Malware Scan Info

malware_scan_info

The malware scan information object describes characteristics, metadata of a malware scanning job.

Attributes

CaptionNameTypeDescription
End Time end_time Timestamp The timestamp indicating when the scan job completed execution.
Name name String The administrator-supplied or application-generated name of the scan. For example: "Home office weekly user database scan", "Scan folders for viruses", "Full system virus scan"
Scanned Files num_files Integer The total number of files analyzed during the scan.
Number of Infected Entities num_infected Integer The total number of files identified as infected with malware during the scan.
Number of Volumes num_volumes Integer The total number of storage volumes examined during the malware scan.
Raw Data raw_data JSON Group:context
The event data as received from the event source.
Record ID record_id String Group:primary
Unique identifier for the object
Size size Long The total size in bytes of all files that were scanned.
Start Time start_time Timestamp The timestamp indicating when the scan job began execution.
Type type String The type of scan.
Type ID type_id Integer The type id of the scan.
  • 0: Unknown (UNKNOWN)
  • 1: Manual (MANUAL)
  • 2: Scheduled (SCHEDULED)
  • 3: Updated Content (UPDATED_CONTENT)
  • 4: Quarantined Items (QUARANTINED_ITEMS)
  • 5: Attached Media (ATTACHED_MEDIA)
  • 6: User Logon (USER_LOGON)
  • 7: ELAM (ELAM)
  • 99: Other (OTHER)
Scan UID uid String The application-defined unique identifier assigned to an instance of a scan.
Unique Malware Count unique_malware_count Integer The number of unique malware detected across all infected files.
Unmapped unmapped Unmapped[] Data from the source that was not mapped into the schema.

Relationships

Malware Scan Info shown in context

Inbound Relationships

These objects and events reference Malware Scan Info in their attributes:

Outbound Relationships

Malware Scan Info references the following objects and events in its attributes:

This page describes qdm-1.5.1+ocsf-1.6.0