Views:
The analysis chain shows object types using the following icons:
Icon
Name
Description
L-object_first_ob=GUID-D64C81D8-CB37-4A29-A78F-6B8811F26473=1=en-us=Low.png
First Observed Object
Marks an object that most likely created the matched object
L-object_matched=GUID-D9DD275B-D1FA-4BC0-8B4B-8B4771088035=1=en-us=Low.png
Matched Criteria
Marks objects matching the investigation criteria
L-object_normal=GUID-27C8C939-9BC9-407A-B910-00FA109EEE30=1=en-us=Low.png
Normal Object
Marks objects that have been verified to not pose a threat
These are usually common system files.
L-object_unrated=GUID-98E3397A-1149-49C4-84BD-D9CEA2E22D69=1=en-us=Low.png
Unrated Object
Marks objects that have not yet been rated
L-object_suspicious=GUID-27AC0DEF-C569-439E-8253-859D2AE7D08C=1=en-us=Low.png
Suspicious Object
Marks objects that exhibit behaviors that are similar to known threats
L-object_malicious=GUID-E3D621BD-E87F-4ACC-A0A3-859C330ACF42=1=en-us=Low.png
Malicious Object
Marks objects that match a known threat
L-type_boot=GUID-D03CDF55-CD63-43E2-9A1A-62DD3B077B36=1=en-us=Low.png
Boot
Objects that launch during system startup
L-type_browser=GUID-DF7BA239-2566-4215-8EA2-E8388F7AD52A=1=en-us=Low.png
Browser
Objects that are capable of displaying web pages, usually a web browser
L-type_email=GUID-E89F7CE3-ED60-4EC7-A371-10C866F92763=1=en-us=Low.png
Email client
Objects that can send and receive email messages, usually an email client or server
icon_emailmsg=GUID-5ACA3359-7197-481B-A09D-9FDF56082DBF=1=en-us=Low.png
Email message
Objects identified through use of the Cloud App Security integration email correlation feature
L-type_file=GUID-46212822-7E1C-46B0-951F-75A1CD56A6EB=1=en-us=Low.png
File
Objects that are files on the disk
L-type_network=GUID-1BC9EAF7-D603-4477-AD73-C3554DEC6ADA=1=en-us=Low.png
Network
Objects related to network connections or the Internet
L-type_process=GUID-C416465F-28C8-4EDA-B047-7AB1CC53202B=1=en-us=Low.png
Process
Objects that are processes running during the time of execution
L-type_registry=GUID-733B93B0-5901-4362-A042-8B16DCD11527=1=en-us=Low.png
Registry
Objects that are registry keys, entries or data
L-action_event=GUID-CBFE9C78-F58D-4789-9537-346B9538001D=1=en-us=Low.png
Event
Indicates actions done by the object
L-action_association=GUID-FF2050D8-B8E6-460E-8679-BA976AEDAA48=1=en-us=Low.png
Association
Indicates relationships between two objects