Malware
malware
The Malware object describes the classification of known malicious software, which is intentionally designed to cause damage to a computer, server, client, or computer network.
Attributes
| Caption | Name | Type | Description |
|---|---|---|---|
| Classification IDs | classification_ids | Integer[] | The list of normalized identifiers of the malware classifications.
|
| Classifications | classifications | String[] | The list of malware classifications, normalized to the captions of the classification_ids values. In the case of 'Other', they are defined by the event source. |
| CVE List | cves | CVE[] | The list of Common Vulnerabilities and Exposures (CVE) identifiers associated with the malware. Reference: CVE |
| Files | files | File[] | Entity: |
| Name | name | String | The malware name, as reported by the detection engine. |
| Number of Infected Entities | num_infected | Integer | The number of files that were identified to be infected by the malware. |
| Path | path | File Path | Entity:
|
| Provider | provider | String | The name or identifier of the security solution or service that provided the malware detection information. |
| Raw Data | raw_data | JSON | Group: |
| Record ID | record_id | String | Group: |
| Severity | severity | String | The severity of the malware, normalized to the captions of the severity_id values. In the case of 'Other', they are defined by the event source. |
| Severity ID | severity_id | Integer | The normalized identifier of the malware severity.
|
| Unique ID | uid | String | A unique identifier for the specific malware instance, as assigned by the detection engine (e.g., virus signature ID or IPS rule ID). |
| Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. |
Relationships
Inbound Relationships
These objects and events reference Malware in their attributes:
- RDP Activity
- Device Config State
- File Hosting Activity
- Email File Activity
- Software Inventory Info
- Device Inventory Info
- Kernel Object Query
- Network Activity
- File Query
- Registry Key Query
- Event Log Activity
- Registry Value Query
- User Inventory Info
- SSH Activity
- Service Query
- Drone Flights Activity
- Cloud Resources Inventory Info
- Security Finding
- Entity Management
- Process Query
- Startup Item Query
- Detection Finding
- OSINT
- NTP Activity
- DHCP Activity
- Network File Activity
- Web Resources Activity
- Remediation Activity
- Compliance Finding
- Vulnerability Finding
- Authentication
- Script Activity
- Scan Activity
- File Remediation Activity
- Process Activity
- Networks Query
- Group Management
- Registry Key Activity
- Scheduled Job Activity
- User Query
- Module Query
- DNS Activity
- Module Activity
- Incident Finding
- Airborne Broadcast Activity
- Email URL Activity
- User Access Management
- Network Remediation Activity
- Tunnel Activity
- User Session Query
- Application Error
- SMB Activity
- Network Connection Query
- Peripheral Device Query
- Windows Resource Activity
- Process Remediation Activity
- Windows Service Activity
- Operating System Patch State
- Data Security Finding
- Job Query
- Folder Query
- Prefetch Query
- Admin Group Query
- Device Config State Change
- Datastore Activity
- Email Activity
- Registry Value Activity
- IAM Analysis Finding
- Application Lifecycle
- Authorize Session
- Kernel Activity
- Application Security Posture Finding
- File System Activity
- FTP Activity
- API Activity
- Kernel Extension Activity
- Web Resource Access Activity
- Live Evidence Info
- Account Change
- Memory Activity
- HTTP Activity
- OSINT Inventory Info
- Base Event
Outbound Relationships
Malware references the following objects and events in its attributes:
This page describes qdm-1.5.1+ocsf-1.6.0
Updated 18 days ago