category: Analytics & SIEM provider: Google sectionorder: - Connect - Collect commonfields: id: GoogleSecOps version: -1 configuration: - displaypassword: User's Service Account JSON name: credentials hiddenusername: true required: true type: 9 section: Connect - display: API URL Format additionalinfo: "Select the API URL format to use for API requests. Default value is '..'." name: url_format required: false type: 15 options: - "-" - ".." section: Connect - display: Google SecOps Project Instance ID additionalinfo: "Provide the Project Instance ID of the Google SecOps.\n\nNote: User can retrieve the Customer ID(Project Instance ID) in the Profile section of the Google SecOps page." name: secops_project_instance_id required: true type: 0 section: Connect - display: Google SecOps Project Number additionalinfo: "Provide the Project Number of the Google SecOps.\n\nNote: User can retrieve the Project Number in the Profile section of the Google SecOps page. If Project Number is not provided, then Project ID(from Service Account JSON) will be used." name: secops_project_number required: false type: 0 section: Connect - additionalinfo: Select the region based on the location of the Google SecOps instance. If the region is not listed in the dropdown, choose the "Other" option and specify the region in the "Other Region" text field. defaultvalue: US display: Region name: region required: true options: - Africa-south1 - Asia-northeast1 - Asia-south1 - Asia-southeast1 - Asia-southeast2 - Australia-southeast1 - EU - Europe-west2 - Europe-west3 - Europe-west6 - Europe-west9 - Europe-west12 - ME-central1 - ME-central2 - ME-west1 - Northamerica-northeast2 - Southamerica-east1 - US - Other type: 15 section: Connect - additionalinfo: Specify the region based on the location of the Google SecOps instance. Only applicable if the "Other" option is selected in the Region dropdown. display: Other Region hidden: false name: other_region required: false type: 0 section: Connect - display: Provide comma(',') separated categories (e.g. APT-Activity, Phishing). Indicators belonging to these "categories" would be considered as "malicious" when executing reputation commands. name: malicious_categories type: 12 section: Collect advanced: true required: false - display: Provide comma(',') separated categories (e.g. Unwanted, VirusTotal YARA Rule Match). Indicators belonging to these "categories" would be considered as "suspicious" when executing reputation commands. name: suspicious_categories type: 12 section: Collect advanced: true required: false - display: Specify the "severity" of indicator that should be considered as "malicious" irrespective of the category. If you wish to consider all indicators with High severity as Malicious, set this parameter to 'High'. Allowed values are 'High', 'Medium' and 'Low'. This configuration is applicable to reputation commands only. name: override_severity_malicious options: - high - medium - low type: 16 section: Collect advanced: true required: false - display: Specify the "severity" of indicator that should be considered as "suspicious" irrespective of the category. If you wish to consider all indicators with Medium severity as Suspicious, set this parameter to 'Medium'. Allowed values are 'High', 'Medium' and 'Low'. This configuration is applicable to reputation commands only. name: override_severity_suspicious options: - high - medium - low type: 16 section: Collect advanced: true required: false - display: Specify the numeric value of "confidence score". If the indicator's confidence score is equal or above the configured threshold, it would be considered as "malicious". The value provided should be greater than the suspicious threshold. This configuration is applicable to reputation commands only. name: override_confidence_score_malicious_threshold type: 0 section: Collect advanced: true required: false - display: Specify the numeric value of "confidence score". If the indicator's confidence score is equal or above the configured threshold, it would be considered as "suspicious". The value provided should be smaller than the malicious threshold. This configuration is applicable to reputation commands only. name: override_confidence_score_suspicious_threshold type: 0 section: Collect advanced: true required: false - display: Select the confidence score level. If the indicator's confidence score level is equal or above the configured level, it would be considered as "malicious". The confidence level configured should have higher precedence than the suspicious level. This configuration is applicable to reputation commands only. Refer the "confidence score" level precedence UNKNOWN SEVERITY < INFORMATIONAL < LOW < MEDIUM < HIGH. name: override_confidence_level_malicious options: - unknown_severity - informational - low - medium - high type: 15 section: Collect advanced: true required: false - display: |- Select the confidence score level. If the indicator's confidence score level is equal or above the configured level, it would be considered as "suspicious". The confidence level configured should have lesser precedence than the malicious level. This configuration is applicable to reputation commands only. Refer the "confidence score" level precedence UNKNOWN SEVERITY < INFORMATIONAL < LOW < MEDIUM < HIGH. name: override_confidence_level_suspicious options: - unknown_severity - informational - low - medium - high type: 15 section: Collect advanced: true required: false - display: Fetch incidents name: isFetch type: 8 section: Collect required: false - display: Incident type name: incidentType type: 13 section: Connect required: false - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true - additionalinfo: |- The UTC date or relative timestamp from where to start fetching incidents. Supported formats: N minutes, N hours, N days, N weeks, N months, N years, yyyy-mm-dd, yyyy-mm-ddTHH:MM:SSZ. For example: 10 minutes, 5 hours, 8 days, 2 weeks, 8 months, 2021-12-31, 01 Mar 2021, 01 Feb 2021 04:45:33, 2022-04-17T14:05:44Z. Default value is 3 days. defaultvalue: 3 days display: First fetch time name: first_fetch type: 0 section: Collect required: false - defaultvalue: '100' display: How many incidents to fetch each time additionalinfo: The maximum number of incidents to fetch in each time. The maximum value is 10,000. Default value is 100. name: max_fetch type: 0 section: Collect required: false - additionalinfo: Select the time window to query Google SecOps. While selecting the time window consider the time delay for an event to appear in Google SecOps after generation. Available options are 60(Default), 120, 240, 360, 480, 600, 720, 1440. defaultvalue: '60' display: Time window (in minutes) name: time_window options: - '60' - '120' - '240' - '360' - '480' - '600' - '720' - '1440' type: 15 section: Collect advanced: true - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: B - Usually reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged type: 15 section: Collect required: false - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false description: Use the Google SecOps integration to retrieve IOC Domain matches as Incidents. This integration also provides reputation and threat enrichment of indicators observed in the enterprise. display: Google SecOps v1 Alpha name: GoogleSecOps script: commands: - arguments: - defaultValue: '100' description: Specify the maximum number of Rules to return. You can specify between 1 and 1000. name: page_size - description: A page token, received from a previous call. Provide this to retrieve the subsequent page. name: page_token description: List the latest versions of all Rules. name: gcb-list-rules outputs: - contextPath: GoogleChronicleBackstory.Rules.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.Rules.versionId description: Unique identifier for a specific version of a rule. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleName description: Name of the rule, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleText description: Source code for the rule, as defined by the user. type: String - contextPath: GoogleChronicleBackstory.Rules.versionCreateTime description: A string representing the time in ISO-8601 format. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationState description: Compilation state of the rule. It can be SUCCEEDED or FAILED. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationError description: A compilation error if compilationState is FAILED, absent if compilationState is SUCCEEDED. type: String - contextPath: GoogleChronicleBackstory.Rules.Metadata.severity description: Severity for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.Metadata.author description: Name of author for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.Metadata.description description: Description of the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.Metadata.reference description: Reference link for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.Metadata.created description: Time at which the rule is created. type: String - contextPath: GoogleChronicleBackstory.Rules.Metadata.updated description: Time at which the rule is updated. type: String - contextPath: GoogleChronicleBackstory.Rules.referenceLists description: Resource names of the reference lists used in this rule. type: String - contextPath: GoogleChronicleBackstory.Rules.allowedRunFrequencies description: The run frequencies that are allowed for the rule. type: String - contextPath: GoogleChronicleBackstory.Token.nextPageToken description: A page token that can be provided to the next call to view the next page of Rules. Absent if this is the last page. type: String - contextPath: GoogleChronicleBackstory.Token.name description: The name of the command to which the value of the nextPageToken corresponds. type: String - arguments: - description: Rule text in YARA-L 2.0 format for the rule to be created. name: rule_text required: true description: Creates a new rule. By default the live rule status will be set to disabled. name: gcb-create-rule outputs: - contextPath: GoogleChronicleBackstory.Rules.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.Rules.versionId description: Unique identifier for a specific version of a rule. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleName description: Name of the rule, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleText description: Source code for the rule, as defined by the user. type: String - contextPath: GoogleChronicleBackstory.Rules.liveRuleEnabled description: Whether the rule is enabled to run as a Live Rule. type: Boolean - contextPath: GoogleChronicleBackstory.Rules.alertingEnabled description: Whether the rule is enabled to generate Alerts. type: Boolean - contextPath: GoogleChronicleBackstory.Rules.versionCreateTime description: A string representing the time in ISO-8601 format. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationState description: Compilation state of the rule. It can be SUCCEEDED or FAILED. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationError description: A compilation error if compilationState is FAILED, absent if compilationState is SUCCEEDED. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleType description: Indicates the type of event in rule. It can be SINGLE_EVENT or MULTI_EVENT. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.severity description: Severity for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.author description: Name of author for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.description description: Description of the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.reference description: Reference link for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.created description: Time at which the rule is created. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.updated description: Time at which the rule is updated. type: String - contextPath: GoogleChronicleBackstory.Rules.referenceLists description: Resource names of the reference lists used in this rule. type: String - contextPath: GoogleChronicleBackstory.Rules.allowedRunFrequencies description: The run frequencies that are allowed for the rule. type: String - arguments: - description: Rule ID or Version ID of the rule to be retrieved. name: id required: true description: Retrieves the rule details of specified Rule ID or Version ID. name: gcb-get-rule outputs: - contextPath: GoogleChronicleBackstory.Rules.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.Rules.versionId description: Unique identifier for a specific version of a rule. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleName description: Name of the rule, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleText description: Source code for the rule, as defined by the user. type: String - contextPath: GoogleChronicleBackstory.Rules.versionCreateTime description: A string representing the time in ISO-8601 format. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationState description: Compilation state of the rule. It can be SUCCEEDED or FAILED. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationError description: A compilation error if compilationState is FAILED, absent if compilationState is SUCCEEDED. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleType description: Indicates the type of event in rule. It can be SINGLE_EVENT or MULTI_EVENT. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.severity description: Severity for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.author description: Name of author for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.description description: Description of the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.reference description: Reference link for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.created description: Time at which the rule is created. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.updated description: Time at which the rule is updated. type: String - contextPath: GoogleChronicleBackstory.Rules.referenceLists description: Resource names of the reference lists used in this rule. type: String - contextPath: GoogleChronicleBackstory.Rules.allowedRunFrequencies description: The run frequencies that are allowed for the rule. type: String - arguments: - description: ID of the rule to be deleted. name: rule_id required: true description: Deletes the rule specified by Rule ID. name: gcb-delete-rule outputs: - contextPath: GoogleChronicleBackstory.DeleteRule.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.DeleteRule.actionStatus description: Whether the rule is successfully deleted or not. type: String - arguments: - description: Rule ID for a Rule for which to create a new version. name: rule_id required: true - description: Rule text in YARA-L 2.0 format for the new version of the rule to be created. name: rule_text required: true description: Creates a new version of an existing rule. name: gcb-create-rule-version outputs: - contextPath: GoogleChronicleBackstory.Rules.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.Rules.versionId description: Unique identifier for a specific version of a rule. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleName description: Name of the rule, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleText description: Source code for the rule, as defined by the user. type: String - contextPath: GoogleChronicleBackstory.Rules.liveRuleEnabled description: Whether the rule is enabled to run as a Live Rule. type: Boolean - contextPath: GoogleChronicleBackstory.Rules.alertingEnabled description: Whether the rule is enabled to generate Alerts. type: Boolean - contextPath: GoogleChronicleBackstory.Rules.versionCreateTime description: A string representing the time in ISO-8601 format. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationState description: Compilation state of the rule. It can be SUCCEEDED or FAILED. type: String - contextPath: GoogleChronicleBackstory.Rules.compilationError description: A compilation error if compilationState is FAILED, absent if compilationState is SUCCEEDED. type: String - contextPath: GoogleChronicleBackstory.Rules.ruleType description: Indicates the type of event in rule. It can be SINGLE_EVENT or MULTI_EVENT. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.severity description: Severity for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.author description: Name of author for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.description description: Description of the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.reference description: Reference link for the rule. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.created description: Time at which the rule is created. type: String - contextPath: GoogleChronicleBackstory.Rules.metadata.updated description: Time at which the rule is updated. type: String - contextPath: GoogleChronicleBackstory.Rules.referenceLists description: Resource names of the reference lists used in this rule. type: String - contextPath: GoogleChronicleBackstory.Rules.allowedRunFrequencies description: The run frequencies that are allowed for the rule. type: String - arguments: - description: ID of the rule. name: rule_id required: true - auto: PREDEFINED description: "New alerting status for the Rule.\n\nPossible values are: \"enable\" or \"disable\"." name: alerting_status predefined: - enable - disable required: true description: Updates the alerting status for a rule specified by Rule ID. name: gcb-change-rule-alerting-status outputs: - contextPath: GoogleChronicleBackstory.RuleAlertingChange.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.RuleAlertingChange.actionStatus description: Whether the alerting status for the rule is successfully updated or not. type: String - contextPath: GoogleChronicleBackstory.RuleAlertingChange.alertingStatus description: New alerting status for the rule. type: String - arguments: - description: ID of the rule. name: rule_id required: true - auto: PREDEFINED description: "New live rule status for the Rule.\n\nPossible values are: \"enable\" or \"disable\"." name: live_rule_status predefined: - enable - disable required: true description: Updates the live rule status for a rule specified by Rule ID. name: gcb-change-live-rule-status outputs: - contextPath: GoogleChronicleBackstory.LiveRuleStatusChange.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.LiveRuleStatusChange.actionStatus description: Whether the live rule status for the rule is successfully updated or not. type: String - contextPath: GoogleChronicleBackstory.LiveRuleStatusChange.liveRuleStatus description: New live rule status for the rule. type: String - arguments: - description: Specify the Rule text in YARA-L 2.0 format to verify. name: rule_text required: true description: Verifies that a rule is a valid YARA-L 2.0 rule without creating a new rule or evaluating it over data. name: gcb-verify-rule outputs: - contextPath: GoogleChronicleBackstory.VerifyRule.success description: Whether rule_text has a valid YARA-L 2.0 format. type: Boolean - contextPath: GoogleChronicleBackstory.VerifyRule.context description: Contains the success message or the compilation error if the verification fails. type: String - contextPath: GoogleChronicleBackstory.VerifyRule.command_name description: The command name. type: String - arguments: - description: Rule ID or Version ID of the rule whose retrohunts are to be listed. If not supplied, retohunts for all versions of all rules will be listed. name: id - auto: PREDEFINED defaultValue: 'False' description: |- Whether to retrieve retrohunts for all versions of a rule with a given rule identifier. Note: If this option is set to true, rule id is required. name: retrohunts_for_all_versions predefined: - 'True' - 'False' - auto: PREDEFINED description: Filter retrohunts based on their status. name: state predefined: - RUNNING - DONE - CANCELLED - defaultValue: '100' description: Specify the maximum number of retohunts to return. You can specify between 1 and 1000. name: page_size - description: A page token, received from a previous call. Provide this to retrieve the subsequent page. name: page_token description: List retrohunts for a rule. name: gcb-list-retrohunts outputs: - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntId description: Unique identifier for a retrohunt, defined and returned by the server. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.versionId description: Unique identifier for a specific version of a rule. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.eventStartTime description: Start time for the time range of logs being processed. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.eventEndTime description: End time for the time range of logs being processed. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntStartTime description: Start time for the retrohunt. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntEndTime description: End time for the retrohunt. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.state description: Current state of the retrohunt. It can be STATE_UNSPECIFIED, RUNNING, DONE or CANCELLED. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.progressPercentage description: Percentage progress towards retrohunt completion (0.00 to 100.00). type: Number - arguments: - description: Rule ID or Version ID of the rule whose retrohunt is to be retrieved. name: id required: true - description: Unique identifier for a retrohunt, defined and returned by the server. You must specify exactly one retrohunt identifier. name: retrohunt_id required: true description: Get retrohunt for a specific version of rule. name: gcb-get-retrohunt outputs: - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntId description: Unique identifier for a retrohunt, defined and returned by the server. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.versionId description: Unique identifier for a specific version of a rule. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.eventStartTime description: Start time for the time range of logs being processed. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.eventEndTime description: End time for the time range of logs being processed. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntStartTime description: Start time for the retrohunt. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntEndTime description: End time for the retrohunt. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.state description: Current state of the retrohunt. It can be STATE_UNSPECIFIED, RUNNING, DONE or CANCELLED. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.progressPercentage description: Percentage progress towards retrohunt completion (0.00 to 100.00). type: Number - arguments: - description: Rule ID or Version ID of the rule whose retrohunt is to be started. name: rule_id required: true - defaultValue: 1 week description: |- Start time for the time range of logs being processed. The format of Date should comply with RFC 3339 (e.g. 2002-10-02T15:00:00Z) or relative time. If not supplied, the product considers UTC time corresponding to 1 week earlier than current time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun. name: start_time - defaultValue: 10 min description: |- End time for the time range of logs being processed. The format of Date should comply with RFC 3339 (e.g. 2002-10-02T15:00:00Z) or relative time. If not supplied, the product considers UTC time corresponding to 10 minutes earlier than current time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun. name: end_time description: Initiate a retrohunt for the specified rule. name: gcb-start-retrohunt outputs: - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntId description: Unique identifier for a retrohunt, defined and returned by the server. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.ruleId description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.versionId description: Unique identifier for a specific version of a rule. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.eventStartTime description: Start time for the time range of logs being processed. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.eventEndTime description: End time for the time range of logs being processed. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntStartTime description: Start time for the retrohunt. type: Date - contextPath: GoogleChronicleBackstory.RetroHunt.state description: Current state of the retrohunt. It can be STATE_UNSPECIFIED, RUNNING, DONE, or CANCELLED. type: String - arguments: - description: Rule ID or Version ID of the rule whose retrohunt is to be cancelled. name: id required: true - description: Unique identifier for a retrohunt, defined and returned by the server. You must specify exactly one retrohunt identifier. name: retrohunt_id required: true description: Cancel a retrohunt for a specified rule. name: gcb-cancel-retrohunt outputs: - contextPath: GoogleChronicleBackstory.RetroHunt.id description: Unique identifier for a Rule. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.retrohuntId description: Unique identifier for a retrohunt, defined and returned by the server. type: String - contextPath: GoogleChronicleBackstory.RetroHunt.cancelled description: Whether the retrohunt is cancelled or not. type: Boolean - arguments: - auto: PREDEFINED description: Specify the identifier type of the asset you are investigating. The possible values are Host Name, IP Address, MAC Address or Product ID. name: asset_identifier_type predefined: - Host Name - IP Address - MAC Address - Product ID required: true - description: Value of the asset identifier. name: asset_identifier required: true - auto: PREDEFINED description: Get events that are discovered during the interval specified. If configured, overrides the start_time and end_time arguments. name: preset_time_range predefined: - Last 1 day - Last 7 days - Last 15 days - Last 30 days - description: 'The value of the start time for your request. The format of Date should comply with RFC 3339 (e.g. 2002-10-02T15:00:00Z) or relative time. If not supplied, the product considers UTC time corresponding to 2 hours earlier than current time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun.' name: start_time - description: 'The value of the end time for your request. The format of Date should comply with RFC 3339 (e.g. 2002-10-02T15:00:00Z) or relative time. If not supplied, the product considers current UTC time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun.' name: end_time - defaultValue: '10000' description: Specify the maximum number of events to fetch. You can specify between 1 and 10000. name: page_size - description: 'Specify the reference time for the asset you are investigating, in RFC 3339 format (e.g. 2002-10-02T15:00:00Z) or relative time. If not supplied, the product considers start time as reference time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun.' name: reference_time description: List all of the events discovered within your enterprise on a particular device within the specified time range. If you receive the maximum number of events you specified using the page_size parameter (or 100, the default), there might still be more events within your Google SecOps account. You can narrow the time range and issue the call again to ensure you have visibility into all possible events. This command returns more than 60 different types of events. Any event would have only specific output context set. Refer the UDM documentation to figure out the output properties specific to the event types. name: gcb-list-events outputs: - contextPath: GoogleChronicleBackstory.Events.eventType description: Specifies the type of the event. type: String - contextPath: GoogleChronicleBackstory.Events.eventTimestamp description: The GMT timestamp when the event was generated. type: Date - contextPath: GoogleChronicleBackstory.Events.collectedTimestamp description: The GMT timestamp when the event was collected by the vendor's local collection infrastructure. type: Date - contextPath: GoogleChronicleBackstory.Events.description description: Human-readable description of the event. type: String - contextPath: GoogleChronicleBackstory.Events.productEventType description: Short, descriptive, human-readable, and product-specific event name or type. type: String - contextPath: GoogleChronicleBackstory.Events.productLogId description: A vendor-specific event identifier to uniquely identify the event (a GUID). Users might use this identifier to search the vendor's proprietary console for the event in question. type: String - contextPath: GoogleChronicleBackstory.Events.productName description: Specifies the name of the product. type: String - contextPath: GoogleChronicleBackstory.Events.productVersion description: Specifies the version of the product. type: String - contextPath: GoogleChronicleBackstory.Events.urlBackToProduct description: URL linking to a relevant website where you can view more information about this specific event or the general event category. type: String - contextPath: GoogleChronicleBackstory.Events.vendorName description: Specifies the product vendor's name. type: String - contextPath: GoogleChronicleBackstory.Events.principal.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.principal.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.principal.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.principal.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.principal.mac description: MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.principal.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.principal.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.target.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.target.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.target.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.target.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.target.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.target.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.target.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.target.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.target.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.target.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.target.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.src.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.src.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.src.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.src.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.src.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.src.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.src.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.src.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.src.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.src.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.src.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.observer.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.observer.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.observer.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.observer.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.observer.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.observer.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.observer.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.about.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.about.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.about.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.about.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.about.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.about.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.about.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.about.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.about.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.about.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.about.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.network.applicationProtocol description: Indicates the network application protocol. type: String - contextPath: GoogleChronicleBackstory.Events.network.direction description: Indicates the direction of network traffic. type: String - contextPath: GoogleChronicleBackstory.Events.network.email description: Specifies the email address for the sender/recipient. type: String - contextPath: GoogleChronicleBackstory.Events.network.ipProtocol description: Indicates the IP protocol. type: String - contextPath: GoogleChronicleBackstory.Events.network.receivedBytes description: Specifies the number of bytes received. type: String - contextPath: GoogleChronicleBackstory.Events.network.sentBytes description: Specifies the number of bytes sent. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.clientHostname description: Hostname for the client. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.clientIdentifier description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.file description: Filename for the boot image. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.flags description: Value for the DHCP flags field. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.hlen description: Hardware address length. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.hops description: DHCP hop count. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.htype description: Hardware address type. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.leaseTimeSeconds description: Client-requested lease time for an IP address in seconds. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.opcode description: BOOTP op code. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.requestedAddress description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.seconds description: Seconds elapsed since the client began the address acquisition/renewal process. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.sname description: Name of the server which the client has requested to boot from. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.transactionId description: Client transaction ID. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.type description: DHCP message type. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.chaddr description: IP address for the client hardware. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.ciaddr description: IP address for the client. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.giaddr description: IP address for the relay agent. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.siaddr description: IP address for the next bootstrap server. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.yiaddr description: Your IP address. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authoritative description: Set to true for authoritative DNS servers. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.id description: Stores the DNS query identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.response description: Set to true if the event is a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.opcode description: Stores the DNS OpCode used to specify the type of DNS query (standard, inverse, server status, etc.). type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.recursionAvailable description: Set to true if a recursive DNS lookup is available. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.recursionDesired description: Set to true if a recursive DNS lookup is requested. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.responseCode description: Stores the DNS response code as defined by RFC 1035, Domain Names - Implementation and Specification. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.truncated description: Set to true if this is a truncated DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.name description: Stores the domain name. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.class description: Stores the code specifying the class of the query. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.type description: Stores the code specifying the type of the query. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.from description: Stores the from email address. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.replyTo description: Stores the reply_to email address. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.to description: Stores the to email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.cc description: Stores the cc email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.bcc description: Stores the bcc email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.mailId description: Stores the mail (or message) ID. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.subject description: Stores the email subject line. type: String - contextPath: GoogleChronicleBackstory.Events.network.ftp.command description: Stores the FTP command. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.method description: Stores the HTTP request method. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.referralUrl description: Stores the URL for the HTTP referer. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.responseCode description: Stores the HTTP response status code, which indicates whether a specific HTTP request has been successfully completed. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.useragent description: Stores the User-Agent request header which includes the application type, operating system, software vendor or software version of the requesting software user agent. type: String - contextPath: GoogleChronicleBackstory.Events.authentication.authType description: Type of system an authentication event is associated with (Chronicle UDM). type: String - contextPath: GoogleChronicleBackstory.Events.authentication.mechanism description: Mechanism(s) used for authentication. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.about description: Provide a description of the security result. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.action description: Specify a security action. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.category description: Specify a security category. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.confidence description: Specify a confidence with regards to a security event as estimated by the product. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.confidenceDetails description: Additional detail with regards to the confidence of a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.priority description: Specify a priority with regards to a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.priorityDetails description: Vendor-specific information about the security result priority. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.ruleId description: Identifier for the security rule. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.ruleName description: Name of the security rule. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.severity description: Severity of a security event as estimated by the product vendor using values defined by the Chronicle UDM. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.severityDetails description: Severity for a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.threatName description: Name of the security threat. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.urlBackToProduct description: URL to direct you to the source product console for this security event. type: String - arguments: - description: |- Specify the ID of the event. Note: The event_id can be retrieved from the output context path (GoogleChronicleBackstory.Events.id) of the gcb-list-events command. name: event_id required: true description: |- Get the specific event with the given ID from Google SecOps. Note: This command returns more than 60 different types of events. Any event would have only specific output context set. Refer the UDM documentation to figure out the output properties specific to the event types. name: gcb-get-event outputs: - contextPath: GoogleChronicleBackstory.Events.eventType description: Specifies the type of the event. type: String - contextPath: GoogleChronicleBackstory.Events.eventTimestamp description: The GMT timestamp when the event was generated. type: Date - contextPath: GoogleChronicleBackstory.Events.collectedTimestamp description: The GMT timestamp when the event was collected by the vendor's local collection infrastructure. type: Date - contextPath: GoogleChronicleBackstory.Events.description description: Human-readable description of the event. type: String - contextPath: GoogleChronicleBackstory.Events.productEventType description: Short, descriptive, human-readable, and product-specific event name or type. type: String - contextPath: GoogleChronicleBackstory.Events.productLogId description: A vendor-specific event identifier to uniquely identify the event (a GUID). Users might use this identifier to search the vendor's proprietary console for the event in question. type: String - contextPath: GoogleChronicleBackstory.Events.productName description: Specifies the name of the product. type: String - contextPath: GoogleChronicleBackstory.Events.productVersion description: Specifies the version of the product. type: String - contextPath: GoogleChronicleBackstory.Events.urlBackToProduct description: URL linking to a relevant website where you can view more information about this specific event or the general event category. type: String - contextPath: GoogleChronicleBackstory.Events.vendorName description: Specifies the product vendor's name. type: String - contextPath: GoogleChronicleBackstory.Events.principal.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.principal.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.principal.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.principal.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.principal.mac description: MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.principal.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.principal.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.target.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.target.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.target.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.target.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.target.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.target.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.target.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.target.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.target.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.target.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.target.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.src.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.src.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.src.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.src.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.src.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.src.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.src.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.src.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.src.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.src.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.src.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.observer.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.observer.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.observer.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.observer.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.observer.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.observer.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.observer.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.about.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.about.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.about.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.about.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.about.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.about.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.about.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.about.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.about.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.about.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.about.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.network.applicationProtocol description: Indicates the network application protocol. type: String - contextPath: GoogleChronicleBackstory.Events.network.direction description: Indicates the direction of network traffic. type: String - contextPath: GoogleChronicleBackstory.Events.network.email description: Specifies the email address for the sender/recipient. type: String - contextPath: GoogleChronicleBackstory.Events.network.ipProtocol description: Indicates the IP protocol. type: String - contextPath: GoogleChronicleBackstory.Events.network.receivedBytes description: Specifies the number of bytes received. type: String - contextPath: GoogleChronicleBackstory.Events.network.sentBytes description: Specifies the number of bytes sent. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.clientHostname description: Hostname for the client. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.clientIdentifier description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.file description: Filename for the boot image. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.flags description: Value for the DHCP flags field. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.hlen description: Hardware address length. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.hops description: DHCP hop count. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.htype description: Hardware address type. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.leaseTimeSeconds description: Client-requested lease time for an IP address in seconds. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.opcode description: BOOTP op code. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.requestedAddress description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.seconds description: Seconds elapsed since the client began the address acquisition/renewal process. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.sname description: Name of the server which the client has requested to boot from. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.transactionId description: Client transaction ID. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.type description: DHCP message type. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.chaddr description: IP address for the client hardware. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.ciaddr description: IP address for the client. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.giaddr description: IP address for the relay agent. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.siaddr description: IP address for the next bootstrap server. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.yiaddr description: Your IP address. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authoritative description: Set to true for authoritative DNS servers. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.id description: Stores the DNS query identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.response description: Set to true if the event is a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.opcode description: Stores the DNS OpCode used to specify the type of DNS query (standard, inverse, server status, etc.). type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.recursionAvailable description: Set to true if a recursive DNS lookup is available. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.recursionDesired description: Set to true if a recursive DNS lookup is requested. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.responseCode description: Stores the DNS response code as defined by RFC 1035, Domain Names - Implementation and Specification. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.truncated description: Set to true if this is a truncated DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.name description: Stores the domain name. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.class description: Stores the code specifying the class of the query. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.type description: Stores the code specifying the type of the query. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.from description: Stores the from email address. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.replyTo description: Stores the reply_to email address. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.to description: Stores the to email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.cc description: Stores the cc email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.bcc description: Stores the bcc email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.mailId description: Stores the mail (or message) ID. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.subject description: Stores the email subject line. type: String - contextPath: GoogleChronicleBackstory.Events.network.ftp.command description: Stores the FTP command. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.method description: Stores the HTTP request method. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.referralUrl description: Stores the URL for the HTTP referer. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.responseCode description: Stores the HTTP response status code, which indicates whether a specific HTTP request has been successfully completed. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.useragent description: Stores the User-Agent request header which includes the application type, operating system, software vendor or software version of the requesting software user agent. type: String - contextPath: GoogleChronicleBackstory.Events.authentication.authType description: Type of system an authentication event is associated with (Chronicle UDM). type: String - contextPath: GoogleChronicleBackstory.Events.authentication.mechanism description: Mechanism(s) used for authentication. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.about description: Provide a description of the security result. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.action description: Specify a security action. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.category description: Specify a security category. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.confidence description: Specify a confidence with regards to a security event as estimated by the product. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.confidenceDetails description: Additional detail with regards to the confidence of a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.priority description: Specify a priority with regards to a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.priorityDetails description: Vendor-specific information about the security result priority. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.ruleId description: Identifier for the security rule. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.ruleName description: Name of the security rule. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.severity description: Severity of a security event as estimated by the product vendor using values defined by the Chronicle UDM. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.severityDetails description: Severity for a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.threatName description: Name of the security threat. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.urlBackToProduct description: URL to direct you to the source product console for this security event. type: String - arguments: - default: true description: |- Unique identifier for a rule or specific version of a rule, defined and returned by the server. You can specify exactly one rule identifier. Use the following format to specify the id: ru_{UUID} or {ruleId}@v_{int64}_{int64}. If not specified then detections for all versions of all rules are returned. name: id - description: |- (Deprecated: use `start_time` instead) Time to begin returning detections, filtering on a detection's "detectionTime". If not specified, the start time is treated as open-ended. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun. name: detection_start_time - description: |- (Deprecated: use `end_time` instead) Time to stop returning detections, filtering on a detection's "detectionTime". If not specified, the end time is treated as open-ended. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun. name: detection_end_time - auto: PREDEFINED description: |- Filter detections on if they are ALERTING or NOT_ALERTING. Avoid specifying to return all detections. name: alert_state predefined: - ALERTING - NOT_ALERTING - defaultValue: '100' description: Specify the limit on the number of detections to display. You can specify between 1 and 1000. name: page_size - description: A page token received from a previous call. Provide this to retrieve the subsequent page. If the page token is configured, overrides the detection start and end time arguments. name: page_token - auto: PREDEFINED defaultValue: 'False' description: |- Whether the user wants to retrieve detections for all versions of a rule with a given rule identifier. Note: If this option is set to true, rule id is required. name: detection_for_all_versions predefined: - 'True' - 'False' - auto: PREDEFINED description: |- Sort detections by "DETECTION_TIME" or by "CREATED_TIME". If not specified, it defaults to "DETECTION_TIME". Detections are returned in descending order of the timestamp. Note: Requires either "start_time" or "end_time" argument. name: list_basis predefined: - DETECTION_TIME - CREATED_TIME - description: |- Time to begin returning detections, filtering by the detection field specified in the listBasis parameter. If not specified, the start time is treated as open-ended. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun. name: start_time - description: |- Time to stop returning detections, filtering by the detection field specified by the listBasis parameter. If not specified, the end time is treated as open-ended. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun. name: end_time description: Return the detections for the specified version of a rule, the latest version of a rule, all versions of a rule, or all versions of all rules. name: gcb-list-detections outputs: - contextPath: GoogleChronicleBackstory.Detections.id description: Identifier for the detection. type: String - contextPath: GoogleChronicleBackstory.Detections.ruleId description: Identifier for the rule generating the detection. type: String - contextPath: GoogleChronicleBackstory.Detections.ruleVersion description: Identifier for the rule version generating the detection. type: String - contextPath: GoogleChronicleBackstory.Detections.ruleName description: Name of the rule generating the detection, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.Detections.timeWindowStartTime description: The start time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.Detections.timeWindowEndTime description: The end time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.Detections.alertState description: Indicates whether the rule generating this detection currently has alerting enabled or disabled. type: String - contextPath: GoogleChronicleBackstory.Detections.urlBackToProduct description: URL pointing to the Chronicle UI for this detection. type: String - contextPath: GoogleChronicleBackstory.Detections.type description: Type of detection. type: String - contextPath: GoogleChronicleBackstory.Detections.createdTime description: Time the detection was created. type: Date - contextPath: GoogleChronicleBackstory.Detections.detectionTime description: The time period the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.Detections.ruleType description: Whether the rule generating this detection is a single event or multi-event rule. type: String - contextPath: GoogleChronicleBackstory.Detections.detectionFields.key description: The key for a field specified in the rule, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.Detections.detectionFields.value description: The value for a field specified in the rule, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.label description: The variable a given set of UDM events belongs to. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principalAssetIdentifier description: Specifies the principal asset identifier of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.targetAssetIdentifier description: Specifies the target asset identifier of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.eventType description: Specifies the type of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.eventTimestamp description: The GMT timestamp when the event was generated. type: Date - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.ingestedTimestamp description: The GMT timestamp when the event was ingested in the vendor's instance. type: Date - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.description description: Human-readable description of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productEventType description: Short, descriptive, human-readable, and product-specific event name or type. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productLogId description: A vendor-specific event identifier to uniquely identify the event (a GUID). Users might use this identifier to search the vendor's proprietary console for the event in question. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productName description: Specifies the name of the product. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productVersion description: Specifies the version of the product. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.urlBackToProduct description: URL linking to a relevant website where you can view more information about this specific event or the general event category. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.vendorName description: Specifies the product vendor's name. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.mac description: MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.applicationProtocol description: Indicates the network application protocol. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.direction description: Indicates the direction of network traffic. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email description: Specifies the email address for the sender/recipient. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.ipProtocol description: Indicates the IP protocol. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.receivedBytes description: Specifies the number of bytes received. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.sentBytes description: Specifies the number of bytes sent. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.clientHostname description: Hostname for the client. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.clientIdentifier description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.file description: Filename for the boot image. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.flags description: Value for the DHCP flags field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.hlen description: Hardware address length. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.hops description: DHCP hop count. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.htype description: Hardware address type. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.leaseTimeSeconds description: Client-requested lease time for an IP address in seconds. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.opcode description: BOOTP op code. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.requestedAddress description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.seconds description: Seconds elapsed since the client began the address acquisition/renewal process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.sname description: Name of the server which the client has requested to boot from. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.transactionId description: Client transaction ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.type description: DHCP message type. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.chaddr description: IP address for the client hardware. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.ciaddr description: IP address for the client. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.giaddr description: IP address for the relay agent. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.siaddr description: IP address for the next bootstrap server. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.yiaddr description: Your IP address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authoritative description: Set to true for authoritative DNS servers. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.id description: Stores the DNS query identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.response description: Set to true if the event is a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.opcode description: Stores the DNS OpCode used to specify the type of DNS query (standard, inverse, server status, etc.). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.recursionAvailable description: Set to true if a recursive DNS lookup is available. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.recursionDesired description: Set to true if a recursive DNS lookup is requested. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.responseCode description: Stores the DNS response code as defined by RFC 1035, Domain Names - Implementation and Specification. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.truncated description: Set to true if this is a truncated DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.questions.name description: Stores the domain name. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.questions.class description: Stores the code specifying the class of the query. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.questions.type description: Stores the code specifying the type of the query. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.from description: Stores the from email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.replyTo description: Stores the reply_to email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.to description: Stores the to email addresses. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.cc description: Stores the cc email addresses. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.bcc description: Stores the bcc email addresses. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.mailId description: Stores the mail (or message) ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.subject description: Stores the email subject line. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.ftp.command description: Stores the FTP command. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.method description: Stores the HTTP request method. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.referralUrl description: Stores the URL for the HTTP referer. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.responseCode description: Stores the HTTP response status code, which indicates whether a specific HTTP request has been successfully completed. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.useragent description: Stores the User-Agent request header which includes the application type, operating system, software vendor or software version of the requesting software user agent. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.authentication.authType description: Type of system an authentication event is associated with (Chronicle UDM). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.authentication.mechanism description: Mechanism(s) used for authentication. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.about description: Provide a description of the security result. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.action description: Specify a security action. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.category description: Specify a security category. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.confidence description: Specify a confidence with regards to a security event as estimated by the product. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.confidenceDetails description: Additional detail with regards to the confidence of a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.priority description: Specify a priority with regards to a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.priorityDetails description: Vendor-specific information about the security result priority. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.ruleId description: Identifier for the security rule. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.ruleName description: Name of the security rule. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.severity description: Severity of a security event as estimated by the product vendor using values defined by the Chronicle UDM. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.severityDetails description: Severity for a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.threatName description: Name of the security threat. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.urlBackToProduct description: URL to direct you to the source product console for this security event. type: String - contextPath: GoogleChronicleBackstory.Token.name description: The name of the command to which the value of the nextPageToken corresponds. type: String - contextPath: GoogleChronicleBackstory.Token.nextPageToken description: A page token that can be provided to the next call to view the next page of detections. Absent if this is the last page. type: String - arguments: - default: false description: Unique identifier for a curated rule, defined and returned by the server. You can specify exactly one curated rule identifier. isArray: false name: id required: true secret: false - auto: PREDEFINED default: false description: |- Filter detections based on whether the alert state is ALERTING or NOT_ALERTING. Do not specify to return all detections. isArray: false name: alert_state predefined: - ALERTING - NOT_ALERTING required: false secret: false - default: false defaultValue: '100' description: Specify the limit on the number of detections to display. You can specify between 1 and 1000. isArray: false name: page_size required: false secret: false - default: false description: A page token received from a previous call. Provide this to retrieve the subsequent page. If the page token is configured, overrides the detection start and end time arguments. isArray: false name: page_token required: false secret: false - auto: PREDEFINED default: false description: Sort detections by "DETECTION_TIME" or by "CREATED_TIME". If not specified, it defaults to "DETECTION_TIME". Detections are returned in descending order of the timestamp. isArray: false name: list_basis predefined: - DETECTION_TIME - CREATED_TIME required: false secret: false - default: false description: |- Start time of the time range to return detections for, filtered by the detection field specified in the list_basis parameter. If not specified, the start time is treated as open-ended. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2023-05-01T00:00:00Z, 2023-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2023 04:45:33, 15 Jun. isArray: false name: start_time required: false secret: false - default: false description: |- End time of the time range to return detections for, filtered by the detection field specified by the list_basis parameter. If not specified, the end time is treated as open-ended. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2023-05-01T00:00:00Z, 2023-05-01, 2 days, 5 hours, 01 Mar 2023, 01 Feb 2021 04:45:33, 15 Jun. isArray: false name: end_time required: false secret: false deprecated: false description: Return the detections for the specified curated rule identifier. execution: false name: gcb-list-curatedrule-detections outputs: - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.id description: Identifier for the detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.ruleId description: Identifier for the rule generating the detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.ruleName description: Name of the rule generating the detection, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.ruleSet description: The identifier of the Chronicle rule set that generated this detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.ruleSetDisplayName description: The display name of the Chronicle rule set that generated this detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.tags description: A list of MITRE tactic and technique IDs covered by the Chronicle rule. type: Unknown - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.timeWindowStartTime description: The start time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.timeWindowEndTime description: The end time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.alertState description: Indicates whether the rule generating this detection currently has alerting enabled or disabled. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.description description: Description of the Chronicle rule that generated the detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.urlBackToProduct description: URL pointing to the Chronicle UI for this detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.type description: Type of detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.createdTime description: Time the detection was created. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.detectionTime description: The time period the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.lastUpdatedTime description: The time period of when the detection was last updated. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.riskScore description: Risk score of the detection. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.severity description: Severity of the detection ("INFORMATIONAL" or "LOW" or "HIGH"). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.summary description: Summary for the generated detection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.ruleType description: Whether the rule generating this detection is a single event or multi-event rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.detectionFields.key description: The key for a field specified in the rule, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.detectionFields.source description: The source for a field specified in the rule, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.detectionFields.value description: The value for a field specified in the rule, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.outcomes.key description: The key for a field specified in the outcomes of the detection, for "MULTI_EVENT" rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.outcomes.source description: The source for a field specified in the outcomes of the detection, for "MULTI_EVENT" rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.outcomes.value description: The value for a field specified in the outcomes of the detection, for "MULTI_EVENT" rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.ruleLabels.key description: The key for a field specified in the Chronicle rule metadata. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.ruleLabels.value description: The value for a field specified in the Chronicle rule metadata. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.label description: The variable a given set of UDM events belongs to. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principalAssetIdentifier description: Specifies the principal asset identifier of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.targetAssetIdentifier description: Specifies the target asset identifier of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.collectedTimestamp description: The GMT timestamp when the event was collected. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.eventType description: Specifies the type of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.eventTimestamp description: The GMT timestamp when the event was generated. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.id description: The event ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.ingestedTimestamp description: The GMT timestamp when the event was ingested in the vendor's instance. type: Date - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.ingestionLabels.key description: The key for a field specified in the ingestion labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.ingestionLabels.value description: The value for a field specified in the ingestion labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.logType description: Type of log. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.description description: Human-readable description of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.productEventType description: Short, descriptive, human-readable, and product-specific event name or type. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.productLogId description: A vendor-specific event identifier to uniquely identify the event (a GUID). Users might use this identifier to search the vendor's proprietary console for the event in question. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.productName description: Specifies the name of the product. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.productVersion description: Specifies the version of the product. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.urlBackToProduct description: URL linking to a relevant website where you can view more information about this specific event or the general event category. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.vendorName description: Specifies the product vendor's name. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.ip description: IP address associated with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.location.countryOrRegion description: Associated country or region for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.location.regionCoordinates.latitude description: Latitude coordinates of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.location.regionCoordinates.longitude description: Longitude coordinates of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.location.regionLatitude description: Latitude of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.location.regionLongitude description: Longitude of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.location.state description: Associated state of IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.network.asn description: Associated ASN with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.network.carrierName description: Associated carrier name with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.network.dnsDomain description: Associated DNS domain with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipGeoArtifact.network.organizationName description: Associated organization name with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipLocation.countryOrRegion description: Associated country or region for the IP location. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipLocation.regionCoordinates.latitude description: Latitude coordinates of the region for the IP location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipLocation.regionCoordinates.longitude description: Longitude coordinates of the region for IP location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipLocation.regionLatitude description: Latitude of the region for the IP location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipLocation.regionLongitude description: Longitude of the region for the IP location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.ipLocation.state description: Associated state of the IP location. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.labels.key description: The key for a field specified in the principal labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.labels.value description: The value for a field specified in the principal labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.location.countryOrRegion description: Associated country or region for the principal location. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.location.regionCoordinates.latitude description: Latitude coordinates of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.location.regionCoordinates.longitude description: Longitude coordinates of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.location.regionLatitude description: Latitude of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.location.regionLongitude description: Longitude of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.location.state description: Associated state of the principal location. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.resource.attribute.cloud.project.name description: Associated name of the project specified in the principal resource. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.resource.attribute.cloud.project.resourceSubtype description: Associated resource sub-type of the project specified in the principal resource. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.resource.attribute.labels.key description: The key for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.resource.attribute.labels.value description: The value for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.attribute.cloud.environment description: Associated environment specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.attribute.cloud.project.id description: Associated ID of the project specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.attribute.permissions.name description: Associated name of the permission specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.attribute.permissions.type description: Associated type of the permission specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.attribute.roles.description description: Associated description of the role specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.attribute.roles.name description: Associated name of the role specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.attribute.roles.type description: Associated type of the role specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.mac description: MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.productObjectId description: Stores the product object ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.principal.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.administrativeDomain description: Domain for which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.application description: Application of the target related to the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.cloud.availabilityZone description: Associated availability zone specified in the event target. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.cloud.environment description: Associated environment specified in the event target. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.cloud.project.name description: Associated name of the project specified in the event target. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.cloud.vpc description: Associated VPC specified in the event target. type: Unknown - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.resource.name description: Associated resource name specified in the event target. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.resource.productObjectId description: Associated product object ID specified in the event target. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.resource.resourceType description: Associated resource type specified in the event target. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.resource.attribute.labels.key description: The key for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.resource.attribute.labels.value description: The value for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.attribute.cloud.environment description: Associated environment specified in the target user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.attribute.cloud.project.id description: Associated ID of the project specified in the target user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.attribute.roles.name description: Associated name of the role specified in the target user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.attribute.roles.type description: Associated type of the role specified in the target user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.emailAddresses description: Stores the email addresses for the user. type: Unknown - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.productObjectId description: Stores the human resources product object ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.target.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.intermediary.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.src.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.observer.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.about.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.applicationProtocol description: Indicates the network application protocol. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.direction description: Indicates the direction of network traffic. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email description: Specifies the email address for the sender/recipient. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.ipProtocol description: Indicates the IP protocol. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.receivedBytes description: Specifies the number of bytes received. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.sentBytes description: Specifies the number of bytes sent. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.clientHostname description: Hostname for the client. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.clientIdentifier description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.file description: Filename for the boot image. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.flags description: Value for the DHCP flags field. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.hlen description: Hardware address length. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.hops description: DHCP hop count. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.htype description: Hardware address type. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.leaseTimeSeconds description: Client-requested lease time for an IP address in seconds. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.opcode description: BOOTP op code. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.requestedAddress description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.seconds description: Seconds elapsed since the client began the address acquisition/renewal process. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.sname description: Name of the server that the client has requested to boot from. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.transactionId description: Client transaction ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.type description: DHCP message type. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.chaddr description: IP address for the client hardware. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.ciaddr description: IP address for the client. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.giaddr description: IP address for the relay agent. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.siaddr description: IP address for the next bootstrap server. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dhcp.yiaddr description: Your IP address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.authoritative description: Set to true for authoritative DNS servers. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.id description: Stores the DNS query identifier. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.response description: Set to true if the event is a DNS response. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.opcode description: Stores the DNS OpCode used to specify the type of DNS query (standard, inverse, server status, etc.). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.recursionAvailable description: Set to true if a recursive DNS lookup is available. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.recursionDesired description: Set to true if a recursive DNS lookup is requested. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.responseCode description: Stores the DNS response code as defined by RFC 1035, Domain Names - Implementation and Specification. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.truncated description: Set to true if this is a truncated DNS response. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.questions.name description: Stores the domain name. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.questions.class description: Stores the code specifying the class of the query. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.questions.type description: Stores the code specifying the type of the query. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.answers.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.answers.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.answers.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.answers.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.answers.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.answers.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.authority.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.authority.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.authority.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.authority.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.authority.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.authority.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.additional.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.additional.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.additional.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.additional.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.additional.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.dns.additional.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email.from description: Stores the from email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email.replyTo description: Stores the reply_to email address. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email.to description: Stores the to email addresses. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email.cc description: Stores the cc email addresses. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email.bcc description: Stores the bcc email addresses. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email.mailId description: Stores the mail (or message) ID. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.email.subject description: Stores the email subject line. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.ftp.command description: Stores the FTP command. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.http.method description: Stores the HTTP request method. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.http.referralUrl description: Stores the URL for the HTTP referer. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.http.responseCode description: Stores the HTTP response status code, which indicates whether a specific HTTP request has been successfully completed. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.network.http.useragent description: Stores the User-Agent request header which includes the application type, operating system, software vendor or software version of the requesting software user agent. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.authentication.authType description: Type of system an authentication event is associated with (Chronicle UDM). type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.authentication.mechanism description: Mechanism(s) used for authentication. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.about description: Provide a description of the security result. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.action description: Specify a security action. type: Unknown - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.category description: Specify a security category. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.categoryDetails description: Specify the security category details. type: Unknown - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.detectionFields.key description: The key for a field specified in the security result, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.detectionFields.value description: The value for a field specified in the security result, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.confidence description: Specify a confidence with regards to a security event as estimated by the product. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.confidenceDetails description: Additional details with regards to the confidence of a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.priority description: Specify a priority with regards to a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.priorityDetails description: Vendor-specific information about the security result priority. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.ruleId description: Identifier for the security rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.ruleName description: Name of the security rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.severity description: Severity of a security event as estimated by the product vendor using values defined by the Chronicle UDM. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.severityDetails description: Severity for a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.threatName description: Name of the security threat. type: String - contextPath: GoogleChronicleBackstory.CuratedRuleDetections.collectionElements.references.securityResult.urlBackToProduct description: URL to direct you to the source product console for this security event. type: String - contextPath: GoogleChronicleBackstory.Token.name description: The name of the command to which the value of the nextPageToken corresponds. type: String - contextPath: GoogleChronicleBackstory.Token.nextPageToken description: A page token that can be provided to the next call to view the next page of detections. Absent if this is the last page. type: String - arguments: - description: Page token received from a previous call. Use to retrieve the next page. name: page_token required: false - defaultValue: '100' description: Specify the maximum number of rules to return. You can specify between 1 and 1000. name: page_size required: false description: List curated rules. name: gcb-list-curatedrules outputs: - contextPath: GoogleChronicleBackstory.CuratedRules.ruleId description: Unique identifier for a rule, defined and returned by the server. type: String - contextPath: GoogleChronicleBackstory.CuratedRules.ruleName description: Name of the rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRules.severity description: Severity of the rule ("Info", "Low", or "High"). type: String - contextPath: GoogleChronicleBackstory.CuratedRules.ruleType description: Type of the rule ("SINGLE_EVENT" or "MULTI_EVENT"). type: String - contextPath: GoogleChronicleBackstory.CuratedRules.precision description: Precision of the rule ("BROAD" or "PRECISE"). type: String - contextPath: GoogleChronicleBackstory.CuratedRules.tactics description: List of MITRE tactic IDs covered by the rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRules.techniques description: List of MITRE technique IDs covered by the rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRules.updateTime description: String representing the time the rule was last updated, in RFC 3339 format. type: Date - contextPath: GoogleChronicleBackstory.CuratedRules.ruleSet description: Unique identifier of the Chronicle rule set containing the rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRules.description description: Description of the rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRules.metadata.false_positives description: Metadata for the rule. type: String - contextPath: GoogleChronicleBackstory.CuratedRules.metadata.reference description: Reference for the rule. type: String - contextPath: GoogleChronicleBackstory.Token.name description: The name of the command to which the value of the nextPageToken corresponds. type: String - contextPath: GoogleChronicleBackstory.Token.nextPageToken description: A page token that can be provided to the next call to view the next page of rules. Absent if this is the last page. type: String - arguments: - description: Rule text in YARA-L 2.0 format for the rule to stream. name: rule_text required: true - description: "Start time for the time range of the rule being tested. The format of Date should comply with RFC 3339 (e.g. 2022-10-02T15:00:00Z) or relative time. \n\nFormats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours.\nExample: 2022-05-01T00:00:00Z, 2022-05-01, 2 days, 5 hours, 01 Mar 2022, 01 Feb 2022 04:45:33, 15 Jun.\n\n\nNote: The time window between start_time and end_time cannot be greater than 2 weeks." name: start_time required: true - description: "End time for the time range of the rule being tested. The format of Date should comply with RFC 3339 (e.g. 2022-10-02T15:00:00Z) or relative time. \n\nFormats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours.\nExample: 2022-05-01T00:00:00Z, 2022-05-01, 2 days, 5 hours, 01 Mar 2022, 01 Feb 2022 04:45:33, 15 Jun.\n\nNote: The time window between start_time and end_time cannot be greater than 2 weeks." name: end_time required: true - default: true defaultValue: '1000' description: Maximum number of results to return. Specify a value between 1 and 10,000. name: max_results description: Test a rule over a specified time range. Return any errors and any detections up to the specified maximum. name: gcb-test-rule-stream outputs: - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.type description: Type of detection. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.detection.ruleName description: Name of the rule generating the detection, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.detection.ruleType description: Whether the rule generating this detection is a single event or multi-event rule. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.detection.ruleLabels description: Information about the rule. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.id description: Identifier for the detection. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.timeWindow.startTime description: The start time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.timeWindow.endTime description: The end time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.productLogId description: A vendor-specific event identifier to uniquely identify the event (a GUID). Users might use this identifier to search the vendor's proprietary console for the event in question. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.eventTimestamp description: The GMT timestamp when the event was generated. type: Date - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.eventType description: Specifies the type of the event. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.vendorName description: Specifies the product vendor's name. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.productName description: Specifies the name of the product. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.productEventType description: Short, descriptive, human-readable, and product-specific event name or type. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.ingestedTimestamp description: The GMT timestamp when the event was ingested in the vendor's instance. type: Date - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.metadata.id description: Stores the ID of metadata. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.emailAddresses description: Stores the email addresses for the user. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.productObjectId description: Stores the products object ID. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.attribute.labels description: Stores users session metrics. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.phoneNumbers description: Stores the phone numbers for the user. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.personalAddress.city description: Stores city of user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.personalAddress.state description: Stores state of user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.personalAddress.name description: Stores address name of user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.companyName description: Stores users company name. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.department description: Stores users departments. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.user.officeAddress.name description: Stores company official address name. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.principal.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.about description: Stores event labels. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.securityResult description: Provide a description of the security result. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.network.applicationProtocol description: Indicates the network application protocol. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.network.dns.questions description: Stores the domain name. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.references.event.network.dns.answers description: Stores dns associated data. type: Unknown - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.collectionElements.label description: The variable a given set of UDM events belongs to. type: String - contextPath: GoogleChronicleBackstory.StreamRules.list.detection.detectionTime description: The time period the detection was found in. type: Date - arguments: - description: 'The value of the start time for your request. The date format should comply with RFC 3339 (e.g., 2023-01-02T15:00:00Z) or relative time. If not supplied, the product considers UTC time corresponding to 3 days earlier than the current time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. If the date is supplied in duration, it will be calculated as time.now() - duration. Example: 2023-04-25T00:00:00Z, 2023-04-25, 2 days, 5 hours, 01 Mar 2023, 01 Feb 2023 04:45:33, 15 Jun.' name: start_time required: false - description: 'The value of the end time for your request. The date format should comply with RFC 3339 (e.g., 2023-01-02T15:00:00Z) or relative time. If not supplied, the product considers current UTC time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. If the date is supplied in duration, it will be calculated as time.now() - duration. Example: 2023-04-25T00:00:00Z, 2023-04-25, 2 days, 5 hours, 01 Mar 2023, 01 Feb 2023 04:45:33, 15 Jun.' name: end_time required: false - defaultValue: '200' description: Specify the maximum number of matched events to return. You can specify between 1 and 1000. name: limit required: false - description: UDM search query. name: query required: true description: "Lists the events for the specified UDM Search query.\nNote: For more information about rate limits, see [Google service limits](https://cloud.google.com/chronicle/docs/reference/service-limits#:~:text=udmSearch-,360%20QPH,-Search%20API#:~:text=udmSearch-,360%20QPH,-Search%20API)." name: gcb-udm-search outputs: - contextPath: GoogleChronicleBackstory.Events.eventType description: Specifies the type of the event. type: String - contextPath: GoogleChronicleBackstory.Events.eventTimestamp description: The GMT timestamp when the event was generated. type: Date - contextPath: GoogleChronicleBackstory.Events.id description: The event ID. type: String - contextPath: GoogleChronicleBackstory.Events.ingestedTimestamp description: The GMT timestamp when the event was ingested in the vendor's instance. type: Date - contextPath: GoogleChronicleBackstory.Events.ingestionLabels.key description: The key for a field specified in the ingestion labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.ingestionLabels.value description: The value for a field specified in the ingestion labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.collectedTimestamp description: The GMT timestamp when the event was collected by the vendor's local collection infrastructure. type: Date - contextPath: GoogleChronicleBackstory.Events.logType description: Type of log. type: String - contextPath: GoogleChronicleBackstory.Events.description description: Human-readable description of the event. type: String - contextPath: GoogleChronicleBackstory.Events.productEventType description: Short, descriptive, human-readable, and product-specific event name or type. type: String - contextPath: GoogleChronicleBackstory.Events.productLogId description: A vendor-specific event identifier to uniquely identify the event (a GUID). Users might use this identifier to search the vendor's proprietary console for the event in question. type: String - contextPath: GoogleChronicleBackstory.Events.productName description: Specifies the name of the product. type: String - contextPath: GoogleChronicleBackstory.Events.productVersion description: Specifies the version of the product. type: String - contextPath: GoogleChronicleBackstory.Events.urlBackToProduct description: URL linking to a relevant website where you can view more information about this specific event or the general event category. type: String - contextPath: GoogleChronicleBackstory.Events.vendorName description: Specifies the product vendor's name. type: String - contextPath: GoogleChronicleBackstory.Events.principal.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.principal.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.principal.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.principal.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.ip description: IP address associated with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.location.countryOrRegion description: Associated country or region for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.location.regionCoordinates.latitude description: Latitude coordinates of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.location.regionCoordinates.longitude description: Longitude coordinates of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.location.regionLatitude description: Latitude of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.location.regionLongitude description: Longitude of the region for IP Geolocation. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.location.state description: Associated state of IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.network.asn description: Associated ASN with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.network.carrierName description: Associated carrier name with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.network.dnsDomain description: Associated DNS domain with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipGeoArtifact.network.organizationName description: Associated organization name with a network connection for IP Geolocation. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipLocation.countryOrRegion description: Associated country or region for the IP location. type: String - contextPath: GoogleChronicleBackstory.Events.principal.ipLocation.regionCoordinates.latitude description: Latitude coordinates of the region for the IP location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipLocation.regionCoordinates.longitude description: Longitude coordinates of the region for the IP location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipLocation.regionLatitude description: Latitude of the region for the IP location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipLocation.regionLongitude description: Longitude of the region for the IP location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.ipLocation.state description: Associated state of the IP location. type: String - contextPath: GoogleChronicleBackstory.Events.principal.labels.key description: The key for a field specified in the principal labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.principal.labels.value description: The value for a field specified in the principal labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.principal.location.countryOrRegion description: Associated country or region for the principal location. type: String - contextPath: GoogleChronicleBackstory.Events.principal.location.regionCoordinates.latitude description: Latitude coordinates of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.location.regionCoordinates.longitude description: Longitude coordinates of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.location.regionLatitude description: Latitude of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.location.regionLongitude description: Longitude of the region for the principal location. type: Number - contextPath: GoogleChronicleBackstory.Events.principal.location.state description: Associated state of the principal location. type: String - contextPath: GoogleChronicleBackstory.Events.principal.resource.attribute.cloud.project.name description: Associated name of the project specified in the principal resource. type: String - contextPath: GoogleChronicleBackstory.Events.principal.resource.attribute.cloud.project.resourceSubtype description: Associated resource sub-type of the project specified in the principal resource. type: String - contextPath: GoogleChronicleBackstory.Events.principal.resource.attribute.labels.key description: The key for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.principal.resource.attribute.labels.value description: The value for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.attribute.cloud.environment description: Associated environment specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.attribute.cloud.project.id description: Associated ID of the project specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.attribute.permissions.name description: Associated name of the permission specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.attribute.permissions.type description: Associated type of the permission specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.attribute.roles.description description: Associated description of the role specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.attribute.roles.name description: Associated name of the role specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.attribute.roles.type description: Associated type of the role specified in the principal user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.principal.mac description: MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.principal.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.principal.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.principal.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.principal.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.employeeId description: Stores the product object ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.productObjectId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.principal.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.target.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.target.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.target.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.target.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.target.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.target.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.target.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.target.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.target.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.target.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.target.application description: Application of the target related to the event. type: String - contextPath: GoogleChronicleBackstory.Events.target.cloud.availabilityZone description: Associated availability zone specified in the event target. type: String - contextPath: GoogleChronicleBackstory.Events.target.cloud.environment description: Associated environment specified in the event target. type: String - contextPath: GoogleChronicleBackstory.Events.target.cloud.project.name description: Associated name of the project specified in the event target. type: String - contextPath: GoogleChronicleBackstory.Events.target.cloud.vpc description: Associated VPC specified in the event target. type: Unknown - contextPath: GoogleChronicleBackstory.Events.target.resource.name description: Associated resource name specified in the event target. type: String - contextPath: GoogleChronicleBackstory.Events.target.resource.productObjectId description: Associated product object ID specified in the event target. type: String - contextPath: GoogleChronicleBackstory.Events.target.resource.resourceType description: Associated resource type specified in the event target. type: String - contextPath: GoogleChronicleBackstory.Events.target.resource.attribute.labels.key description: The key for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.target.resource.attribute.labels.value description: The value for a field specified in the principal resource labels of the event. type: String - contextPath: GoogleChronicleBackstory.Events.target.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.target.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.target.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.attribute.cloud.environment description: Associated environment specified in the target user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.attribute.cloud.project.id description: Associated ID of the project specified in the target user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.attribute.roles.name description: Associated name of the role specified in the target user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.attribute.roles.type description: Associated type of the role specified in the target user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.productObjectId description: Stores the human resources product object ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.target.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.intermediary.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.src.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.src.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.src.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.src.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.src.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.src.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.src.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.src.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.src.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.src.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.src.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.src.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.src.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.src.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.observer.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.observer.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.observer.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.observer.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.observer.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.observer.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.observer.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.observer.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.observer.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.observer.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.observer.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.about.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Events.about.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Events.about.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Events.about.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Events.about.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Events.about.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Events.about.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Events.about.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Events.about.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Events.about.administrativeDomain description: Domain that the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Events.about.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Events.about.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Events.about.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Events.about.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Events.network.applicationProtocol description: Indicates the network application protocol. type: String - contextPath: GoogleChronicleBackstory.Events.network.direction description: Indicates the direction of network traffic. type: String - contextPath: GoogleChronicleBackstory.Events.network.email description: Specifies the email address for the sender/recipient. type: String - contextPath: GoogleChronicleBackstory.Events.network.ipProtocol description: Indicates the IP protocol. type: String - contextPath: GoogleChronicleBackstory.Events.network.receivedBytes description: Specifies the number of bytes received. type: String - contextPath: GoogleChronicleBackstory.Events.network.sentBytes description: Specifies the number of bytes sent. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.clientHostname description: Hostname for the client. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.clientIdentifier description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.file description: Filename for the boot image. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.flags description: Value for the DHCP flags field. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.hlen description: Hardware address length. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.hops description: DHCP hop count. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.htype description: Hardware address type. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.leaseTimeSeconds description: Client-requested lease time for an IP address in seconds. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.opcode description: BOOTP op code. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.requestedAddress description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.seconds description: Seconds elapsed since the client began the address acquisition/renewal process. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.sname description: Name of the server that the client has requested to boot from. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.transactionId description: Client transaction ID. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.type description: DHCP message type. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.chaddr description: IP address for the client hardware. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.ciaddr description: IP address for the client. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.giaddr description: IP address for the relay agent. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.siaddr description: IP address for the next bootstrap server. type: String - contextPath: GoogleChronicleBackstory.Events.network.dhcp.yiaddr description: Your IP address. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authoritative description: Set to true for authoritative DNS servers. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.id description: Stores the DNS query identifier. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.response description: Set to true if the event is a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.opcode description: Stores the DNS OpCode used to specify the type of DNS query (standard, inverse, server status, etc.). type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.recursionAvailable description: Set to true if a recursive DNS lookup is available. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.recursionDesired description: Set to true if a recursive DNS lookup is requested. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.responseCode description: Stores the DNS response code as defined by RFC 1035, Domain Names - Implementation and Specification. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.truncated description: Set to true if this is a truncated DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.name description: Stores the domain name. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.class description: Stores the code specifying the class of the query. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.questions.type description: Stores the code specifying the type of the query. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.answers.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.authority.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Events.network.dns.additional.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.from description: Stores the from email address. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.replyTo description: Stores the reply_to email address. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.to description: Stores the to email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.cc description: Stores the cc email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.bcc description: Stores the bcc email addresses. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.mailId description: Stores the mail (or message) ID. type: String - contextPath: GoogleChronicleBackstory.Events.network.email.subject description: Stores the email subject line. type: String - contextPath: GoogleChronicleBackstory.Events.network.ftp.command description: Stores the FTP command. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.method description: Stores the HTTP request method. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.referralUrl description: Stores the URL for the HTTP referer. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.responseCode description: Stores the HTTP response status code, which indicates whether a specific HTTP request has been successfully completed. type: String - contextPath: GoogleChronicleBackstory.Events.network.http.useragent description: Stores the User-Agent request header which includes the application type, operating system, software vendor or software version of the requesting software user agent. type: String - contextPath: GoogleChronicleBackstory.Events.authentication.authType description: Type of system an authentication event is associated with (Chronicle UDM). type: String - contextPath: GoogleChronicleBackstory.Events.authentication.mechanism description: Mechanism(s) used for authentication. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.about description: Provide a description of the security result. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.action description: Specify a security action. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.category description: Specify a security category. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.categoryDetails description: Specify the security category details. type: Unknown - contextPath: GoogleChronicleBackstory.Events.securityResult.detectionFields.key description: The key for a field specified in the security result, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.detectionFields.value description: The value for a field specified in the security result, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.confidence description: Specify a confidence with regards to a security event as estimated by the product. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.confidenceDetails description: Additional details with regards to the confidence of a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.priority description: Specify a priority with regards to a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.priorityDetails description: Vendor-specific information about the security result priority. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.ruleId description: Identifier for the security rule. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.ruleName description: Name of the security rule. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.severity description: Severity of a security event as estimated by the product vendor using values defined by the Chronicle UDM. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.severityDetails description: Severity for a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.threatName description: Name of the security threat. type: String - contextPath: GoogleChronicleBackstory.Events.securityResult.urlBackToProduct description: URL to direct you to the source product console for this security event. type: String - arguments: - description: Provide the name of the list to retrieve the result. name: name required: true - auto: PREDEFINED default: true defaultValue: FULL description: Select option to control the returned response. BASIC will return the metadata for the list, but not the full contents. FULL will return everything. name: view predefined: - FULL - BASIC description: Returns the specified list. name: gcb-get-reference-list outputs: - contextPath: GoogleChronicleBackstory.ReferenceList.name description: Unique name of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.description description: Description of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.createTime description: Time when the list was created. type: Date - contextPath: GoogleChronicleBackstory.ReferenceList.lines description: List of line items. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.contentType description: Content type of the reference list. type: String - arguments: - description: Provide a unique name of the list to create a reference list. name: name required: true - description: Description of the list. name: description required: true - description: |- Enter the content to be added into the reference list. Format accepted is: "Line 1, Line 2, Line 3". name: lines required: false - description: |- Provide a unique file id consisting of lines to add. Note: Please provide either one of "lines" or "entry_id". You can get the entry_id from the context path(File.EntryID). name: entry_id required: false - default: true defaultValue: ',' description: |- Delimiter by which the content of the list is separated. Eg: " , " , " : ", " ; ". name: delimiter - auto: PREDEFINED defaultValue: PLAIN_TEXT description: Select the content type for reference list. name: content_type predefined: - PLAIN_TEXT - CIDR - REGEX - default: false defaultValue: 'False' description: A flag to determine whether to split lines from file with the provided delimiter. name: use_delimiter_for_file required: false description: Create a new reference list. name: gcb-create-reference-list outputs: - contextPath: GoogleChronicleBackstory.ReferenceList.name description: Unique name of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.description description: Description of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.lines description: List of line items. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.createTime description: Time when the list was created. type: Date - contextPath: GoogleChronicleBackstory.ReferenceList.contentType description: Content type of the reference list. type: String - arguments: - description: Provide the name of the list to update. name: name required: true - description: |- Enter the content to be updated into the reference list. Format accepted is: "Line 1, Line 2, Line 3". Note: Use gcb-get-reference-list to retrieve the content and description of the list. name: lines required: false - description: |- Provide a unique file id consisting of lines to update. Note: Please provide either one of "lines" or "entry_id". You can get the entry_id from the context path(File.EntryID). name: entry_id required: false - description: Description to be updated of the list. name: description - defaultValue: ',' description: |- Delimiter by which the content of the list is separated. Eg: " , " , " : ", " ; ". name: delimiter - auto: PREDEFINED description: Select the content type for reference list. name: content_type predefined: - PLAIN_TEXT - CIDR - REGEX - default: false defaultValue: 'False' description: A flag to determine whether to split lines from file with the provided delimiter. name: use_delimiter_for_file required: false description: Updates an existing reference list. name: gcb-update-reference-list outputs: - contextPath: GoogleChronicleBackstory.ReferenceList.name description: Unique name of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.description description: Description of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.lines description: List of line items. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.createTime description: Time when the list was created. type: Date - contextPath: GoogleChronicleBackstory.ReferenceList.contentType description: Content type of the reference list. type: String - arguments: - default: true defaultValue: '100' description: Number of results to retrieve in the response. Maximum size allowed is 1000. name: page_size - description: The next page token to retrieve the next set of results. name: page_token - auto: PREDEFINED defaultValue: BASIC description: Select option to control the returned response. BASIC will return the metadata for the list, but not the full contents. FULL will return everything. name: view predefined: - BASIC - FULL description: Retrieve all the reference lists. name: gcb-list-reference-list outputs: - contextPath: GoogleChronicleBackstory.ReferenceLists.name description: Unique name of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceLists.description description: Description of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceLists.createTime description: Time when the list was created. type: Date - contextPath: GoogleChronicleBackstory.ReferenceLists.lines description: List of line items. type: String - contextPath: GoogleChronicleBackstory.ReferenceLists.contentType description: Content type of the reference list. type: String - arguments: - description: "Enter the content to be validated in the reference list.\nFormat accepted is: 'Line 1, Line 2, Line 3'." name: lines required: true - auto: PREDEFINED defaultValue: PLAIN_TEXT description: Select the content type for reference list. name: content_type predefined: - PLAIN_TEXT - CIDR - REGEX - defaultValue: ',' description: |- Delimiter by which the content of the list is separated. Eg: " , " , " : ", " ; ". name: delimiter description: Validates list content and returns any errors found for each line. name: gcb-verify-reference-list outputs: - contextPath: GoogleChronicleBackstory.VerifyReferenceList.success description: Whether lines content are valid or not. type: Boolean - contextPath: GoogleChronicleBackstory.VerifyReferenceList.errors.linenumber description: The line number where the error occurred. type: Number - contextPath: GoogleChronicleBackstory.VerifyReferenceList.errors.errorMessage description: The error message describing the invalid pattern. type: String - contextPath: GoogleChronicleBackstory.VerifyReferenceList.command_name description: The name of the command. type: String - arguments: - description: |- Specify the values to search in reference lists. Format accepted is: "value 1, value 2, value 3". name: values required: true isArray: true - description: Specify the reference list names to search through. Supports comma separated values. name: reference_list_names required: true isArray: true - description: If set to true, the command performs case insensitive matching. name: case_insensitive_search required: false defaultValue: 'False' auto: PREDEFINED predefined: - 'True' - 'False' - description: |- Delimiter by which the content of the values list is separated. Eg: " , " , " : ", " ; ". defaultValue: ',' name: delimiter - description: If set to true, the command will add the not found reference list names to the HR and the context. name: add_not_found_reference_lists required: false defaultValue: 'False' auto: PREDEFINED predefined: - 'True' - 'False' description: Check if provided values are found in the reference lists in Google SecOps. name: gcb-verify-value-in-reference-list outputs: - contextPath: GoogleChronicleBackstory.VerifyValueInReferenceList.value description: The item value to search in the reference list. type: String - contextPath: GoogleChronicleBackstory.VerifyValueInReferenceList.found_in_lists description: List of Reference list names, where item was found. type: String - contextPath: GoogleChronicleBackstory.VerifyValueInReferenceList.not_found_in_lists description: List of Reference list names, where item not was found. type: String - contextPath: GoogleChronicleBackstory.VerifyValueInReferenceList.overall_status description: Whether value found in any reference list. type: String - arguments: - description: Provide the name of the list to append content. name: name required: true - description: |- Enter the content to be appended into the reference list. Format accepted is: "Line 1, Line 2, Line 3". Note: Use "gcb-get-reference-list" to retrieve the content of the list. name: lines isArray: true required: false - description: |- Provide a unique file id consisting of lines to append. Note: Please provide either one of "lines" or "entry_id". You can get the entry_id from the context path(File.EntryID). name: entry_id required: false - defaultValue: ',' description: |- Delimiter by which the content of the list is separated. Eg: " , " , " : ", " ; ". name: delimiter - defaultValue: 'False' description: Flag to control how the file content is split. If set to True, it uses the provided delimiter; otherwise it splits by new lines (\n). name: use_delimiter_for_file required: false auto: PREDEFINED predefined: - 'True' - 'False' - defaultValue: 'False' description: A flag to determine whether to apply deduplication logic over new lines. name: append_unique required: false auto: PREDEFINED predefined: - 'True' - 'False' description: Appends lines into an existing reference list. name: gcb-reference-list-append-content outputs: - contextPath: GoogleChronicleBackstory.ReferenceList.name description: The unique name of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.description description: The description of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.lines description: The list of line items. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.createTime description: The time when the list was created. type: Date - contextPath: GoogleChronicleBackstory.ReferenceList.contentType description: The content type of the reference list. type: String - arguments: - description: Provide the name of the list to remove content. name: name required: true - description: |- Enter the content to be removed from the reference list. Format accepted is: "Line 1, Line 2, Line 3". Note: Use "gcb-get-reference-list" to retrieve the content of the list. name: lines isArray: true required: false - description: |- Provide a unique file id consisting of lines to remove. Note: Please provide either one of "lines" or "entry_id". You can get the entry_id from the context path(File.EntryID). name: entry_id required: false - defaultValue: ',' description: |- Delimiter by which the content of the list is separated. Eg: " , " , " : ", " ; ". name: delimiter - defaultValue: 'False' description: Flag to control how the file content is split. If set to True, it uses the provided delimiter; otherwise it splits by new lines (\n). name: use_delimiter_for_file required: false auto: PREDEFINED predefined: - 'True' - 'False' description: Removes lines from an existing reference list. name: gcb-reference-list-remove-content outputs: - contextPath: GoogleChronicleBackstory.ReferenceList.name description: The unique name of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.description description: The description of the list. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.lines description: The list of line items. type: String - contextPath: GoogleChronicleBackstory.ReferenceList.createTime description: The time when the list was created. type: Date - contextPath: GoogleChronicleBackstory.ReferenceList.contentType description: The content type of the reference list. type: String - arguments: - auto: PREDEFINED description: Fetches IOC Domain matches in the specified time interval. If configured, overrides the start_time and end_time arguments. name: preset_time_range predefined: - Last 1 day - Last 7 days - Last 15 days - Last 30 days - description: 'The value of the start time for your request, in RFC 3339 format (e.g. 2002-10-02T15:00:00Z) or relative time. If not supplied, the default is the UTC time corresponding to 3 days earlier than current time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2020-05-01T00:00:00Z, 2020-05-01, 2 days, 5 hours, 01 Mar 2021, 01 Feb 2021 04:45:33, 15 Jun.' name: start_time - description: 'The value of the end time for your request, in RFC 3339 format (e.g. 2025-11-01T15:00:00Z) or relative time. If not supplied, the default is the current UTC time. Formats: YYYY-MM-ddTHH:mm:ssZ, YYYY-MM-dd, N days, N hours. Example: 2025-11-01T00:00:00Z, 2025-11-01, 2 days, 5 hours, 01 Nov 2025, 01 Nov 2025 04:45:33, 15 Oct.' name: end_time - defaultValue: '10000' description: The maximum number of IOCs to return. You can specify between 1 and 10000. name: page_size description: Lists the IOC Domain matches within your enterprise for the specified time interval. The indicator of compromise (IOC) domain matches lists for which the domains that your security infrastructure has flagged as both suspicious and that have been seen recently within your enterprise. name: gcb-list-iocs outputs: - contextPath: Domain.Name description: The domain name of the artifact. type: String - contextPath: GoogleChronicleBackstory.Iocs.Artifact description: The Indicator artifact. type: String - contextPath: GoogleChronicleBackstory.Iocs.IocIngestTime description: Time(UTC) the IOC was first seen by Chronicle. type: Date - contextPath: GoogleChronicleBackstory.Iocs.FirstAccessedTime description: Time(UTC) the artifact was first seen within your enterprise. type: Date - contextPath: GoogleChronicleBackstory.Iocs.LastAccessedTime description: Time(UTC) the artifact was most recently seen within your enterprise. type: Date - contextPath: GoogleChronicleBackstory.Iocs.Sources.Category description: Source Category represents the behavior of the artifact. type: String - contextPath: GoogleChronicleBackstory.Iocs.Sources.IntRawConfidenceScore description: The numeric confidence score of the IOC reported by the source. type: Number - contextPath: GoogleChronicleBackstory.Iocs.Sources.NormalizedConfidenceScore description: The normalized confidence score of the IOC reported by the source. type: String - contextPath: GoogleChronicleBackstory.Iocs.Sources.RawSeverity description: The severity of the IOC as reported by the source. type: String - contextPath: GoogleChronicleBackstory.Iocs.Sources.Source description: The source that reported the IOC. type: String - arguments: - description: The artifact indicator value. The supported artifact types are IP and domain. name: artifact_value required: true description: Accepts an artifact indicator and returns any threat intelligence associated with the artifact. The threat intelligence information is drawn from your enterprise security systems and from Chronicle's IoC partners (for example, the DHS threat feed). name: gcb-ioc-details outputs: - contextPath: Domain.Name description: The domain name of the artifact. type: String - contextPath: IP.Address description: The IP address of the of the artifact. type: String - contextPath: GoogleChronicleBackstory.IocDetails.IoCQueried description: The artifact entered by the user. type: String - contextPath: GoogleChronicleBackstory.IocDetails.Sources.Address.IpAddress description: The IP address of the artifact. type: String - contextPath: GoogleChronicleBackstory.IocDetails.Sources.Address.Domain description: The domain name of the artifact. type: String - contextPath: GoogleChronicleBackstory.IocDetails.Sources.Address.Port description: The port numbers of the artifact. type: Unknown - contextPath: GoogleChronicleBackstory.IocDetails.Sources.Category description: The behavior of the artifact. type: String - contextPath: GoogleChronicleBackstory.IocDetails.Sources.ConfidenceScore description: The confidence score indicating the accuracy and appropriateness of the assigned category. type: Number - contextPath: GoogleChronicleBackstory.IocDetails.Sources.FirstAccessedTime description: The time the IOC was first accessed within the enterprise. type: Date - contextPath: GoogleChronicleBackstory.IocDetails.Sources.LastAccessedTime description: The time the IOC was most recently seen within your enterprise. type: Date - contextPath: GoogleChronicleBackstory.IocDetails.Sources.Severity description: Impact of the artifact on the enterprise. type: String - arguments: - default: true description: The IP address to check. isArray: true name: ip required: true description: Checks the reputation of an IP address. name: ip outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: IP.Address description: The IP address of the artifact. type: String - contextPath: IP.Malicious.Vendor description: For malicious IPs, the vendor that made the decision. type: String - contextPath: IP.Malicious.Description description: For malicious IPs, the reason that the vendor made the decision. type: String - contextPath: GoogleChronicleBackstory.IP.IoCQueried description: The artifact that was queried. type: String - contextPath: GoogleChronicleBackstory.IP.Sources.Address.IpAddress description: The IP address of the artifact. type: String - contextPath: GoogleChronicleBackstory.IP.Sources.Address.Domain description: The domain name of the artifact. type: String - contextPath: GoogleChronicleBackstory.IP.Sources.Address.Port description: The port numbers of the artifact. type: Unknown - contextPath: GoogleChronicleBackstory.IP.Sources.Category description: The behavior of the artifact. type: String - contextPath: GoogleChronicleBackstory.IP.Sources.ConfidenceScore description: The confidence score indicating the accuracy and appropriateness of the assigned category. type: Number - contextPath: GoogleChronicleBackstory.IP.Sources.FirstAccessedTime description: The time the IOC was first accessed within the enterprise. type: Date - contextPath: GoogleChronicleBackstory.IP.Sources.LastAccessedTime description: The time the IOC was most recently seen within your enterprise. type: Date - contextPath: GoogleChronicleBackstory.IP.Sources.Severity description: Impact of the artifact on the enterprise. type: String - arguments: - default: true description: The domain name to check. isArray: true name: domain required: true description: Checks the reputation of a domain. name: domain outputs: - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: 'The actual score.' type: Number - contextPath: Domain.Name description: The domain name of the artifact. type: String - contextPath: Domain.Malicious.Vendor description: For malicious domains, the vendor that made the decision. type: String - contextPath: Domain.Malicious.Description description: For malicious domains, the reason that the vendor made the decision. type: String - contextPath: GoogleChronicleBackstory.Domain.IoCQueried description: The domain that queried. type: String - contextPath: GoogleChronicleBackstory.Domain.Sources.Address.IpAddress description: The IP address of the artifact. type: String - contextPath: GoogleChronicleBackstory.Domain.Sources.Address.Domain description: The domain name of the artifact. type: String - contextPath: GoogleChronicleBackstory.Domain.Sources.Address.Port description: The port numbers of the artifact. type: Unknown - contextPath: GoogleChronicleBackstory.Domain.Sources.Category description: The behavior of the artifact. type: String - contextPath: GoogleChronicleBackstory.Domain.Sources.ConfidenceScore description: The confidence score indicating the accuracy and appropriateness of the assigned category. type: Number - contextPath: GoogleChronicleBackstory.Domain.Sources.FirstAccessedTime description: The time the IOC was first accessed within the enterprise. type: Date - contextPath: GoogleChronicleBackstory.Domain.Sources.LastAccessedTime description: The time the IOC was most recently seen within your enterprise. type: Date - contextPath: GoogleChronicleBackstory.Domain.Sources.Severity description: Impact of the artifact on the enterprise. type: String - arguments: - name: page_size required: false description: |- Specify the maximum number of data tables to return. You can specify between 1 and 1000. The maximum value is 1000, values above 1000 will be corrected to 1000. defaultValue: '100' - name: page_token required: false description: Specify the page token to use for pagination. description: Returns a list of data tables. name: gcb-list-data-tables outputs: - contextPath: GoogleChronicleBackstory.DataTable.name description: The identifier of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.displayName description: The name of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.description description: The description of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.createTime description: The time when the data table was created. type: Date - contextPath: GoogleChronicleBackstory.DataTable.updateTime description: The time when the data table was updated. type: Date - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.originalColumn description: The original column name. type: String - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.columnType description: The type of the column. type: String - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.columnIndex description: The index of the column. type: Number - contextPath: GoogleChronicleBackstory.DataTable.dataTableUuid description: The UUID of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.approximateRowCount description: The approximate count of rows of the data table. type: Number - arguments: - name: name required: true description: Provide a unique name for the data table. - name: description required: false description: Provide a description for the data table. - name: columns auto: PREDEFINED type: keyValue required: true description: "Provide the columns of the data table.\nFormat accepted is:\n{\"column_name_1\": \"column_1_type\", \"column_name_2\": \"column_2_type\"}.\n\nExpected values for column_type are: String, REGEX, CIDR, Number and Entity key field map path.\n\nNote: If the same column name is provided multiple times, only the last value will be considered." name: gcb-create-data-table description: Creates a new data table schema. outputs: - contextPath: GoogleChronicleBackstory.DataTable.name description: The identifier of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.displayName description: The name of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.description description: The description of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.createTime description: The time when the data table was created. type: Date - contextPath: GoogleChronicleBackstory.DataTable.updateTime description: The time when the data table was updated. type: Date - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.originalColumn description: The original column name. type: String - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.columnType description: The type of the column. type: String - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.columnIndex description: The index of the column. type: Number - contextPath: GoogleChronicleBackstory.DataTable.dataTableUuid description: The UUID of the data table. type: String - arguments: - name: name required: true description: Provide the name of the data table. - name: view description: Select option to control the returned response. BASIC will return the metadata for the data table, but not the data table rows contents. FULL will return everything. defaultValue: BASIC auto: PREDEFINED predefined: - FULL - BASIC - name: max_rows_to_return description: "Specify how many data table rows to return.\n\nNote: this parameter is only applied if “view” is FULL. The maximum value is 1000; values above 1000 will be coerced to 1000." defaultValue: '100' - name: page_token description: "The page token to retrieve the next set of data table rows.\n\nNote: this parameter is only applied if “view” is FULL." name: gcb-get-data-table description: Retrieves the data table details of specified data table name. outputs: - contextPath: GoogleChronicleBackstory.DataTable.name description: The identifier of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.displayName description: The name of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.description description: The description of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.createTime description: The time when the data table was created. type: Date - contextPath: GoogleChronicleBackstory.DataTable.updateTime description: The time when the data table was updated. type: Date - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.originalColumn description: The original column name. type: String - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.columnType description: The type of the column. type: String - contextPath: GoogleChronicleBackstory.DataTable.columnInfo.columnIndex description: The index of the column. type: Number - contextPath: GoogleChronicleBackstory.DataTable.dataTableUuid description: The UUID of the data table. type: String - contextPath: GoogleChronicleBackstory.DataTable.rows.name description: The identifier of the row. type: String - contextPath: GoogleChronicleBackstory.DataTable.rows.values description: The values of the row. type: String - contextPath: GoogleChronicleBackstory.DataTable.rows.createTime description: The time when the row was created. type: Date - contextPath: GoogleChronicleBackstory.DataTable.rows.updateTime description: The time when the row was updated. type: Date - arguments: - name: values required: true isArray: true description: "Provide the values to search in the data table.\nFormat accepted is: \"value 1, value 2, value 3\"." - name: name required: true description: Provide a data table name to search through. - name: columns required: false isArray: true description: "Provide the columns that need to be searched within the data table.\nFormat accepted is: \"column 1, column 2, column 3\".\n\nNote: Use \"gcb-get-data-table\" to retrieve the column names of the data table. If nothing is provided, the command will search within all columns." - name: case_insensitive_search description: If set to true, the command performs case insensitive matching. required: false defaultValue: 'False' auto: PREDEFINED predefined: - 'True' - 'False' - description: |- Delimiter by which the content of the values list is separated. Eg: " , " , " : ", " ; ". defaultValue: ',' name: delimiter - description: If set to true, the command will add the not found column names to the HR and the context. name: add_not_found_columns required: false defaultValue: 'False' auto: PREDEFINED predefined: - 'True' - 'False' - name: page_token description: The page token to search the next set of data table rows. name: gcb-verify-value-in-data-table description: "Check if provided values are found in the data table.\n\nNote: This command only searches in the first 1000 data table rows. To search next set of rows, use the page_token argument." outputs: - contextPath: GoogleChronicleBackstory.VerifyValueInDataTable.value description: The value that was searched. type: String - contextPath: GoogleChronicleBackstory.VerifyValueInDataTable.found_in_columns description: The columns in which the value was found. type: String - contextPath: GoogleChronicleBackstory.VerifyValueInDataTable.not_found_in_columns description: The columns in which the value was not found. type: String - contextPath: GoogleChronicleBackstory.VerifyValueInDataTable.overall_status description: The overall status of the search. type: String - arguments: - description: Provide the name of the data table. name: name required: true - description: |- Provide the list of rows data that need to be added in the data table. Format accepted is: [{"columnName1": "value1","columnName2": "value2"},{"columnName1": "value3","columnName2": "value4"}] Note: Use "gcb-get-data-table" to retrieve the column names of the data table. name: rows required: false auto: PREDEFINED type: keyValue - description: |- Provide a unique file id of comma separated CSV file consisting of rows to add. Note: Please provide either one of "rows" or "entry_id". A maximum of 1000 rows can be added in a single execution. You can get the entry_id from the context path(File.EntryID). name: entry_id required: false description: Adds rows to a data table. name: gcb-data-table-add-row outputs: - contextPath: GoogleChronicleBackstory.DataTableRows.name description: The identifier of the data table row. type: String - contextPath: GoogleChronicleBackstory.DataTableRows.values description: The values of the data table row. type: String - arguments: - description: Provide the name of the data table. name: name required: true - description: |- Provide the list of rows data that need to be removed from the data table. Format accepted is: [{"columnName1": "value1","columnName2": "value2"},{"columnName1": "value3","columnName2": "value4"}] Example: If you provide [{"columnName1": "value1"}] then it will remove all the rows from the data table where column1 has value1. If you provide [{"columnName1": "value1", "columnName2": "value2"}] then it will remove all the rows from the data table where column1 has value1 and column2 has value2. Note: Use "gcb-get-data-table" to retrieve the column names of the data table. name: rows required: false auto: PREDEFINED type: keyValue - description: |- Provide a unique file id of comma separated CSV file consisting of row data for removal. Note: Please provide either one of "rows" or "entry_id". You can get the entry_id from the context path(File.EntryID). name: entry_id required: false - name: page_token description: The page token to search and remove the next set of data table rows. description: "Removes rows from a data table based on specified row data.\n\nNote: This command only removes the first 1000 data table rows. To remove the next set of rows, use the page_token argument." name: gcb-data-table-remove-row outputs: - contextPath: GoogleChronicleBackstory.RemovedDataTableRows.name description: The identifier of the row. type: String - contextPath: GoogleChronicleBackstory.RemovedDataTableRows.values description: The values of the row. type: String - contextPath: GoogleChronicleBackstory.RemovedDataTableRows.createTime description: The time when the row was created. type: Date - contextPath: GoogleChronicleBackstory.RemovedDataTableRows.updateTime description: The time when the row was updated. type: Date - arguments: - name: rule_id required: true description: "Specify the ID or version ID of the rule. You can specify exactly one rule identifier. Use the following format to specify the ID: ru_{UUID} or {ruleId}@v_{int64}_{int64}.\n\nNote: Use gcb-list-rules command to retrieve rule ID." - name: detection_id required: true description: "Specify the ID of the detection.\n\nNote: Use gcb-list-detections command to retrieve detection ID." name: gcb-get-detection description: Retrieves the detection details of specified detection ID. outputs: - contextPath: GoogleChronicleBackstory.Detections.id description: Identifier for the detection. type: String - contextPath: GoogleChronicleBackstory.Detections.ruleId description: Identifier for the rule generating the detection. type: String - contextPath: GoogleChronicleBackstory.Detections.ruleVersion description: Identifier for the rule version generating the detection. type: String - contextPath: GoogleChronicleBackstory.Detections.ruleName description: Name of the rule generating the detection, as parsed from ruleText. type: String - contextPath: GoogleChronicleBackstory.Detections.timeWindowStartTime description: The start time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.Detections.timeWindowEndTime description: The end time of the window the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.Detections.alertState description: Indicates whether the rule generating this detection currently has alerting enabled or disabled. type: String - contextPath: GoogleChronicleBackstory.Detections.urlBackToProduct description: URL pointing to the Chronicle UI for this detection. type: String - contextPath: GoogleChronicleBackstory.Detections.type description: Type of detection. type: String - contextPath: GoogleChronicleBackstory.Detections.createdTime description: Time the detection was created. type: Date - contextPath: GoogleChronicleBackstory.Detections.detectionTime description: The time period the detection was found in. type: Date - contextPath: GoogleChronicleBackstory.Detections.ruleType description: Whether the rule generating this detection is a single event or multi-event rule. type: String - contextPath: GoogleChronicleBackstory.Detections.detectionFields.key description: The key for a field specified in the rule, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.Detections.detectionFields.value description: The value for a field specified in the rule, for MULTI_EVENT rules. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.label description: The variable a given set of UDM events belongs to. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principalAssetIdentifier description: Specifies the principal asset identifier of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.targetAssetIdentifier description: Specifies the target asset identifier of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.eventType description: Specifies the type of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.eventTimestamp description: The GMT timestamp when the event was generated. type: Date - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.ingestedTimestamp description: The GMT timestamp when the event was ingested in the vendor's instance. type: Date - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.description description: Human-readable description of the event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productEventType description: Short, descriptive, human-readable, and product-specific event name or type. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productLogId description: A vendor-specific event identifier to uniquely identify the event (a GUID). Users might use this identifier to search the vendor's proprietary console for the event in question. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productName description: Specifies the name of the product. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.productVersion description: Specifies the version of the product. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.urlBackToProduct description: URL linking to a relevant website where you can view more information about this specific event or the general event category. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.vendorName description: Specifies the product vendor's name. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.mac description: MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.principal.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.target.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.intermediary.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.src.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.observer.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.assetId description: Vendor-specific unique device identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.email description: Email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.hostname description: Client hostname or domain name field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.platform description: Platform operating system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.platformPatchLevel description: Platform operating system patch level. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.platformVersion description: Platform operating system version. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.ip description: IP address associated with a network connection. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.port description: Source or destination network port number when a specific network connection is described within an event. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.mac description: One or more MAC addresses associated with a device. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.administrativeDomain description: Domain which the device belongs to (for example, the Windows domain). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.url description: Standard URL. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.commandLine description: Stores the command line string for the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.productSpecificProcessId description: Stores the product specific process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.productSpecificParentProcessId description: Stores the product specific process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file description: Stores the file name of the file in use by the process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.fileMetadata description: Metadata associated with the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.fullPath description: Full path identifying the location of the file on the system. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.md5 description: MD5 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.mimeType description: Multipurpose Internet Mail Extensions (MIME) type of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.sha1 description: SHA-1 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.sha256 description: SHA-256 hash value of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.file.size description: Size of the file. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.parentPid description: Stores the process ID for the parent process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.process.pid description: Stores the process ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.registry.registryKey description: Stores the registry key associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.registry.registryValueName description: Stores the name of the registry value associated with an application or system component. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.registry.registryValueData description: Stores the data associated with a registry value. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.emailAddresses description: Stores the email addresses for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.employeeId description: Stores the human resources employee ID for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.firstName description: Stores the first name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.middleName description: Stores the middle name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.lastName description: Stores the last name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.groupid description: Stores the group ID associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.phoneNumbers description: Stores the phone numbers for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.title description: Stores the job title for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.userDisplayName description: Stores the display name for the user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.userid description: Stores the user ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.about.user.windowsSid description: Stores the Microsoft Windows security identifier (SID) associated with a user. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.applicationProtocol description: Indicates the network application protocol. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.direction description: Indicates the direction of network traffic. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email description: Specifies the email address for the sender/recipient. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.ipProtocol description: Indicates the IP protocol. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.receivedBytes description: Specifies the number of bytes received. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.sentBytes description: Specifies the number of bytes sent. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.clientHostname description: Hostname for the client. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.clientIdentifier description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.file description: Filename for the boot image. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.flags description: Value for the DHCP flags field. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.hlen description: Hardware address length. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.hops description: DHCP hop count. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.htype description: Hardware address type. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.leaseTimeSeconds description: Client-requested lease time for an IP address in seconds. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.opcode description: BOOTP op code. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.requestedAddress description: Client identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.seconds description: Seconds elapsed since the client began the address acquisition/renewal process. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.sname description: Name of the server which the client has requested to boot from. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.transactionId description: Client transaction ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.type description: DHCP message type. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.chaddr description: IP address for the client hardware. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.ciaddr description: IP address for the client. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.giaddr description: IP address for the relay agent. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.siaddr description: IP address for the next bootstrap server. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dhcp.yiaddr description: Your IP address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authoritative description: Set to true for authoritative DNS servers. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.id description: Stores the DNS query identifier. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.response description: Set to true if the event is a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.opcode description: Stores the DNS OpCode used to specify the type of DNS query (standard, inverse, server status, etc.). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.recursionAvailable description: Set to true if a recursive DNS lookup is available. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.recursionDesired description: Set to true if a recursive DNS lookup is requested. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.responseCode description: Stores the DNS response code as defined by RFC 1035, Domain Names - Implementation and Specification. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.truncated description: Set to true if this is a truncated DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.questions.name description: Stores the domain name. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.questions.class description: Stores the code specifying the class of the query. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.questions.type description: Stores the code specifying the type of the query. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.answers.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.authority.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.binaryData description: Stores the raw bytes of any non-UTF8 strings that might be included as part of a DNS response. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.class description: Stores the code specifying the class of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.data description: Stores the payload or response to the DNS question for all responses encoded in UTF-8 format. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.name description: Stores the name of the owner of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.ttl description: Stores the time interval for which the resource record can be cached before the source of the information should again be queried. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.dns.additional.type description: Stores the code specifying the type of the resource record. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.from description: Stores the from email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.replyTo description: Stores the reply_to email address. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.to description: Stores the to email addresses. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.cc description: Stores the cc email addresses. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.bcc description: Stores the bcc email addresses. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.mailId description: Stores the mail (or message) ID. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.email.subject description: Stores the email subject line. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.ftp.command description: Stores the FTP command. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.method description: Stores the HTTP request method. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.referralUrl description: Stores the URL for the HTTP referer. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.responseCode description: Stores the HTTP response status code, which indicates whether a specific HTTP request has been successfully completed. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.network.http.useragent description: Stores the User-Agent request header which includes the application type, operating system, software vendor or software version of the requesting software user agent. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.authentication.authType description: Type of system an authentication event is associated with (Chronicle UDM). type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.authentication.mechanism description: Mechanism(s) used for authentication. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.about description: Provide a description of the security result. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.action description: Specify a security action. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.category description: Specify a security category. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.confidence description: Specify a confidence with regards to a security event as estimated by the product. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.confidenceDetails description: Additional detail with regards to the confidence of a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.priority description: Specify a priority with regards to a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.priorityDetails description: Vendor-specific information about the security result priority. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.ruleId description: Identifier for the security rule. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.ruleName description: Name of the security rule. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.severity description: Severity of a security event as estimated by the product vendor using values defined by the Chronicle UDM. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.severityDetails description: Severity for a security event as estimated by the product vendor. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.threatName description: Name of the security threat. type: String - contextPath: GoogleChronicleBackstory.Detections.collectionElements.references.securityResult.urlBackToProduct description: URL to direct you to the source product console for this security event. type: String dockerimage: demisto/googleapi-python3:1.0.0.10182333 isfetch: true runonce: false script: '' subtype: python3 type: python fromversion: 6.10.0 defaultmapperin: 'Chronicle-mapper' defaultclassifier: 'Chronicle' marketplaces: - xsoar - marketplacev2 - platform tests: - No tests (auto formatted)