Device
device
The Device object represents an addressable computer system or host, which is typically connected to a computer network and participates in the transmission or processing of data within the computer network.
Attributes
| Caption | Name | Type | Description |
|---|---|---|---|
| Agent List | agent_list | Agent[] | A list of agent objects associated with a device, endpoint, or resource. |
| Autoscale UID | autoscale_uid | String | The unique identifier of the cloud autoscale configuration. |
| Boot Time | boot_time | Timestamp | The time the system was booted. |
| Boot UID | boot_uid | String | A unique identifier of the device that changes after every reboot. For example, the value of /proc/sys/kernel/random/boot_id from Linux's procfs. |
| Container | container | Container[] | Entity: |
| Created Time | created_time | Timestamp | The time when the device was known to have been created. |
| Description | desc | String | The description of the device, ordinarily as reported by the operating system. |
| Domain | domain | String | The network domain where the device resides. For example: work.example.com. |
| EID | eid | String | An Embedded Identity Document, is a unique serial number that identifies an eSIM-enabled device. |
| First Seen | first_seen_time | Timestamp | The initial discovery time of the device. |
| Groups | groups | Group[] | The group names to which the device belongs. For example: ["Windows Laptops", "Engineering"]. |
| Hostname | hostname | Hostname | Entity: |
| Hardware Info | hw_info | Device Hardware Info[] | The endpoint hardware information. |
| Hypervisor | hypervisor | String | The name of the hypervisor running on the device. For example, Xen, VMware, Hyper-V, VirtualBox, etc. |
| ICCID | iccid | String | The Integrated Circuit Card Identification of a mobile device. Typically it is a unique 18 to 22 digit number that identifies a SIM card. |
| Image | image | Image[] | The image used as a template to run the virtual machine. |
| IMEI | imei | String | The International Mobile Equipment Identity that is associated with the device.
|
| IMEI List | imei_list | String[] | The International Mobile Equipment Identity values that are associated with the device. |
| Instance ID | instance_uid | String | The unique identifier of a VM instance. |
| Network Interface Name | interface_name | String | The name of the network interface (e.g. eth2). |
| Network Interface ID | interface_uid | String | The unique identifier of the network interface. |
| IP Address | ip | IP Address | Entity: |
| Back Ups Configured | is_backed_up | Boolean | Indicates whether the device or resource has a backup enabled, such as an automated snapshot or a cloud backup. For example, this is indicated by the cloudBackupEnabled value within JAMF Pro mobile devices or the registration of an AWS ARN with the AWS Backup service. |
| Compliant Device | is_compliant | Boolean | The event occurred on a compliant device. |
| Managed Device | is_managed | Boolean | The event occurred on a managed device. |
| Mobile Account Active | is_mobile_account_active | Boolean | Indicates whether the device has an active mobile account. For example, this is indicated by the itunesStoreAccountActive value within JAMF Pro mobile devices. |
| Personal Device | is_personal | Boolean | The event occurred on a personal device. |
| Shared Device | is_shared | Boolean | The event occurred on a shared device. |
| Supervised Device | is_supervised | Boolean | The event occurred on a supervised device. Devices that are supervised are typically mobile devices managed by a Mobile Device Management solution and are restricted from specific behaviors such as Apple AirDrop. |
| Trusted Device | is_trusted | Boolean | The event occurred on a trusted device. |
| Last Seen | last_seen_time | Timestamp | The most recent discovery time of the device. |
| Geo Location | location | Geo Location[] | Entity: |
| MAC Address | mac | MAC Address | Entity: |
| MEID | meid | String | The Mobile Equipment Identifier. It's a unique number that identifies a Code Division Multiple Access (CDMA) mobile device. |
| Model | model | String | The model of the device. For example ThinkPad X1 Carbon. |
| Modified Time | modified_time | Timestamp | The time when the device was last known to have been modified. |
| Name | name | String | The alternate device name, ordinarily as assigned by an administrator. Note: The Name could be any other string that helps to identify the device, such as a phone number; for example 310-555-1234. |
| Namespace PID | namespace_pid | Integer | Group: |
| Network Interfaces | network_interfaces | Network Interface[] | The physical or virtual network interfaces that are associated with the device, one for each unique MAC address/IP address/hostname/name combination.Note: The first element of the array is the network information that pertains to the event. |
| Organization | org | Organization[] | Organization and org unit related to the device. |
| OS | os | Operating System (OS)[] | The endpoint operating system. |
| OS Machine UUID | os_machine_uuid | UUID | The operating system assigned Machine ID. In Windows, this is the value stored at the registry path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid. In Linux, this is stored in the file: /etc/machine-id. |
| Owner | owner | User[] | Entity: |
| Raw Data | raw_data | JSON | Group: |
| Record ID | record_id | String | Group: |
| Region | region | String | The region where the virtual machine is located. For example, an AWS Region. |
| Risk Level | risk_level | String | The risk level, normalized to the caption of the risk_level_id value. |
| Risk Level ID | risk_level_id | Integer | The normalized risk level id.
|
| Risk Score | risk_score | Integer | The risk score as reported by the event source. |
| Subnet | subnet | Subnet | Entity: |
| Subnet UID | subnet_uid | String | The unique identifier of a virtual subnet. |
| Type | type | String | The device type. For example: unknown, server, desktop, laptop, tablet, mobile, virtual, browser, or other. |
| Type ID | type_id | Integer | The device type ID.
|
| Unique Device Identifier | udid | String | The Apple assigned Unique Device Identifier (UDID). For iOS, iPadOS, tvOS, watchOS and visionOS devices, this is the UDID. For macOS devices, it is the Provisioning UDID. For example: 00008020-008D4548007B4F26 |
| Unique ID | uid | String | Entity: |
| Alternate ID | uid_alt | String | An alternate unique identifier of the device if any. For example the ActiveDirectory DN. |
| Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. |
| Vendor Name | vendor_name | String | The vendor for the device. For example Dell or Lenovo. |
| VLAN | vlan_uid | String | The Virtual LAN identifier. |
| VPC UID | vpc_uid | String | The unique identifier of the Virtual Private Cloud (VPC). |
| Network Zone | zone | String | The network zone or LAN segment. |
Relationships
Inbound Relationships
These objects and events reference Device in their attributes:
- FTP Activity
- Web Resource Access Activity
- Scan Activity
- Email File Activity
- File System Activity
- Device Config State Change
- User Inventory Info
- Module Query
- Kernel Activity
- User
- IAM Analysis Finding
- Base Event
- SSH Activity
- Group Management
- Registry Value Query
- Data Security Finding
- Email Activity
- File Remediation Activity
- Authentication Factor
- Module Activity
- Managed Entity
- Windows Service Activity
- Device Inventory Info
- File Hosting Activity
- Authorize Session
- Registry Value Activity
- Application Lifecycle
- DNS Activity
- Account Change
- Airborne Broadcast Activity
- Operating System Patch State
- Incident Finding
- Drone Flights Activity
- DHCP Activity
- Logger
- Remediation Activity
- Kernel Extension Activity
- User Session Query
- Cloud Resources Inventory Info
- Web Resources Activity
- Script Activity
- File Query
- Detection Finding
- Windows Evidence Artifacts
- Process Query
- OSINT Inventory Info
- Compliance Finding
- Network Activity
- Entity Management
- Vulnerability Finding
- Admin Group Query
- RDP Activity
- Peripheral Device Query
- Network Connection Query
- Windows Resource Activity
- Application Security Posture Finding
- Live Evidence Info
- Registry Key Activity
- Authentication
- Application Error
- Folder Query
- Datastore Activity
- Tunnel Activity
- Process Remediation Activity
- NTP Activity
- Event Log Activity
- Scheduled Job Activity
- Prefetch Query
- Process Activity
- Memory Activity
- Startup Item Query
- Network File Activity
- Security Finding
- Registry Key Query
- Kernel Object Query
- User Access Management
- Service Query
- Job Query
- API Activity
- HTTP Activity
- Device Config State
- Email URL Activity
- Network Remediation Activity
- Networks Query
- Software Inventory Info
- User Query
- SMB Activity
Outbound Relationships
Device references the following objects and events in its attributes:
- Group
- Agent
- Device Hardware Info
- Image
- Organization
- Operating System (OS)
- Network Interface
- User
- Unmapped
- Geo Location
- Container
This page describes qdm-1.5.1+ocsf-1.6.0
Updated 13 days ago