- JSON representation
- NounProvenance
- FieldProvenance
- UserProvenance
- LocationProvenance
- GoogleTypeLatLngProvenance
- AttributeProvenance
- LabelProvenance
- PermissionProvenance
- RoleProvenance
- TimeOffProvenance
- ProcessProvenance
- FileProvenance
- FileMetadataProvenance
- PeFileMetadataProvenance
- SecurityResultProvenance
- Unsupported
- AnalyticsMetadataProvenance
- AttackDetailsProvenance
- TacticProvenance
- TechniqueProvenance
- AssociationProvenance
- AssociationAliasProvenance
- VerdictProvenance
- ProviderMLVerdictProvenance
- SourceProvenance
- AnalystVerdictProvenance
- VerdictInfoProvenance
- IoCStatsProvenance
- ThreatCollectionItemProvenance
- FileMetadataPEProvenance
- FileMetadataSectionProvenance
- FileMetadataImportsProvenance
- FileMetadataPeResourceInfoProvenance
- StringToInt64MapEntryProvenance
- FileMetadataSignatureInfoProvenance
- SignerInfoProvenance
- X509Provenance
- PrevalenceProvenance
- ExifInfoProvenance
- SignatureInfoProvenance
- FileMetadataCodesignProvenance
- PDFInfoProvenance
- FaviconProvenance
- NtfsFileMetadataProvenance
- AssetProvenance
- HardwareProvenance
- PlatformSoftwareProvenance
- SoftwareProvenance
- VulnerabilityProvenance
- ArtifactProvenance
- NetworkProvenance
- FtpProvenance
- EmailProvenance
- DnsProvenance
- QuestionProvenance
- ResourceRecordProvenance
- DhcpProvenance
- OptionProvenance
- HttpProvenance
- UserAgentProtoProvenance
- TlsProvenance
- ClientProvenance
- CertificateProvenance
- ServerProvenance
- SmtpProvenance
- ProxyInfoProvenance
- SSLCertificateProvenance
- TunnelsProvenance
- ArtifactClientProvenance
JSON representation |
---|
{ "principal": { object ( |
Fields | |
---|---|
principal |
|
src |
|
target |
|
NounProvenance
JSON representation |
---|
{ "hostname": { object ( |
Fields | |
---|---|
hostname |
|
assetId |
|
user |
|
process |
|
ip[] |
|
mac[] |
|
file |
|
location |
|
asset |
|
ipGeoArtifact[] |
|
FieldProvenance
JSON representation |
---|
{ "logSource": string, "logType": enum ( |
Fields | |
---|---|
logSource |
|
logType |
|
logTypes[] |
|
eventId |
A base64-encoded string. |
fromRawLog |
|
nonlogSource |
|
UserProvenance
JSON representation |
---|
{ "productObjectId": { object ( |
Fields | |
---|---|
productObjectId |
|
userid |
|
userDisplayName |
|
firstName |
|
middleName |
|
lastName |
|
phoneNumbers[] |
|
personalAddress |
|
attribute |
|
firstSeenTime |
|
accountType |
|
groupid |
|
groupIdentifiers[] |
|
windowsSid |
|
emailAddresses[] |
|
employeeId |
|
title |
|
companyName |
|
department[] |
|
officeAddress |
|
managers[] |
|
hireDate |
|
terminationDate |
|
timeOff[] |
|
lastLoginTime |
|
lastPasswordChangeTime |
|
passwordExpirationTime |
|
accountExpirationTime |
|
accountLockoutTime |
|
lastBadPasswordAttemptTime |
|
userAuthenticationStatus |
|
roleName |
|
roleDescription |
|
userRole |
|
LocationProvenance
JSON representation |
---|
{ "city": { object ( |
Fields | |
---|---|
city |
|
state |
|
countryOrRegion |
|
name |
|
deskName |
|
floorName |
|
regionLatitude |
|
regionLongitude |
|
regionCoordinates |
|
GoogleTypeLatLngProvenance
JSON representation |
---|
{ "latitude": { object ( |
Fields | |
---|---|
latitude |
|
longitude |
|
AttributeProvenance
JSON representation |
---|
{ "labels": [ { object ( |
Fields | |
---|---|
labels[] |
|
permissions[] |
|
roles[] |
|
creationTime |
|
lastUpdateTime |
|
LabelProvenance
JSON representation |
---|
{ "key": { object ( |
Fields | |
---|---|
key |
|
value |
|
source |
|
rbacEnabled |
|
PermissionProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
description |
|
type |
|
RoleProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
description |
|
type |
|
TimeOffProvenance
This type has no fields.
ProcessProvenance
JSON representation |
---|
{ "pid": { object ( |
Fields | |
---|---|
pid |
|
parentPid |
|
parentProcess |
|
file |
|
commandLine |
|
commandLineHistory[] |
|
productSpecificProcessId |
|
accessMask |
|
integrityLevelRid |
|
euid |
|
ruid |
|
egid |
|
rgid |
|
pgid |
|
sessionLeaderPid |
|
tty |
|
tokenElevationType |
|
productSpecificParentProcessId |
|
FileProvenance
JSON representation |
---|
{ "sha256": { object ( |
Fields | |
---|---|
sha256 |
|
md5 |
|
sha1 |
|
size |
|
fullPath |
|
mimeType |
|
fileMetadata |
|
securityResult |
|
peFile |
|
ssdeep |
|
vhash |
|
ahash |
|
authentihash |
|
symhash |
|
fileType |
|
capabilitiesTags[] |
|
names[] |
|
tags[] |
|
lastModificationTime |
|
createTime |
|
lastAccessTime |
|
prevalence |
|
firstSeenTime |
|
lastSeenTime |
|
statMode |
|
statInode |
|
statDev |
|
statNlink |
|
statFlags |
|
lastAnalysisTime |
|
embeddedUrls[] |
|
embeddedDomains[] |
|
embeddedIps[] |
|
exifInfo |
|
signatureInfo |
|
pdfInfo |
|
firstSubmissionTime |
|
lastSubmissionTime |
|
mainIcon |
|
ntfs |
|
FileMetadataProvenance
JSON representation |
---|
{
"pe": {
object ( |
Fields | |
---|---|
pe |
|
PeFileMetadataProvenance
JSON representation |
---|
{
"importHash": {
object ( |
Fields | |
---|---|
importHash |
|
SecurityResultProvenance
JSON representation |
---|
{ "about": { object ( |
Fields | |
---|---|
about |
|
category[] |
|
categoryDetails[] |
|
threatName |
|
ruleSet |
|
ruleSetDisplayName |
|
rulesetCategoryDisplayName |
|
ruleId |
|
ruleName |
|
ruleVersion |
|
ruleType |
|
ruleAuthor |
|
ruleLabels[] |
|
alertState |
|
detectionFields[] |
|
outcomes[] |
|
unsupportedVariables |
|
summary |
|
description |
|
action[] |
|
actionDetails |
|
severity |
|
confidence |
|
priority |
|
riskScore |
|
confidenceScore |
|
analyticsMetadata[] |
|
severityDetails |
|
confidenceDetails |
|
priorityDetails |
|
urlBackToProduct |
|
threatId |
|
threatFeedName |
|
threatIdNamespace |
|
threatStatus |
|
attackDetails |
|
firstDiscoveredTime |
|
associations[] |
|
campaigns[] |
|
reports[] |
|
verdict |
|
lastUpdatedTime |
|
verdictInfo[] |
|
threatVerdict |
|
lastDiscoveredTime |
|
detectionDepth |
|
threatCollections[] |
|
Unsupported
This type has no fields.
AnalyticsMetadataProvenance
JSON representation |
---|
{
"analytic": {
object ( |
Fields | |
---|---|
analytic |
|
AttackDetailsProvenance
JSON representation |
---|
{ "version": { object ( |
Fields | |
---|---|
version |
|
tactics[] |
|
techniques[] |
|
TacticProvenance
JSON representation |
---|
{ "id": { object ( |
Fields | |
---|---|
id |
|
name |
|
TechniqueProvenance
JSON representation |
---|
{ "id": { object ( |
Fields | |
---|---|
id |
|
name |
|
subtechniqueId |
|
subtechniqueName |
|
AssociationProvenance
JSON representation |
---|
{ "id": { object ( |
Fields | |
---|---|
id |
|
countryCode[] |
|
type |
|
name |
|
description |
|
role |
|
sourceCountry |
|
alias[] |
|
firstReferenceTime |
|
lastReferenceTime |
|
industriesAffected[] |
|
associatedActors[] |
|
regionCode |
|
sponsorRegion |
|
targetedRegions[] |
|
tags[] |
|
AssociationAliasProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
company |
|
VerdictProvenance
JSON representation |
---|
{ "sourceCount": { object ( |
Fields | |
---|---|
sourceCount |
|
responseCount |
|
neighbourInfluence |
|
verdict |
|
analystVerdict |
|
ProviderMLVerdictProvenance
JSON representation |
---|
{ "sourceProvider": { object ( |
Fields | |
---|---|
sourceProvider |
|
benignCount |
|
maliciousCount |
|
confidenceScore |
|
mandiantSources[] |
|
thirdPartySources[] |
|
SourceProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
benignCount |
|
maliciousCount |
|
quality |
|
responseCount |
|
sourceCount |
|
threatIntelligenceSources[] |
|
AnalystVerdictProvenance
JSON representation |
---|
{ "confidenceScore": { object ( |
Fields | |
---|---|
confidenceScore |
|
verdictTime |
|
verdictResponse |
|
VerdictInfoProvenance
JSON representation |
---|
{ "sourceCount": { object ( |
Fields | |
---|---|
sourceCount |
|
responseCount |
|
neighbourInfluence |
|
verdictType |
|
sourceProvider |
|
benignCount |
|
maliciousCount |
|
confidenceScore |
|
iocStats[] |
|
verdictTime |
|
verdictResponse |
|
globalCustomerCount |
|
globalHitsCount |
|
pwn |
|
categoryDetails |
|
pwnFirstTaggedTime |
|
IoCStatsProvenance
JSON representation |
---|
{ "iocStatsType": { object ( |
Fields | |
---|---|
iocStatsType |
|
firstLevelSource |
|
secondLevelSource |
|
benignCount |
|
quality |
|
maliciousCount |
|
responseCount |
|
sourceCount |
|
ThreatCollectionItemProvenance
JSON representation |
---|
{ "id": { object ( |
Fields | |
---|---|
id |
|
type |
|
altNames[] |
|
FileMetadataPEProvenance
JSON representation |
---|
{ "imphash": { object ( |
Fields | |
---|---|
imphash |
|
entryPoint |
|
entryPointExiftool |
|
compilationTime |
|
compilationExiftoolTime |
|
section[] |
|
imports[] |
|
resource[] |
|
resourcesTypeCount[] |
|
resourcesLanguageCount[] |
|
resourcesTypeCountStr[] |
|
resourcesLanguageCountStr[] |
|
signatureInfo |
|
FileMetadataSectionProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
entropy |
|
rawSizeBytes |
|
virtualSizeBytes |
|
md5Hex |
|
FileMetadataImportsProvenance
JSON representation |
---|
{ "library": { object ( |
Fields | |
---|---|
library |
|
functions[] |
|
FileMetadataPeResourceInfoProvenance
JSON representation |
---|
{ "sha256Hex": { object ( |
Fields | |
---|---|
sha256Hex |
|
filetypeMagic |
|
languageCode |
|
entropy |
|
fileType |
|
StringToInt64MapEntryProvenance
JSON representation |
---|
{ "key": { object ( |
Fields | |
---|---|
key |
|
value |
|
FileMetadataSignatureInfoProvenance
JSON representation |
---|
{ "verificationMessage": { object ( |
Fields | |
---|---|
verificationMessage |
|
verified |
|
signer[] |
|
signers[] |
|
x509[] |
|
SignerInfoProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
status |
|
validUsage |
|
certIssuer |
|
X509Provenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
algorithm |
|
thumbprint |
|
certIssuer |
|
serialNumber |
|
PrevalenceProvenance
JSON representation |
---|
{ "rollingMax": { object ( |
Fields | |
---|---|
rollingMax |
|
dayCount |
|
rollingMaxSubDomains |
|
dayMax |
|
dayMaxSubDomains |
|
ExifInfoProvenance
JSON representation |
---|
{ "originalFile": { object ( |
Fields | |
---|---|
originalFile |
|
product |
|
company |
|
fileDescription |
|
entryPoint |
|
compilationTime |
|
SignatureInfoProvenance
JSON representation |
---|
{ "sigcheck": { object ( |
Fields | |
---|---|
sigcheck |
|
codesign |
|
FileMetadataCodesignProvenance
JSON representation |
---|
{ "id": { object ( |
Fields | |
---|---|
id |
|
format |
|
compilationTime |
|
teamId |
|
PDFInfoProvenance
JSON representation |
---|
{ "js": { object ( |
Fields | |
---|---|
js |
|
javascript |
|
launchActionCount |
|
objectStreamCount |
|
endobjCount |
|
header |
|
acroform |
|
autoaction |
|
embeddedFile |
|
encrypted |
|
flash |
|
jbig2Compression |
|
objCount |
|
endstreamCount |
|
pageCount |
|
streamCount |
|
openaction |
|
startxref |
|
suspiciousColors |
|
trailer |
|
xfa |
|
xref |
|
FaviconProvenance
JSON representation |
---|
{ "rawMd5": { object ( |
Fields | |
---|---|
rawMd5 |
|
dhash |
|
NtfsFileMetadataProvenance
JSON representation |
---|
{ "changeTime": { object ( |
Fields | |
---|---|
changeTime |
|
filenameCreateTime |
|
filenameModifyTime |
|
filenameAccessTime |
|
filenameChangeTime |
|
AssetProvenance
JSON representation |
---|
{ "productObjectId": { object ( |
Fields | |
---|---|
productObjectId |
|
hostname |
|
assetId |
|
ip[] |
|
mac[] |
|
natIp[] |
|
firstSeenTime |
|
hardware[] |
|
platformSoftware |
|
software[] |
|
location |
|
category |
|
type |
|
networkDomain |
|
creationTime |
|
firstDiscoverTime |
|
lastDiscoverTime |
|
systemLastUpdateTime |
|
lastBootTime |
|
labels[] |
|
deploymentStatus |
|
vulnerabilities[] |
|
attribute |
|
HardwareProvenance
JSON representation |
---|
{ "serialNumber": { object ( |
Fields | |
---|---|
serialNumber |
|
manufacturer |
|
model |
|
cpuPlatform |
|
cpuModel |
|
cpuClockSpeed |
|
cpuMaxClockSpeed |
|
cpuNumberCores |
|
ram |
|
PlatformSoftwareProvenance
JSON representation |
---|
{ "platform": { object ( |
Fields | |
---|---|
platform |
|
platformVersion |
|
platformPatchLevel |
|
SoftwareProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
version |
|
permissions[] |
|
description |
|
vendorName |
|
VulnerabilityProvenance
JSON representation |
---|
{ "about": { object ( |
Fields | |
---|---|
about |
|
name |
|
description |
|
vendor |
|
scanStartTime |
|
scanEndTime |
|
firstFound |
|
lastFound |
|
severity |
|
severityDetails |
|
cvssBaseScore |
|
cvssVector |
|
cvssVersion |
|
cveId |
|
cveDescription |
|
vendorVulnerabilityId |
|
vendorKnowledgeBaseArticleId |
|
ArtifactProvenance
JSON representation |
---|
{ "ip": { object ( |
Fields | |
---|---|
ip |
|
prevalence |
|
firstSeenTime |
|
lastSeenTime |
|
location |
|
network |
|
asOwner |
|
asn |
|
jarm |
|
lastHttpsCertificate |
|
lastHttpsCertificateDate |
|
regionalInternetRegistry |
|
tags[] |
|
whois |
|
whoisDate |
|
tunnels[] |
|
anonymous |
|
artifactClient |
|
risks[] |
|
NetworkProvenance
JSON representation |
---|
{ "sentBytes": { object ( |
Fields | |
---|---|
sentBytes |
|
receivedBytes |
|
sentPackets |
|
receivedPackets |
|
sessionDuration |
|
sessionId |
|
parentSessionId |
|
applicationProtocolVersion |
|
communityId |
|
direction |
|
ipProtocol |
|
applicationProtocol |
|
ftp |
|
email |
|
dns |
|
dhcp |
|
http |
|
tls |
|
smtp |
|
asn |
|
dnsDomain |
|
carrierName |
|
organizationName |
|
ipSubnetRange |
|
isProxy |
|
proxyInfo |
|
FtpProvenance
JSON representation |
---|
{
"command": {
object ( |
Fields | |
---|---|
command |
|
EmailProvenance
JSON representation |
---|
{ "from": { object ( |
Fields | |
---|---|
from |
|
replyTo |
|
to[] |
|
cc[] |
|
bcc[] |
|
mailId |
|
subject[] |
|
bounceAddress |
|
DnsProvenance
JSON representation |
---|
{ "id": { object ( |
Fields | |
---|---|
id |
|
response |
|
opcode |
|
authoritative |
|
truncated |
|
recursionDesired |
|
recursionAvailable |
|
responseCode |
|
questions[] |
|
answers[] |
|
authority[] |
|
additional[] |
|
QuestionProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
type |
|
class |
|
prevalence |
|
ResourceRecordProvenance
JSON representation |
---|
{ "name": { object ( |
Fields | |
---|---|
name |
|
type |
|
class |
|
ttl |
|
data |
|
binaryData |
|
DhcpProvenance
JSON representation |
---|
{ "opcode": { object ( |
Fields | |
---|---|
opcode |
|
htype |
|
hlen |
|
hops |
|
transactionId |
|
seconds |
|
flags |
|
ciaddr |
|
yiaddr |
|
siaddr |
|
giaddr |
|
chaddr |
|
sname |
|
file |
|
options[] |
|
type |
|
leaseTimeSeconds |
|
clientHostname |
|
clientIdentifier |
|
requestedAddress |
|
clientIdentifierString |
|
OptionProvenance
JSON representation |
---|
{ "code": { object ( |
Fields | |
---|---|
code |
|
data |
|
HttpProvenance
JSON representation |
---|
{ "method": { object ( |
Fields | |
---|---|
method |
|
referralUrl |
|
userAgent |
|
responseCode |
|
parsedUserAgent |
|
UserAgentProtoProvenance
This type has no fields.
TlsProvenance
JSON representation |
---|
{ "client": { object ( |
Fields | |
---|---|
client |
|
server |
|
cipher |
|
curve |
|
version |
|
versionProtocol |
|
established |
|
nextProtocol |
|
resumed |
|
ClientProvenance
JSON representation |
---|
{ "certificate": { object ( |
Fields | |
---|---|
certificate |
|
ja3 |
|
serverName |
|
supportedCiphers[] |
|
CertificateProvenance
JSON representation |
---|
{ "version": { object ( |
Fields | |
---|---|
version |
|
serial |
|
subject |
|
issuer |
|
md5 |
|
sha1 |
|
sha256 |
|
notBefore |
|
notAfter |
|
ServerProvenance
JSON representation |
---|
{ "certificate": { object ( |
Fields | |
---|---|
certificate |
|
ja3s |
|
SmtpProvenance
JSON representation |
---|
{ "helo": { object ( |
Fields | |
---|---|
helo |
|
mailFrom |
|
rcptTo[] |
|
serverResponse[] |
|
messagePath |
|
isWebmail |
|
isTls |
|
ProxyInfoProvenance
JSON representation |
---|
{ "anonymous": { object ( |
Fields | |
---|---|
anonymous |
|
anonymousVpn |
|
publicProxy |
|
torExitNode |
|
smartDnsProxy |
|
hostingProvider |
|
vpnDatacenter |
|
residentialProxy |
|
vpnServiceName |
|
proxyOverVpn |
|
relayProxy |
|
SSLCertificateProvenance
This type has no fields.
TunnelsProvenance
JSON representation |
---|
{ "provider": { object ( |
Fields | |
---|---|
provider |
|
type |
|
ArtifactClientProvenance
JSON representation |
---|
{ "behaviors": [ { object ( |
Fields | |
---|---|
behaviors[] |
|
proxies[] |
|