Windows Service
win_service
The Windows Service object describes a Windows service.
Attributes
| Caption | Name | Type | Description | 
|---|---|---|---|
| Command Line | cmd_line | String | Entity: | 
| Labels | labels | String[] | The list of labels associated with the service. | 
| Load Order Group | load_order_group | String | The name of the load ordering group of which this service is a member. | 
| Name | name | String | The unique name of the service. | 
| Raw Data | raw_data | JSON | Group: | 
| Record ID | record_id | String | Group: | 
| Service Category | service_category | String | The service category, normalized to the caption of the service_category_id value. In the case of 'Other', it is defined by the event source. | 
| Service Category ID | service_category_id | Integer | The normalized identifier of the service category. 
 | 
| Service Dependencies | service_dependencies | String[] | The names of other services upon which this service has a dependency. | 
| Service Error Control | service_error_control | String | The service error control, normalized to the caption of the  | 
| Service Error Control ID | service_error_control_id | Integer | The normalized identifier of the service error control. 
 | 
| Service Start Name | service_start_name | String | For a user mode service, this attribute represents the name of the account under which the service is run. For a kernel mode driver, this attribute represents the object name used to load the driver. | 
| Service Start Type | service_start_type | String | The service start type, normalized to the caption of the  | 
| Service Start Type ID | service_start_type_id | Integer | The normalized identifier of the service start type. 
 | 
| Service Type | service_type | String | The service type, normalized to the caption of the service_type_id value. In the case of 'Other', it is defined by the event source. | 
| Service Type ID | service_type_id | Integer | The normalized identifier of the service type. 
 | 
| Tags | tags | Key:Value object[] | The list of tags;  | 
| Unique ID | uid | String | The unique identifier of the service. | 
| Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. | 
| Version | version | String | The version of the service. | 
Relationships
Inbound Relationships
These objects and events reference Windows Service in their attributes:
Outbound Relationships
Windows Service references the following objects and events in its attributes:
This page describes ocsf-1.4.0
Updated about 9 hours ago