Windows Resource
win_resource
The Windows resource object describes a resource object managed by Windows, such as mutant or timer.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Data | data |
JSON | Additional data describing the resource. |
Data Classification | data_classification |
Data Classification[] |
Group:context The Data Classification object includes information about data classification levels and data category types.
|
Data Classification | data_classifications |
Data Classification[] |
Group:context A list of Data Classification objects, that include information about data classification levels and data category types, indentified by a classifier. |
Details | details |
String | The string detailing the attributes of the resource object. |
Labels | labels |
String[] | The list of labels associated to the resource. |
Name | name |
String | The name of the resource object. |
Raw Data | raw_data |
JSON |
Group:context The event data as received from the event source. |
Record ID | record_id |
String |
Group:primary Unique identifier for the object |
Service Name | svc_name |
String | The Windows service acting as the object server for the resource object, such as Security or Security Account Manager. |
Tags | tags |
Key:Value object[] |
The list of tags; {key:value} pairs associated to the resource.
|
Type | type |
String | The type of the Windows resource object. |
Type ID | type_id |
Integer |
The normalized type identifier of the Windows resource object accessed.
|
Unique ID | uid |
Resource UID |
Entity:RESOURCE_UID The Windows provided handle identifier for the resource object |
Unmapped | unmapped |
Unmapped[] | Data from the source that was not mapped into the schema. |
Relationships
Inbound Relationships
These objects and events reference Windows Resource in their attributes:
Outbound Relationships
Windows Resource references the following objects and events in its attributes:
This page describes ocsf-1.4.0
Updated 3 days ago