Kernel Extension

kernel_driver

The Kernel Extension object describes a kernel driver that has been loaded or unloaded into the operating system (OS) kernel.

Attributes

CaptionNameTypeDescription
FilefileFile[]

Entity:FILE
Group:primary
The driver/extension file object.

Raw Dataraw_dataJSON

Group:context
The event data as received from the event source.

Record IDrecord_idString

Group:primary
Unique identifier for the object

UnmappedunmappedUnmapped[]

Data from the source that was not mapped into the schema.

Relationships

Kernel Extension shown in context

Inbound Relationships

These objects and events reference Kernel Extension in their attributes:

Outbound Relationships

Kernel Extension references the following objects and events in its attributes:

This page describes ocsf-1.4.0