Cybereason

Download 0
Last updated Jun 15, 2026

cybereason-suspicions

Get a list of suspicions from the Cybereason server.

cybereason-suspicions [profile=VALUE] [duration=VALUE] [from=VALUE] [to=VALUE]
profile=VALUE
Optional. Cybereason connect profile identifier
duration=VALUE
Optional. Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=VALUE
Optional. Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=VALUE
Optional. End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
profileStringConnect profileCybereason connect profile identifier
event_timeDateEvent timeCreation time of the suspicious event
end_timeDateEnd timeEnd time of the suspicious event
process_nameStringProcess nameDisplay name of the process
process_infoStringProcess infoDetailed information about the process element
suspicionsStringSuspicionsSuspicion details and indicators
guidStringGUIDUnique identifier of the suspicious element
is_maliciousBooleanIs maliciousWhether the element is marked as malicious
is_suspectBooleanIs suspectWhether the element is marked as suspect
is_malicious_verdictBooleanIs malicious verdictFinal verdict on whether the element is malicious