Actor Actor ↗
The Actor actor is the process that performed the action.
| Field Name | Data Type | Description |
|---|---|---|
| actor_causality_id | STRING | Will match 'causality_actor_causality_id' in the causality owner actor fields. |
| actor_effective_user_sid | STRING | <p>Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.</p> |
| actor_effective_username | STRING | <p>Name assigned to 'actor_effective_user_sid'. Win: Includes the domain.</p> |
| actor_is_injected_thread | BOOLEAN | Indicates whether or not a user can connect to the USB port that the device is connected to. |
| actor_os_process_instance_id | STRING | Cortex XDR/XSIAM unique identifier for the operating system's actor process. |
| actor_primary_user_sid | STRING | <p>Win: Primary user token of the executed binary. Unix: Effective UID of the executed binary.</p> |
| actor_primary_username | STRING | Name assigned to the user_sid. |
| actor_process_auth_id | STRING | Windows: LUID (uint64) representing the token of the process. |
| actor_process_causality_id | STRING | Cortex XDR/XSIAM unique causality ID for the actor casuality chain. |
| actor_process_command_line | STRING | Process command line - The command used to execute the process. |
| actor_process_command_line_indices | STRING | Process command line - The command used to execute the process. |
| actor_process_device_info | RECORD | Info about the device (volume + HW) from which this process started. including name, class guid, class name, bus type, volume guid, mount point, file system, drive type, vendor id, product id, and serial number. |
| actor_process_execution_time | INTEGER | Timestamp of the execution in epoch time. |
| actor_process_file_access_time | INTEGER | Creation time of the file that created the actor process. |
| actor_process_file_create_time | INTEGER | Creation time of the file that created the process. |
| actor_process_file_mod_time | INTEGER | Modification time of the file that created the process. |
| actor_process_file_size | INTEGER | Size of the file involved in the process in bytes. |
| actor_process_image_command_line | STRING | Process command line - The command used to execute the process. |
| actor_process_image_extension | STRING | Process image extension - File extension. |
| actor_process_image_md5 | STRING | MD5 of the binary. |
| actor_process_image_name | STRING | File name of the actor_process_image_path. |
| actor_process_image_path | STRING | Process image path - A string identifying the location of the execution. |
| actor_process_image_sha256 | STRING | SHA256 of the binary. |
| actor_process_instance_id | STRING | Cortex XDR/XSIAM unique identifier of the actor process. |
| actor_process_integrity_level | INTEGER | Integrity level of the process. |
| actor_process_is_64bit | BOOLEAN | Indicates whether or not the process is a 64-bit process. |
| actor_process_is_native | BOOLEAN | Indicates whether or not this process a "native process". |
| actor_process_is_replay | BOOLEAN | Indicates whether or not the agent was alive during the execution of the process. |
| actor_process_is_special | INTEGER | <p>Indicates special system processes: RegularProcess = 0 KernelProcess = 1 AppContainerProcess = 2 NonWin32SubsystemProcess = 3</p> |
| actor_process_logon_id | STRING | Windows: LUID (uint64) representing the token of the process. |
| actor_process_os_pid | INTEGER | The Operating System (OS) Process Identifier (PID) of the actor process. |
| actor_process_session_id | INTEGER | Windows: Session ID of the process. |
| actor_process_signature_is_embedded | BOOLEAN | Indicates whether or not the signature embedded inside the Program Executable (PE) or part of an external catalog file. |
| actor_process_signature_product | STRING | Signature product - The product family part of the signature. |
| actor_process_signature_status | INTEGER | <p>Signature status of the process: Signed = 1 SignedInvalid = 2 Unsigned = 3 FailedToObtain = 4 WeakHash = 5, where the MD5 is used as the hash algorithm. Unsupported = 6, which means the signature was not calculated. InvalidCVE2020_0601 = 7, which means the executable is malicious and is trying to exploit the windows vulnerability CVE2020-0601. Deleted = 8, which means that the file was deleted by the time the agent tried to calculate the signature.</p> |
| actor_process_signature_vendor | STRING | Signature vendor - The vendor part of the signature. |
| actor_remote_host | STRING | Relevant when the actor is a remote actor and the host was resolved successfully. |
| actor_remote_ip | STRING | Relevant when the actor is a remote actor, where the type is not local and the IP was resolved successfully. |
| actor_remote_pipe_name | STRING | Relevant when the actor is a remote actor, where the type is RemoteRpcNamedPipe. |
| actor_remote_port | INTEGER | Relevant when the actor is a remote actor, where the type is RemoteRpcTcp. |
| actor_thread_thread_id | INTEGER | An identifier of the OS thread which is responsible for the event. |
| actor_type | INTEGER | <p>Enum describing actor type: Local = 1, where the actor is a local process. RemoteRpcNamedPipe = 2, where the actor is a remote procedure call (RPC) over a named-pipe/SMB connection. RemoteRpcHttp = 3, where the actor is a remote procedure call (RPC) over a remote HTTP connection. RemoteRpcTcp = 4, where the actor is a remote procedure call (RPC) over a TCP connection. RemoteFileSmb = 5, where the actor is a remote file operation over SMB.</p> |
| actor_primary_normalized_user | RECORD | A normalized user for the actor. |
| actor_effective_normalized_user | RECORD | Normalized user information. |
| actor_container_info | RECORD | Container information for the process. |
| actor_process_ns_pid | ||
| actor_ns_user_sid | ||
| actor_process_container_id | ||
| actor_rpc_interface_uuid | STRING | MS-RPC interface unique identifier. |
| actor_rpc_func_opnum | INTEGER | MS-RPC function operation identitifer. |
| actor_rpc_interface_version_major | INTEGER | MS-RPC interface major version. |
| actor_rpc_interface_version_minor | INTEGER | MS-RPC interface minor version. |
| actor_rpc_protocol | STRING | MS-RPC protocol type. |
| actor_local_ip | STRING | Source IP of the network activity. |
| actor_local_port | INTEGER | Source port for the network activity |
| actor_process_image_auth_sha2 | STRING | Process image SHA-2 authenticode. |
| actor_process_image_auth_sha1 | STRING | Process image SHA-1 authenticode. |
| actor_process_last_writer_actor | STRING | Cortex instance ID of the last process that has written the actor process image. |
| actor_process_static_analysis_score | DEPRECATED | |
| actor_process_file_original_name | STRING | Original file name of the actor image based on the file information metadata. |
| actor_process_file_internal_name | STRING | Internal name of the actor image based on the file information metadata. |