Genian EDR

Download 35
Last updated Aug 6, 2023

Threat Log

Normalize threat logs in Genian EDR.

TypeFieldDisplay Name
DATE_timeTime
INTlevelLevel
IPhost_ipHost IP
STRINGnt_domainNT domain
STRINGhostnameHostname
STRINGplatformPlatform
STRINGdetect_typeDetect type
STRINGdetect_subtypeDetect Subtype
STRINGsignatureSignature
INTscoreScore
STRINGactionAction
STRINGpathPath
STRINGpath2Path2
STRINGcmd_lineCommand line
STRINGimageProcess name
STRINGimage_pathProcess path
STRINGdirectionDirection
IPlocal_ipLocal IP
INTlocal_portLocal port
IPremote_ipRemote IP
INTremote_portRemote port
STRINGprotocolProtocol
STRINGfile_nameFile name
LONGfile_sizeFile size
STRINGfile_pathFile path
STRINGmd5MD5
STRINGsha256SHA256
STRINGlogon_idLogon ID
INTsession_idSession ID
INTpidPID
STRINGpguidProcess GUID
STRINGdevice_idDevice ID
LONGevent_seqEvent sequence
BOOLauto_resolveAuto resolved
STRINGav_nameAnti-virus name
STRINGcategory_nameCategory name
STRINGdetect_idDetect ID
STRINGdetect_key_stringDetect key string
DATEdetect_timeDetect time
DATEevent_timeEvent time
DATEfirst_seenFirst seen
BOOLis_knownIs known threat
STRINGmacMAC
INTml_levelML level
INTml_scoreML score