Server Message Block (SMB) Protocol Activity events report client/server connections sharing resources within the network.
Caption Name Type Description Action actionString The normalized caption of action_id.
Action ID action_idInteger The action taken by a control or other policy-based system leading to an outcome or disposition. An unknown action may still correspond to a known disposition. Refer to disposition_id for the outcome of the action.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)2: Denied (DENIED)3: Observed (OBSERVED)4: Modified (MODIFIED)99: Other (OTHER)Activity ID activity_idInteger Group: classification
0: Unknown (UNKNOWN)1: File Supersede (FILE_SUPERSEDE)2: File Open (FILE_OPEN)3: File Create (FILE_CREATE)4: File Open If (FILE_OPEN_IF)5: File Overwrite (FILE_OVERWRITE)6: File Overwrite If (FILE_OVERWRITE_IF)99: Other (OTHER)Activity activity_nameString Group: classification
Actor actorActor[] The actor object describes details about the user/role/process that was the source of the activity. Note that this is not the threat actor of a campaign but may be part of a campaign.
API Details apiAPI[] Group: context
Application Name app_nameString Group: context
MITRE ATT&CK® Details attacksMITRE ATT&CK®[] An array of MITRE ATT&CK®  objects describing identified tactics, techniques & sub-techniques.
Authorization Information authorizationsAuthorization Result[] Provides details about an authorization, such as authorization outcome, and any associated policies related to the activity/event.
Category category_nameString Group: classification
Category ID category_uidInteger Group: classification
4: Network Activity (NETWORK_ACTIVITY)Class class_nameString Group: classification
Class ID class_uidInteger Group: classification
4006: SMB Activity (SMB_ACTIVITY)Client Dialects client_dialectsString[] Group: context
Cloud cloudCloud[] Group: primary
Command commandString Group: primary
Confidence confidenceString Group: context
Confidence ID confidence_idInteger Group: context
0: Unknown (UNKNOWN)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)99: Other (OTHER)Confidence Score confidence_scoreInteger Group: context
Connection Info connection_infoNetwork Connection Information[] Group: primary
Count countInteger Group: occurrenceStart Time  to End Time  period.
Distributed Computing Environment/Remote Procedure Call (DCE/RPC) dce_rpcDCE/RPC[] Group: context
Device deviceDevice[] An addressable device, computer system or host.
Dialect dialectString Group: context
Disposition dispositionString The disposition name, normalized to the caption of the disposition_id value. In the case of 'Other', it is defined by the event source.
Disposition ID disposition_idInteger Describes the outcome or action taken by a security control, such as access control checks, malware detections or various types of policy violations.
0: Unknown (UNKNOWN)1: Allowed (ALLOWED)10: Exonerated (EXONERATED)11: Corrected (CORRECTED)12: Partially Corrected (PARTIALLY_CORRECTED)13: Uncorrected (UNCORRECTED)14: Delayed (DELAYED)15: Detected (DETECTED)16: No Action (NO_ACTION)17: Logged (LOGGED)18: Tagged (TAGGED)19: Alert (ALERT)2: Blocked (BLOCKED)20: Count (COUNT)21: Reset (RESET)22: Captcha (CAPTCHA)23: Challenge (CHALLENGE)24: Access Revoked (ACCESS_REVOKED)25: Rejected (REJECTED)26: Unauthorized (UNAUTHORIZED)27: Error (ERROR)3: Quarantined (QUARANTINED)4: Isolated (ISOLATED)5: Deleted (DELETED)6: Dropped (DROPPED)7: Custom Action (CUSTOM_ACTION)8: Approved (APPROVED)9: Restored (RESTORED)99: Other (OTHER)Destination Endpoint dst_endpointNetwork Endpoint[] Group: primary
Duration Milliseconds durationLong Group: occurrencestart_time to end_time in milliseconds.
End Time end_timeTimestamp Group: occurrence
Enrichments enrichmentsEnrichment[] Group: context
JSON 
[
  {
    "name": "answers.ip",
    "value": "92.24.47.250",
    "type": "location",
    "data": {
      "city": "Socotra",
      "continent": "Asia",
      "coordinates": [-25.4153, 17.0743],
      "country": "YE",
      "desc": "Yemen"
    }
  }
]File fileFile[] Entity: FILEGroup: primary
Firewall Rule firewall_ruleFirewall Rule[] The firewall rule that pertains to the control that triggered the event, if applicable.
Alert is_alertBoolean Indicates that the event is considered to be an alertable signal. Should be set to true if disposition_id = Alert among other dispositions, and/or risk_level_id or severity_id of the event is elevated. Not all control events will be alertable, for example if disposition_id = Exonerated or disposition_id = Allowed.
JA4+ Fingerprints ja4_fingerprint_listJA4+ Fingerprint[] Group: context
Load Balancer load_balancerLoad Balancer[] The Load Balancer object contains information related to the device that is distributing incoming traffic to specified destinations.
Malware malwareMalware[] A list of Malware objects, describing details about the identified malware.
Message messageString Group: primary
Metadata metadataMetadata[] Group: context
Observables observablesObservable[] Group: primary
Open Type open_typeString Group: primary
OSINT osintOSINT[] Group: primary
Policy policyPolicy[] The policy that pertains to the control that triggered the event, if applicable. For example the name of an anti-malware policy or an access control policy.
Proxy proxyNetwork Proxy Endpoint[] Group: primary
🚧 WARNING: DEPRECATED Proxy has been deprecated since 1.1.0. Use the proxy_endpoint attribute instead.
Proxy Connection Info proxy_connection_infoNetwork Connection Information[] The connection information from the proxy server to the remote server.
Proxy Endpoint proxy_endpointNetwork Proxy Endpoint[] The proxy (server) in a network connection.
Proxy HTTP Request proxy_http_requestHTTP Request[] The HTTP Request from the proxy server to the remote server.
Proxy HTTP Response proxy_http_responseHTTP Response[] The HTTP Response from the remote server to the proxy server.
Proxy TLS proxy_tlsTransport Layer Security (TLS)[] The TLS protocol negotiated between the proxy server and the remote server.
Proxy Traffic proxy_trafficNetwork Traffic[] The network traffic refers to the amount of data moving across a network, from proxy to remote server at a given point of time.
Raw Data raw_dataJSON Group: context
Record ID record_idString Group: primary
API Response Details responseResponse Elements[] Group: primary
Risk Details risk_detailsString Group: context
Risk Level risk_levelString Group: context
Risk Level ID risk_level_idInteger Group: context
0: Info (INFO)1: Low (LOW)2: Medium (MEDIUM)3: High (HIGH)4: Critical (CRITICAL)99: Other (OTHER)Risk Score risk_scoreInteger Group: context
Severity severityString Group: classification
Severity ID severity_idInteger Group: classification
The normalized identifier of the event/finding severity.
The normalized severity is a measurement the effort and expense required to manage and resolve an event or incident. Smaller numerical values represent lower impact events, and larger numerical values represent higher impact events.0: Unknown (UNKNOWN)1: Informational (INFORMATIONAL)2: Low (LOW)3: Medium (MEDIUM)4: High (HIGH)5: Critical (CRITICAL)6: Fatal (FATAL)99: Other (OTHER)Share shareString Group: primary
Share Type share_typeString Group: primary
Share Type ID share_type_idInteger Group: primary
0: Unknown (UNKNOWN)1: File (FILE)2: Pipe (PIPE)3: Print (PRINT)99: Other (OTHER)Source Endpoint src_endpointNetwork Endpoint[] Group: primary
Start Time start_timeTimestamp Group: occurrence
Status statusString Group: primary
Status Code status_codeString Group: primary
Status Detail status_detailString Group: primary
Status ID status_idInteger Group: primary
0: Unknown (UNKNOWN)1: Success (SUCCESS)2: Failure (FAILURE)99: Other (OTHER)Event Time timeTimestamp Group: occurrence
Timezone Offset timezone_offsetInteger Group: occurrencetime is ahead or behind UTC, in the range -1,080 to +1,080.
TLS tlsTransport Layer Security (TLS)[] Group: context
Traffic trafficNetwork Traffic[] Group: primary
Tree UID tree_uidString Group: primary
Type Name type_nameString Group: classification
Type ID type_uidLong Group: classificationclass_uid * 100 + activity_id.
400600: SMB Activity: Unknown (SMB_ACTIVITY_UNKNOWN)400601: SMB Activity: File Supersede (SMB_ACTIVITY_FILE_SUPERSEDE)400602: SMB Activity: File Open (SMB_ACTIVITY_FILE_OPEN)400603: SMB Activity: File Create (SMB_ACTIVITY_FILE_CREATE)400604: SMB Activity: File Open If (SMB_ACTIVITY_FILE_OPEN_IF)400605: SMB Activity: File Overwrite (SMB_ACTIVITY_FILE_OVERWRITE)400606: SMB Activity: File Overwrite If (SMB_ACTIVITY_FILE_OVERWRITE_IF)400699: SMB Activity: Other (SMB_ACTIVITY_OTHER)Unmapped unmappedUnmapped[] Group: context