Common Fields
These fields are common to various event types. They have the prefix “Event name - Event”, for example, “Binary Changed - Binary Attribute - CTime (epoch nanoseconds)”
Field |
Description |
---|---|
Binary Attribute - CTime (epoch nanoseconds) |
Changed time in linux/ Create time in windows of the binary |
Binary Attribute - Hash |
Sha256 hash of the binary |
Binary Attribute - MTime (epoch nanoseconds) |
Modified time of the binary |
Binary Attribute - Filename |
Name of the binary on the file system |
Binary Attribute - Size (bytes) |
Size of the binary on the file system |
Event Binary Path |
Full path of the binary |
Command Line |
Full command line of the process that gets executed |