EDR Supported Fields

This document shows the fields supported by each provider and operation.

get_endpoint

FieldCrowdStrike EDRDefender EDRSentinelOne EDRSophos EDRType
result.activity_idnumber
result.activity_namestring
result.category_namestring
result.category_uidnumber
result.class_uidnumber
result.cloud.providerstring
result.device.descstring
result.device.domainstring
result.device.first_seen_timetimestamp
result.device.hostnamestring
result.device.hw_info.bios_manufacturerstring
result.device.hw_info.bios_verstring
result.device.hw_info.chassisstring
result.device.hw_info.cpu_coresnumber
result.device.hw_info.cpu_countnumber
result.device.hw_info.cpu_typestring
result.device.hw_info.serial_numberstring
result.device.instance_uidstring
result.device.ipstring
result.device.ip_addresses[]string
result.device.last_seen_timetimestamp
result.device.last_seen_time_dtstring
result.device.macstring
result.device.mac_addresses[]string
result.device.modified_timetimestamp
result.device.namestring
result.device.network_interfaces[].hostnamestring
result.device.network_interfaces[].ipstring
result.device.network_interfaces[].macstring
result.device.network_interfaces[].type_idnumber
result.device.network_interfaces[].uidstring
result.device.network_statusstring
result.device.network_status_idnumber
result.device.org.namestring
result.device.org.ou_namestring
result.device.org.ou_uidstring
result.device.org.uidstring
result.device.os.buildstring
result.device.os.namestring
result.device.os.typestring
result.device.os.type_idnumber
result.device.os.versionstring
result.device.risk_levelstring
result.device.sw_info[].namestring
result.device.sw_info[].vendor_namestring
result.device.sw_info[].versionstring
result.device.typestring
result.device.type_idnumber
result.device.uidstring
result.device.zonestring
result.messagestring
result.metadata.labels[]string
result.metadata.loggers[].namestring
result.metadata.loggers[].versionstring
result.metadata.product.namestring
result.metadata.product.vendor_namestring
result.metadata.product.versionstring
result.metadata.tenant_uidstring
result.metadata.versionstring
result.raw_datastring
result.severitystring
result.severity_idnumber
result.statusstring
result.status_codestring
result.status_detailstring
result.status_idnumber
result.timenumber
result.time_dtstring
result.type_namestring
result.type_uidnumber
result.unmapped.connection_mac_addressstring
result.unmapped.default_gateway_ipstring
result.unmapped.deployment_typestring
result.unmapped.kernel_versionstring
result.unmapped.local_ipstring
result.unmapped.provision_statusstring

query_alerts

FieldCrowdStrike EDRDefender EDRMalwarebytes EDRSentinelOne EDRType
activity_idnumber
activity_namestring
actor.user.domainstring
actor.user.namestring
attacks[].tactic.namestring
attacks[].tactic.uidstring
attacks[].technique.namestring
attacks[].technique.uidstring
category_namestring
category_uidnumber
class_namestring
class_uidnumber
commentstring
confidence_scorenumber
device.first_seen_timetimestamp
device.first_seen_time_dtstring
device.hostnamestring
device.hw_info.bios_manufacturerstring
device.hw_info.bios_verstring
device.ipstring
device.last_seen_timetimestamp
device.last_seen_time_dtstring
device.macstring
device.modified_timetimestamp
device.modified_time_dtstring
device.namestring
device.network_interfaces[].hostnamestring
device.network_interfaces[].ipstring
device.network_interfaces[].macstring
device.network_interfaces[].type_idnumber
device.org.uidstring
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.typestring
device.type_idnumber
device.uidstring
device.uid_altstring
evidences[].actor.user.full_namestring
evidences[].process.cmd_linestring
evidences[].process.created_timetimestamp
evidences[].process.created_time_dtstring
evidences[].process.file.hashes[].algorithmstring
evidences[].process.file.hashes[].algorithm_idnumber
evidences[].process.file.hashes[].valuestring
evidences[].process.file.modified_timetimestamp
evidences[].process.file.modified_time_dtstring
evidences[].process.file.namestring
evidences[].process.file.pathstring
evidences[].process.file.type_idnumber
evidences[].process.namestring
evidences[].process.parent_process.cmd_linestring
evidences[].process.parent_process.namestring
evidences[].process.parent_process.pathstring
evidences[].process.parent_process.pidnumber
evidences[].process.parent_process.sha256string
evidences[].process.pidnumber
evidences[].process.terminated_timetimestamp
evidences[].process.uidstring
evidences[].process.user.namestring
finding_info.analytic.categorystring
finding_info.analytic.descstring
finding_info.analytic.namestring
finding_info.analytic.typestring
finding_info.analytic.type_idnumber
finding_info.analytic.uidstring
finding_info.analytic.versionstring
finding_info.created_timetimestamp
finding_info.created_time_dtstring
finding_info.first_seen_timetimestamp
finding_info.first_seen_time_dtstring
finding_info.last_seen_timetimestamp
finding_info.last_seen_time_dtstring
finding_info.modified_timetimestamp
finding_info.modified_time_dtstring
finding_info.product_uidstring
finding_info.titlestring
finding_info.types[]string
finding_info.uidstring
metadata.loggers[].logged_timetimestamp
metadata.loggers[].logged_time_dtstring
metadata.product.feature.namestring
metadata.product.feature.uidstring
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
resources[].namestring
resources[].uidstring
risk_scorenumber
severitystring
severity_idnumber
start_timetimestamp
start_time_dtstring
statusstring
status_detailstring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber
vulnerabilities[].descstring
vulnerabilities[].titlestring

query_applications

FieldCrowdStrike EDRDefender EDRMalwarebytes EDRSophos EDRType
activity_idnumber
activity_namestring
category_namestring
category_uidnumber
class_uidnumber
device.groups[].namestring
device.groups[].uidstring
device.hostnamestring
device.ipstring
device.macstring
device.namestring
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.typestring
device.type_idnumber
device.uidstring
metadata.modified_timetimestamp
metadata.modified_time_dtstring
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.versionstring
observables[].namestring
observables[].typestring
observables[].type_idnumber
observables[].valuestring
product.namestring
product.pathstring
product.uidstring
product.vendor_namestring
product.versionstring
severitystring
severity_idnumber
start_timetimestamp
start_time_dtstring
statusstring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber

query_endpoints

FieldCrowdStrike EDRDefender EDRMalwarebytes EDRSentinelOne EDRSophos EDRType
activity_idnumber
activity_namestring
category_namestring
category_uidnumber
class_uidnumber
cloud.account.uidstring
cloud.project_uidstring
cloud.providerstring
countnumber
device.created_timetimestamp
device.created_time_dtstring
device.descstring
device.domainstring
device.first_seen_timetimestamp
device.hostnamestring
device.hw_info.bios_manufacturerstring
device.hw_info.bios_verstring
device.hw_info.chassisstring
device.hw_info.cpu_coresnumber
device.hw_info.cpu_countnumber
device.hw_info.cpu_typestring
device.hw_info.serial_numberstring
device.instance_uidstring
device.ipstring
device.ip_addresses[]string
device.last_seen_timetimestamp
device.last_seen_time_dtstring
device.macstring
device.mac_addresses[]string
device.modified_timetimestamp
device.namestring
device.network_interfaces[].hostnamestring
device.network_interfaces[].ipstring
device.network_interfaces[].macstring
device.network_interfaces[].typestring
device.network_interfaces[].type_idnumber
device.network_interfaces[].uidstring
device.network_statusstring
device.network_status_idnumber
device.org.namestring
device.org.ou_namestring
device.org.ou_uidstring
device.org.uidstring
device.os.buildstring
device.os.cpu_bitsnumber
device.os.namestring
device.os.typestring
device.os.type_idnumber
device.os.versionstring
device.risk_levelstring
device.sw_info[].namestring
device.sw_info[].vendor_namestring
device.sw_info[].versionstring
device.typestring
device.type_idnumber
device.uidstring
device.uid_altstring
device.zonestring
messagestring
metadata.labels[]string
metadata.loggers[].namestring
metadata.loggers[].versionstring
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.tenant_uidstring
metadata.versionstring
result.activity_idnumber
result.activity_namestring
result.category_namestring
result.category_uidnumber
result.class_uidnumber
result.device.domainstring
result.device.first_seen_timetimestamp
result.device.hostnamestring
result.device.hw_info.cpu_coresnumber
result.device.hw_info.cpu_countnumber
result.device.hw_info.cpu_typestring
result.device.instance_uidstring
result.device.ipstring
result.device.last_seen_timetimestamp
result.device.macstring
result.device.modified_timetimestamp
result.device.namestring
result.device.network_interfaces[].hostnamestring
result.device.network_interfaces[].ipstring
result.device.network_interfaces[].macstring
result.device.network_interfaces[].type_idnumber
result.device.network_interfaces[].uidstring
result.device.network_statusstring
result.device.network_status_idnumber
result.device.org.namestring
result.device.org.ou_namestring
result.device.org.ou_uidstring
result.device.org.uidstring
result.device.os.namestring
result.device.os.typestring
result.device.os.type_idnumber
result.device.os.versionstring
result.device.typestring
result.device.type_idnumber
result.device.uidstring
result.metadata.product.namestring
result.metadata.product.vendor_namestring
result.metadata.product.versionstring
result.metadata.versionstring
result.severity_idnumber
result.timenumber
result.type_uidnumber
severitystring
severity_idnumber
statusstring
status_codestring
status_detailstring
status_idnumber
timenumber
time_dtstring
type_namestring
type_uidnumber

query_iocs

FieldCrowdStrike EDRDefender EDRSentinelOne EDRType
actionstring
applied_globallyboolean
createdstring
created_by_ref.createdstring
created_by_ref.idstring
created_by_ref.modifiedstring
created_by_ref.namestring
created_by_ref.spec_versionstring
created_by_ref.typestring
data.creationTimestring
data.descriptionstring
data.externalIdstring
data.groupIds[]string
data.labels[]string
data.methodstring
data.namestring
data.patternstring
data.patternTypestring
data.severitynumber
data.sourcestring
data.tenantboolean
data.validUntilstring
descriptionstring
expirationstring
extensions.actionstring
extensions.alertboolean
extensions.rbacGroupNames[]string
extensions.severitystring
filter.groupIds[]string
filter.tenantboolean
idstring
modifiedstring
namestring
patternstring
pattern_typestring
platforms[]string
severitystring
sourcestring
spec_versionstring
tags[]string
typestring
valid_fromstring
valid_untilstring
valuestring

query_posture_score

FieldCrowdStrike EDRDefender EDRType
activity_idnumber
activity_namestring
category_namestring
category_uidnumber
class_uidnumber
cloud.project_uidstring
cloud.providerstring
device.hw_info.serial_numberstring
device.os.namestring
device.os.type_idnumber
device.type_idnumber
device.uidstring
device.vendor.uidstring
enrichments[].dataunknown
enrichments[].namestring
enrichments[].reputation.base_scorenumber
enrichments[].reputation.scorestring
enrichments[].reputation.score_idnumber
enrichments[].valuestring
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.versionstring
osintunknown
osint[].commentstring
osint[].confidencestring
osint[].namestring
osint[].type_idnumber
osint[].uidstring
osint[].valuestring
osint[].vendor_namestring
severity_idnumber
statusstring
status_idnumber
timenumber
time_dtstring
type_uidnumber

query_threatevents

FieldCrowdStrike EDRDefender EDRMalwarebytes EDRType
actionstring
action_idnumber
activity_idnumber
activity_namestring
actor.invoked_bystring
actor.process.cmd_linestring
actor.process.file.hashes[].algorithmstring
actor.process.file.hashes[].algorithm_idnumber
actor.process.file.hashes[].valuestring
actor.process.file.namestring
actor.process.file.pathstring
actor.process.file.typestring
actor.process.file.type_idnumber
actor.process.namestring
actor.user.namestring
attacks[].tactic.namestring
attacks[].tactic.uidstring
attacks[].technique.namestring
attacks[].technique.uidstring
category_namestring
category_uidnumber
class_uidnumber
confidence_idnumber
confidence_scorenumber
device.first_seen_timetimestamp
device.first_seen_time_dtstring
device.hostnamestring
device.hw_info.bios_manufacturerstring
device.hw_info.bios_verstring
device.idstring
device.ipstring
device.last_seen_timetimestamp
device.last_seen_time_dtstring
device.macstring
device.modified_timetimestamp
device.modified_time_dtstring
device.network_interfaces[].hostnamestring
device.network_interfaces[].ipstring
device.network_interfaces[].macstring
device.os.namestring
device.os.typestring
device.os.versionstring
device.typestring
device.type_idnumber
device.uidstring
enrichments[].datastring
enrichments[].namestring
enrichments[].typestring
enrichments[].valuestring
finding_infounknown
finding_info.created_timetimestamp
finding_info.created_time_dtstring
finding_info.data_sources[]string
finding_info.first_seen_timetimestamp
finding_info.first_seen_time_dtstring
finding_info.last_seen_timetimestamp
finding_info.last_seen_time_dtstring
finding_info.modified_timetimestamp
finding_info.modified_time_dtstring
finding_info.product_uidstring
finding_info.titlestring
finding_info.uidstring
messagestring
metadata.correlation_uidstring
metadata.product.namestring
metadata.product.vendor_namestring
metadata.product.versionstring
metadata.tenant_uidstring
metadata.uidstring
metadata.versionstring
severitystring
severity_idnumber
statusstring
status_idnumber
timenumber
time_dtstring
type_uidnumber