Cybereason

Download 0
Last updated Aug 3, 2026

Cybereason MalOp

MalOp detection log (syslog CEF, event_id = Malop)

TypeFieldNameDescription
Date_timeTime
Stringevent_nameEvent namee.g. Malop Created, Malop Updated, Malop Machine Information, Malop Machine Added, Malop Process Added, Malop User Added, Malop Connection Added
StringriskRiskLOW, MEDIUM, HIGH
Stringactivity_typeActivity typee.g. RANSOMWARE, MALICIOUS_INFECTION
Stringdetect_typeDetection typee.g. RANSOMWARE, EXTENSION_MANIPULATION
StringsignatureKey suspicione.g. Shadow Copy Deletion
StringsuspectSuspecte.g. sample.exe
Stringaffected_userAffected usere.g. user01
Stringaffected_machine_idAffected machine IDe.g. PC-0001
Stringmalop_idMalOp IDe.g. 11.-1234567890123456789
StringxrefReference URLe.g. https://edr.example.com:443/#/malop/11.-1234567890123456789
StringuserUsere.g. /user01@example.com
StringreasonReasone.g. whitelist, indifferent
Stringdetection_ruleDetection rulee.g. My Detection Rule
Datestart_timeStart time
Datesuspect_createdSuspect creation time
DateupdatedUpdated
Dateingested_timeIngested time
Stringrequest_contextRequest contexte.g. c:\program files (x86)\sample\sample.exe 2/pbpolicy
Stringdevice_dns_domainDevice DNS domaine.g. example.com
Stringparent_processParent processe.g. explorer.exe
Stringchildren_processChild processese.g. sample.exe
Stringos_verOS versione.g. Windows 10
Booleanis_onlineOnline
Booleanis_original_machineOriginal machine
Booleanis_signedSigned
Integeraffected_machine_cntAffected machine counte.g. 23
Stringaffected_machinesAffected machinese.g. PC-0001, PC-0002
IP addressaffected_machine_ip_addrsAffected machine IPe.g. 10.0.0.10
StringhostnameAffected machine domaine.g. pc-0001.example.com
Stringaffected_machine_os_verAffected machine OS versione.g. Windows 10
Integeraffected_user_cntAffected user counte.g. 23
Stringaffected_user_domainAffected user domaine.g. EXAMPLE
Stringaffected_user_privilegeAffected user privilegee.g. Administrator
Datemalicious_process_createdMalicious process creation time
Longmalicious_process_pidMalicious process PIDe.g. 4820
Stringmalicious_process_nameMalicious process namee.g. sample.exe
Stringmalicious_process_cmdMalicious process command linee.g. c:\users\user01\downloads\sample.exe -install
Stringprocess_file_nameProcess file namee.g. sample.exe
Stringprocess_file_pathProcess file pathe.g. c:\users\user01\downloads\sample.exe
Stringprocess_file_sha1Process file SHA1e.g. da39a3ee5e6b4b0d3255bfef95601890afd80709
Stringprocess_file_md5Process file MD5e.g. d41d8cd98f00b204e9800998ecf8427e
Dateparent_process_createdParent process creation time
LongppidParent process IDe.g. 3120
Stringparent_process_nameParent process namee.g. explorer.exe
Stringparent_process_cmdParent process command linee.g. c:\windows\explorer.exe