Cloud
The Cloud object contains information about a cloud or Software-as-a-Service account or similar construct, such as AWS Account ID, regions, organizations, folders, compartments, tenants, etc.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Account | account |
Account[] | The account object describes details about the account that was the source or target of the activity. |
Account Type | account_type |
String |
The user account type, as defined by the event source.
|
Account Type ID | account_type_id |
Integer |
The normalized user account type identifier.
|
Account UID | account_uid |
String |
The unique identifier of the account(e.g. AWS Account ID).
|
Organization | org |
Organization[] | Organization and org unit relevant to the event or object. |
Org ID | org_uid |
String |
The unique identifier of the organization to which the user belongs. For example, Active Directory or AWS Org ID.
|
Project ID | project_uid |
String |
The unique identifier of a Cloud project.
|
Provider | provider |
String | The unique name of the Cloud services provider, such as AWS, MS Azure, GCP, etc. |
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
Region | region |
String | The name of the cloud region, as defined by the cloud provider. |
Resource ID | resource_uid |
Resource UID |
The unique identifier of a cloud resource. For example, S3 Bucket name, EC2 Instance Id.
|
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Network Zone | zone |
String | The availability zone in the cloud region, as defined by the cloud provider. |
Relationships
Inbound Relationships
These objects and events reference Cloud in their attributes:
- Process Remediation Activity
- SMB Activity
- Security Finding
- Module Query
- Device Config State
- Networks Query
- Finding
- Account Change
- Admin Group Query
- Application Lifecycle
- Discovery Result
- File Query
- File Hosting Activity
- Scheduled Job Activity
- Base Event
- Folder Query
- Incident Finding
- Memory Activity
- Data Security Finding
- Email URL Activity
- Software Inventory Info
- Network Remediation Activity
- API Activity
- Network File Activity
- RDP Activity
- Compliance Finding
- Entity Management
- Application Activity
- Job Query
- Email Delivery Activity
- File Remediation Activity
- Email File Activity
- Device Inventory Info
- HTTP Activity
- User Inventory Info
- Datastore Activity
- User Session Query
- User Access Management
- User Query
- FTP Activity
- Operating System Patch State
- Peripheral Device Query
- Authentication
- Network
- Process Query
- Windows Service Activity
- Network Connection Query
- Web Resources Activity
- File System Activity
- Registry Key Query
- Registry Key Activity
- OSINT Inventory Info
- Registry Value Activity
- Authorize Session
- Scan Activity
- Remediation Activity
- Group Management
- SSH Activity
- Service Query
- System Activity
- Event Log Activity
- Tunnel Activity
- DNS Activity
- Kernel Activity
- Network Activity
- Module Activity
- Discovery
- Registry Value Query
- Web Resource Access Activity
- Kernel Object Query
- Process Activity
- Resource Details
- Email Activity
- NTP Activity
- Identity & Access Management
- DHCP Activity
- Device Config State Change
- Detection Finding
- Windows Resource Activity
- Prefetch Query
- Kernel Extension Activity
- Vulnerability Finding
Outbound Relationships
Cloud references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated 2 months ago