Cybereason MalOp (API)
MalOp records collected from the MalOp management API (POST /rest/mmng/v2/malops)
| Type | Field | Name | Description |
|---|---|---|---|
| Date | _time | Time | |
| String | risk | Risk | HIGH, MEDIUM, LOW |
| String | signatures | Detection types | e.g. RANSOMWARE |
| String | signature | Signature | e.g. Shadow Copy Deletion |
| String | activity_type | Activity type | e.g. RANSOMWARE |
| String | decision_statuses | Decision statuses | |
| String | investigation_status | Investigation status | Pending, Reopened, UnderInvestigation, OnHold, Closed |
| String | status | Status | Active, Inactive, Resolved, Excluded |
| String | detection_engines | Detection engines | e.g. EDR, NGAV |
| String | mitre_tactics | MITRE tactics | e.g. TA0040 |
| String | mitre_techniques | MITRE techniques | e.g. T1486 |
| String | file_name | Display name | e.g. sample.exe |
| Date | created | Created | |
| Date | updated | Updated | |
| Date | meta_updated | Metadata updated | |
| String | root_cause_hash | Root cause hash | e.g. da39a3ee5e6b4b0d3255bfef95601890afd80709 |
| String | root_cause_type | Root cause type | e.g. Process, File |
| String | malop_type | MalOp type | |
| String | close_admin | Closed by | e.g. /user01@example.com |
| Boolean | is_escalated | Escalated | |
| Boolean | is_edr | EDR | |
| String | group_id | Group ID | e.g. 00000000-0000-0000-0000-000000000000 |
| String | affected_machines | Affected machines | e.g. PC-0001 |
| String | affected_users | Affected users | e.g. EXAMPLE\user01 |
| String | malware_guid | MalOp GUID | e.g. 11.-1234567890123456789 |
| String | icon_base64 | Icon (Base64) |