Retrieves JSON-formatted process hash details for a specific suspicious event, used to power the AI triage detail view. Customer ID and login ID are resolved automatically from the authenticated session.
get /edr/api/ai/triage/{alertId}/details
https://{serverurl}/edr/api/ai/triage/{alertId}/details Copied!
Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52
Unique identifier of the suspicious event whose process hash details are to be retrieved. Get alertId from Get Alerts details .
curl --request GET \
--url https://appdomains/edr/api/ai/triage/{alertId}/details \
--header 'Accept: application/json' \
--header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52'Outcome of the operation. 'success' or 'failed'.
On success, the process hash detail map for the suspicious event. Absent on failure.
Root node of the suspicious process tree, recursively describing the flagged process and every descendant process spawned as part of the alert chain.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Whether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Whether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Unique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Whether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Whether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Unique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Whether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Whether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Unique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Unique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.
File/registry operation performed (e.g., 'Create File Map', 'Read'). Present only on event-based behaviour entries.
File path involved in the behaviour/event. Present only on event-based behaviour entries.
MITRE ATT&CK technique name associated with this entry (e.g., 'Credentials_From_Password_Stores'). Absent when not mapped to a MITRE technique.
Display name of the behaviour or alert (e.g., 'Behavior : browser secret stealer', 'Alert : Generating first alert').
Human-readable description of the detected behaviour or alert.
Category of the underlying event (e.g., 'File Event'). Present only on event-based behaviour entries.
MITRE ATT&CK technique ID (e.g., 'T1555'). Absent when not mapped to a MITRE technique.
Detection rule version string (e.g., 'Rule Version : 26080402'). Present only on entries with type 'alertAble'.
'normal' for informational behaviour entries, 'alertAble' for the entry that triggered the alert.
Refer to edrTriageBehaviourEntryWhether the process image is digitally signed.
SHA-256 hash of the process image.
Executable file name of the process (e.g., 'cmd.exe').
Full file system path of the process executable.
Timestamp when the process-start event was recorded (e.g., 'Aug 5, 2026 01:30 PM').
Windows Security Identifier (SID) of the user that started the process.
Windows domain of the user that started the process.
Node classification, e.g. 'normal'.
Full command-line string used to launch the process.
Username of the user that started the process.
Refer to edrTriageProcessNodeDataUnique identifier of the process event represented by this node.
Child process nodes spawned by this process. Absent on leaf nodes with no recorded child processes.
Process identity, execution context, and associated behaviour/alert entries for this node.
Behaviour and alert entries (MITRE-mapped detections, file events, etc.) recorded against this process.