Windows Resource
The Windows resource object describes a resource object managed by Windows, such as mutant or timer.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Data | data |
JSON | Additional data describing the resource. |
Data Classification | data_classification |
Data Classification[] | The Data Classification object includes information about data classification levels and data category types. |
Details | details |
String | The string detailing the attributes of the resource object. |
Labels | labels |
String[] | The list of labels/tags associated to a resource. |
Name | name |
String | The name of the resource object. |
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
Service Name | svc_name |
String | The Windows service acting as the object server for the resource object, such as Security or Security Account Manager. |
Type | type |
String | The type of the Windows resource object. |
Type ID | type_id |
Integer |
The normalized type identifier of the Windows resource object accessed.
|
Unique ID | uid |
String | The Windows provided handle identifier for the resource object |
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Relationships
Inbound Relationships
These objects and events reference Windows Resource in their attributes:
Outbound Relationships
Windows Resource references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated about 1 month ago