For the complete documentation index, see llms.txt. This page is also available as Markdown.

Causality Actor

The Causality actor—also referred to as the causality group owner (CGO)—is the parent process in the execution chain that the Cortex XDR/XSIAM agent identified as being responsible for initiating the process tree.

Field Name
Data Type
Description

causality_actor_causality_id

STRING

Causality ID of the causality actor.

causality_actor_effective_user_sid

STRING

Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.

causality_actor_effective_username

STRING

Source effective username.

causality_actor_primary_user_sid

STRING

Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.

causality_actor_primary_username

STRING

Name assigned to the user_sid.

causality_actor_process_auth_id

STRING

Windows: LUID (uint64) representing the token of the process.

causality_actor_process_causality_id

STRING

Causality ID of the causality actor process.

causality_actor_process_command_line

STRING

Process command line - The command used to execute the process.

causality_actor_process_command_line_indices

STRING

Process command line - The command used to execute the process.

causality_actor_process_device_info

RECORD

Info about the device (volume + HW) from which this process started. including name, class guid, class name, bus type, volume guid, mount point, file system, drive type, vendor id, product id, and serial number.

causality_actor_process_execution_time

INTEGER

Causality actor process execution time in epoch time.

causality_actor_process_file_access_time

INTEGER

Access time of the file that created the process.

causality_actor_process_file_create_time

INTEGER

Creation time of the file that created the process.

causality_actor_process_file_mod_time

INTEGER

Modification time of the file that created the process.

causality_actor_process_file_size

INTEGER

Size of the file involved in the process in bytes.

causality_actor_process_image_extension

STRING

Process image extension - File extension.

causality_actor_process_image_md5

STRING

MD5 of the binary.

causality_actor_process_image_name

STRING

File name of the 'causality_actor_process_image_path'.

causality_actor_process_image_path

STRING

Process image path - A string identifying the location of the execution.

causality_actor_process_image_sha256

STRING

SHA256 of the binary.

causality_actor_process_instance_id

STRING

Cortex XDR/XSIAM unique identifier for the causality actor process.

causality_actor_process_integrity_level

INTEGER

Process integrity level.

causality_actor_process_is_64bit

BOOLEAN

Indicates whether or not the process is 64-bit.

causality_actor_process_is_native

BOOLEAN

Indicates whether this process is a "native process". On a 32-bit machine the value is always true; on a 64-bit machine, it is true, if the process is a 64-bit process.

causality_actor_process_is_replay

BOOLEAN

Indicates whether or not the Agent was alive during the execution of the process.

causality_actor_process_is_special

INTEGER

Indicates special system processes: RegularProcess = 0 KernelProcess = 1 AppContainerProcess = 2 NonWin32SubsystemProcess = 3

causality_actor_process_logon_id

STRING

Windows: LUID (uint64) representing the token of the process.

causality_actor_process_os_pid

INTEGER

The Operating System (OS) Process Identifier (PID) of the causality actor process

causality_actor_process_session_id

INTEGER

Windows: Session ID of the process.

causality_actor_process_signature_is_embedded

BOOLEAN

Indicates whether or not the signature is embedded inside the Program Executable (PE) or part of an external catalog file.

causality_actor_process_signature_product

STRING

Signature product - The product family part of the signature.

causality_actor_process_signature_status

INTEGER

Signature status of the process: Signed = 1 SignedInvalid = 2 Unsigned = 3 FailedToObtain = 4 WeakHash = 5, which means that MD5 is used as the hash algorithm. Unsupported = 6, which means the signature was not calculated. InvalidCVE2020_0601 = 7, which means the executable is malicious and is trying to exploit the windows vulnerability CVE2020-0601. Deleted = 8, which means that the file was deleted by the time the agent tried to calculate the signature.

causality_actor_process_signature_vendor

STRING

Signature vendor - The vendor part of the signature.

causality_actor_remote_host

STRING

Relevant when the actor is a remote actor and the host was resolved successfully.

causality_actor_remote_ip

STRING

Relevant when the actor is a remote actor, where the type is not local and the IP was resolved successfully.

causality_actor_remote_pipe_name

STRING

Relevant when the actor is a remote actor, where the type is RemoteRpcNamedPipe.

causality_actor_remote_port

INTEGER

Relevant when the actor is a remote actor, where the type is RemoteRpcTcp.

causality_actor_remote_port_pipe_name

STRING

Relevant when the actor is a remote actor, where the type is RemoteRpcTcp.

causality_actor_session_id

INTEGER

Sesion ID

causality_actor_type

INTEGER

Local = 1. The actor is a local process RemoteRpcNamedPipe = 2. The actor is a remote procedure call (RPC) over a named-pipe/SMB connection. RemoteRpcHttp = 3. The actor is a remote procedure call (RPC) over a remote HTTP connection. RemoteRpcTcp = 4. The actor is a remote procedure call (RPC) over a TCP connection. RemoteFileSmb = 5. The actor is a remote file operation over SMB.

causality_actor_primary_normalized_user

RECORD

Normalized user information.

causality_actor_container_info

RECORD

The container information for the process.

causality_actor_process_ns_pid

causality_actor_ns_user_sid

causality_actor_rpc_interface_uuid

STRING

MS-RPC interface unique identifier.

causality_actor_rpc_func_opnum

INTEGER

MS-RPC function operation identitifer.

causality_actor_rpc_interface_version_major

INTEGER

MS-RPC interface major version.

causality_actor_rpc_interface_version_minor

INTEGER

MS-RPC interface minor version.

causality_actor_rpc_protocol

STRING

MS-RPC protocol type.

causality_actor_local_ip

causality_actor_process_last_writer_actor

STRING

Cortex instance ID of the last process that has written the causality actor process image.

causality_actor_process_static_analysis_score

DEPRECATED

causality_actor_local_port

causality_actor_process_container_id

causality_actor_process_image_auth_sha1

STRING

Process image SHA-2 authenticode.

causality_actor_process_image_auth_sha2

STRING

Process image SHA-1 authenticode.

causality_actor_process_file_original_name

STRING

Original file name of the casuality actor image based on the file information metadata.

causality_actor_process_file_internal_name

STRING

Internal name of the casuality actor image based on the file information metadata.

Last updated

Was this helpful?