AhnLab EPP

Download 245
Last updated Mar 5, 2024

AhnLab EPP EDR V3 Detect

EDR_V3_DETECT Event

TypeFieldDisplay NameDescription
Date_timeTime
StringseveritySeveritye.g. 6
Stringevent_idEvent ID
IP addresssrc_ipSource IP
Stringsrc_macSource MAC
StringhostnameHostname
StringuserAccount
Stringdept_nameDepartment
Stringuser_nameUser name
StringcategoryCategorye.g. Backdoor
StringsignatureSignaturee.g. Backdoor/EDR.Akdoor
Stringscan_type_textScan typee.g. 빠른 검사
LongppidPPID
LongpidPID
StringimageProcess
Stringfile_nameFile name
Stringfile_pathFile path
StringactionActione.g. 치료 완료
Stringstatus_textStatus messagee.g. 치료 완료(파일 자체가 악성코드이므로 파일을 삭제했습니다.)
MD5md5MD5
SHA256sha256SHA256
Stringengine_versionEngine vere.g. 2024.06.10.01
Stringnode_idNode IDe.g. 4
Stringgroup_idGroup IDe.g. 1662
Stringplatform_idPlatfrom IDe.g. WINDOWS_10_X64
Stringplatform_namePlatform namee.g. Windows 10 x64
Dateclient_timeClient time
Stringscan_typeScan type codee.g. 2
StringstatusStatus codee.g. 1008
Stringon_demandOndemend codee.g. P
Stringobj_idObject ID
Datecreate_timeCreate time