# EDR Telemetry Field Reference — Field Guide ## EDR Threat Hunting Reference Manual | Property | Value | |---|---| | Audience | Security analysts querying EDR telemetry | | Format | Every telemetry event is a JSON object delivered as a gzip-compressed batch. This manual explains each field, its meaning, and how to use it for analysis and investigation. | | Schema | OCSF (Open Cybersecurity Schema Framework) v1.3.0 | | Product | Endpoint Central Agent | ### Table of Contents 1. Quick Start — How to Read an Event 2. How Telemetry Collection Works 2.1 Collection and Delivery 2.2 Data Posting Interval 2.3 Fallback and Retry Mechanism 2.4 Health Monitoring 2.5 Per-Process Daily Event Limits 3. Event Types 4. Understanding "Actor" — The Most Important Concept 5. Field Types and Search Operators 5.1 Field Types 5.2 Search Operators 5.3 Combining Operators (Boolean Logic) 5.4 DateTime Fields Reference 6. Field Glossary 6.1 Classification Fields 6.2 Metadata Fields 6.3 Device Fields 6.4 Endpoint Identifier Fields 6.5 Status Fields 6.6 Observable Fields 6.7 Time Fields 6.8 Process Fields (Process Activity Events) 6.9 File Fields (File Activity Events) 6.10 Registry Fields (Registry Activity Events) 6.11 Network Fields (Network Activity Events) 6.12 DNS Fields (DNS Activity Events) 6.13 Authentication Fields 6.14 Finding Info Fields (Behavioral Detections) 6.15 User Object Fields 6.16 Hash Object Fields 6.17 File Object Fields (Executable Metadata) 6.18 Module Fields (Module Activity Events) 7. Complete Enum Reference 7.1 activity_id — Event Activity 7.2 class_uid — Event Class 7.3 category_uid — Event Category 7.4 type_uid — Composite Event Type 7.5 severity_id — Event Severity 7.6 status_id — Activity Status 7.7 device.os.type_id — Operating System Type 7.8 device.type_id — Device Type 7.9 user.type_id — User Account Type 7.10 file.type_id — File Type 7.11 hashes.algorithm_id — Hash Algorithm 7.12 logon_type_id — Windows Logon Type 7.13 auth_protocol_id — Authentication Protocol 7.14 reg_value.type_id — Registry Value Type 7.15 query.opcode_id — DNS Operation Code 7.16 rcode_id — DNS Response Code 7.17 connection_info.direction_id — Connection Direction 7.18 connection_info.protocol_num — Network Protocol (IANA) 7.19 connection_info.protocol_ver_id — IP Version 7.20 observables.type_id — Observable Type 7.21 module.load_type_id — Module Load Type 8. Investigation Query Patterns 9. Search Examples by Event Class 9.1 File Activity Examples 9.2 Process Activity Examples 9.3 Network Activity Examples 9.4 DNS Activity Examples 9.5 Registry Activity Examples 9.6 Authentication Examples 9.7 Module Activity Example 10. Advanced Correlation Techniques 10.1 Cross-Event Correlation Using actor.process.uid 10.2 Process Tree Reconstruction via lineage_uid 10.3 Full Activity Profile of a Single Process 10.4 Useful Starter Query Templates ## 1. Quick Start — How to Read an Event Every telemetry event is a JSON object with the following high-level structure: | Section | Fields | |---|---| | Classification | class_uid, type_uid, activity_id, severity_id, category_uid | | When | time, timezone_offset | | Where | device (hostname, ip, OS), componentid, customerid, resourceid | | Who Did It (Actor) | actor.process, actor.user, actor.process.parent_process | | What Happened | Depends on event type: Process → process, process.parent; File → file, file_result; Registry → reg_key, reg_value; Network → src_endpoint, dst_endpoint; DNS → query, answers; Auth → user, session; Module → module (file, load_type) | | Status | status_id, status, status_detail | | Detection (if triggered) | finding_info → analytic, attacks (MITRE ATT&CK) | | Metadata | metadata (product, log_name, version) | ## 2. How Telemetry Collection Works ### 2.1 Collection and Delivery The EDR agent on each endpoint continuously monitors system activity (processes, files, registry, network, DNS, and authentication). Each captured event is transformed into a standardized OCSF v1.3.0 JSON object, then grouped into compressed batches and uploaded to the server over HTTPS. #### How batching works: Events are collected and grouped into batches. A batch is created when either 5,000 events accumulate or 5 minutes have elapsed, whichever comes first. Each batch is compressed (gzip) and uploaded as a single file. Every event in the batch shares a common batch_id for traceability. Batch ID format: ```text __ ``` Example: `1001000000012345_1772685020358_297` ### 2.2 Data Posting Interval Under normal load, batches are uploaded at a steady interval with a short pause (2 seconds) between successive uploads. High-activity endpoints batch more frequently (hitting the 5,000 event count threshold), while low-activity endpoints batch on the 5-minute time threshold. ### 2.3 Fallback and Retry Mechanism If a batch upload fails, the system uses an adaptive retry strategy: | Failure Type | Action | |---|---| | Network failures | Retried up to 3 times with increasing delay. If all retries fail, the batch is discarded and the next batch is attempted. | | Rate limiting (HTTP 429) | Exponential backoff with increasing delays, up to a maximum of 30 minutes between retries. | | Payload too large (HTTP 413) | The batch is discarded immediately. | | Other errors | Retried up to 3 times with a 5-minute delay. | When a batch is discarded after exhausting retries, the drop is recorded in health metrics and the system moves to the next batch. #### Disk safeguards: Maximum telemetry folder size: 500 MB. Files exceeding this limit are removed to prevent unbounded disk usage. Maximum single batch file size: 4 MB (compressed). ### 2.4 Health Monitoring The system reports health data daily, including: - Total batches uploaded successfully - Total upload failures - Total batches dropped (not delivered) - Current consecutive retry count After every batch (success or failure), a health summary is posted to the server containing: batch name, event time range, record count, raw and compressed sizes, and failure status code. ### 2.5 Per-Process Daily Event Limits To prevent any single process from generating excessive telemetry, each process has a daily cap on the number of events it can produce per activity type. Once a process reaches the limit for a given activity, further events of that type from that process are not collected until the next day. Events from other processes are unaffected. #### File Activity (class_uid = 1001): | Activity | Daily Limit Per Process | |---|---| | Create | 40,000 | | Read | 40,000 | | Write | 40,000 | | Delete | 40,000 | | Rename | 40,000 | | Directory Create | 10,000 | #### Registry Key Activity (class_uid = 201001): | Activity | Daily Limit Per Process | |---|---| | Create | 50,000 | | Delete | 50,000 | | Rename | 30,000 | | Set Security | 20,000 | #### Registry Value Activity (class_uid = 201002): | Activity | Daily Limit Per Process | |---|---| | Modify | 50,000 | | Delete | 50,000 | #### Network Activity (class_uid = 4001): | Activity | Daily Limit Per Process | |---|---| | Traffic | 100,000 | #### DNS Activity (class_uid = 4003): | Activity | Daily Limit Per Process | |---|---| | Query | 100,000 | **Note:** Process Activity and Authentication events are not subject to per-process rate limits. ## 3. Event Types The EDR agent collects eight types of telemetry events. Each event type has a unique class_uid that tells you what kind of activity was captured. | class_uid | Event Type | Description | |---|---|---| | 1007 | Process Activity | A process was launched, terminated, or opened. The most fundamental event type — it tells you what programs ran on the endpoint. | | 1001 | File Activity | A file was created, written to, deleted, renamed, encrypted, or had its attributes/security changed. Critical for identifying patterns such as mass renames with extension changes. | | 201001 | Registry Key Activity | A Windows registry key was created, deleted, renamed, or had its security permissions modified. | | 201002 | Registry Value Activity | A Windows registry value was created, modified, or deleted. Especially important for persistence detection. | | 4001 | Network Activity | A network connection was opened, traffic was observed, or a connection was closed/reset/refused. | | 4003 | DNS Activity | A DNS query was sent or a DNS response was received. Reveals domain resolutions and identifies unusual resolution patterns. | | 3002 | Authentication | A user logon, logoff, or authentication ticket event occurred. Essential for understanding user session activity. | | 1005 | Module Activity | A DLL or shared library was loaded into a process. Helps identify unexpected libraries being loaded, DLL sideloading, and reflective DLL injection. | ## 4. Understanding "Actor" — The Most Important Concept The actor field is present in every event and is critical for threat hunting. However, it means different things depending on the event type. ### Actor in Process Events In a Process Activity event (class_uid = 1007), three separate process objects are present: | Field | Role | Description | |---|---|---| | process | The subject process | The process that was launched or terminated. This is the new process you are investigating. | | process.parent_process | The claimed parent | The process that Windows reports as the parent (based on PPID). Under normal conditions, this is the real parent. However, PPID spoofing can cause this value to be inaccurate. | | actor.process | The real initiator | The process that actually caused the launch. Under normal conditions, identical to process.parent_process. When PPID spoofing is detected, the EDR kernel driver identifies the discrepancy and sets actor.process to the real parent. | **Example — Normal case:** ```text cmd.exe (PID 1234) launches powershell.exe (PID 5678) → process = powershell.exe (PID 5678) → process.parent_process = cmd.exe (PID 1234) → actor.process = cmd.exe (PID 1234) ← Same as parent ``` **Example — PPID Spoofing:** ```text A process (PID 9999) launches powershell.exe (PID 5678) but tells Windows the parent is explorer.exe (PID 1000) → process = powershell.exe (PID 5678) → process.parent_process = explorer.exe (PID 1000) ← FAKE parent → actor.process = originating process (PID 9999) ← REAL parent ``` **Tip:** If `actor.process.pid` differs from `process.parent_process.pid`, PPID spoofing is taking place. ### Actor in File, Registry, Network, and DNS Events For all non-process event types, `actor.process` is the process that performed the action: | Event Type | actor.process meaning | Example | |---|---|---| | File Activity | The process that created, wrote, deleted, or renamed the file | notepad.exe wrote document.txt | | Registry Activity | The process that modified the registry key or value | svchost.exe set a Run key value | | Network Activity | The process that opened the network connection | chrome.exe connected to `1.2.3.4:443` | | DNS Activity | The process that made the DNS query | powershell.exe resolved example-domain.com | In all these event types, `actor.process.parent_process` is also populated, giving you two levels of process context. ### Actor in Authentication Events | Field | Role | Description | |---|---|---| | actor.user | The subject user | The account that initiated the logon (e.g., a service account or machine account). | | actor.process | The logon handler | The process handling the logon — usually lsass.exe, winlogon.exe, or similar. Only present when the logon event has a valid PID. | | user (top-level) | The target user | The account being logged into. This is the account whose access is being granted or denied. | **Tip:** In lateral movement scenarios, `actor.user` and `user` will be different — one account is used to authenticate as another. ## 5. Field Types and Search Operators Understanding how fields are typed is essential for writing correct search queries. ### 5.1 Field Types | Type | Description | Operators | Groupby | |---|---|---|---| | String | A single text value. Supports the full operator set including substring, prefix, suffix, and proximity. | All operators | Yes | | Long | A 64-bit integer. NOT compatible with string operators like contains or startswith. | =, !=, <, <=, >, >=, in, notin | Yes | | DateTime | A Long field storing timestamps as epoch milliseconds. Use < and > for time-range queries. | =, !=, <, <=, >, >=, in, notin | Yes | | JSONObject | A container object with child fields accessed via dot-notation. Cannot filter directly — navigate to leaf children. | Container only | No | | JSONArray | An array of objects. Searching matches if ANY element satisfies the condition. | Container only | No | | String[] | A flat array of string values. Matches if ANY element matches. | contains, notcontains, spanNear | No | | Long[] | A flat array of integer values. | =, !=, <, <=, >, >= | No | **Note:** Fields marked `Groupby = Yes` can be used in aggregation queries (e.g., count by, top values). ### 5.2 Search Operators | Operator | Applies To | Description | Example | |---|---|---|---| | = / != | String, Long, DateTime | Exact match / not equal | `class_name = "File Activity"` | | < / <= / > / >= | Long, DateTime, String (lexicographic) | Range comparison | `traffic.bytes >= 5000000` | | in / notin | String, Long | List membership (comma-separated) | `activity_id in 1,2,3` | | contains / notcontains | String, String[] | Substring match or array element match | `file.path contains "AppData"` | | startswith / notstartswith | String | Prefix match | `file.path startswith "C:\Users\"` | | endswith / notendswith | String | Suffix match | `file.name endswith ".ps1"` | | spanNear | String, String[] | Proximity search — terms appear near each other | `actor.process.cmd_line spanNear ("powershell","hidden")` | spanNear syntax: ```text field spanNear ("term1","term2"[,distance[,ordered]]) ``` ### 5.3 Combining Operators (Boolean Logic) Use `and`, `or`, and `and not` to combine filter conditions. Use parentheses to control precedence. ```text class_name = "Process Activity" and actor.process.user.type_id = 3 and process.name = "powershell.exe" class_name = "File Activity" and (file.ext = "exe" or file.ext = "ps1") and file.path contains "Temp" class_name = "Authentication" and status_id = 2 and not src_endpoint.ip = "192.168.1.10" ``` ### 5.4 DateTime Fields Reference All timestamp fields store time as epoch milliseconds (milliseconds since January 1, 1970 UTC). | Field | Event Classes | |---|---| | time | ALL | | actor.process.created_time | ALL | | actor.process.parent_process.created_time | File, DNS, Registry, Network, Auth | | process.created_time | Process Activity | | process.parent_process.created_time | Process Activity | | query_time | DNS Activity | | metadata.original_time | ALL | Time-range query patterns: ```text # Events in a specific 24-hour window: time >= 1704067200000 and time < 1704153600000 # Events after a specific time: time > 1735600000000 # Filter by process creation window: actor.process.created_time >= 1704067200000 and actor.process.created_time < 1704153600000 # DNS queries in a time range: class_name = "DNS Activity" and query_time >= 1704067200000 and query_time < 1704153600000 ``` The `timezone_offset` field contains the device's UTC offset in minutes. The `time` field itself is always normalized to UTC epoch milliseconds. ## 6. Field Glossary Each field is described individually below, organized by category. ### 6.1 Classification Fields These fields tell you what kind of event this is. | Field | Type | Present In | Description | |---|---|---|---| | class_uid | integer | All events | Unique identifier for the event class. Values: 1007=Process, 1001=File, 201001=Reg Key, 201002=Reg Value, 4001=Network, 4003=DNS, 3002=Auth, 1005=Module | | class_name | string | All events | Human-readable name. Example: "Process Activity", "File Activity", "DNS Activity" | | type_uid | integer | All events | Specific event type within the class. Encodes both class and activity. See Section 7.4. | | type_name | string | All events | Human-readable. Example: "Process Activity: Launch", "File System Activity: Delete" | | activity_id | integer | All events | Specific activity within the event class. See Section 7.1. | | activity_name | string | All events | Human-readable. Example: "Launch", "Terminate", "Update", "Delete" | | category_uid | integer | All events | High-level category. 0=Unknown, 1=System Activity, 3=Identity & Access Mgmt, 4=Network Activity | | category_name | string | All events | Human-readable. Example: "System Activity", "Network Activity" | | severity_id | integer | All events | 0=Unknown, 1=Informational, 2=Low, 3=Medium, 4=High, 5=Critical, 6=Fatal | | severity | string | All events | Human-readable severity. Example: "Informational", "Low", "High" | ### 6.2 Metadata Fields The metadata object identifies the product and schema version. | Field | Type | Description | Example | |---|---|---|---| | metadata.product.name | string | Product name | "Endpoint Central" | | metadata.product.vendor_name | string | Vendor name | "ManageEngine" | | metadata.product.version | string | Installed agent version on the endpoint | "`1.0.63.7`" | | metadata.product.uid | string | Product identifier | "ManageEngine_EDR" | | metadata.log_name | string | Log source name | "ME_EDR_ProcessActivity" | | metadata.log_provider | string | Logging provider | "Endpoint Central" | | metadata.version | string | OCSF schema version | "1.3.0" | | metadata.tenant_uid | string | Tenant unique identifier (same as zaaid) | | ### 6.3 Device Fields The device object describes which endpoint generated the event. | Field | Type | Description | Example | |---|---|---|---| | device.hostname | string | DNS hostname of the machine | "WORKSTATION-01" | | device.ip | string | Primary IPv4 address | "`192.168.1.100`" | | device.uid | string | Unique device identifier (UUID) | | | device.type_id | integer | Device type identifier. See Section 7.8. | | | device.os.type_id | integer | Operating system type. See Section 7.7. | | | device.os.version | string | Full OS version string | "Microsoft Windows 11 Pro" | ### 6.4 Endpoint Identifier Fields These numeric IDs link the event to your management infrastructure. | Field | Type | Description | |---|---|---| | componentid | string (numeric) | Unique identifier for this specific endpoint agent installation. Use this to filter all events from a single machine. | | customerid | string (numeric) | Customer/organization identifier within the management platform. | | resourceid | string (numeric) | Resource identifier within the management platform. Correlate with your asset management inventory. | | zoid | integer | Zone/office identifier. Use this to filter by site or office location. | | zaaid | integer | Account area identifier (tenant). Same value as metadata.tenant_uid. | | batch_id | string | Identifier of the batch this event was delivered in. Format: `__`. | ### 6.5 Status Fields | Field | Type | Description | Example | |---|---|---|---| | status_id | integer | Normalized outcome. 0=Unknown, 1=Success, 2=Failure, 99=Other | | | status | string | Human-readable outcome | "Success", "Failure" | | status_code | string | Numeric status code from the event source | "0" | | status_detail | string | Detailed status description | "Launch Success", "DNS Query Failed" | | message | string | Human-readable summary of what happened | "Process was launched" | ### 6.6 Observable Fields The observables array provides an at-a-glance summary of the event. | Field | Type | Description | |---|---|---| | observables | array of objects | Quick summary of observable artifacts in the event. | | observables[].type_id | integer | Observable type. See Section 7.20. | | observables[].type | string | Human-readable type name. For registry events: "Registry". For auth events: "User". | | observables[].name | string | The observable value or description. | Common `observables.name` values by event class: | observables.name | Event Class / Activity | |---|---| | Process Launch Event | Process Activity, activity_id = 1 | | Process Terminate Event | Process Activity, activity_id = 2 | | File Create Event | File Activity, activity_id = 6 | | File Delete Event | File Activity, activity_id = 9 | | File Rename Event | File Activity, activity_id = 10 | | Directory Create Event | File Activity, activity_id = 20 | | Registry Value Modify Event | Registry Value, activity_id = 203 | | Registry Value Delete Event | Registry Value, activity_id = 204 | | Registry Key Modify Event | Registry Key, activity_id = 103 | | Registry Key Delete Event | Registry Key, activity_id = 104 | | Registry Key Security Event | Registry Key, activity_id = 106 | | Network Connection | Network Activity | | DNS Query Event | DNS Activity, activity_id = 401 | | DNS Response Event | DNS Activity, activity_id = 402 | | `` | Module Activity, activity_id = 601 | **Tip:** `observables.name` can be used as a quick filter shorthand: ```text observables.name = "File Write Event" and actor.process.name = "powershell.exe" ``` ### 6.7 Time Fields | Field | Type | Description | |---|---|---| | time | integer (epoch ms) | When the event occurred on the endpoint, in milliseconds since Unix epoch (January 1, 1970 UTC). | | timezone_offset | integer | Minutes offset from UTC for the endpoint's local timezone. Example: IST = 330, EST = -300, UTC = 0. | | exit_code | integer | Process exit code. 0 typically means success. Defaults to 0 if not applicable. | ### 6.8 Process Fields (Process Activity Events) These fields appear when `class_uid = 1007` (Process Activity). | Field | Type | Description | |---|---|---| | process.pid | integer | Process ID assigned by Windows. Note: PIDs are reused by the OS. Use process.uid for reliable correlation. | | process.uid | string (UUID) | Globally unique process identifier. Primary key for correlating all events from this process across file, registry, network, and DNS telemetry. Unlike PID, this UUID is never reused. | | process.name | string | Executable file name. Example: "powershell.exe", "svchost.exe" | | process.cmd_line | string | Full command line including all arguments. High-value field — look for encoded commands, unexpected arguments, or living-off-the-land binary usage. | | process.created_time | integer (epoch ms) | When the process was created. Present on Launch events. | | process.terminated_time | integer (epoch ms) | When the process exited. Present on Terminate events. | | process.file | object (File) | File details of the process executable. See Section 6.17. | | process.user | object (User) | The user account under which the process runs. See Section 6.15. | | process.lineage_uid | String[] | Ordered array of ancestor process UUIDs from the immediate parent upward. | | process.parent_process.pid | integer | Parent process ID (PPID). Under PPID spoofing, this is the FAKE parent. | | process.parent_process.uid | string (UUID) | Parent process UUID. | | process.parent_process.name | string | Parent executable file name. | | process.parent_process.cmd_line | string | Parent process command line. | | process.parent_process.file | object (File) | File details of the parent's executable. | | process.parent_process.user | object (User) | User account of the parent process. | | process.file.company_name | string | Company name from the executable's PE header. | | process.file.version | string | Product version from the PE header. | | process.file.size | long | File size of the executable in bytes. | | process.file.accessed_time | datetime (epoch ms) | Last access time. | | process.file.modified_time | datetime (epoch ms) | Last modification time. | | process.file.created_time | datetime (epoch ms) | Creation time. | | actor.process | object (Process) | The real initiator. Same sub-fields: pid, uid, name, cmd_line, created_time, file, user. | **Tip:** Compare `actor.process.pid` with `process.parent_process.pid`. If they differ, PPID spoofing is occurring. #### Understanding process.lineage_uid: `lineage_uid` is an ordered array of ancestor process UUIDs that lets you trace the full parentage chain without querying each parent individually. ```text explorer.exe (uid: AAA) → cmd.exe (uid: BBB) → powershell.exe (uid: CCC) → updater.exe (uid: DDD) ``` The Process Launch event for updater.exe would contain: ```text process.uid = "DDD" ← updater.exe itself process.lineage_uid = ["CCC", ← index 0: parent (powershell.exe) "BBB", ← index 1: grandparent (cmd.exe) "AAA"] ← index 2: great-grandparent (explorer.exe) ``` To find all events from any descendant of cmd.exe (BBB): ```text actor.process.lineage_uid contains "BBB" ``` ### 6.9 File Fields (File Activity Events) These fields appear when `class_uid = 1001` (File Activity). | Field | Type | Description | |---|---|---| | file.path | string | Full file path. Example: "C:\Users\Admin\Documents\report.docx" | | file.name | string | File name only (without directory path). Example: "report.docx" | | file.ext | string | File extension without the leading dot. Example: "docx", "exe" | | file.type_id | integer | File type identifier. See Section 7.10. | | file_result | object (File) | The file state after the operation. Most useful on Rename events. | | actor.process | object (Process) | The process that performed the file operation. | | is_remote | boolean | True if the file operation was performed over a remote connection (e.g., SMB/network share). When true, src_endpoint.ip identifies the remote machine that performed the file operation. Only present when is_remote = true. | #### Understanding file vs file_result: `file` is the file before the operation. `file_result` is the file after the operation. For most activities (Create, Write, Delete), both are the same. The distinction matters on Rename events. **Example — Rename event (activity_id = 10):** ```text file.path = "C:\Users\Admin\Documents\report.docx" ← BEFORE rename file.name = "report.docx" file.ext = "docx" file_result.path = "C:\Users\Admin\Documents\report.locked" ← AFTER rename file_result.name = "report.locked" file_result.ext = "locked" ``` **Example — Write event (activity_id = 8):** ```text file.path = "C:\Users\Admin\Downloads\payload.exe" ← The file being written file_result.path = "C:\Users\Admin\Downloads\payload.exe" ← Same as file (no change) ``` **Tip:** Compare `file.ext` vs `file_result.ext` on Rename events. If extensions change unexpectedly (e.g., `.docx` → `.locked`, `.xlsx` → `.encrypted`), this pattern is worth investigating. **Tip:** Filter `is_remote = true` to find file operations originating from other machines on the network (e.g., lateral movement via SMB). ### 6.10 Registry Fields (Registry Activity Events) These fields appear when `class_uid = 201001` (Registry Key Activity) or `class_uid = 201002` (Registry Value Activity). | Field | Type | Description | |---|---|---| | reg_key.path | string | Full registry key path. Example: "\registry\machine\software\microsoft\windows\currentversion\run" | | reg_value.name | string | Name of the registry value. Example: "SecurityHealth" | | reg_value.path | string | Full registry key path where this value is located. | | reg_value.type_id | integer | Windows registry value data type. See Section 7.14. | | reg_value.type | string | Human-readable type name. Example: "REG_SZ", "REG_DWORD" | | reg_value.reg_string_data | string | Data content for REG_SZ, REG_EXPAND_SZ, or REG_LINK types. | | reg_value.reg_integer_data | integer | Data content for REG_DWORD, REG_DWORD_BIG_ENDIAN, or REG_QWORD types. | | reg_value.reg_binary_data | string (base64) | Data content for REG_BINARY or REG_NONE types. | | reg_value.reg_string_list_data | array of strings | Data content for REG_MULTI_SZ type. | | prev_reg_key | string | Previous registry key path before a rename operation. | **Tip:** Review registry writes to persistence locations (Run, RunOnce, Services, Image File Execution Options) where `actor.process.name` is unexpected. ### 6.11 Network Fields (Network Activity Events) These fields appear when `class_uid = 4001` (Network Activity). | Field | Type | Description | |---|---|---| | src_endpoint.ip | string | Source IP address. See direction examples below. | | src_endpoint.port | integer | Source port number. | | dst_endpoint.ip | string | Destination IP address. See direction examples below. | | dst_endpoint.port | integer | Destination port number. | | connection_info.direction_id | integer | Connection direction. See Section 7.17. | | connection_info.direction | string | Human-readable direction: "Inbound", "Outbound", "Unknown". | | connection_info.protocol_num | integer | IP protocol number (IANA). 6 = TCP, 17 = UDP. | | connection_info.protocol_name | string | Protocol name: "tcp", "udp". | | connection_info.protocol_ver_id | integer | IP version. 4 = IPv4, 6 = IPv6. | | connection_info.protocol_ver | string | Human-readable IP version: "IPv4", "IPv6". | | traffic.bytes | integer | Total bytes transferred in the connection. | | url.url_string | string | Full URL observed in the network payload, if detected. | #### Understanding src_endpoint and dst_endpoint by direction: | Direction | src_endpoint (source) | dst_endpoint (destination) | |---|---|---| | Outbound (direction_id = 2) | Your endpoint (local machine) | The remote server | | Inbound (direction_id = 1) | The remote machine initiating the connection | Your endpoint (local machine) | | Lateral (direction_id = 3) | One internal machine | Another internal machine | | Local (direction_id = 4) | localhost (`127.0.0.1`) | localhost (`127.0.0.1`) | **Example — Outbound connection (chrome.exe browsing a website):** ```text connection_info.direction_id = 2 (Outbound) src_endpoint.ip = 192.168.1.100 ← Your workstation src_endpoint.port = 52431 ← Ephemeral port assigned by OS dst_endpoint.ip = 142.250.189.206 ← Remote server (e.g., google.com) dst_endpoint.port = 443 ← HTTPS ``` **Example — Inbound connection (remote machine connecting to a local service):** ```text connection_info.direction_id = 1 (Inbound) src_endpoint.ip = 10.0.0.50 ← Remote machine initiating the connection src_endpoint.port = 49832 ← Remote ephemeral port dst_endpoint.ip = 192.168.1.100 ← Your workstation (receiving the connection) dst_endpoint.port = 445 ← SMB port on your machine ``` **Note:** For outbound traffic, filter on `dst_endpoint.ip` and `dst_endpoint.port` to find what your machines are talking to. For inbound traffic, filter on `src_endpoint.ip` to find who is connecting to your machines. ### 6.12 DNS Fields (DNS Activity Events) These fields appear when `class_uid = 4003` (DNS Activity). | Field | Type | Description | |---|---|---| | query.hostname | string | The domain name being queried. Example: "www.example.com" | | query.opcode_id | integer | DNS opcode. See Section 7.15. | | query_time | integer (epoch ms) | When the DNS query was made. | | answers | array of objects | DNS answer records. Only present on DNS Response events (activity_id = 402). | | answers[].rdata | string | The response data (IP address, CNAME, etc.). Example: "`93.184.216.34`" | | rcode_id | integer | DNS response code. See Section 7.16. | | rcode | string | Human-readable DNS response code: "NoError", "NXDomain", etc. | **Tip:** High rates of `rcode_id = 3` (NXDomain) from a single process is noteworthy and worth investigating. #### Network connection fields in DNS events: DNS events also include the underlying network connection details: | Field | Type | Description | |---|---|---| | src_endpoint.ip | string | Source IP of the DNS connection. For outbound queries, this is the local machine. | | src_endpoint.port | integer | Source port of the DNS connection. | | dst_endpoint.ip | string | Destination IP. For outbound queries, this is the DNS server address. | | dst_endpoint.port | integer | Destination port (typically 53 for standard DNS). | | connection_info.direction_id | integer | Same values as Network Activity (0=Unknown, 1=Inbound, 2=Outbound). | | connection_info.protocol_num | integer | IANA protocol number (typically 17=UDP or 6=TCP for DNS). | | connection_info.protocol_name | string | Protocol name: "udp" or "tcp". | | connection_info.protocol_ver_id | integer | IP version: 4=IPv4, 6=IPv6. | **Tip:** Use `dst_endpoint.ip` to identify which DNS server resolved the query. ### 6.13 Authentication Fields These fields appear when `class_uid = 3002` (Authentication). | Field | Type | Description | |---|---|---| | user (top-level) | object (User) | The target user — the account being logged into. | | actor.user | object (User) | The subject/initiator — the account that initiated the logon. | | actor.user.domain | string | Domain of the actor user. Example: "WORKGROUP", "CONTOSO" | | logon_type_id | integer | Windows logon type. See Section 7.12. | | logon_type | string | Human-readable logon type: "Interactive", "Network", etc. | | auth_protocol_id | integer | Authentication protocol. See Section 7.13. | | auth_protocol | string | Protocol name: "NTLM", "Kerberos", "Negotiate", etc. | | session.uid | string | Windows Logon Session ID. Well-known values: 0x3E7 = SYSTEM, 0x3E4 = NETWORK SERVICE, 0x3E5 = LOCAL SERVICE. | | is_remote | boolean | True if the logon originated from a remote machine. | | src_endpoint.ip | string | Source IP of the logon attempt for remote logons. Value is "-" for local logons. | **Tip:** `auth_protocol_id = 1` (NTLM) on Network logons is noteworthy, especially in Kerberos-enabled environments. **Tip:** Filter `is_remote = true` with `logon_type_id` 3 or 10 to identify remote sessions. ### 6.14 Finding Info Fields (Behavioral Detections) When the EDR behavioral detection engine identifies noteworthy behavior, a `finding_info` object is attached to the event. Events with findings have their `severity_id` elevated from 1 (Informational) to 2 (Low) or higher. | Field | Type | Description | |---|---|---| | finding_info.uid | string | Unique identifier for this detection rule. | | finding_info.title | string | Human-readable name. Example: "PowerShell Encoded Command Detected" | | finding_info.desc | string | Description of what was detected and why. | | finding_info.types | array of strings | Finding categories. Typically ["behaviour", "detection"]. | | finding_info.created_time | integer (epoch ms) | When the detection was triggered. | | finding_info.src_url | string | URL to the MITRE ATT&CK technique page (when applicable). | | finding_info.analytic.uid | string | Detection rule identifier. | | finding_info.analytic.name | string | Detection rule name. | | finding_info.analytic.type_id | integer | Analytic type. 1 = Rule-based. | | finding_info.analytic.category | string | "behaviour" | | finding_info.analytic.version | string | Rule version for tracking rule updates. | | finding_info.attacks[].tactic.uid | string | MITRE ATT&CK Tactic ID. Example: "TA0002" (Execution) | | finding_info.attacks[].tactic.name | string | MITRE ATT&CK Tactic name. Example: "Execution", "Persistence" | | finding_info.attacks[].technique.uid | string | MITRE ATT&CK Technique ID. Example: "T1059.001" (PowerShell) | | finding_info.attacks[].technique.name | string | MITRE ATT&CK Technique name. Example: "PowerShell" | | finding_info.attacks[].version | string | MITRE ATT&CK framework version. Example: "15.1" | ### 6.15 User Object Fields User objects appear in `process.user`, `actor.process.user`, `actor.user`, and the top-level `user` field. | Field | Type | Description | Example | |---|---|---|---| | user.uid | string | Windows SID (Security Identifier) | "S-1-5-18" (SYSTEM) | | user.name | string | Username | "SYSTEM", "Administrator", "john.doe" | | user.type_id | integer | Account type. 0=Unknown, 1=User, 2=Admin, 3=System | | | user.type | string | Human-readable type: "User", "Admin", "System" | | | user.domain | string | Domain name. Present primarily in authentication events. | "CONTOSO", "NT AUTHORITY" | ### 6.16 Hash Object Fields Hash arrays appear inside File objects (`process.file.hashes`, `actor.process.file.hashes`). | Field | Type | Description | |---|---|---| | hashes[].algorithm_id | integer | Hash algorithm. 0=Unknown, 1=MD5, 2=SHA-1, 3=SHA-256 | | hashes[].algorithm | string | Algorithm name: "MD5", "SHA-1", "SHA256" | | hashes[].value | string | The hex-encoded hash value. | ### 6.17 File Object Fields (Executable Metadata) When a File object represents a process executable (`process.file`, `actor.process.file`), it contains rich metadata from the PE header. | Field | Type | Description | |---|---|---| | file.path | string | Full file path of the executable. | | file.name | string | File name of the executable. | | file.ext | string | Extension without the dot. | | file.sha256 | string | SHA-256 hash. Convenience field so you can query without traversing the hashes array. | | file.size | integer | File size in bytes. | | file.version | string | Product version from the PE file header. | | file.company_name | string | Company name from the PE file header. | | file.accessed_time | integer (epoch ms) | Last access time. | | file.modified_time | integer (epoch ms) | Last write/modification time. | | file.created_time | integer (epoch ms) | File creation time. | **Tip:** A `svchost.exe` with `company_name` not equal to "Microsoft Corporation" is worth investigating. ### 6.18 Module Fields (Module Activity Events) These fields appear when `class_uid = 1005` (Module Activity). | Field | Type | Description | |---|---|---| | module.load_type_id | integer | How the module was loaded. 1 = Standard (loaded via LoadLibrary or normal OS mechanism). | | module.load_type | string | Human-readable load type: "Standard". | | module.file.path | string | Full file path of the loaded module (DLL/shared library). Example: "C:\Windows\System32\ntdll.dll" | | module.file.name | string | File name of the loaded module. Example: "ntdll.dll" | | module.file.ext | string | Extension of the module file. Example: "dll" | | module.file.type_id | integer | File type. Always 1 (Regular File). | | module.file.sha1 | string | SHA-1 hash of the module file. | | module.file.hashes[] | array of Hash objects | Hash array for the module. Contains SHA-1 hash (algorithm_id = 2). | | actor.process | object (Process) | The process that loaded the module. Contains pid, uid, name, cmd_line, file, user, and parent_process. | **Tip:** Unexpected DLLs loaded by system processes may indicate DLL sideloading or injection. ## 7. Complete Enum Reference Quick-reference for all enumerated (`_id`) fields. ### 7.1 activity_id — Event Activity Values are class-specific. #### Process Activity (class_uid = 1007): | Value | Meaning | |---|---| | 0 | Unknown | | 1 | Launch | | 2 | Terminate | | 99 | Other | #### File Activity (class_uid = 1001): | Value | Meaning | |---|---| | 0 | Unknown | | 6 | Create | | 7 | Read | | 8 | Update (Write) | | 9 | Delete | | 10 | Rename | | 20 | Directory Create | | 99 | Other | #### Registry Key Activity (class_uid = 201001): | Value | Meaning | |---|---| | 100 | Unknown | | 101 | Create | | 104 | Delete | | 105 | Rename | | 106 | Set Security | #### Registry Value Activity (class_uid = 201002): | Value | Meaning | |---|---| | 203 | Modify | | 204 | Delete | #### Network Activity (class_uid = 4001): | Value | Meaning | |---|---| | 306 | Traffic | #### DNS Activity (class_uid = 4003): | Value | Meaning | |---|---| | 401 | Query | | 402 | Response | #### Authentication (class_uid = 3002): | Value | Meaning | |---|---| | 501 | Logon | #### Module Activity (class_uid = 1005): | Value | Meaning | |---|---| | 601 | Load | ### 7.2 class_uid — Event Class | Value | Meaning | |---|---| | 1001 | File Activity | | 1005 | Module Activity | | 1007 | Process Activity | | 3002 | Authentication | | 4001 | Network Activity | | 4003 | DNS Activity | | 201001 | Registry Key Activity | | 201002 | Registry Value Activity | ### 7.3 category_uid — Event Category | Value | Meaning | |---|---| | 1 | System Activity (Process, File, Registry events) | | 3 | Identity & Access Mgmt (Authentication events) | ### 7.4 type_uid — Composite Event Type Encodes class + activity into a single identifier. #### Process: | Value | Meaning | |---|---| | 100701 | Process Activity: Launch | | 100702 | Process Activity: Terminate | #### File: | Value | Meaning | |---|---| | 100100 | File System Activity: Unknown | | 100101 | File System Activity: Create | | 100102 | File System Activity: Read | | 100103 | File System Activity: Update | | 100104 | File System Activity: Delete | | 100105 | File System Activity: Rename | | 100115 | File System Activity: Directory Create | #### Registry Key: | Value | Meaning | |---|---| | 20100100 | Registry Key Activity: Unknown | | 20100101 | Registry Key Activity: Create | | 20100104 | Registry Key Activity: Delete | | 20100105 | Registry Key Activity: Rename | | 20100106 | Registry Key Activity: Set Security | #### Registry Value: | Value | Meaning | |---|---| | 20100203 | Registry Value Activity: Modify | | 20100204 | Registry Value Activity: Delete | #### Network: | Value | Meaning | |---|---| | 400106 | Network Activity: Traffic | #### DNS: | Value | Meaning | |---|---| | 400301 | DNS Activity: Query | | 400302 | DNS Activity: Response | #### Authentication: | Value | Meaning | |---|---| | 300201 | Authentication: Logon | #### Module: | Value | Meaning | |---|---| | 100501 | Module Activity: Load | ### 7.5 severity_id — Event Severity | Value | Meaning | |---|---| | 0 | Unknown | | 1 | Informational | | 2 | Low | | 3 | Medium | | 4 | High | | 5 | Critical | | 6 | Fatal | ### 7.6 status_id — Activity Status | Value | Meaning | |---|---| | 0 | Unknown | | 1 | Success | | 2 | Failure | | 99 | Other | ### 7.7 device.os.type_id — Operating System Type | Value | Meaning | |---|---| | 0 | Unknown | | 100 | Windows | | 200 | Linux | | 300 | macOS | ### 7.8 device.type_id — Device Type | Value | Meaning | |---|---| | 0 | Unknown | | 2 | Desktop | | 3 | Laptop | | 5 | Tablet | | 6 | Mobile | ### 7.9 user.type_id — User Account Type Applies to: `actor.user.type_id`, `actor.process.user.type_id`, `actor.process.parent_process.user.type_id`, `process.user.type_id`, `process.parent_process.user.type_id`. | Value | Meaning | |---|---| | 0 | Unknown | | 1 | User (regular account) | | 2 | Admin (elevated/admin account) | | 3 | System (e.g., Windows SYSTEM or computer account with $) | ### 7.10 file.type_id — File Type | Value | Meaning | |---|---| | 0 | Unknown | | 1 | Regular File | | 2 | Folder | | 3 | Character Device | | 4 | Block Device | | 5 | Local Socket | | 6 | Named Pipe | | 7 | Symbolic Link | | 99 | Other | ### 7.11 hashes.algorithm_id — Hash Algorithm Applies to: `file.hashes`, `actor.process.file.hashes`, `process.file.hashes`. | Value | Meaning | |---|---| | 0 | Unknown | | 1 | MD5 | | 2 | SHA-1 | | 3 | SHA-256 | ### 7.12 logon_type_id — Windows Logon Type Applies to: Authentication events (`class_uid = 3002`). | Value | Meaning | |---|---| | 0 | Unknown | | 1 | System (System account startup) | | 2 | Interactive (Local console logon) | | 3 | Network (Logon from the network) | | 4 | Batch (Batch/scheduled task) | | 5 | Service (Service/daemon startup) | | 7 | Unlock (Workstation unlock) | | 8 | NetworkCleartext (Network with unhashed password) | | 9 | NewCredentials (Cloned token, new credentials) | | 10 | RemoteInteractive (Terminal Services / RDP) | | 11 | CachedInteractive (Cached domain credentials) | | 12 | CachedRemoteInteractive (Internal audit variant of 10) | | 13 | CachedUnlock (Cached unlock) | | 99 | Other | **Note:** Logon type 6 is not used by Windows. ### 7.13 auth_protocol_id — Authentication Protocol Applies to: Authentication events (`class_uid = 3002`). | Value | Meaning | |---|---| | 0 | Unknown | | 1 | NTLM | | 2 | Kerberos | | 3 | Digest | | 12 | LDAP | ### 7.14 reg_value.type_id — Registry Value Type Applies to: `reg_value.type_id` in Registry Value Activity events. Matches the Windows `REG_*` constants. | Value | Meaning | |---|---| | 0 | REG_NONE | | 1 | REG_SZ | | 2 | REG_EXPAND_SZ | | 3 | REG_BINARY | | 4 | REG_DWORD | | 5 | REG_DWORD_BIG_ENDIAN | | 6 | REG_LINK | | 7 | REG_MULTI_SZ | | 8 | REG_RESOURCE_LIST | | 9 | REG_FULL_RESOURCE_DESCRIPTOR | | 10 | REG_RESOURCE_REQUIREMENTS_LIST | | 11 | REG_QWORD | ### 7.15 query.opcode_id — DNS Operation Code Applies to: DNS Activity events (`class_uid = 4003`). | Value | Meaning | |---|---| | 0 | Query | | 1 | Inverse Query | | 2 | Status | | 3 | Reserved | | 4 | Notify | | 5 | Update | | 6 | DSO Message | ### 7.16 rcode_id — DNS Response Code Applies to: DNS Activity response events. | Value | Meaning | |---|---| | 0 | NoError — successful resolution | | 1 | FormError — query format error | | 2 | ServError — DNS server failure | | 3 | NXDomain — non-existent domain | | 4 | NotImp — not implemented | | 5 | Refused — query refused | | 6 | YXDomain — name should not exist but does | | 7 | YXRRSet — RR set should not exist but does | | 8 | NXRRSet — required RR set does not exist | | 9 | NotAuth — not authoritative | | 10 | NotZone — name not in zone | | 11 | DSOTYPENI — DSO-TYPE not implemented | | 99 | Other — unmapped response code | ### 7.17 connection_info.direction_id — Connection Direction | Value | Meaning | |---|---| | 0 | Unknown | | 1 | Inbound | | 2 | Outbound | | 3 | Lateral | | 4 | Local | ### 7.18 connection_info.protocol_num — Network Protocol (IANA) IANA protocol numbers for network connections: | Value | Meaning | |---|---| | 0 | HOPOPT | | 1 | ICMP | | 6 | TCP | | 17 | UDP | | 58 | ICMPv6 | ### 7.19 connection_info.protocol_ver_id — IP Version | Value | Meaning | |---|---| | 4 | IPv4 | | 6 | IPv6 | ### 7.20 observables.type_id — Observable Type | Value | Meaning | |---|---| | 0 | Unknown | | 1 | Hostname | | 2 | IP Address | | 24 | File | | 25 | Process | | 99 | Other | ### 7.21 module.load_type_id — Module Load Type Applies to: Module Activity events (`class_uid = 1005`). | Value | Meaning | |---|---| | 1 | Standard — loaded via LoadLibrary or normal OS mechanism | ## 8. Investigation Query Patterns ### Identifying PPID Spoofing ```text Filter: class_uid = 1007 AND activity_id = 1 Condition: actor.process.pid != process.parent_process.pid ``` If the real parent (actor) differs from the claimed parent (`parent_process`), the process is performing PPID spoofing. ### Identifying Unexpected File Extension Changes ```text Filter: class_uid = 1001 AND activity_id = 10 (Rename) Condition: file.ext IN ("docx","xlsx","pdf","jpg","png","pptx") AND file_result.ext NOT IN known extensions ``` Look for mass file renames where the extension changes to something unexpected (e.g., `.locked`, `.encrypted`, `.crypt`). ### Reviewing Registry Persistence Entries ```text Filter: class_uid = 201002 AND activity_id IN (201, 203) Condition: reg_value.path CONTAINS "CurrentVersion\Run" ``` Review `actor.process.name` — legitimate writes come from installers, Group Policy, or known system processes. Other writers are worth reviewing. ### Identifying High-Volume NXDomain Patterns ```text Filter: class_uid = 4003 AND rcode_id = 3 (NXDomain) Group by: actor.process.uid Condition: COUNT > 50 within 5 minutes ``` A single process generating many NXDomain responses is unusual and worth investigating. ### Reviewing Remote Authentication Sessions ```text Filter: class_uid = 3002 AND activity_id = 501 (Logon) Condition: logon_type_id IN (3, 10) AND is_remote = true ``` Review `src_endpoint.ip` for unexpected sources. Check for `auth_protocol_id = 1` (NTLM) in Kerberos-enabled environments. ### Reviewing Unusual Outbound Connections ```text Filter: class_uid = 4001 AND connection_info.direction_id = 2 Condition: actor.process.name NOT IN known browsers/services AND dst_endpoint.port NOT IN (80, 443) ``` Non-browser processes connecting to unusual ports on external IPs are worth reviewing. ### Tracing a Full Activity Chain 1. Start with a `process.uid` of interest from any event. 2. Find the Process Launch event: ```text class_uid = 1007 AND activity_id = 1 AND process.uid = "" ``` 3. Get `actor.process.uid` — this is the real parent. 4. Use `process.lineage_uid` for up to 5 ancestor UUIDs. 5. Search file/registry/network/DNS events where `actor.process.uid` matches any process in the chain. ## 9. Search Examples by Event Class Practical query examples organized by event class. ### 9.1 File Activity Examples Find executables written to Temp by scripting engines: ```text class_name = "File Activity" and activity_id in 6,8 and file.ext in "exe","dll","ps1","bat","vbs","js" and file.path contains "Temp" and actor.process.name in "powershell.exe","wscript.exe","cscript.exe","cmd.exe" ``` Find files written to startup folders: ```text class_name = "File Activity" and activity_id in 6,8 and file.path contains "\Microsoft\Windows\Start Menu\Programs\Startup" ``` Find files renamed with unexpected extension change: ```text class_name = "File Activity" and activity_id = 10 and file.ext = "exe" and file_result.ext != "exe" ``` Track a file by SHA-256: ```text class_name = "File Activity" and file.sha256 = "your-sha256-hash-here" ``` Find double-extension files (e.g., invoice.pdf.exe): ```text class_name = "File Activity" and file.name contains ".pdf.exe" ``` Find files written by PowerShell: ```text class_name = "File Activity" and activity_id = 8 and actor.process.name = "powershell.exe" ``` ### 9.2 Process Activity Examples Find PowerShell running as SYSTEM: ```text class_name = "Process Activity" and activity_id = 1 and process.name = "powershell.exe" and process.user.type_id = 3 ``` Find cmd.exe spawned by Office applications: ```text class_name = "Process Activity" and activity_id = 1 and process.name in "cmd.exe","powershell.exe","wscript.exe","cscript.exe" and actor.process.name in "winword.exe","excel.exe","powerpnt.exe","outlook.exe" ``` Find encoded PowerShell commands: ```text class_name = "Process Activity" and activity_id = 1 and process.name = "powershell.exe" and (process.cmd_line contains "-encodedcommand" or process.cmd_line contains "-enc ") ``` Find processes launched from Temp directories: ```text class_name = "Process Activity" and activity_id = 1 and process.file.path contains "Temp" ``` Find living-off-the-land binary (LOLBin) usage: ```text class_name = "Process Activity" and activity_id = 1 and process.name in "certutil.exe","regsvr32.exe","mshta.exe","wmic.exe", "rundll32.exe","bitsadmin.exe" ``` Hunt command lines with proximity search: ```text actor.process.cmd_line spanNear ("powershell","hidden",10,false) actor.process.cmd_line spanNear ("certutil","decode",5,true) ``` ### 9.3 Network Activity Examples Find outbound TCP connections to non-standard ports: ```text class_name = "Network Activity" and connection_info.protocol_name = "tcp" and connection_info.direction_id = 2 and dst_endpoint.port notin 80,443,53,22,25,587,8080,8443 ``` Find large data transfers: ```text class_name = "Network Activity" and traffic.bytes > 50000000 ``` Find connections to a specific IP: ```text class_name = "Network Activity" and dst_endpoint.ip = "203.0.113.42" ``` Find connections from PowerShell: ```text class_name = "Network Activity" and actor.process.name = "powershell.exe" ``` Find inbound connections: ```text class_name = "Network Activity" and connection_info.direction_id = 1 ``` Find connections over ICMP: ```text class_name = "Network Activity" and connection_info.protocol_num = 1 ``` ### 9.4 DNS Activity Examples Find NXDomain responses: ```text class_name = "DNS Activity" and rcode_id = 3 ``` Find queries for a specific domain: ```text class_name = "DNS Activity" and query.hostname contains "example.com" ``` Find queries by domain suffix: ```text class_name = "DNS Activity" and query.hostname endswith ".xyz" ``` Find queries where the resolved IP matches a known indicator: ```text class_name = "DNS Activity" and answers.rdata contains "203.0.113.42" ``` Find DNS queries from non-browser processes: ```text class_name = "DNS Activity" and actor.process.name notin "svchost.exe","chrome.exe","firefox.exe","msedge.exe" ``` Find DNS queries using TCP (possible tunneling): ```text class_name = "DNS Activity" and connection_info.protocol_name = "tcp" ``` ### 9.5 Registry Activity Examples Find modifications to Run keys: ```text class_name = "Registry Value Activity" and activity_id = 203 and reg_value.path contains "CurrentVersion\Run" ``` Find registry modifications by scripting engines: ```text class_name = "Registry Value Activity" and activity_id = 203 and actor.process.name in "powershell.exe","wscript.exe","cscript.exe","cmd.exe" ``` Find Image File Execution Options modifications: ```text class_name = "Registry Value Activity" and activity_id = 203 and reg_value.path contains "Image File Execution Options" ``` Find registry key deletions: ```text class_name = "Registry Key Activity" and activity_id = 104 ``` Find registry key security changes: ```text class_name = "Registry Key Activity" and activity_id = 106 ``` Find registry modifications from non-System32 processes: ```text class_name = "Registry Value Activity" and activity_id = 203 and actor.process.file.path notcontains "System32" and actor.process.file.path notcontains "Program Files" ``` ### 9.6 Authentication Examples Find failed logon attempts: ```text class_name = "Authentication" and status_id = 2 ``` Find failed logons by a specific user: ```text class_name = "Authentication" and status_id = 2 and actor.user.name = "administrator" ``` Find remote logon sessions: ```text class_name = "Authentication" and is_remote = true ``` Find service-type logons: ```text class_name = "Authentication" and logon_type_id = 5 ``` Find System account logons: ```text class_name = "Authentication" and status_id = 1 and user.type_id = 3 ``` Find logons using a specific authentication protocol: ```text class_name = "Authentication" and auth_protocol_id = 2 ``` ### 9.7 Module Activity Example Find modules loaded by PowerShell: ```text class_name = "Module Activity" and actor.process.name = "powershell.exe" ``` ## 10. Advanced Correlation Techniques This section covers techniques for reconstructing process trees and correlating events across classes. ### 10.1 Cross-Event Correlation Using actor.process.uid `actor.process.uid` is a unique identifier for a specific process instance. It does not repeat across process restarts. Use it as a pivot to gather all telemetry from a single process. Step 1: Find the process UID. ```text class_name = "Process Activity" and activity_id = 1 and process.name = "target-process.exe" ``` Capture `process.uid` from the result. Step 2: Gather all activity by that process instance. ```text actor.process.uid = "the-captured-uid" ``` This spans all event classes and returns everything that process did: files it touched, registry keys it modified, DNS queries it made, and network connections it opened. ### 10.2 Process Tree Reconstruction via lineage_uid `lineage_uid` is a String[] field present on both `actor.process` and `process` (Process Activity only). It contains an ordered array of process UIDs representing the full ancestry chain. ```text actor.process.lineage_uid = ["root-uid", "svchost-uid", "parent-uid"] ``` Because `lineage_uid` is a String[], a `contains` search checks whether ANY element in the array matches — meaning you can find all processes that are descendants of a specific ancestor. Step 1: Identify a process UID of interest. ```text class_name = "Process Activity" and process.name = "powershell.exe" and process.cmd_line contains "-encoded" ``` Step 2: Find all events from any descendant process. ```text actor.process.lineage_uid contains "uid-of-interest" ``` This returns File, Network, DNS, Registry, and Authentication events from any process in the descendant tree. ### 10.3 Full Activity Profile of a Single Process Reconstruct the complete activity of a single process across all classes: ```text // All files it touched: class_name = "File Activity" and actor.process.uid = "target-uid" // All network connections it made: class_name = "Network Activity" and actor.process.uid = "target-uid" // All registry operations it performed: class_name = "Registry Value Activity" and actor.process.uid = "target-uid" // All DNS queries it made: class_name = "DNS Activity" and actor.process.uid = "target-uid" ``` Or as a single cross-class query: ```text actor.process.uid = "target-uid" ``` ### 10.4 Useful Starter Query Templates ```text # Scope to a specific event class: class_name = "File Activity" # Filter by device: device.hostname = "WORKSTATION-01" and class_name = "Process Activity" # Filter by time range: time >= 1704067200000 and time < 1704086400000 # Enrich with actor context: class_name = "File Activity" and actor.process.name = "powershell.exe" and actor.process.user.type_id = 3 # Trace all activity by a process UID: actor.process.uid = "your-target-uid" # Reconstruct process tree descendants: actor.process.lineage_uid contains "ancestor-process-uid" # Search for a hash across all event classes: file.hashes.value = "your-sha256-hash" or actor.process.file.hashes.value = "your-sha256-hash" or process.file.hashes.value = "your-sha256-hash" ``` Document version: 3.3 | Schema: OCSF v1.3.0 | Product: Endpoint Central