DNS Activity events report DNS queries and answers as seen on the network.
Caption Name Type Description Action actionString The normalized caption of action_id.
Action ID action_idInteger The action taken by a control or other policy-based system leading to an outcome or disposition. An unknown action may still correspond to a known disposition. Refer to disposition_id for the outcome of the action.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)2: Denied (DENIED)3: Observed (OBSERVED)4: Modified (MODIFIED)99: Other (OTHER)Activity ID activity_idInteger Group: classification
0: Unknown (UNKNOWN)1: Query (QUERY)2: Response (RESPONSE)6: Traffic (TRAFFIC)99: Other (OTHER)Activity activity_nameString Group: classification
Actor actorActor[] The actor object describes details about the user/role/process that was the source of the activity. Note that this is not the threat actor of a campaign but may be part of a campaign.
DNS Answer answersDNS Answer[] Group: primary
API Details apiAPI[] Group: context
Application Name app_nameString Group: context
MITRE ATT&CK® Details attacksMITRE ATT&CK®[] An array of MITRE ATT&CK®  objects describing identified tactics, techniques & sub-techniques.
Authorization Information authorizationsAuthorization Result[] Provides details about an authorization, such as authorization outcome, and any associated policies related to the activity/event.
Category category_nameString Group: classification
Category ID category_uidInteger Group: classification
4: Network Activity (NETWORK_ACTIVITY)Class class_nameString Group: classification
Class ID class_uidInteger Group: classification
4003: DNS Activity (DNS_ACTIVITY)Cloud cloudCloud[] Group: primary
Confidence confidenceString Group: context
Confidence ID confidence_idInteger Group: context
0: Unknown (UNKNOWN)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)99: Other (OTHER)Confidence Score confidence_scoreInteger Group: context
Connection Info connection_infoNetwork Connection Information[] Group: context
Count countInteger Group: occurrenceStart Time  to End Time  period.
Device deviceDevice[] An addressable device, computer system or host.
Disposition dispositionString The disposition name, normalized to the caption of the disposition_id value. In the case of 'Other', it is defined by the event source.
Disposition ID disposition_idInteger Describes the outcome or action taken by a security control, such as access control checks, malware detections or various types of policy violations.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)10: Exonerated (EXONERATED)11: Corrected (CORRECTED)12: Partially Corrected (PARTIALLY_CORRECTED)13: Uncorrected (UNCORRECTED)14: Delayed (DELAYED)15: Detected (DETECTED)16: No Action (NO_ACTION)17: Logged (LOGGED)18: Tagged (TAGGED)19: Alert (ALERT)2: Blocked (BLOCKED)20: Count (COUNT)21: Reset (RESET)22: Captcha (CAPTCHA)23: Challenge (CHALLENGE)24: Access Revoked (ACCESS_REVOKED)25: Rejected (REJECTED)26: Unauthorized (UNAUTHORIZED)27: Error (ERROR)3: Quarantined (QUARANTINED)4: Isolated (ISOLATED)5: Deleted (DELETED)6: Dropped (DROPPED)7: Custom Action (CUSTOM_ACTION)8: Approved (APPROVED)9: Restored (RESTORED)99: Other (OTHER)Destination Endpoint dst_endpointNetwork Endpoint[] Group: primary
Duration Milliseconds durationLong Group: occurrencestart_time to end_time in milliseconds.
End Time end_timeTimestamp Group: occurrence
Enrichments enrichmentsEnrichment[] Group: context
JSON 
[
  {
    "name": "answers.ip",
    "value": "92.24.47.250",
    "type": "location",
    "data": {
      "city": "Socotra",
      "continent": "Asia",
      "coordinates": [-25.4153, 17.0743],
      "country": "YE",
      "desc": "Yemen"
    }
  }
]Firewall Rule firewall_ruleFirewall Rule[] The firewall rule that pertains to the control that triggered the event, if applicable.
Alert is_alertBoolean Indicates that the event is considered to be an alertable signal. Should be set to true if disposition_id = Alert among other dispositions, and/or risk_level_id or severity_id of the event is elevated. Not all control events will be alertable, for example if disposition_id = Exonerated or disposition_id = Allowed.
JA4+ Fingerprints ja4_fingerprint_listJA4+ Fingerprint[] Group: context
Load Balancer load_balancerLoad Balancer[] The Load Balancer object contains information related to the device that is distributing incoming traffic to specified destinations.
Malware malwareMalware[] A list of Malware objects, describing details about the identified malware.
Message messageString Group: primary
Metadata metadataMetadata[] Group: context
Observables observablesObservable[] Group: primary
OSINT osintOSINT[] Group: primary
Policy policyPolicy[] The policy that pertains to the control that triggered the event, if applicable. For example the name of an anti-malware policy or an access control policy.
Proxy proxyNetwork Proxy Endpoint[] Group: primary
🚧 WARNING: DEPRECATED Proxy has been deprecated since 1.1.0. Use the proxy_endpoint attribute instead.
Proxy Connection Info proxy_connection_infoNetwork Connection Information[] The connection information from the proxy server to the remote server.
Proxy Endpoint proxy_endpointNetwork Proxy Endpoint[] The proxy (server) in a network connection.
Proxy HTTP Request proxy_http_requestHTTP Request[] The HTTP Request from the proxy server to the remote server.
Proxy HTTP Response proxy_http_responseHTTP Response[] The HTTP Response from the remote server to the proxy server.
Proxy TLS proxy_tlsTransport Layer Security (TLS)[] The TLS protocol negotiated between the proxy server and the remote server.
Proxy Traffic proxy_trafficNetwork Traffic[] The network traffic refers to the amount of data moving across a network, from proxy to remote server at a given point of time.
DNS Query queryDNS Query[] Group: primary
Query Time query_timeTimestamp Group: occurrence
Raw Data raw_dataJSON Group: context
Response Code rcodeString Group: primary
Response Code ID rcode_idInteger Group: primaryRFC-6895 .
0: NoError (NOERROR)1: FormError (FORMERROR)10: NotZone (NOTZONE)11: DSOTYPENI (DSOTYPENI)16: BADSIG_VERS (BADSIG_VERS)17: BADKEY (BADKEY)18: BADTIME (BADTIME)19: BADMODE (BADMODE)2: ServError (SERVERROR)20: BADNAME (BADNAME)21: BADALG (BADALG)22: BADTRUNC (BADTRUNC)23: BADCOOKIE (BADCOOKIE)24: Unassigned (UNASSIGNED)25: Reserved (RESERVED)3: NXDomain (NXDOMAIN)4: NotImp (NOTIMP)5: Refused (REFUSED)6: YXDomain (YXDOMAIN)7: YXRRSet (YXRRSET)8: NXRRSet (NXRRSET)9: NotAuth (NOTAUTH)99: Other (OTHER)Record ID record_idString Group: primary
Response Time response_timeTimestamp Group: occurrence
Risk Details risk_detailsString Group: context
Risk Level risk_levelString Group: context
Risk Level ID risk_level_idInteger Group: context
0: Info (INFO)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)4: Critical (CRITICAL)99: Other (OTHER)Risk Score risk_scoreInteger Group: context
Severity severityString Group: classification
Severity ID severity_idInteger Group: classification
The normalized identifier of the event/finding severity.
The normalized severity is a measurement the effort and expense required to manage and resolve an event or incident. Smaller numerical values represent lower impact events, and larger numerical values represent higher impact events.0: Unknown (UNKNOWN)1: Informational (INFORMATIONAL)2: Low (LOW)3: Medium (MEDIUM)4: High (HIGH)5: Critical (CRITICAL)6: Fatal (FATAL)99: Other (OTHER)Source Endpoint src_endpointNetwork Endpoint[] Group: primary
Start Time start_timeTimestamp Group: occurrence
Status statusString Group: primary
Status Code status_codeString Group: primary
Status Detail status_detailString Group: primary
Status ID status_idInteger Group: primary
0: Unknown (UNKNOWN)1: Success (SUCCESS)2: Failure (FAILURE)99: Other (OTHER)Event Time timeTimestamp Group: occurrence
Timezone Offset timezone_offsetInteger Group: occurrencetime is ahead or behind UTC, in the range -1,080 to +1,080.
TLS tlsTransport Layer Security (TLS)[] Group: context
Traffic trafficNetwork Traffic[] Group: context
Type Name type_nameString Group: classification
Type ID type_uidLong Group: classificationclass_uid * 100 + activity_id.
400300: DNS Activity: Unknown (DNS_ACTIVITY_UNKNOWN)400301: DNS Activity: Query (DNS_ACTIVITY_QUERY)400302: DNS Activity: Response (DNS_ACTIVITY_RESPONSE)400306: DNS Activity: Traffic (DNS_ACTIVITY_TRAFFIC)400399: DNS Activity: Other (DNS_ACTIVITY_OTHER)Unmapped unmappedUnmapped[] Group: context