Network Endpoint
network_endpoint
The network endpoint object describes source or destination of a network connection.
Attributes
| Caption | Name | Type | Description |
|---|---|---|---|
| Agent List | agent_list | Agent[] | A list of agent objects associated with a device, endpoint, or resource. |
| Autonomous System | autonomous_system | Autonomous System[] | The Autonomous System details associated with an IP address. |
| Container | container | Container[] | Entity: |
| Domain | domain | String | The name of the domain that the endpoint belongs to or that corresponds to the endpoint. |
| Hostname | hostname | Hostname | Entity: |
| Hardware Info | hw_info | Device Hardware Info[] | The endpoint hardware information. |
| Instance ID | instance_uid | String | The unique identifier of a VM instance. |
| Network Interface Name | interface_name | String | The name of the network interface (e.g. eth2). |
| Network Interface ID | interface_uid | String | The unique identifier of the network interface. |
| Intermediate IP Addresses | intermediate_ips | IP Address[] | Entity: |
| IP Address | ip | IP Address | Entity: |
| IP Intelligence | ip_intelligence | IP Threat Intelligence[] | Insights from threat intelligence platforms about IP Address |
| ISP Name | isp | String | The name of the Internet Service Provider (ISP). |
| ISP Org | isp_org | String | The organization name of the Internet Service Provider (ISP). This represents the parent organization or company that owns/operates the ISP. For example, Comcast Corporation would be the ISP org for Xfinity internet service. This attribute helps identify the ultimate provider when ISPs operate under different brand names. |
| Geo Location | location | Geo Location[] | Entity: |
| MAC Address | mac | MAC Address | Entity: |
| Name | name | String | The short name of the endpoint. |
| Namespace PID | namespace_pid | Integer | Group: |
| OS | os | Operating System (OS)[] | The endpoint operating system. |
| Owner | owner | User[] | Entity: |
| Port | port | Port | Entity: |
| Proxy Endpoint | proxy_endpoint | Network Proxy Endpoint[] | Entity: |
| Raw Data | raw_data | JSON | Group: |
| Record ID | record_id | String | Group: |
| Subnet UID | subnet_uid | String | The unique identifier of a virtual subnet. |
| Service Name | svc_name | String | The service name in service-to-service connections. For example, AWS VPC logs the pkt-src-aws-service and pkt-dst-aws-service fields identify the connection is coming from or going to an AWS service. |
| Type | type | String | The network endpoint type. For example: unknown, server, desktop, laptop, tablet, mobile, virtual, browser, or other. |
| Type ID | type_id | Integer | The network endpoint type ID.
|
| Unique ID | uid | String | The unique identifier of the endpoint. |
| Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. |
| VLAN | vlan_uid | String | The Virtual LAN identifier. |
| VPC UID | vpc_uid | String | The unique identifier of the Virtual Private Cloud (VPC). |
| Network Zone | zone | String | The network zone or LAN segment. |
Relationships
Inbound Relationships
These objects and events reference Network Endpoint in their attributes:
- FTP Activity
- Network File Activity
- File Hosting Activity
- Web Resource Access Activity
- Authorize Session
- DNS Activity
- Network Activity
- Account Change
- Airborne Broadcast Activity
- User Access Management
- Entity Management
- Drone Flights Activity
- DHCP Activity
- RDP Activity
- API Activity
- HTTP Activity
- Endpoint Connection
- Load Balancer
- SSH Activity
- Group Management
- Authentication
- Data Security Finding
- Web Resources Activity
- Email Activity
- Datastore Activity
- Tunnel Activity
- NTP Activity
- Event Log Activity
- Windows Evidence Artifacts
- SMB Activity
Outbound Relationships
Network Endpoint references the following objects and events in its attributes:
- Network Proxy Endpoint
- IP Threat Intelligence
- Agent
- Autonomous System
- Device Hardware Info
- Operating System (OS)
- User
- Unmapped
- Geo Location
- Container
This page describes qdm-1.5.1+ocsf-1.6.0
Updated 1 day ago