Kernel Extension

The Kernel Extension object describes a kernel driver that has been loaded or unloaded into the operating system (OS) kernel. Defined by D3FEND d3f:KernelModule.

Attributes

CaptionNameTypeDescription
File file File[] The driver/extension file object.
Raw Data raw_data JSON The event data as received from the event source.
Record ID record_id String Unique identifier for the object
Unmapped Data unmapped Unmapped[] The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source.

Relationships

Kernel Extension shown in context

Inbound Relationships

These objects and events reference Kernel Extension in their attributes:

Outbound Relationships

Kernel Extension references the following objects and events in its attributes:

This page describes qdm-1.3.2+ocsf-1.3.0