SentinelOne

다운로드 43
업데이트 2026. 5. 8.

SentinelOne 프로세스 이벤트

event.category = process

번호타입필드이름설명
1날짜_time시각예: 2026-05-03 00:14:33
2날짜event_time이벤트시각예: 2026-05-03 00:14:33
3문자열site_name사이트명예: ACME
4문자열hostname호스트명예: DESKTOP-EXAMPLE
5문자열user계정예: DESKTOP-EXAMPLE\demouser
6문자열event_type이벤트유형예: Process Creation
7문자열target_image대상이미지예: UserOOBEBroker.exe
8문자열image이미지예: svchost.exe
9문자열cmd_line명령줄예: C:\WINDOWS\system32\svchost.ex...
10문자열parent_image부모이미지예: services.exe
11문자열target_cmd_line대상명령줄예: C:\Windows\System32\oobe\UserO...
12문자열parent_cmd_line부모명령줄예: C:\WINDOWS\system32\services.exe
13문자열event_category이벤트분류예: process
14문자열event_name이벤트이름예: PROCESSCREATION, ...
15문자열endpoint_type단말유형예: desktop
16문자열os_familyOS유형예: windows
17문자열os_nameOS이름예: Windows 11 Pro
18문자열os_revOS리비전예: 26100
19문자열user_sid계정SID예: S-1-5-18
2032비트 정수target_session_id대상세션ID예: 2
21문자열target_user_sid대상계정SID예: S-1-5-21-1214884534-2691577776...
22날짜parent_start_time부모시작일시예: 2026-04-15 03:04:01
2364비트 정수ppidPPID예: 880
24문자열parent_user부모계정예: DESKTOP-EXAMPLE\demouser
25문자열parent_effective_user부모실제계정예: demouser
26MD5parent_image_md5부모이미지MD516진수 32자
27SHA1parent_image_sha1부모이미지SHA116진수 40자
28SHA256parent_image_sha256부모이미지SHA25616진수 64자
29불리언is_parent_image_signed부모이미지서명여부예: true
30문자열parent_image_path부모이미지경로예: C:\Windows\System32\services.exe
31문자열parent_image_signer부모디지털서명예: MICROSOFT WINDOWS PUBLISHER
32문자열parent_integrity_level부모무결성수준예: SYSTEM
33문자열parent_subsystem부모서브시스템예: SYS_WIN32
34날짜start_time시작일시예: 2026-04-15 03:06:13
3564비트 정수pidPID예: 4472
36문자열effective_user실제계정예: demouser
37문자열image_display_name이미지표시이름예: Host Process for Windows Services
3864비트 정수image_size이미지크기바이트 단위
39MD5image_md5이미지MD516진수 32자
40SHA1image_sha1이미지SHA116진수 40자
41SHA256image_sha256이미지SHA25616진수 64자
42문자열image_path이미지경로예: C:\Windows\System32\svchost.exe
43문자열image_signer디지털서명예: MICROSOFT WINDOWS
44불리언is_image_signed이미지서명여부예: true
45불리언is_sign_verified서명검증여부예: true
46문자열integrity_level무결성수준예: SYSTEM
47문자열subsystem서브시스템예: SYS_WIN32
48날짜target_process_start_time대상프로세스시작일시예: 2026-05-03 01:28:30
4964비트 정수target_pid대상PID예: 14352
50문자열target_user대상계정예: DESKTOP-EXAMPLE\demouser
51문자열target_image_display_name대상이미지표시이름예: User OOBE Broker
5264비트 정수target_image_size대상이미지크기바이트 단위
53MD5target_image_md5대상이미지MD516진수 32자
54SHA1target_image_sha1대상이미지SHA116진수 40자
55SHA256target_image_sha256대상이미지SHA25616진수 64자
56문자열target_image_path대상이미지경로예: C:\Windows\System32\oobe\UserO...
57불리언is_target_image_signed대상이미지서명여부예: true
58불리언is_target_sign_verified대상서명검증여부예: true
59문자열target_image_signer대상디지털서명예: MICROSOFT WINDOWS
60문자열target_integrity_level대상무결성수준예: MEDIUM
61문자열agent_ver에이전트버전예: 25.1.4.434
62문자열agent_uuid에이전트식별자16진수 32자
6332비트 정수session_id세션ID예: 0
64문자열account_id계정ID예: 1234567890123456789
65문자열account_name계정명예: Sentinel Labs PTE Korea
66문자열mgmt_id관리ID예: 365
67문자열mgmt_url관리URL예: apne1-9999-xxx.sentinelone.net
68문자열site_id사이트ID예: 2387424777214565688
69문자열group_id그룹ID예: 3497CB5FB28F00A7
70문자열event_id이벤트IDULID 26자 + _순번
71문자열trace_id추적IDULID 26자 (Crockford Base32)
72문자열packet_id패킷ID16진수 32자
73문자열parent_process_uuid부모프로세스식별자16진수 16자
74문자열process_uuid프로세스식별자16진수 16자
75문자열target_process_uuid대상프로세스식별자16진수 16자
76문자열parent_storyline부모스토리라인16진수 16자
77문자열storyline스토리라인16진수 16자
78문자열target_process_storyline대상프로세스스토리라인16진수 16자
79문자열process_unique_key프로세스고유키16진수 16자