Cybereason

Download 0
Last updated Aug 3, 2026

Cybereason MalOp (API)

MalOp records collected from the MalOp management API (POST /rest/mmng/v2/malops)

TypeFieldNameDescription
Date_timeTime
StringriskRiskHIGH, MEDIUM, LOW
StringsignaturesDetection typese.g. RANSOMWARE
StringsignatureSignaturee.g. Shadow Copy Deletion
Stringactivity_typeActivity typee.g. RANSOMWARE
Stringdecision_statusesDecision statuses
Stringinvestigation_statusInvestigation statusPending, Reopened, UnderInvestigation, OnHold, Closed
StringstatusStatusActive, Inactive, Resolved, Excluded
Stringdetection_enginesDetection enginese.g. EDR, NGAV
Stringmitre_tacticsMITRE tacticse.g. TA0040
Stringmitre_techniquesMITRE techniquese.g. T1486
Stringfile_nameDisplay namee.g. sample.exe
DatecreatedCreated
DateupdatedUpdated
Datemeta_updatedMetadata updated
Stringroot_cause_hashRoot cause hashe.g. da39a3ee5e6b4b0d3255bfef95601890afd80709
Stringroot_cause_typeRoot cause typee.g. Process, File
Stringmalop_typeMalOp type
Stringclose_adminClosed bye.g. /user01@example.com
Booleanis_escalatedEscalated
Booleanis_edrEDR
Stringgroup_idGroup IDe.g. 00000000-0000-0000-0000-000000000000
Stringaffected_machinesAffected machinese.g. PC-0001
Stringaffected_usersAffected userse.g. EXAMPLE\user01
Stringmalware_guidMalOp GUIDe.g. 11.-1234567890123456789
Stringicon_base64Icon (Base64)