Windows Service
win_service
The Windows Service object describes a Windows service.
Attributes
| Caption | Name | Type | Description |
|---|---|---|---|
| Command Line | cmd_line | String | Entity: |
| Labels | labels | String[] | The list of labels associated with the service. |
| Load Order Group | load_order_group | String | The name of the load ordering group of which this service is a member. |
| Name | name | String | The unique name of the service. |
| Raw Data | raw_data | JSON | Group: |
| Record ID | record_id | String | Group: |
| Service Category | service_category | String | The service category, normalized to the caption of the service_category_id value. In the case of 'Other', it is defined by the event source. |
| Service Category ID | service_category_id | Integer | The normalized identifier of the service category.
|
| Service Dependencies | service_dependencies | String[] | The names of other services upon which this service has a dependency. |
| Service Error Control | service_error_control | String | The service error control, normalized to the caption of the |
| Service Error Control ID | service_error_control_id | Integer | The normalized identifier of the service error control.
|
| Service Start Name | service_start_name | String | For a user mode service, this attribute represents the name of the account under which the service is run. For a kernel mode driver, this attribute represents the object name used to load the driver. |
| Service Start Type | service_start_type | String | The service start type, normalized to the caption of the |
| Service Start Type ID | service_start_type_id | Integer | The normalized identifier of the service start type.
|
| Service Type | service_type | String | The service type, normalized to the caption of the service_type_id value. In the case of 'Other', it is defined by the event source. |
| Service Type ID | service_type_id | Integer | The normalized identifier of the service type.
|
| Tags | tags | Key:Value object[] | The list of tags; |
| Unique ID | uid | String | The unique identifier of the service. |
| Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. |
| Version | version | String | The version of the service. |
Relationships
Inbound Relationships
These objects and events reference Windows Service in their attributes:
Outbound Relationships
Windows Service references the following objects and events in its attributes:
This page describes ocsf-1.4.0
Updated 6 months ago