Malware Scan Info
malware_scan_info
The malware scan information object describes characteristics, metadata of a malware scanning job.
Attributes
| Caption | Name | Type | Description | 
|---|---|---|---|
| End Time | end_time | 
        Timestamp | The timestamp indicating when the scan job completed execution. | 
| Name | name | 
        String | The administrator-supplied or application-generated name of the scan. For example: "Home office weekly user database scan", "Scan folders for viruses", "Full system virus scan" | 
| Scanned Files | num_files | 
        Integer | The total number of files analyzed during the scan. | 
| Number of Infected Entities | num_infected | 
        Integer | The total number of files identified as infected with malware during the scan. | 
| Number of Volumes | num_volumes | 
        Integer | The total number of storage volumes examined during the malware scan. | 
| Raw Data | raw_data | 
        JSON | 
            Group:contextThe event data as received from the event source.  | 
    
| Record ID | record_id | 
        String | 
            Group:primaryUnique identifier for the object  | 
    
| Size | size | 
        Long | The total size in bytes of all files that were scanned. | 
| Start Time | start_time | 
        Timestamp | The timestamp indicating when the scan job began execution. | 
| Type | type | 
        String | The type of scan. | 
| Type ID | type_id | 
        Integer | 
        The type id of the scan.
        
            
  | 
    
| Scan UID | uid | 
        String | The application-defined unique identifier assigned to an instance of a scan. | 
| Unique Malware Count | unique_malware_count | 
        Integer | The number of unique malware detected across all infected files. | 
| Unmapped | unmapped | 
        Unmapped[] | Data from the source that was not mapped into the schema. | 
Relationships
Inbound Relationships
These objects and events reference Malware Scan Info in their attributes:
- API Activity
 - User Inventory Info
 - DHCP Activity
 - Authentication
 - Network Remediation Activity
 - Memory Activity
 - Detection Finding
 - Prefetch Query
 - Authorize Session
 - Web Resources Activity
 - File Remediation Activity
 - Remediation Activity
 - Windows Service Activity
 - Network Activity
 - Account Change
 - OSINT Inventory Info
 - Security Finding
 - Process Query
 - Email File Activity
 - Startup Item Query
 - Networks Query
 - Admin Group Query
 - SSH Activity
 - Device Config State
 - Service Query
 - Live Evidence Info
 - Group Management
 - Device Config State Change
 - Base Event
 - HTTP Activity
 - RDP Activity
 - Windows Resource Activity
 - User Session Query
 - Cloud Resources Inventory Info
 - Registry Key Activity
 - Vulnerability Finding
 - Incident Finding
 - NTP Activity
 - Folder Query
 - Network Connection Query
 - Registry Value Query
 - File Query
 - User Query
 - Drone Flights Activity
 - Software Inventory Info
 - Compliance Finding
 - File System Activity
 - Operating System Patch State
 - Registry Value Activity
 - Data Security Finding
 - SMB Activity
 - IAM Analysis Finding
 - Email URL Activity
 - Application Lifecycle
 - FTP Activity
 - Registry Key Query
 - Scan Activity
 - Airborne Broadcast Activity
 - Module Query
 - Network File Activity
 - Device Inventory Info
 - Event Log Activity
 - Kernel Activity
 - Tunnel Activity
 - Application Security Posture Finding
 - Scheduled Job Activity
 - Kernel Object Query
 - Web Resource Access Activity
 - Peripheral Device Query
 - DNS Activity
 - User Access Management
 - Entity Management
 - Job Query
 - Datastore Activity
 - Application Error
 - Process Activity
 - Email Activity
 - Script Activity
 - Process Remediation Activity
 - Module Activity
 - Kernel Extension Activity
 - File Hosting Activity
 
Outbound Relationships
Malware Scan Info references the following objects and events in its attributes:
This page describes qdm-1.5.1+ocsf-1.6.0
Updated about 7 hours ago