Windows Service
win_service
The Windows Service object describes a Windows service.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
Command Line | cmd_line | String | Entity: |
Labels | labels | String[] | The list of labels associated with the service. |
Load Order Group | load_order_group | String | The name of the load ordering group of which this service is a member. |
Name | name | String | The unique name of the service. |
Raw Data | raw_data | JSON | Group: |
Record ID | record_id | String | Group: |
Service Category | service_category | String | The service category, normalized to the caption of the service_category_id value. In the case of 'Other', it is defined by the event source. |
Service Category ID | service_category_id | Integer | The normalized identifier of the service category.
|
Service Dependencies | service_dependencies | String[] | The names of other services upon which this service has a dependency. |
Service Error Control | service_error_control | String | The service error control, normalized to the caption of the |
Service Error Control ID | service_error_control_id | Integer | The normalized identifier of the service error control.
|
Service Start Name | service_start_name | String | For a user mode service, this attribute represents the name of the account under which the service is run. For a kernel mode driver, this attribute represents the object name used to load the driver. |
Service Start Type | service_start_type | String | The service start type, normalized to the caption of the |
Service Start Type ID | service_start_type_id | Integer | The normalized identifier of the service start type.
|
Service Type | service_type | String | The service type, normalized to the caption of the service_type_id value. In the case of 'Other', it is defined by the event source. |
Service Type ID | service_type_id | Integer | The normalized identifier of the service type.
|
Tags | tags | Key:Value object[] | The list of tags; |
Unique ID | uid | String | The unique identifier of the service. |
Unmapped | unmapped | Unmapped[] | Data from the source that was not mapped into the schema. |
Version | version | String | The version of the service. |
Relationships
Inbound Relationships
These objects and events reference Windows Service in their attributes:
Outbound Relationships
Windows Service references the following objects and events in its attributes:
This page describes ocsf-1.4.0
Updated 9 days ago