Prefetch Query events report information about Windows prefetch files.
Caption Name Type Description Action actionString The normalized caption of action_id.
Action ID action_idInteger The action taken by a control or other policy-based system leading to an outcome or disposition. An unknown action may still correspond to a known disposition. Refer to disposition_id for the outcome of the action.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)2: Denied (DENIED)3: Observed (OBSERVED)4: Modified (MODIFIED)99: Other (OTHER)Activity ID activity_idInteger Group: classification
0: Unknown (UNKNOWN)1: Query (QUERY)99: Other (OTHER)Activity activity_nameString Group: classification
Actor actorActor[] The actor object describes details about the user/role/process that was the source of the activity. Note that this is not the threat actor of a campaign but may be part of a campaign.
API Details apiAPI[] Group: context
MITRE ATT&CK® Details attacksMITRE ATT&CK®[] An array of MITRE ATT&CK®  objects describing identified tactics, techniques & sub-techniques.
Authorization Information authorizationsAuthorization Result[] Provides details about an authorization, such as authorization outcome, and any associated policies related to the activity/event.
Category category_nameString Group: classification
Category ID category_uidInteger Group: classification
Class class_nameString Group: classification
Class ID class_uidInteger Group: classification
205019: Prefetch Query (PREFETCH_QUERY)Cloud cloudCloud[] Group: primary
Confidence confidenceString Group: context
Confidence ID confidence_idInteger Group: context
0: Unknown (UNKNOWN)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)99: Other (OTHER)Confidence Score confidence_scoreInteger Group: context
Count countInteger Group: occurrenceStart Time  to End Time  period.
Device deviceDevice[] An addressable device, computer system or host.
Disposition dispositionString The disposition name, normalized to the caption of the disposition_id value. In the case of 'Other', it is defined by the event source.
Disposition ID disposition_idInteger Describes the outcome or action taken by a security control, such as access control checks, malware detections or various types of policy violations.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)10: Exonerated (EXONERATED)11: Corrected (CORRECTED)12: Partially Corrected (PARTIALLY_CORRECTED)13: Uncorrected (UNCORRECTED)14: Delayed (DELAYED)15: Detected (DETECTED)16: No Action (NO_ACTION)17: Logged (LOGGED)18: Tagged (TAGGED)19: Alert (ALERT)2: Blocked (BLOCKED)20: Count (COUNT)21: Reset (RESET)22: Captcha (CAPTCHA)23: Challenge (CHALLENGE)24: Access Revoked (ACCESS_REVOKED)25: Rejected (REJECTED)26: Unauthorized (UNAUTHORIZED)27: Error (ERROR)3: Quarantined (QUARANTINED)4: Isolated (ISOLATED)5: Deleted (DELETED)6: Dropped (DROPPED)7: Custom Action (CUSTOM_ACTION)8: Approved (APPROVED)9: Restored (RESTORED)99: Other (OTHER)Duration Milliseconds durationLong Group: occurrencestart_time to end_time in milliseconds.
End Time end_timeTimestamp Group: occurrence
Enrichments enrichmentsEnrichment[] Group: context
JSON 
[
  {
    "name": "answers.ip",
    "value": "92.24.47.250",
    "type": "location",
    "data": {
      "city": "Socotra",
      "continent": "Asia",
      "coordinates": [-25.4153, 17.0743],
      "country": "YE",
      "desc": "Yemen"
    }
  }
]Firewall Rule firewall_ruleFirewall Rule[] The firewall rule that pertains to the control that triggered the event, if applicable.
Alert is_alertBoolean Indicates that the event is considered to be an alertable signal. Should be set to true if disposition_id = Alert among other dispositions, and/or risk_level_id or severity_id of the event is elevated. Not all control events will be alertable, for example if disposition_id = Exonerated or disposition_id = Allowed.
Last Run last_run_timeTimestamp Group: occurrence
Malware malwareMalware[] A list of Malware objects, describing details about the identified malware.
Message messageString Group: primary
Metadata metadataMetadata[] Group: context
Name nameString Group: primary
Observables observablesObservable[] Group: primary
OSINT osintOSINT[] Group: primary
Policy policyPolicy[] The policy that pertains to the control that triggered the event, if applicable. For example the name of an anti-malware policy or an access control policy.
Query Info query_infoQuery Information[] Group: primary
Query Result query_resultString Group: primary
Query Result ID query_result_idInteger Group: primary
0: Unknown (UNKNOWN)1: Exists (EXISTS)2: Partial (PARTIAL)3: Does not exist (DOES_NOT_EXIST)4: Error (ERROR)5: Unsupported (UNSUPPORTED)99: Other (OTHER)Raw Data raw_dataJSON Group: context
Record ID record_idString Group: primary
Risk Details risk_detailsString Group: context
Risk Level risk_levelString Group: context
Risk Level ID risk_level_idInteger Group: context
0: Info (INFO)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)4: Critical (CRITICAL)99: Other (OTHER)Risk Score risk_scoreInteger Group: context
Run Count run_countInteger Group: primary
Severity severityString Group: classification
Severity ID severity_idInteger Group: classification
The normalized identifier of the event/finding severity.
The normalized severity is a measurement the effort and expense required to manage and resolve an event or incident. Smaller numerical values represent lower impact events, and larger numerical values represent higher impact events.0: Unknown (UNKNOWN)1: Informational (INFORMATIONAL)2: Low (LOW)3: Medium (MEDIUM)4: High (HIGH)5: Critical (CRITICAL)6: Fatal (FATAL)99: Other (OTHER)Start Time start_timeTimestamp Group: occurrence
Status statusString Group: primary
Status Code status_codeString Group: primary
Status Detail status_detailString Group: primary
Status ID status_idInteger Group: primary
0: Unknown (UNKNOWN)1: Success (SUCCESS)2: Failure (FAILURE)99: Other (OTHER)Event Time timeTimestamp Group: occurrence
Timezone Offset timezone_offsetInteger Group: occurrencetime is ahead or behind UTC, in the range -1,080 to +1,080.
Type Name type_nameString Group: classification
Type ID type_uidLong Group: classificationclass_uid * 100 + activity_id.
20501900: Prefetch Query: Unknown (PREFETCH_QUERY_UNKNOWN)20501901: Prefetch Query: Query (PREFETCH_QUERY_QUERY)20501999: Prefetch Query: Other (PREFETCH_QUERY_OTHER)Unmapped unmappedUnmapped[] Group: context