Views:
Field Name
Type
General Field
Description
Example
Products
act
-
-
The actions taken to mitigate the event
  • log
  • isolate
  • terminate
  • not blocked
  • Block
  • Reset
  • Trend Cloud One - Endpoint & Workload Security
actResult
-
-
The result of an action
  • Dropped
  • Successful
  • Accepted
  • Trend Cloud One - Endpoint & Workload Security
behaviorCat
-
-
The matched policy category
  • Policy Enforcement
  • Grey-Detection
  • Threat-Detection
  • Trend Cloud One - Endpoint & Workload Security
cves
-
-
The CVEs associated with this filter
  • CVE-2014-3567
  • CVE-2016-6304
  • CVE-2011-1385
  • Trend Cloud One - Endpoint & Workload Security
detectionType
-
-
The detection type
  • 1
  • File
  • Process
  • net
  • Trend Cloud One - Endpoint & Workload Security
dmac
-
-
The MAC address of the destination IP (dest_ip)
  • 00:09:0f:09:e6:18
  • 01:00:5E:7F:FF:FA
  • 00:00:0c:9f:f0:0a
  • Trend Cloud One - Endpoint & Workload Security
dpt
-
  • Port
The destination port
  • 0
  • 445
  • 80
  • Trend Cloud One - Endpoint & Workload Security
dst
-
  • IPv4
  • IPv6
The destination IP
  • 239.255.255.250
  • 0.0.0.0
  • 10.46.91.40
  • Trend Cloud One - Endpoint & Workload Security
duser
-
  • EmailRecipient
The email recipient
  • (no user)
  • SYSTEM
  • SYSTEM
  • Trend Cloud One - Endpoint & Workload Security
endpointGUID
-
  • EndpointID
The GUID of the agent which reported the detection
  • ae4d64aa-f8b8-bb36-b265-f59272ed342f
  • 8fb979f6-1376-bed3-227f-f2886e66194e
  • ca2b3a7e-8415-c571-cc19-e45f69470026
  • Trend Cloud One - Endpoint & Workload Security
endpointHostName
-
  • EndpointName
The endpoint hostname or node where the event was detected
  • 10.124.17.69 (swpos-aws-aza02) [i-0fd28720e80225308]
  • 10.124.21.139 (swpos-aws-azc02) [i-07e2c4a803cd0fa93]
  • 10.15.52.160 (swpos-aws-azc02) [i-06d8a16f428e7e85b]
  • ip-192-168-57-42.us-west-1.compute.internal
  • Trend Cloud One - Endpoint & Workload Security
endpointIp
-
  • IPv4
  • IPv6
The endpoint host IP (for ptp/stp: the client IP)
  • 192.168.204.215
  • 192.168.26.167
  • 192.168.46.168
  • Trend Cloud One - Endpoint & Workload Security
eventId
-
-
The event ID from the logs of each product
  • 100116
  • 100117
  • 100119
  • Trend Cloud One - Endpoint & Workload Security
eventName
-
-
The event type
  • LOG_INSPECTION_EVENT
  • SECURITY_RISK_DETECTION
  • WEB_THREAT_DETECTION
  • LOG_INSPECTION_EVENT
  • MALWARE_DETECTION
  • PROCESS_ACTIVITY
  • WEB_POLICY_VIOLATION
  • DEEP_PACKET_INSPECTION_EVENT
  • INTEGRITY_MONITORING_EVENT
  • DISRUPTIVE_APPLICATION_DETECTION
  • PRODUCT_SUMMARY
  • PRODUCT_UPDATE
  • BEHAVIORAL_VIOLATION
  • FIREWALL_POLICY_VIOLATION
  • SUSPICIOUS_BEHAVIOUR_DETECTION
  • DENYLIST_CHANGE
  • MACHINE_LEARNING_DETECTION
  • DLP_VIOLATION
  • MALWARE_OUTBREAK_DETECTION
  • Trend Cloud One - Endpoint & Workload Security
eventSubId
-
-
The access type
  • 4
  • 101
  • 102
  • Trend Cloud One - Endpoint & Workload Security
eventSubName
-
-
The event type sub-name
  • IPS Detection
  • Personal Firewall
  • Attack Discovery
  • Trend Cloud One - Endpoint & Workload Security
fileHash
-
  • FileSHA1
The SHA-1 of the file that triggered the rule or policy
  • DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
  • 89CE26EAD139D52B8A6B61BFFC6AF89AF246580F
  • 3AD1F4E7CAA11E5199EE80B8983677ADDD065450
  • Trend Cloud One - Endpoint & Workload Security
fileName
-
  • FileName
The file name
  • spoolss
  • hosts
  • svcrestarttask
  • Trend Cloud One - Endpoint & Workload Security
fileOperation
-
-
The operation of the file
  • Created
  • Updated
  • Deleted
  • Trend Cloud One - Endpoint & Workload Security
filePath
-
  • FileFullPath
The file path without the file name
  • security
  • /var/log/audit/audit.log
  • application
  • Trend Cloud One - Endpoint & Workload Security
filePathName
-
  • FileFullPath
The file path with the file name
  • vss
  • spoolss
  • /etc/hosts
  • Trend Cloud One - Endpoint & Workload Security
firstAct
-
-
The first scan action
  • Pass
  • Quarantine
  • Clean
  • Trend Cloud One - Endpoint & Workload Security
firstActResult
-
-
The first scan action result
  • File passed
  • Unable to quarantine file
  • File quarantined
  • Trend Cloud One - Endpoint & Workload Security
fullPath
-
  • FileFullPath
The combination of the file path and the file name
  • \etc\hosts
  • c:\windows\system32\tasks\microsoft\windows\softwareprotectionplatform\svcrestarttask
  • \var\log\auth.log
  • Trend Cloud One - Endpoint & Workload Security
groups
-
-
The OSSEC rule group names
  • auditd,audit,
  • dirservice_log,authentication_failure,
  • windows,authentication_failures,
  • Trend Cloud One - Endpoint & Workload Security
hostName
-
  • DomainName
  • HostDomain
The computer name of the client host (the hostname from the suspicious URL detected by Deep Discovery Inspector)
  • Let's Encrypt
  • 35.247.144.219
  • 204.65.0.20
  • Trend Cloud One - Endpoint & Workload Security
instanceId
-
-
The ID of the instance that indicates the meta-cloud or data center VM
  • 52294e7b-f732-c6e9-b2c3-7a6b6f50d101
  • 00030912-c5e7-4348-9012-7c684751c531
  • 0008ae58-db0c-34ee-3e5c-5dfc9b10a739
  • i-0b22a22eec53b9321
  • Trend Cloud One - Endpoint & Workload Security
interestedIp
-
  • IPv4
  • IPv6
The IP of the interestedHost
  • 192.168.204.215
  • 192.168.26.167
  • 192.168.46.168
  • Trend Cloud One - Endpoint & Workload Security
isEntity
-
-
The current entity (or after change/modification)
  • {"key":"VSS","type":"Service","attributes":[{"friendlyValue":null,"name":"binaryPathName","value":"C:\\Windows\\system32\\vssvc.exe"},{"friendlyValue":"manual","name":"startType","value":"3"},{"friendlyValue":"running","name":"state","value":"4"}]}
  • {"key":"VSS","type":"Service","attributes":[{"friendlyValue":null,"name":"binaryPathName","value":"C:\\Windows\\system32\\vssvc.exe"},{"friendlyValue":"manual","name":"startType","value":"3"},{"friendlyValue":"stopped","name":"state","value":"1"}]}
  • {"key":"/etc/hosts","type":"File","attributes":[]}
  • Trend Cloud One - Endpoint & Workload Security
logKey
-
-
The unique key of the event
  • 000D3A920166-5C348B85-05A7-6D6A-DA63_52294e7b-f732-c6e9-b2c3-7a6b6f50d101_88d7575d75e1d7f79d95300dd2cab4a85352a0707ebd43f968ab550991e3e915
  • 000D3A920166-5C348B85-05A7-6D6A-DA63_52294e7b-f732-c6e9-b2c3-7a6b6f50d101_c1802e89c5df3676025af5743a1dfe2d9f6d99da33cf3dcd7c02ad9ceb64e844
  • 000D3A920166-5C348B85-05A7-6D6A-DA63_52294e7b-f732-c6e9-b2c3-7a6b6f50d101_34392932f47013709193001781e05a4b3f78ea17e1618753f79e9436258af004
  • Trend Cloud One - Endpoint & Workload Security
mDeviceGUID
-
-
The GUID of the agent host
  • C5B09EDD-C725-907F-29D9-B8C30D18C48F
  • C05B75AB-B518-BDD0-D2B5-E9CB631C539F
  • 9C28ACD3-D0EC-22A4-B08D-5B0BEFF501FC
  • Trend Cloud One - Endpoint & Workload Security
majorVirusType
-
-
The virus type
  • Virus
  • Suspicious Activity
  • Trojan
  • TROJ
  • Trend Cloud One - Endpoint & Workload Security
malFamily
-
-
The threat family
  • EQUATED
  • STARTER
  • 0
  • Trend Cloud One - Endpoint & Workload Security
malName
-
-
The name of the detected malware
  • SecurityLevelDrop
  • Regla Logs All
  • USR_SUSPICIOUS_DOMAIN.UMXX
  • Trend Cloud One - Endpoint & Workload Security
malType
-
-
The risk type for Network Content Correlation Engine rules
  • OTHERS
  • MALWARE
  • Others
  • Trend Cloud One - Endpoint & Workload Security
mitreVersion
-
-
The MITRE version
  • v9
  • v6
  • Trend Cloud One - Endpoint & Workload Security
mpname
-
-
The management product name
  • Cloud One - Workload Security
  • Deep Security Software
  • Trend Cloud One - Endpoint & Workload Security
mpver
-
-
The product version
  • Microsoft-Windows-Security-Auditing
  • Level -- Medium security
  • TASK1
  • Trend Cloud One - Endpoint & Workload Security
objectCmd
-
  • CLICommand
The object process command line
  • C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding
  • "C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" -NoLogo -Noninteractive -NoProfile -ExecutionPolicy Bypass "& 'C:\WINDOWS\CCM\SystemTemp\afd6f0e5-e491-4764-a20a-9f1d9edf3cce.ps1'"
  • C:\WINDOWS\system32\lsass.exe
  • Trend Cloud One - Endpoint & Workload Security
objectFileHashMd5
-
  • FileMD5
The MD5 of the object
  • 801E8003C257C8F540B20F1E0DECD3A6
  • CDA48FC75952AD12D99E526D0B6BF70A
  • D5120786925038601A77C2E1EB9A3A0A
  • Trend Cloud One - Endpoint & Workload Security
objectFileHashSha1
-
  • FileSHA1
The SHA-1 of the objectFilePath object
  • 51B8646308EE0B68AD1F7F1291B85395434DE49A
  • 36C5D12033B2EAF251BAE61C00690FFB17FDDC87
  • 2586528000199793730B05D3F169BCF139E4D7A1
  • Trend Cloud One - Endpoint & Workload Security
objectFileHashSha256
-
  • FileSHA2
The SHA-256 of the object (objectFilePath)
  • A75C85F3B089993E9C042FB82ECB7757E8F460ED8065FC7991CAA38A6DE0F50C
  • 908B64B1971A979C7E3E8CE4621945CBA84854CB98D76367B791A6E22B5F6D53
  • 1A2ABAAD8A166B66CA35AB51C7432C5A7E46996472C8174281842896408D7F96
  • Trend Cloud One - Endpoint & Workload Security
objectFilePath
-
  • FileFullPath
The file path of the target process image or target file
  • c:\windows\system32\windowspowershell\v1.0\powershell.exe
  • zwwritevirtualmemory
  • c:\windows\system32\wbem\wmiprvse.exe
  • Trend Cloud One - Endpoint & Workload Security
objectIp
-
  • IPv4
  • IPv6
The IP address of the domain
  • 10.10.23.240
  • 0.0.0.0
  • 10.11.3.22
  • Trend Cloud One - Endpoint & Workload Security
objectRegistryData
-
  • RegistryValueData
The registry data contents
  • 07EFCDAB010001007CE21B54433A0CD356BCEA7C1C5DEE683999E759484BD7E82BDE5B3F598057F5AFCBB15B2C6EFB679F0744879657
  • C:\Program Files\AlertMedia\AlertMedia Desktop Notifications\AlertMedia.exe
  • Trend Cloud One - Endpoint & Workload Security
objectRegistryKeyHandle
-
  • RegistryKey
The registry key path
  • HKCR\CID\{42003200-2F00-6400-6800-4E0034003800}
  • HKLM\SOFTWARE\WOW6432Node\Eos
  • HKCU\SOFTWARE\Cerner\InstantAccess
  • Trend Cloud One - Endpoint & Workload Security
objectRegistryRoot
-
-
The name of the object registry root key
  • HKCR
  • HKLM
  • HKCU
  • Trend Cloud One - Endpoint & Workload Security
objectRegistryValue
-
  • RegistryValue
The registry value name
  • 1
  • key
  • reg
  • Trend Cloud One - Endpoint & Workload Security
objectType
-
-
The object type
  • file
  • process
  • qil
  • Trend Cloud One - Endpoint & Workload Security
objectUser
-
  • UserAccount
The owner name of the target process or the sign-in user name
  • Système
  • SYSTEM
  • SISTEMA
  • Trend Cloud One - Endpoint & Workload Security
objectUserDomain
-
-
The owner domain of the target process
  • NT AUTHORITY
  • UNEB
  • Trend Cloud One - Endpoint & Workload Security
parentPid
-
-
The PID of the parent process
-
  • Trend Cloud One - Endpoint & Workload Security
parentUser
-
-
The account name of the parent process
  • Administrator
  • Trend Cloud One - Endpoint & Workload Security
parentUserDomain
-
-
The domain name of the parent process
  • builtindomain
  • Trend Cloud One - Endpoint & Workload Security
pname
-
-
The internal product ID
  • Trend Cloud One - Endpoint & Workload Security
policyId
-
-
The policy ID of which the event was detected
  • 00000001-0001-0001-0001-000000007610
  • 007
  • 003
  • apiPostedPolicy-20k8uSUpUtTcLbvkrbBeALP0YEf
  • Trend Cloud One - Endpoint & Workload Security
processCmd
-
  • CLICommand
The subject process command line
  • "C:\Program Files (x86)\AADM\AADM.exe"
  • /usr/lib/inet/sendmail -bl -q15m
  • ComDir
  • Trend Cloud One - Endpoint & Workload Security
processFileCreation
-
-
The Unix time of object creation
  • 1645828113585
  • 1655412594237
  • 1647162053219
  • Trend Cloud One - Endpoint & Workload Security
processFileHashMd5
-
  • FileMD5
The MD5 of the subject process
  • D07ADD0CE6E000D3CD20193B891E8ED3
  • 1a9ba93ebe4cb60030831f8ce9e7d5f9
  • EEE6691B48D2FB604DDF0CBC90D75B0E
  • Trend Cloud One - Endpoint & Workload Security
processFileHashSha1
-
  • FileSHA1
The SHA-1 of the subject process
  • C0885381EBAC94AB20E78936434FA208F6B65352
  • ac373ed32b491da22924e2e11e36574e5d582a35
  • DF93F7DF887E86C3B56539B5046B286001C6F150
  • Trend Cloud One - Endpoint & Workload Security
processFileHashSha256
-
  • FileSHA2
The SHA-256 of the subject process
  • 4314A869B8DAE1BD3FFF810B1366E90FB7C961D4A3424260692377FDD87361D2
  • 7824c45fc033696603fe97d8f193a1872dfb2b5db75f0cda21df27017b3cb623
  • 1A6D5986EFEAE89308D9EE11B4A7907012603392E0E66D0E529DB09DF1B4CB64
  • Trend Cloud One - Endpoint & Workload Security
processFilePath
-
  • ProcessFullPath
  • FileFullPath
  • FileName
The file path of the subject process
  • c:\windows\system32\svchost.exe
  • c:\windows\system32\windowspowershell\v1.0\powershell.exe
  • c:\windows\syswow64\srts\wmipr.exe
  • Trend Cloud One - Endpoint & Workload Security
processImagePath
-
-
The process triggered by the file event
  • c:\windows\system32\svchost.exe
  • /usr/bin/python2.7
  • /usr/bin/sed
  • Trend Cloud One - Endpoint & Workload Security
processLaunchTime
-
-
The time the subject process was launched
  • 1656400286556
  • 1656566610259
  • 1656587180493
  • Trend Cloud One - Endpoint & Workload Security
processName
-
  • ProcessName
The image name of the process that triggered the event
  • c:\windows\system32\svchost.exe
  • /usr/bin/python2.7
  • /usr/bin/sed
  • Trend Cloud One - Endpoint & Workload Security
processPid
-
-
The PID of the subject process
-
  • Trend Cloud One - Endpoint & Workload Security
processUser
-
  • UserAccount
The user name of the process or the file creator
  • SYSTEM
  • SVC_JENKINS_CODE_DEV
  • NETWORK SERVICE
  • Trend Cloud One - Endpoint & Workload Security
processUserDomain
-
-
The owner domain of the subject process image
  • NT AUTHORITY
  • DOMAINBA
  • PAEDMZ
  • Trend Cloud One - Endpoint & Workload Security
proto
-
-
The exploited network protocol layer
  • 6
  • TCP
  • 17
  • Trend Cloud One - Endpoint & Workload Security
protoFlag
-
-
The data flags
  • ACK PSH DF=1
  • ACK DF=1
  • DF=1
  • Trend Cloud One - Endpoint & Workload Security
regionId
-
-
The cloud asset region
  • US East (N. Virginia)
  • Europe (Frankfurt)
  • Trend Cloud One - Endpoint & Workload Security
remarks
-
-
The additional information
  • warning: fork: Resource temporarily unavailable
  • pam_unix(cron:session): session opened for user root by (uid=0)
  • WinEvtLog: Application: AUDIT_FAILURE(18470): MSSQL$SA: (no user): no domain: SVR-CCS-ARMSD-3.elrosado.com: Login failed for user 'rherrera'. Reason: The account is disabled. [CLIENT: 172.29.3.180]
  • Trend Cloud One - Endpoint & Workload Security
request
-
  • URL
The notable URLs
  • http://detectportal.firefox.com/canonical.html
  • http://35.247.144.219/
  • http://35.247.144.219
  • Trend Cloud One - Endpoint & Workload Security
riskLevel
-
-
The risk level
  • 1
  • high
  • No Risk
  • Trend Cloud One - Endpoint & Workload Security
rtDate
-
-
The date of the log generation
  • 1655337600000
  • Trend Cloud One - Endpoint & Workload Security
rtWeekDay
-
-
The weekday of the log generation
  • Monday
  • Tuesday
  • Friday
  • Trend Cloud One - Endpoint & Workload Security
ruleName
-
-
The name of the rule that triggered the event
  • Directory Server - Microsoft Windows Active Directory
  • Microsoft Windows Events
  • Microsoft Windows Security Events - 3
  • (T1234) New executable created (chmod)
  • Trend Cloud One - Endpoint & Workload Security
ruleType
-
-
The access rule type
  • udso
  • point of entry
  • unknown
  • Trend Cloud One - Endpoint & Workload Security
ruleVer
-
-
The rule version
  • 202207060001
  • 202207190001
  • Trend Cloud One - Endpoint & Workload Security
scanType
-
-
The scan type
  • realtime_mailmeta-exchange
  • exchange_mailbox_realtime_detection_logs
  • gateway_realtime_blocking_traffic
  • Trend Cloud One - Endpoint & Workload Security
secondAct
-
-
The second scan action
  • Unknown
  • N/A
  • Deny Access
  • Trend Cloud One - Endpoint & Workload Security
secondActResult
-
-
The result of the second scan action
  • Unknown
  • N/A
  • Access denied
  • Trend Cloud One - Endpoint & Workload Security
senderGUID
-
-
The sender GUID
  • 346648FC-9862-D2F0-F94C-FAB1A838ABD7
  • 36E5239E-EEBA-0100-C10E-C057E0455E1D
  • 9606BBD5-38A7-9024-83C8-9C88A2AF90CC
  • Trend Cloud One - Endpoint & Workload Security
severity
-
-
The severity of the event
  • 2
  • 4
  • 6
  • 8
  • Trend Cloud One - Endpoint & Workload Security
shost
-
  • DomainName
The source hostname
  • dns.google
  • sw_us-east-1a_10-124-17-69
  • sw_us-east-1c_10-124-21-139
  • Trend Cloud One - Endpoint & Workload Security
smac
-
-
The source MAC address
  • a8:d0:e5:5c:cb:c5
  • 00:50:56:b2:93:46
  • 00:09:0f:09:00:06
  • Trend Cloud One - Endpoint & Workload Security
sproc
-
-
The OSSEC program name
  • postfix/sendmail
  • CRON
  • sshd
  • Trend Cloud One - Endpoint & Workload Security
spt
-
  • Port
The source port
  • 53
  • 0
  • 7680
  • Trend Cloud One - Endpoint & Workload Security
src
-
  • IPv4
  • IPv6
The source IP
  • 8.8.8.8
  • 0.0.0.0
  • 10.150.54.5
  • Trend Cloud One - Endpoint & Workload Security
subRuleId
-
-
The sub-rule ID
  • 85262
  • 914520
  • 18152
  • Trend Cloud One - Endpoint & Workload Security
subRuleName
-
-
The sub-rule name
  • Pre-authentication failed.
  • ATTACK T1070.002,T1070.004: Indicator Removal on Host : Clear Linux or Mac System Logs,File Deletion
  • ATTACK T1110: Multiple Windows Logon Failures
  • invisible_url_domain
  • Trend Cloud One - Endpoint & Workload Security
suid
-
  • UserAccount
The user name or mailbox
  • root
  • NT AUTHORITY\SYSTEM
  • telnet.user@internal.firs.gov.ng
  • Trend Cloud One - Endpoint & Workload Security
targetType
-
-
The target object type
  • File System
  • Uncategorized
  • Exploit
  • Trend Cloud One - Endpoint & Workload Security
vpcId
-
-
The virtual private cloud that contains the cloud asset
  • vpc-01234567890abcdef
  • Trend Cloud One - Endpoint & Workload Security
wasEntity
-
-
The entity before change/modification
  • {"key":"VSS","type":"Service","attributes":[{"friendlyValue":null,"name":"binaryPathName","value":"C:\\Windows\\system32\\vssvc.exe"},{"friendlyValue":"manual","name":"startType","value":"3"},{"friendlyValue":"stopped","name":"state","value":"1"}]}
  • {"key":"VSS","type":"Service","attributes":[{"friendlyValue":null,"name":"binaryPathName","value":"C:\\Windows\\system32\\vssvc.exe"},{"friendlyValue":"manual","name":"startType","value":"3"},{"friendlyValue":"running","name":"state","value":"4"}]}
  • {"key":"/etc/hosts","type":"File","attributes":[]}
  • Trend Cloud One - Endpoint & Workload Security
winEventId
-
-
The Windows Event ID
  • 11
  • 4624
  • 4670
  • Trend Cloud One - Endpoint & Workload Security