Software Secure Workload
Activity Configure

Common Fields

These fields are common to various event types. They have the prefix “Event name - Event”, for example, “Binary Changed - Binary Attribute - CTime (epoch nanoseconds)”

Field

Description

Binary Attribute - CTime (epoch nanoseconds)

Changed time in linux/ Create time in windows of the binary

Binary Attribute - Hash

Sha256 hash of the binary

Binary Attribute - MTime (epoch nanoseconds)

Modified time of the binary

Binary Attribute - Filename

Name of the binary on the file system

Binary Attribute - Size (bytes)

Size of the binary on the file system

Event Binary Path

Full path of the binary

Command Line

Full command line of the process that gets executed