Device
device
The Device object represents an addressable computer system or host, which is typically connected to a computer network and participates in the transmission or processing of data within the computer network.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Agent List | agent_list | Agent[] | A list of |
Autoscale UID | autoscale_uid | String | The unique identifier of the cloud autoscale configuration. |
Boot Time | boot_time | Timestamp | The time the system was booted. |
Container | container | Container[] | Entity: |
Created Time | created_time | Timestamp | The time when the device was known to have been created. |
Description | desc | String | The description of the device, ordinarily as reported by the operating system. |
Domain | domain | String | The network domain where the device resides. For example: |
EID | eid | String | An Embedded Identity Document, is a unique serial number that identifies an eSIM-enabled device. |
First Seen | first_seen_time | Timestamp | The initial discovery time of the device. |
Groups | groups | Group[] | The group names to which the device belongs. For example: |
Hostname | hostname | Hostname | Entity: |
Hardware Info | hw_info | Device Hardware Info[] | The endpoint hardware information. |
Hypervisor | hypervisor | String | The name of the hypervisor running on the device. For example, |
ICCID | iccid | String | The Integrated Circuit Card Identification of a mobile device. Typically it is a unique 18 to 22 digit number that identifies a SIM card. |
Image | image | Image[] | The image used as a template to run the virtual machine. |
IMEI | imei | String | The International Mobile Equipment Identity that is associated with the device.
|
IMEI List | imei_list | String[] | The International Mobile Equipment Identity values that are associated with the device. |
Instance ID | instance_uid | String | The unique identifier of a VM instance. |
Network Interface Name | interface_name | String | The name of the network interface (e.g. eth2). |
Network Interface ID | interface_uid | String | The unique identifier of the network interface. |
IP Address | ip | IP Address | Entity: |
Back Ups Configured | is_backed_up | Boolean | Indicates whether the device or resource has a backup enabled, such as an automated snapshot or a cloud backup. For example, this is indicated by the |
Compliant Device | is_compliant | Boolean | The event occurred on a compliant device. |
Managed Device | is_managed | Boolean | The event occurred on a managed device. |
Mobile Account Active | is_mobile_account_active | Boolean | Indicates whether the device has an active mobile account. For example, this is indicated by the |
Personal Device | is_personal | Boolean | The event occurred on a personal device. |
Shared Device | is_shared | Boolean | The event occurred on a shared device. |
Supervised Device | is_supervised | Boolean | The event occurred on a supervised device. Devices that are supervised are typically mobile devices managed by a Mobile Device Management solution and are restricted from specific behaviors such as Apple AirDrop. |
Trusted Device | is_trusted | Boolean | The event occurred on a trusted device. |
Last Seen | last_seen_time | Timestamp | The most recent discovery time of the device. |
Geo Location | location | Geo Location[] | Entity: |
MAC Address | mac | MAC Address | Entity: |
MEID | meid | String | The Mobile Equipment Identifier. It's a unique number that identifies a Code Division Multiple Access (CDMA) mobile device. |
Model | model | String | The model of the device. For example |
Modified Time | modified_time | Timestamp | The time when the device was last known to have been modified. |
Name | name | String | The alternate device name, ordinarily as assigned by an administrator. Note: The Name could be any other string that helps to identify the device, such as a phone number; for example |
Namespace PID | namespace_pid | Integer | Group: |
Network Interfaces | network_interfaces | Network Interface[] | The network interfaces that are associated with the device, one for each unique MAC address/IP address/hostname/name combination. Note: The first element of the array is the network information that pertains to the event. |
Organization | org | Organization[] | Organization and org unit related to the device. |
OS | os | Operating System (OS)[] | The endpoint operating system. |
OS Machine UUID | os_machine_uuid | UUID | The operating system assigned Machine ID. In Windows, this is the value stored at the registry path: |
Owner | owner | User[] | Entity: |
Raw Data | raw_data | JSON | Group: |
Record ID | record_id | String | Group: |
Region | region | String | The region where the virtual machine is located. For example, an AWS Region. |
Risk Level | risk_level | String | The risk level, normalized to the caption of the risk_level_id value. |
Risk Level ID | risk_level_id | Integer | The normalized risk level id.
|
Risk Score | risk_score | Integer | The risk score as reported by the event source. |
Subnet | subnet | Subnet | Entity: |
Subnet UID | subnet_uid | String | The unique identifier of a virtual subnet. |
Type | type | String | The device type. For example: |
Type ID | type_id | Integer | The device type ID.
|
Unique Device Identifier | udid | String | The Unique Device Identifier, used for iOS and macOS devices. |
Unique ID | uid | String | The unique identifier of the device. For example the Windows TargetSID or AWS EC2 ARN. |
Alternate ID | uid_alt | String | An alternate unique identifier of the device if any. For example the ActiveDirectory DN. |
Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. |
Vendor Name | vendor_name | String | The vendor for the device. For example |
VLAN | vlan_uid | String | The Virtual LAN identifier. |
VPC UID | vpc_uid | String | The unique identifier of the Virtual Private Cloud (VPC). |
Network Zone | zone | String | The network zone or LAN segment. |
Relationships
Inbound Relationships
These objects and events reference Device in their attributes:
- Kernel Object Query
- Web Resource Access Activity
- Email URL Activity
- Discovery
- Web Resources Activity
- Network Connection Query
- Kernel Activity
- Memory Activity
- Script Activity
- Authentication
- Group Management
- Software Inventory Info
- Unmanned Systems
- NTP Activity
- Logger
- Job Query
- Registry Key Activity
- Authorize Session
- Detection Finding
- User Session Query
- Module Query
- Scheduled Job Activity
- Device Inventory Info
- Process Remediation Activity
- Remediation Activity
- Network Remediation Activity
- User Access Management
- API Activity
- DHCP Activity
- Device Config State Change
- Drone Flights Activity
- Admin Group Query
- Security Finding
- Prefetch Query
- Email File Activity
- Networks Query
- Network Activity
- Network File Activity
- File System Activity
- Event Log Activity
- Compliance Finding
- File Query
- User Inventory Info
- File Remediation Activity
- Application Activity
- HTTP Activity
- Module Activity
- Application Lifecycle
- Datastore Activity
- FTP Activity
- Base Event
- Vulnerability Finding
- Cloud Resources Inventory Info
- Registry Value Query
- Tunnel Activity
- Authentication Factor
- User
- Network
- Windows Resource Activity
- Peripheral Device Query
- Airborne Broadcast Activity
- Process Activity
- Device Config State
- Kernel Extension Activity
- User Query
- System Activity
- Email Activity
- Operating System Patch State
- RDP Activity
- Evidence Artifacts
- Application Error
- Startup Item Query
- Registry Key Query
- Service Query
- Entity Management
- DNS Activity
- Registry Value Activity
- Process Query
- Data Security Finding
- File Hosting Activity
- Folder Query
- SMB Activity
- Finding
- Incident Finding
- Managed Entity
- Windows Service Activity
- Scan Activity
- SSH Activity
- Account Change
- Identity & Access Management
- Discovery Result
- OSINT Inventory Info
Outbound Relationships
Device references the following objects and events in its attributes:
- Device Hardware Info
- Agent
- Container
- Unmapped
- Geo Location
- Network Interface
- Group
- Image
- Operating System (OS)
- Organization
- User
This page describes ocsf-1.4.0
Updated 12 days ago