Actor Actor

The Actor actor is the process that performed the action.

Field Name Data Type Description
actor_causality_id STRING Will match 'causality_actor_causality_id' in the causality owner actor fields.
actor_effective_user_sid STRING <p>Win: Primary user token of the executed binary.
Unix: Effective UID of the executed binary.</p>
actor_effective_username STRING <p>Name assigned to 'actor_effective_user_sid'.
Win: Includes the domain.</p>
actor_is_injected_thread BOOLEAN Indicates whether or not a user can connect to the USB port that the device is connected to.
actor_os_process_instance_id STRING Cortex XDR/XSIAM unique identifier for the operating system's actor process.
actor_primary_user_sid STRING <p>Win: Primary user token of the executed binary.
Unix: Effective UID of the executed binary.</p>
actor_primary_username STRING Name assigned to the user_sid.
actor_process_auth_id STRING Windows: LUID (uint64) representing the token of the process.
actor_process_causality_id STRING Cortex XDR/XSIAM unique causality ID for the actor casuality chain.
actor_process_command_line STRING Process command line - The command used to execute the process.
actor_process_command_line_indices STRING Process command line - The command used to execute the process.
actor_process_device_info RECORD Info about the device (volume + HW) from which this process started. including name, class guid, class name, bus type, volume guid, mount point, file system, drive type, vendor id, product id, and serial number.
actor_process_execution_time INTEGER Timestamp of the execution in epoch time.
actor_process_file_access_time INTEGER Creation time of the file that created the actor process.
actor_process_file_create_time INTEGER Creation time of the file that created the process.
actor_process_file_mod_time INTEGER Modification time of the file that created the process.
actor_process_file_size INTEGER Size of the file involved in the process in bytes.
actor_process_image_command_line STRING Process command line - The command used to execute the process.
actor_process_image_extension STRING Process image extension - File extension.
actor_process_image_md5 STRING MD5 of the binary.
actor_process_image_name STRING File name of the actor_process_image_path.
actor_process_image_path STRING Process image path - A string identifying the location of the execution.
actor_process_image_sha256 STRING SHA256 of the binary.
actor_process_instance_id STRING Cortex XDR/XSIAM unique identifier of the actor process.
actor_process_integrity_level INTEGER Integrity level of the process.
actor_process_is_64bit BOOLEAN Indicates whether or not the process is a 64-bit process.
actor_process_is_native BOOLEAN Indicates whether or not this process a "native process".
actor_process_is_replay BOOLEAN Indicates whether or not the agent was alive during the execution of the process.
actor_process_is_special INTEGER <p>Indicates special system processes:
RegularProcess = 0
KernelProcess = 1
AppContainerProcess = 2
NonWin32SubsystemProcess = 3</p>
actor_process_logon_id STRING Windows: LUID (uint64) representing the token of the process.
actor_process_os_pid INTEGER The Operating System (OS) Process Identifier (PID) of the actor process.
actor_process_session_id INTEGER Windows: Session ID of the process.
actor_process_signature_is_embedded BOOLEAN Indicates whether or not the signature embedded inside the Program Executable (PE) or part of an external catalog file.
actor_process_signature_product STRING Signature product - The product family part of the signature.
actor_process_signature_status INTEGER <p>Signature status of the process:
Signed = 1
SignedInvalid = 2
Unsigned = 3
FailedToObtain = 4
WeakHash = 5, where the MD5 is used as the hash algorithm.
Unsupported = 6, which means the signature was not calculated.
InvalidCVE2020_0601 = 7, which means the executable is malicious and is trying to exploit the windows vulnerability CVE2020-0601.
Deleted = 8, which means that the file was deleted by the time the agent tried to calculate the signature.</p>
actor_process_signature_vendor STRING Signature vendor - The vendor part of the signature.
actor_remote_host STRING Relevant when the actor is a remote actor and the host was resolved successfully.
actor_remote_ip STRING Relevant when the actor is a remote actor, where the type is not local and the IP was resolved successfully.
actor_remote_pipe_name STRING Relevant when the actor is a remote actor, where the type is RemoteRpcNamedPipe.
actor_remote_port INTEGER Relevant when the actor is a remote actor, where the type is RemoteRpcTcp.
actor_thread_thread_id INTEGER An identifier of the OS thread which is responsible for the event.
actor_type INTEGER <p>Enum describing actor type:
Local = 1, where the actor is a local process.
RemoteRpcNamedPipe = 2, where the actor is a remote procedure call (RPC) over a named-pipe/SMB connection.
RemoteRpcHttp = 3, where the actor is a remote procedure call (RPC) over a remote HTTP connection.
RemoteRpcTcp = 4, where the actor is a remote procedure call (RPC) over a TCP connection.
RemoteFileSmb = 5, where the actor is a remote file operation over SMB.</p>
actor_primary_normalized_user RECORD A normalized user for the actor.
actor_effective_normalized_user RECORD Normalized user information.
actor_container_info RECORD Container information for the process.
actor_process_ns_pid    
actor_ns_user_sid    
actor_process_container_id    
actor_rpc_interface_uuid STRING MS-RPC interface unique identifier.
actor_rpc_func_opnum INTEGER MS-RPC function operation identitifer.
actor_rpc_interface_version_major INTEGER MS-RPC interface major version.
actor_rpc_interface_version_minor INTEGER MS-RPC interface minor version.
actor_rpc_protocol STRING MS-RPC protocol type.
actor_local_ip STRING Source IP of the network activity.
actor_local_port INTEGER Source port for the network activity
actor_process_image_auth_sha2 STRING Process image SHA-2 authenticode.
actor_process_image_auth_sha1 STRING Process image SHA-1 authenticode.
actor_process_last_writer_actor STRING Cortex instance ID of the last process that has written the actor process image.
actor_process_static_analysis_score DEPRECATED  
actor_process_file_original_name STRING Original file name of the actor image based on the file information metadata.
actor_process_file_internal_name STRING Internal name of the actor image based on the file information metadata.