Enrichment
enrichment
The Enrichment object provides inline enrichment data for specific attributes of interest within an event. It serves as a mechanism to enhance or supplement the information associated with the event by adding additional relevant details or context.
Attributes
| Caption | Name | Type | Description |
|---|---|---|---|
| Created Time | created_time | Timestamp | The time when the enrichment data was generated. |
| Data | data | JSON | The enrichment data associated with the attribute and value. The meaning of this data depends on the type the enrichment record. |
| Description | desc | String | A long description of the enrichment data. |
| Name | name | String | The name of the attribute to which the enriched data pertains. |
| Provider | provider | String | The enrichment data provider name. |
| Raw Data | raw_data | JSON | Group: |
| Record ID | record_id | String | Group: |
| Reputation Scores | reputation | Reputation[] | The reputation of the enrichment data. |
| Short Description | short_desc | String | A short description of the enrichment data. |
| Source URL | src_url | URL String | Entity: |
| Type | type | String | The enrichment type. For example: location. |
| Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. |
| Value | value | String | The value of the attribute to which the enriched data pertains. |
Relationships
Inbound Relationships
These objects and events reference Enrichment in their attributes:
- User Session Query
- SMB Activity
- Remediation Activity
- Base Event
- Datastore Activity
- Kernel Object Query
- Account Change
- Network Activity
- Software Inventory Info
- Networks Query
- Email File Activity
- Module Query
- Vulnerability Finding
- Live Evidence Info
- Tunnel Activity
- Startup Item Query
- File Remediation Activity
- Admin Group Query
- Job Query
- DHCP Activity
- Module Activity
- Process Query
- Memory Activity
- Entity Management
- Process Activity
- Process Remediation Activity
- Registry Key Activity
- Registry Value Query
- Device Inventory Info
- Application Lifecycle
- Event Log Activity
- Registry Value Activity
- Kernel Activity
- OSINT Inventory Info
- File Query
- NTP Activity
- HTTP Activity
- User Query
- Authorize Session
- Prefetch Query
- File System Activity
- User Access Management
- Application Error
- Device Config State Change
- Data Security Finding
- Security Finding
- FTP Activity
- Registry Key Query
- User Inventory Info
- Application Security Posture Finding
- API Activity
- SSH Activity
- Detection Finding
- Peripheral Device Query
- Windows Service Activity
- Web Resources Activity
- Authentication
- Network File Activity
- Group Management
- Network Connection Query
- IAM Analysis Finding
- Email URL Activity
- Incident Finding
- Drone Flights Activity
- Network Remediation Activity
- Operating System Patch State
- Scan Activity
- Kernel Extension Activity
- Device Config State
- Cloud Resources Inventory Info
- Folder Query
- Airborne Broadcast Activity
- DNS Activity
- Windows Resource Activity
- Email Activity
- File Hosting Activity
- Scheduled Job Activity
- RDP Activity
- Compliance Finding
- Web Resource Access Activity
- Script Activity
- Service Query
Outbound Relationships
Enrichment references the following objects and events in its attributes:
This page describes qdm-1.5.1+ocsf-1.6.0