Retrieve process hash details for a specific suspicious event

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

Retrieves JSON-formatted process hash details for a specific suspicious event, used to power the AI triage detail view. Customer ID and login ID are resolved automatically from the authenticated session.

Request URL

https://{serverurl}/edr/api/ai/triage/{alertId}/details Copied!

Scope

DesktopCentralCloud.EDR.READCopied!

Header

Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52

Request Parameters

- Request Headers

AcceptstringMandatory
application/jsonapplication/jsonCopied!

- Path Parameters

alertIdlongMandatory

Unique identifier of the suspicious event whose process hash details are to be retrieved. Get alertId from Get Alerts details .

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request GET \
  --url https://appdomains/edr/api/ai/triage/{alertId}/details \
  --header 'Accept: application/json' \
  --header 'Authorization: Zoho-oauthtoken  d92d4xxxxxxxxxxxxx15f52'

Response Parameters

- HTTP code 200

Response Body - application/json
JSON Object
Hide Sub-Attributes
statusstring

Outcome of the operation. 'success' or 'failed'.

dataJSON Object

On success, the process hash detail map for the suspicious event. Absent on failure.

Show Sub-Attributes
suspiciousProcessTreeJSON Object

Root node of the suspicious process tree, recursively describing the flagged process and every descendant process spawned as part of the alert chain.

Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
behaviourOperationstring

File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.

behaviourFilePathstring

File path involved in the behaviour/event. Present only on event-based behaviour entries.

mitreNamestring

MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.

namestring

Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').

descriptionstring

Human-readable description of the detected behaviour or alert.

behaviourEventTypestring

Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.

mitreIdstring

MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.

ruleVersionstring

Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.

typestring

'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.

Refer to edrTriageBehaviourEntry
isSignedboolean

Whether the process image is digitally signed.

sha256string

SHA-256 hash of the process image.

processNamestring

Executable file name of the process (e.g., 'cmd.exe').

imagePathstring

Full file system path of the process executable.

eventCreatedTimestring

Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').

userSidstring

Windows Security Identifier (SID) of the user that started the process.

userDomainstring

Windows domain of the user that started the process.

typestring

Node classification, e.g. 'normal'.

commandLinestring

Full command-line string used to launch the process.

userNamestring

Username of the user that started the process.

Refer to edrTriageProcessNodeData
process_event_idstring

Unique identifier of the process event represented by this node.

childrenJSON Array

Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.

Show Sub-Attributes
JSON Object
Show Sub-Attributes
dataJSON Object

Process identity, execution context, and associated behaviour/alert entries for this node.

Show Sub-Attributes
processInfoJSON Array

Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.

Show Sub-Attributes