Container
The Container object describes an instance of a specific container. A container is a prepackaged, portable system image that runs isolated on an existing system using a container runtime like containerd.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Port | exposed_port |
Port |
The port exposed by container to allow access of run application remotely.
|
Fingerprint | fingerprint |
Fingerprint[] |
The SHA256 hash of the container.
|
Hash | hash |
Fingerprint[] |
Commit hash of image created for docker or the SHA256 hash of the container. For example: 13550340a8681c84c861aac2e5b440161c2b33a3e4f302ac680ca5b686de48de .
|
Image | image |
Image[] | The container image used as a template to run the container. |
Name | name |
String | The container name. |
Network Driver | network_driver |
String | The network driver used by the container. For example, bridge, overlay, host, none, etc. |
Orchestrator | orchestrator |
String | The orchestrator managing the container, such as ECS, EKS, K8s, or OpenShift. |
Pod UUID | pod_uuid |
UUID | The unique identifier of the pod (or equivalent) that the container is executing on. |
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
Runtime | runtime |
String | The backend running the container, such as containerd or cri-o. |
Size | size |
Long | The size of the container image. |
Image Tag | tag |
String | The tag used by the container. It can indicate version, format, OS. |
Unique ID | uid |
String |
The full container unique identifier for this instantiation of the container. For example: ac2ea168264a08f9aaca0dfc82ff3551418dfd22d02b713142a6843caa2f61bf .
|
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Relationships
Inbound Relationships
These objects and events reference Container in their attributes:
- Linux Process
- Endpoint
- Request Elements
- Network Proxy Endpoint
- Network Endpoint
- Response Elements
- Device
- Windows Evidence Artifacts
Outbound Relationships
Container references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated about 2 months ago