique |
MITRE ATT&CK technique. |
String |
| TechniqueId |
The MITRE ATT&CK technique ID associated with the detection. |
String |
| TechniqueIds |
MITRE ATT&CK technique IDs associated with the detection. |
String |
| Techniques |
MITRE ATT&CK techniques associated with the detection. |
String |
| TenantId |
Unique identifier of the tenant into which the data connector ingests data. |
String |
| TimeGenerated |
The timestamp (in UTC) when the log entry was generated. |
DateTime |
| TraceId |
Trace ID for request tracing. |
String |
| TreeId |
Tree identifier for the process tree. |
String |
| Type |
The name of the table |
String |
| UserAgent |
User agent string of the request. |
String |
| UserId |
User ID associated with the activity. |
String |
| UserIp |
IP address of the user making the API call. |
String |
| UserName |
Username who performed the action. |
String |
| UserSourceIp |
Source IP of the user. |
String |
| UserUuid |
UUID of the user who owns the scheduled report. |
String |
| XdrType |
Type of XDR detection (e.g., xdr). |
String |