Data Mapping: Message Activity Data

Tip:

Data collected after January 20, 2022 (00:00 UTC+00:00) is also available using Email Activity Data. Switch to Email Activity Data to use keyword searches and more robust syntax.

Field

General Field

Example

Notes

srcDomain

DomainName

self.events.data.microsoft.com

DNS event

src

  • IPv4

  • IPv6

  • 192.0.2.0

  • 2001:0db8:85a3:0000:0000:8a2e:0370:7334

Trend Micro Apex One records all IP addresses including 127.0.01 and virtual machine addresses.

request

URL

https://www.example.com

-

attachmentFileHash

FileSHA1

98A9A1C8F69373B211E5F1E303BA8762F44BC898

Information about each attachment file in the email message

attachmentFileHashSha256

FileSHA2

16e4e8b57e82159a16f5d7d898da9e2a4fbe90c17cd95c02074e75226337c90a

 

attachmentFileName

FileName

example.exe

 

fileExt

-

txt

 

mailMsgSubject

EmailSubject

Subject: From the desk of the Nigerian Prince

-

msgId

EmailMessageID

<rRzmIhBrXbgjvr4uhIwCcbtE6BnmgNTtAU51qWmqY@example.online>

-

suser

EmailSender

john_doe@example.com

-

duser

EmailRecipient

john_doe@example.com

-

suid

-

john_doe@example.com

-