DST OS Actor
The DST OS actor is the process identified by the operation system on the remote host as the process that performed an action that was responsible for the entire chain of execution.
dst_os_actor_causality_id
STRING
Causality chain ID.
dst_os_actor_effective_user_sid
STRING
Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.
dst_os_actor_effective_username
STRING
Effective username
dst_os_actor_is_injected_thread
BOOLEAN
Indicates whether or not the thread is injected.
dst_os_actor_primary_user_sid
STRING
Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.
dst_os_actor_primary_username
STRING
Name assigned to the user_sid.
dst_os_actor_process_auth_id
STRING
Windows: LUID (uint64) representing the token of the process.
dst_os_actor_process_causality_id
STRING
Process causality chain ID.
dst_os_actor_process_command_line
STRING
Process command line - The command used to execute the process.
dst_os_actor_process_command_line_indices
STRING
Process command line - The command used to execute the process.
dst_os_actor_process_device_info
RECORD
Info about the device (volume + HW) from which this process started. including name, class guid, class name, bus type, volume guid, mount point, file system, drive type, vendor id, product id, and serial number.
dst_os_actor_process_execution_time
INTEGER
Process execution time in epoch time.
dst_os_actor_process_file_access_time
INTEGER
Access time of the file that created the process.
dst_os_actor_process_file_create_time
INTEGER
Creation time of the file that created the process.
dst_os_actor_process_file_mod_time
INTEGER
Modification time of the file that created the process.
dst_os_actor_process_file_size
INTEGER
Size of the file involved in the process in bytes.
dst_os_actor_process_image_command_line
STRING
Process command line - The command used to execute the process.
dst_os_actor_process_image_extension
STRING
Process image extension - File extension.
dst_os_actor_process_image_md5
STRING
MD5 of the binary.
dst_os_actor_process_image_name
STRING
Process image name.
dst_os_actor_process_image_path
STRING
Process image path - A string identifying the location of the execution.
dst_os_actor_process_image_sha256
STRING
SHA256 of the binary.
dst_os_actor_process_instance_id
STRING
Process instance ID.
dst_os_actor_process_integrity_level
INTEGER
Integrity level of the process.
dst_os_actor_process_is_64bit
BOOLEAN
Indicates whether or not the process is 64-bit.
dst_os_actor_process_is_native
BOOLEAN
Indicates whether or not this process is a "native process". On a 32-bit machine, the value is always true, and on 64-bit machine, the value is true, if the process is 64-bit.
dst_os_actor_process_is_replay
BOOLEAN
Indicates whether or not the process event data is replayed or not. Replayed means that the agent sent the data after the action occurred, for example, after a reboot.
dst_os_actor_process_is_special
INTEGER
Indicates special system processes: RegularProcess = 0 KernelProcess = 1 AppContainerProcess = 2 NonWin32SubsystemProcess = 3
dst_os_actor_process_logon_id
STRING
Windows: LUID (uint64) representing the token of the process.
dst_os_actor_process_os_pid
INTEGER
The Operating System (OS) Process Identifier (PID) of the destination operating system actor process.
dst_os_actor_process_session_id
INTEGER
Windows: Session ID of the process.
dst_os_actor_process_signature_is_embedded
BOOLEAN
Indicates whether or not the signature is embedded inside the Program Executable or part of an external catalog file.
dst_os_actor_process_signature_product
STRING
Signature product - The product family part of the signature.
dst_os_actor_process_signature_status
INTEGER
Signature status of the process: Signed = 1 SignedInvalid = 2 Unsigned = 3 FailedToObtain = 4 WeakHash = 5, where the MD5 is used as the hash algorithm. Unsupported = 6, which means the signature was not calculated. InvalidCVE2020_0601 = 7, which means the executable is malicious and is trying to exploit the windows vulnerability CVE2020-0601. Deleted = 8, which means that the file was deleted by the time the agent tried to calculate the signature.
dst_os_actor_process_signature_vendor
STRING
Signature vendor - The vendor part of the signature.
dst_os_actor_remote_host
STRING
Relevant when the actor is a remote actor and the host was resolved successfully.
dst_os_actor_remote_ip
STRING
Relevant when the actor is a remote actor, where the type is not local and the IP was resolved successfully.
dst_os_actor_remote_port
INTEGER
Relevant when the actor is a remote actor, where the type is RemoteRpcTcp.
dst_os_actor_session_id
INTEGER
Windows: Session ID of the process.
dst_os_actor_thread_thread_id
INTEGER
An identifier of the Operating System (OS) thread responsible for the event.
dst_os_actor_type
INTEGER
Operating System actor type: Local = 1. The actor is a local process. RemoteRpcNamedPipe = 2. The actor is a remote procedure call (RPC) over a named-pipe/SMB connection. RemoteRpcHttp = 3. The actor is a remote procedure call (RPC) over a remote HTTP connection. RemoteRpcTcp = 4. The actor is a remote procedure call (RPC) over a TCP connection. RemoteFileSmb = 5. The actor is a remote file operation over a SMB connection.
dst_os_actor_container_info
RECORD
Container information for the process.
dst_os_actor_process_ns_pid
dst_os_actor_ns_user_sid
dst_os_actor_process_container_id
dst_os_actor_process_image_auth_sha1
STRING
Process image SHA-1 authenticode.
dst_os_actor_process_image_auth_sha2
STRING
The process image SHA-2 authenticode.
dst_os_actor_process_last_writer_actor
STRING
Cortex instance ID of the last process that has written the os actor process image.
dst_os_actor_rpc_func_opnum
INTEGER
MS-RPC function operation identitifer.
dst_os_actor_rpc_interface_version_major
INTEGER
MS-RPC interface major version.
dst_os_actor_rpc_interface_version_minor
INTEGER
MS-RPC interface minor version.
dst_os_actor_rpc_protocol
STRING
MS-RPC protocol type.
dst_os_actor_rpc_interface_uuid
STRING
MS-RPC interface unique identifier.
dst_os_actor_process_static_analysis_score
DEPRECATED
dst_os_actor_process_file_original_name
STRING
Original file name of the destination os actor image based on the file information metadata.
dst_os_actor_process_file_internal_name
STRING
Internal name of the destination os actor image based on the file information metadata.
Last updated
Was this helpful?
