Application Lifecycle events report installation, removal, start, stop of an application or service.
Caption Name Type Description Action actionString The normalized caption of action_id.
Action ID action_idInteger The action taken by a control or other policy-based system leading to an outcome or disposition. An unknown action may still correspond to a known disposition. Refer to disposition_id for the outcome of the action.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)2: Denied (DENIED)3: Observed (OBSERVED)4: Modified (MODIFIED)99: Other (OTHER)Activity ID activity_idInteger Group: classification
0: Unknown (UNKNOWN)1: Install (INSTALL)2: Remove (REMOVE)3: Start (START)4: Stop (STOP)5: Restart (RESTART)6: Enable (ENABLE)7: Disable (DISABLE)8: Update (UPDATE)99: Other (OTHER)Activity activity_nameString Group: classification
Actor actorActor[] The actor object describes details about the user/role/process that was the source of the activity. Note that this is not the threat actor of a campaign but may be part of a campaign.
API Details apiAPI[] Group: context
Application appProduct[] Group: primary
MITRE ATT&CK® Details attacksMITRE ATT&CK®[] An array of MITRE ATT&CK®  objects describing identified tactics, techniques & sub-techniques.
Authorization Information authorizationsAuthorization Result[] Provides details about an authorization, such as authorization outcome, and any associated policies related to the activity/event.
Category category_nameString Group: classification
Category ID category_uidInteger Group: classification
6: Application Activity (APPLICATION_ACTIVITY)Class class_nameString Group: classification
Class ID class_uidInteger Group: classification
6002: Application Lifecycle (APPLICATION_LIFECYCLE)Cloud cloudCloud[] Group: primary
Confidence confidenceString Group: context
Confidence ID confidence_idInteger Group: context
0: Unknown (UNKNOWN)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)99: Other (OTHER)Confidence Score confidence_scoreInteger Group: context
Count countInteger Group: occurrenceStart Time  to End Time  period.
Device deviceDevice[] An addressable device, computer system or host.
Disposition dispositionString The disposition name, normalized to the caption of the disposition_id value. In the case of 'Other', it is defined by the event source.
Disposition ID disposition_idInteger Describes the outcome or action taken by a security control, such as access control checks, malware detections or various types of policy violations.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)10: Exonerated (EXONERATED)11: Corrected (CORRECTED)12: Partially Corrected (PARTIALLY_CORRECTED)13: Uncorrected (UNCORRECTED)14: Delayed (DELAYED)15: Detected (DETECTED)16: No Action (NO_ACTION)17: Logged (LOGGED)18: Tagged (TAGGED)19: Alert (ALERT)2: Blocked (BLOCKED)20: Count (COUNT)21: Reset (RESET)22: Captcha (CAPTCHA)23: Challenge (CHALLENGE)24: Access Revoked (ACCESS_REVOKED)25: Rejected (REJECTED)26: Unauthorized (UNAUTHORIZED)27: Error (ERROR)3: Quarantined (QUARANTINED)4: Isolated (ISOLATED)5: Deleted (DELETED)6: Dropped (DROPPED)7: Custom Action (CUSTOM_ACTION)8: Approved (APPROVED)9: Restored (RESTORED)99: Other (OTHER)Duration Milliseconds durationLong Group: occurrencestart_time to end_time in milliseconds.
End Time end_timeTimestamp Group: occurrence
Enrichments enrichmentsEnrichment[] Group: context
JSON 
[{
  "name": "answers.ip",
  "value": "92.24.47.250",
  "type": "location",
  "data": {
    "city": "Socotra",
    "continent": "Asia",
    "coordinates": [-25.4153, 17.0743],
    "country": "YE",
    "desc": "Yemen"
  }
}]Firewall Rule firewall_ruleFirewall Rule[] The firewall rule that pertains to the control that triggered the event, if applicable.
Alert is_alertBoolean Indicates that the event is considered to be an alertable signal. Should be set to true if disposition_id = Alert among other dispositions, and/or risk_level_id or severity_id of the event is elevated. Not all control events will be alertable, for example if disposition_id = Exonerated or disposition_id = Allowed.
Malware malwareMalware[] A list of Malware objects, describing details about the identified malware.
Message messageString Group: primary
Metadata metadataMetadata[] Group: context
Observables observablesObservable[] Group: primary
OSINT osintOSINT[] Group: primary
Policy policyPolicy[] The policy that pertains to the control that triggered the event, if applicable. For example the name of an anti-malware policy or an access control policy.
Raw Data raw_dataJSON Group: context
Record ID record_idString Group: primary
Risk Details risk_detailsString Group: context
Risk Level risk_levelString Group: context
Risk Level ID risk_level_idInteger Group: context
0: Info (INFO)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)4: Critical (CRITICAL)99: Other (OTHER)Risk Score risk_scoreInteger Group: context
Severity severityString Group: classification
Severity ID severity_idInteger Group: classification
The normalized identifier of the event/finding severity.
The normalized severity is a measurement the effort and expense required to manage and resolve an event or incident. Smaller numerical values represent lower impact events, and larger numerical values represent higher impact events.0: Unknown (UNKNOWN)1: Informational (INFORMATIONAL)2: Low (LOW)3: Medium (MEDIUM)4: High (HIGH)5: Critical (CRITICAL)6: Fatal (FATAL)99: Other (OTHER)Start Time start_timeTimestamp Group: occurrence
Status statusString Group: primary
Status Code status_codeString Group: primary
Status Detail status_detailString Group: primary
Status ID status_idInteger Group: primary
0: Unknown (UNKNOWN)1: Success (SUCCESS)2: Failure (FAILURE)99: Other (OTHER)Event Time timeTimestamp Group: occurrence
Timezone Offset timezone_offsetInteger Group: occurrencetime is ahead or behind UTC, in the range -1,080 to +1,080.
Type Name type_nameString Group: classification
Type ID type_uidLong Group: classificationclass_uid * 100 + activity_id.
600200: Application Lifecycle: Unknown (APPLICATION_LIFECYCLE_UNKNOWN)600201: Application Lifecycle: Install (APPLICATION_LIFECYCLE_INSTALL)600202: Application Lifecycle: Remove (APPLICATION_LIFECYCLE_REMOVE)600203: Application Lifecycle: Start (APPLICATION_LIFECYCLE_START)600204: Application Lifecycle: Stop (APPLICATION_LIFECYCLE_STOP)600205: Application Lifecycle: Restart (APPLICATION_LIFECYCLE_RESTART)600206: Application Lifecycle: Enable (APPLICATION_LIFECYCLE_ENABLE)600207: Application Lifecycle: Disable (APPLICATION_LIFECYCLE_DISABLE)600208: Application Lifecycle: Update (APPLICATION_LIFECYCLE_UPDATE)600299: Application Lifecycle: Other (APPLICATION_LIFECYCLE_OTHER)Unmapped unmappedUnmapped[] Group: context
Application Lifecycle references the following objects and events in its attributes: