OS Actor
The OS actor is the process identified by the operation system as the process that performed the action.
os_actor_causality_id
STRING
the causality chain identifier of the Operating System actor
os_actor_effective_user_sid
STRING
Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.
os_actor_effective_username
STRING
the username which launched the Operating System actor process
os_actor_is_injected_thread
BOOLEAN
Indicates whether or not the thread is injected to the operating system actor process.
os_actor_primary_user_sid
STRING
Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.
os_actor_primary_username
STRING
Name assigned to the user_sid.
os_actor_process_auth_id
STRING
Windows: LUID (uint64) representing the token of the process.
os_actor_process_causality_id
STRING
the causality chain identifier of the Operating System actor process
os_actor_process_command_line
STRING
Process command line - The command used to execute the process.
os_actor_process_command_line_indices
STRING
Process command line - The command used to execute the process.
os_actor_process_device_info
RECORD
Info about the device (volume + HW) from which this process started. including name, class guid, class name, bus type, volume guid, mount point, file system, drive type, vendor id, product id, and serial number.
os_actor_process_execution_time
INTEGER
the execution timestamp
os_actor_process_file_access_time
INTEGER
Access time of the file that created the process
os_actor_process_file_create_time
INTEGER
Creation time of the file that created the process.
os_actor_process_file_mod_time
INTEGER
Modification time of the file that created the process.
os_actor_process_file_size
INTEGER
Size of the file involved in the process in bytes.
os_actor_process_image_command_line
STRING
Process command line - The command used to execute the process.
os_actor_process_image_extension
STRING
Process image extension - File extension.
os_actor_process_image_md5
STRING
MD5 of the binary.
os_actor_process_image_name
STRING
the process image name on the disk
os_actor_process_image_path
STRING
Process image path - A string identifying the location of the execution.
os_actor_process_image_sha256
STRING
SHA256 of the binary.
os_actor_process_instance_id
STRING
Process instance identifier.
os_actor_process_integrity_level
INTEGER
the integrity level of the process (INTEGER)
os_actor_process_is_64bit
BOOLEAN
Indicates whether or not the process is compiled for 64 bit.
os_actor_process_is_native
BOOLEAN
Indicates whether or not this process is a "native process". On a 32 bit machine the value will be always true, on 64 bit machine it will be true if the process is 64 bit.
os_actor_process_is_replay
BOOLEAN
Indicates whether or not the process event data is replayed or not. replayed means that the agent sent the data after the action occured for example after a reboot
os_actor_process_is_special
INTEGER
Indicates special system processes: RegularProcess = 0 KernelProcess = 1 AppContainerProcess = 2 NonWin32SubsystemProcess = 3
os_actor_process_logon_id
STRING
Windows: LUID (uint64) representing the token of the process.
os_actor_process_os_pid
INTEGER
The Operating System (OS) Process Identifier (PID) of the operating system actor process
os_actor_process_session_id
INTEGER
Windows: Session ID of the process.
os_actor_process_signature_is_embedded
BOOLEAN
Indicates whether or not the signature is embedded inside the Program Executable (PE) or part of an external catalog file.
os_actor_process_signature_product
STRING
Signature product - The product family part of the signature.
os_actor_process_signature_status
INTEGER
Signature status of the process: Signed = 1 SignedInvalid = 2 Unsigned = 3 FailedToObtain = 4 WeakHash = 5, where the MD5 is used as the hash algorithm. Unsupported = 6, which means the signature was not calculated. InvalidCVE2020_0601 = 7, which means the executable is malicious and is trying to exploit the windows vulnerability CVE2020-0601. Deleted = 8, which means that the file was deleted by the time the agent tried to calculate the signature.
os_actor_process_signature_vendor
STRING
Signature vendor - The vendor part of the signature.
os_actor_remote_host
STRING
Relevant when the actor is a remote actor and the host was resolved successfully.
os_actor_remote_ip
STRING
Relevant when the actor is a remote actor, where the type is not local and the IP was resolved successfully.
os_actor_remote_port
INTEGER
Relevant when the actor is a remote actor, where the type is RemoteRpcTcp.
os_actor_session_id
INTEGER
session id of the actor process
os_actor_thread_thread_id
INTEGER
thread id of the thread in the process which made the action
os_actor_type
INTEGER
Enum describing actor type: Local = 1. The actor is a local process RemoteRpcNamedPipe = 2. The actor is remote RPC over a named-pipe/SMB connection RemoteRpcHttp = 3. The actor is remote RPC a remote HTTP connection RemoteRpcTcp = 4. The actor is remote RPC over a TCP connection RemoteFileSmb = 5. The actor is a remote file operation over SMB
os_actor_container_info
RECORD
Container information for the process.
os_actor_process_ns_pid
os_actor_ns_user_sid
os_actor_process_container_id
os_actor_process_image_auth_sha1
STRING
Process image SHA-1 authenticode.
os_actor_process_image_auth_sha2
STRING
Process image SHA-2 authenticode.
os_actor_process_last_writer_actor
STRING
Cortex instance ID of the last process that has written the os actor process image.
os_actor_rpc_func_opnum
INTEGER
MS-RPC function operation identitifer.
os_actor_rpc_interface_version_major
INTEGER
MS-RPC interface major version.
os_actor_rpc_interface_version_minor
INTEGER
MS-RPC interface minor version.
os_actor_rpc_protocol
STRING
MS-RPC protocol type.
os_actor_rpc_interface_uuid
STRING
MS-RPC interface unique identifier.
os_actor_process_static_analysis_score
DEPRECATED
os_actor_process_file_original_name
STRING
Original file name of the casuality actor image based on the file information metadata.
os_actor_process_file_internal_name
STRING
Internal name of the casuality actor image based on the file information metadata.
Last updated
Was this helpful?
