Package com.google.backstory (0.3.0)

GitHub Repository

Client Classes

Client classes are the main entry point to using a package. They contain several variations of Java methods for each of the API's methods.

Client Description
com.google.backstory.ArtifactClient

Entity or software accessing or utilizing network resources.

com.google.backstory.Tls.Client

Transport Layer Security (TLS) information associated with the client (for example, Certificate or JA3 hash).

Classes

Class Description
com.google.backstory.AnalyticsMetadata Stores information about an analytics metric used in a rule.
com.google.backstory.AnalyticsMetadata.Builder Stores information about an analytics metric used in a rule.
com.google.backstory.AppCompatMetadata Windows AppCompatCache (Application Compatibility) metadata.
com.google.backstory.AppCompatMetadata.Builder Windows AppCompatCache (Application Compatibility) metadata.
com.google.backstory.Artifact Information about an artifact. The artifact can only be an IP.
com.google.backstory.Artifact.Builder Information about an artifact. The artifact can only be an IP.
com.google.backstory.ArtifactClient.Builder Entity or software accessing or utilizing network resources.
com.google.backstory.Asset Information about a compute asset such as a workstation, laptop, phone, virtual desktop, or VM.
com.google.backstory.Asset.Builder Information about a compute asset such as a workstation, laptop, phone, virtual desktop, or VM.
com.google.backstory.AtiPrioritization AtiPrioritization contains various fields used to calculate a priority score for an entity identified as a threat.
com.google.backstory.AtiPrioritization.Builder AtiPrioritization contains various fields used to calculate a priority score for an entity identified as a threat.
com.google.backstory.AttackDetails MITRE ATT&CK details.
com.google.backstory.AttackDetails.Builder MITRE ATT&CK details.
com.google.backstory.AttackDetails.Tactic Tactic information related to an attack or threat.
com.google.backstory.AttackDetails.Tactic.Builder Tactic information related to an attack or threat.
com.google.backstory.AttackDetails.Technique Technique information related to an attack or threat.
com.google.backstory.AttackDetails.Technique.Builder Technique information related to an attack or threat.
com.google.backstory.Attribute Attribute is a container for generic entity attributes including common attributes across core entities (such as, user or asset). For example, Cloud is a generic entity attribute since it can apply to an asset (for example, a
com.google.backstory.Attribute.Builder Attribute is a container for generic entity attributes including common attributes across core entities (such as, user or asset). For example, Cloud is a generic entity attribute since it can apply to an asset (for example, a
com.google.backstory.Authentication The Authentication extension captures details specific to authentication events. General guidelines for authentication events:
com.google.backstory.Authentication.Builder The Authentication extension captures details specific to authentication events. General guidelines for authentication events:
com.google.backstory.BoolSequence BoolSequence represents a sequence of bools.
com.google.backstory.BoolSequence.Builder BoolSequence represents a sequence of bools.
com.google.backstory.Browser Information about an entry in the web browser's local history database.
com.google.backstory.Browser.Builder Information about an entry in the web browser's local history database.
com.google.backstory.Browser.Cookie Browser cookie.
com.google.backstory.Browser.Cookie.Builder Browser cookie.
com.google.backstory.BytesSequence BytesSequence represents a sequence of bytes.
com.google.backstory.BytesSequence.Builder BytesSequence represents a sequence of bytes.
com.google.backstory.Certificate Certificate information
com.google.backstory.Certificate.Builder Certificate information
com.google.backstory.Cloud Metadata related to the cloud environment.
com.google.backstory.Cloud.Builder Metadata related to the cloud environment.
com.google.backstory.Collection Collection represents a container of objects (such as events, entity context metadata, detection finding metadata) and state (such as investigation details).
com.google.backstory.Collection.Builder Collection represents a container of objects (such as events, entity context metadata, detection finding metadata) and state (such as investigation details).
com.google.backstory.CollectionOuterClass
com.google.backstory.DNSRecord DNS record.
com.google.backstory.DNSRecord.Builder DNS record.
com.google.backstory.DataAccess
com.google.backstory.DataAccessIngestionLabel Label used in data access for ingestion.
com.google.backstory.DataAccessIngestionLabel.Builder Label used in data access for ingestion.
com.google.backstory.DataAccessLabels Label used in data access.
com.google.backstory.DataAccessLabels.Builder Label used in data access.
com.google.backstory.DataTableRowInfo DataTableRowInfo captures information about a data table row including the name of the data table.
com.google.backstory.DataTableRowInfo.Builder DataTableRowInfo captures information about a data table row including the name of the data table.
com.google.backstory.Dhcp DHCP information.
com.google.backstory.Dhcp.Builder DHCP information.
com.google.backstory.Dhcp.Option DHCP options.
com.google.backstory.Dhcp.Option.Builder DHCP options.
com.google.backstory.Dns DNS information.
com.google.backstory.Dns.Builder DNS information.
com.google.backstory.Dns.Question DNS Questions. See RFC1035, section 4.1.2.
com.google.backstory.Dns.Question.Builder DNS Questions. See RFC1035, section 4.1.2.
com.google.backstory.Dns.ResourceRecord DNS Resource Records. See RFC1035, section 4.1.3.
com.google.backstory.Dns.ResourceRecord.Builder DNS Resource Records. See RFC1035, section 4.1.3.
com.google.backstory.Domain Information about a domain.
com.google.backstory.Domain.Builder Information about a domain.
com.google.backstory.DoubleSequence DoubleSequence represents a sequence of doubles.
com.google.backstory.DoubleSequence.Builder DoubleSequence represents a sequence of doubles.
com.google.backstory.Element Protobuf type google.backstory.Element
com.google.backstory.Element.Builder Protobuf type google.backstory.Element
com.google.backstory.Email Email info.
com.google.backstory.Email.Builder Email info.
com.google.backstory.Entity An Entity provides additional context about an item in a UDM event. For example, a PROCESS_LAUNCH event describes that user 'abc@example.corp' launched process 'shady.exe'.
com.google.backstory.Entity.Builder An Entity provides additional context about an item in a UDM event. For example, a PROCESS_LAUNCH event describes that user 'abc@example.corp' launched process 'shady.exe'.
com.google.backstory.EntityGraphEnrichment EntityGraphEnrichment contains the data table name and the enrichment applied to the entity.
com.google.backstory.EntityGraphEnrichment.Builder EntityGraphEnrichment contains the data table name and the enrichment applied to the entity.
com.google.backstory.EntityMetadata Information about the Entity and the product where the entity was created.
com.google.backstory.EntityMetadata.Builder Information about the Entity and the product where the entity was created.
com.google.backstory.EntityProto
com.google.backstory.EntityRisk Stores information related to the risk score of an entity.
com.google.backstory.EntityRisk.Builder Stores information related to the risk score of an entity.
com.google.backstory.EntityRiskProto
com.google.backstory.ExifInfo Exif information.
com.google.backstory.ExifInfo.Builder Exif information.
com.google.backstory.Extensions Extensions to a UDM event.
com.google.backstory.Extensions.Builder Extensions to a UDM event.
com.google.backstory.Favicon Difference hash and MD5 hash of the domain's favicon.
com.google.backstory.Favicon.Builder Difference hash and MD5 hash of the domain's favicon.
com.google.backstory.File Information about a file.
com.google.backstory.File.Builder Information about a file.
com.google.backstory.FileMetadata Metadata about a file. Place metadata about different file types here, for example data from the Microsoft Windows VersionInfo block or digital signer details.
com.google.backstory.FileMetadata.Builder Metadata about a file. Place metadata about different file types here, for example data from the Microsoft Windows VersionInfo block or digital signer details.
com.google.backstory.FileMetadataCodesign File metadata from the codesign utility.
com.google.backstory.FileMetadataCodesign.Builder File metadata from the codesign utility.
com.google.backstory.FileMetadataImports File metadata imports.
com.google.backstory.FileMetadataImports.Builder File metadata imports.
com.google.backstory.FileMetadata Metadata about the Portable Executable (PE) file.
com.google.backstory.FileMetadataPE.Builder Metadata about the Portable Executable (PE) file.
com.google.backstory.FileMetadataPeResourceInfo File metadata for PE resource.
com.google.backstory.FileMetadataPeResourceInfo.Builder File metadata for PE resource.
com.google.backstory.FileMetadataSection File metadata section.
com.google.backstory.FileMetadataSection.Builder File metadata section.
com.google.backstory.FileMetadataSignatureInfo Signature information.
com.google.backstory.FileMetadataSignatureInfo.Builder Signature information.
com.google.backstory.FindingVariable A structure that holds the value and associated metadata for values extracted while producing a Finding.
com.google.backstory.FindingVariable.Builder A structure that holds the value and associated metadata for values extracted while producing a Finding.
com.google.backstory.Ftp FTP info.
com.google.backstory.Ftp.Builder FTP info.
com.google.backstory.Group Information about an organizational group.
com.google.backstory.Group.Builder Information about an organizational group.
com.google.backstory.GroupedFields Grouped fields are aliases for groups of related UDM fields. All fields grouped together are of type string.
com.google.backstory.GroupedFields.Builder Grouped fields are aliases for groups of related UDM fields. All fields grouped together are of type string.
com.google.backstory.Hardware Hardware specification details for a resource, including both physical and virtual hardware.
com.google.backstory.Hardware.Builder Hardware specification details for a resource, including both physical and virtual hardware.
com.google.backstory.Http Specify the full URL of the HTTP request within "target". Also specify any uploaded or downloaded file information within "source" or "target".
com.google.backstory.Http.Builder Specify the full URL of the HTTP request within "target". Also specify any uploaded or downloaded file information within "source" or "target".
com.google.backstory.Id Identifier to identify a UDM object like a UDM event, Entity, Collection. The full identifier for persistence is created by setting the 32 most significant bits as the Id.Namespace enum This is a convenience wrapper to
com.google.backstory.Id.Builder Identifier to identify a UDM object like a UDM event, Entity, Collection. The full identifier for persistence is created by setting the 32 most significant bits as the Id.Namespace enum This is a convenience wrapper to
com.google.backstory.IdOuterClass
com.google.backstory.Int64Sequence Int64Sequence represents a sequence of int64s.
com.google.backstory.Int64Sequence.Builder Int64Sequence represents a sequence of int64s.
com.google.backstory.Investigation Represents the aggregated state of an investigation such as categorization, severity, and status. Can be expanded to include analyst assignment details and more.
com.google.backstory.Investigation.Builder Represents the aggregated state of an investigation such as categorization, severity, and status. Can be expanded to include analyst assignment details and more.
com.google.backstory.Label Key value labels.
com.google.backstory.Label.Builder Key value labels.
com.google.backstory.LatencyMetrics LatencyMetrics contains relevant timestamps for measuring latency per event variable. These metrics are calculated from ALL of the events that contribute to the detection, not just the sampled ones.
com.google.backstory.LatencyMetrics.Builder LatencyMetrics contains relevant timestamps for measuring latency per event variable. These metrics are calculated from ALL of the events that contribute to the detection, not just the sampled ones.
com.google.backstory.LinuxUtmp The LinuxUtmp extension captures details specific to Linux Utmp events.
com.google.backstory.LinuxUtmp.Builder The LinuxUtmp extension captures details specific to Linux Utmp events.
com.google.backstory.Location Information about a location.
com.google.backstory.Location.Builder Information about a location.
com.google.backstory.Metadata General information associated with a UDM event.
com.google.backstory.Metadata.Builder General information associated with a UDM event.
com.google.backstory.Metric Stores precomputed aggregated analytic data for an entity.
com.google.backstory.Metric.Builder Stores precomputed aggregated analytic data for an entity.
com.google.backstory.Metric.Measure Describes the precomputed measure.
com.google.backstory.Metric.Measure.Builder Describes the precomputed measure.
com.google.backstory.Network A network event.
com.google.backstory.Network.Builder A network event.
com.google.backstory.Noun The Noun type is used to represent the different entities in an event: principal, src, target, observer, intermediary, and about. It stores attributes known about the entity. For example, if the entity is a device
com.google.backstory.Noun.Builder The Noun type is used to represent the different entities in an event: principal, src, target, observer, intermediary, and about. It stores attributes known about the entity. For example, if the entity is a device
com.google.backstory.NtfsFileMetadata NTFS-specific file metadata.
com.google.backstory.NtfsFileMetadata.Builder NTFS-specific file metadata.
com.google.backstory.OutlookMetadata Microsoft Outlook specific metadata.
com.google.backstory.OutlookMetadata.Builder Microsoft Outlook specific metadata.
com.google.backstory.PDFInfo Information about the PDF file structure. See https://developers.virustotal.com/reference/pdf_info
com.google.backstory.PDFInfo.Builder Information about the PDF file structure. See https://developers.virustotal.com/reference/pdf_info
com.google.backstory.PeFileMetadata Metadata about a Microsoft Windows Portable Executable.
com.google.backstory.PeFileMetadata.Builder Metadata about a Microsoft Windows Portable Executable.
com.google.backstory.Permission System permission for resource access and modification.
com.google.backstory.Permission.Builder System permission for resource access and modification.
com.google.backstory.PlatformSoftware Platform software information about an operating system.
com.google.backstory.PlatformSoftware.Builder Platform software information about an operating system.
com.google.backstory.PopularityRank Domain's position in popularity ranks for sources such as Alexa, Quantcast, or Statvoo.
com.google.backstory.PopularityRank.Builder Domain's position in popularity ranks for sources such as Alexa, Quantcast, or Statvoo.
com.google.backstory.PrefetchFileMetadata Windows Prefetch file metadata.
com.google.backstory.PrefetchFileMetadata.Builder Windows Prefetch file metadata.
com.google.backstory.Prevalence The prevalence of a resource within the customer's environment. This measures how common it is for assets to access the resource.
com.google.backstory.Prevalence.Builder The prevalence of a resource within the customer's environment. This measures how common it is for assets to access the resource.
com.google.backstory.Process Information about a process.
com.google.backstory.Process.Builder Information about a process.
com.google.backstory.ProxyInfo Proxy information.
com.google.backstory.ProxyInfo.Builder Proxy information.
com.google.backstory.Reference Reference to model primatives including event and entity. As support is added for fast retrieval of objects by identifiers, this will be expanded to include ID references rather than full object copies.
com.google.backstory.Reference.Builder Reference to model primatives including event and entity. As support is added for fast retrieval of objects by identifiers, this will be expanded to include ID references rather than full object copies.
com.google.backstory.Registry Information about a registry key or value.
com.google.backstory.Registry.Builder Information about a registry key or value.
com.google.backstory.Relation Defines the relationship between the entity (a) and another entity (b).
com.google.backstory.Relation.Builder Defines the relationship between the entity (a) and another entity (b).
com.google.backstory.Resource Information about a resource such as a task, Cloud Storage bucket, database, disk, logical policy, or something similar.
com.google.backstory.Resource.Builder Information about a resource such as a task, Cloud Storage bucket, database, disk, logical policy, or something similar.
com.google.backstory.ResourceUsage The ResourceUsage extension captures details about what is using a resource.
com.google.backstory.ResourceUsage.Builder The ResourceUsage extension captures details about what is using a resource.
com.google.backstory.ResponsePlatformInfo Related info of an Alert in customer's SOAR platform.
com.google.backstory.ResponsePlatformInfo.Builder Related info of an Alert in customer's SOAR platform.
com.google.backstory.RiskDelta Describes the difference in risk score between two points in time.
com.google.backstory.RiskDelta.Builder Describes the difference in risk score between two points in time.
com.google.backstory.Role System role for resource access and modification.
com.google.backstory.Role.Builder System role for resource access and modification.
com.google.backstory.SSLCertificate SSL certificate.
com.google.backstory.SSLCertificate.AuthorityKeyId Identifies the public key to be used to verify the signature on this certificate or CRL.
com.google.backstory.SSLCertificate.AuthorityKeyId.Builder Identifies the public key to be used to verify the signature on this certificate or CRL.
com.google.backstory.SSLCertificate.Builder SSL certificate.
com.google.backstory.SSLCertificate.CertSignature Certificate's signature and algorithm.
com.google.backstory.SSLCertificate.CertSignature.Builder Certificate's signature and algorithm.
com.google.backstory.SSLCertificate. EC public key information.
com.google.backstory.SSLCertificate.EC.Builder EC public key information.
com.google.backstory.SSLCertificate.Extension Certificate's extensions.
com.google.backstory.SSLCertificate.Extension.Builder Certificate's extensions.
com.google.backstory.SSLCertificate.PublicKey Subject public key info.
com.google.backstory.SSLCertificate.PublicKey.Builder Subject public key info.
com.google.backstory.SSLCertificate. RSA public key information.
com.google.backstory.SSLCertificate.RSA.Builder RSA public key information.
com.google.backstory.SSLCertificate.Subject Subject data.
com.google.backstory.SSLCertificate.Subject.Builder Subject data.
com.google.backstory.SSLCertificate.Validity Defines certificate's validity period.
com.google.backstory.SSLCertificate.Validity.Builder Defines certificate's validity period.
com.google.backstory.ScheduledAnacronTask Information about a scheduled anacron task.
com.google.backstory.ScheduledAnacronTask.Builder Information about a scheduled anacron task.
com.google.backstory.ScheduledCronTask Information about a scheduled cron task.
com.google.backstory.ScheduledCronTask.Builder Information about a scheduled cron task.
com.google.backstory.ScheduledTask Deprecated: use WindowsScheduledTask for Windows scheduled tasks or ScheduledCronTask for cron jobs. Information about a scheduled task.
com.google.backstory.ScheduledTask.Builder Deprecated: use WindowsScheduledTask for Windows scheduled tasks or ScheduledCronTask for cron jobs. Information about a scheduled task.
com.google.backstory.SecurityResult Security related metadata for the event. A security result might be something like "virus detected and quarantined," "malicious connection blocked," or "sensitive data included in document foo.doc." Each security result, of which
com.google.backstory.SecurityResult.AnalystVerdict Verdict provided by the human analyst. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.AnalystVerdict.Builder Verdict provided by the human analyst. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.Association Associations represents different metadata about malware and threat actors involved with an IoC.
com.google.backstory.SecurityResult.Association.AssociationAlias Association Alias used to represent Mandiant Threat Intelligence.
com.google.backstory.SecurityResult.Association.AssociationAlias.Builder Association Alias used to represent Mandiant Threat Intelligence.
com.google.backstory.SecurityResult.Association.Builder Associations represents different metadata about malware and threat actors involved with an IoC.
com.google.backstory.SecurityResult.Builder Security related metadata for the event. A security result might be something like "virus detected and quarantined," "malicious connection blocked," or "sensitive data included in document foo.doc." Each security result, of which
com.google.backstory.SecurityResult.IoCStats Information about the threat intelligence source. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.IoCStats.Builder Information about the threat intelligence source. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.ProviderMLVerdict Deprecated. MLVerdict result provided from threat providers, like Mandiant. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.ProviderMLVerdict.Builder Deprecated. MLVerdict result provided from threat providers, like Mandiant. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.Source Deprecated. Information about the threat intelligence source. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.Source.Builder Deprecated. Information about the threat intelligence source. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.ThreatCollectionItem Threat Collection that is either a threat campaign or a threat report.
com.google.backstory.SecurityResult.ThreatCollectionItem.Builder Threat Collection that is either a threat campaign or a threat report.
com.google.backstory.SecurityResult.Verdict Deprecated. Encapsulates the threat verdict provided by human analysts and ML models. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.Verdict.Builder Deprecated. Encapsulates the threat verdict provided by human analysts and ML models. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.VerdictInfo Describes the threat verdict provided by human analysts and machine learning models. These fields are used to model Mandiant sources.
com.google.backstory.SecurityResult.VerdictInfo.Builder Describes the threat verdict provided by human analysts and machine learning models. These fields are used to model Mandiant sources.
com.google.backstory.Service Information about a Windows service.
com.google.backstory.Service.Builder Information about a Windows service.
com.google.backstory.SignatureInfo File signature information extracted from different tools.
com.google.backstory.SignatureInfo.Builder File signature information extracted from different tools.
com.google.backstory.SignerInfo File metadata related to the signer information.
com.google.backstory.SignerInfo.Builder File metadata related to the signer information.
com.google.backstory.Smtp SMTP info. See RFC 2821.
com.google.backstory.Smtp.Builder SMTP info. See RFC 2821.
com.google.backstory.SoarAlertMetadata Metadata fields of alerts coming from other SIEM systems.
com.google.backstory.SoarAlertMetadata.Builder Metadata fields of alerts coming from other SIEM systems.
com.google.backstory.Software Information about a software package or application.
com.google.backstory.Software.Builder Information about a software package or application.
com.google.backstory.Srum The Srum extension captures details specific to Windows System Resource Usage Monitor (SRUM) events.
com.google.backstory.Srum.Builder The Srum extension captures details specific to Windows System Resource Usage Monitor (SRUM) events.
com.google.backstory.StringSequence StringSequence represents a sequence of string.
com.google.backstory.StringSequence.Builder StringSequence represents a sequence of string.
com.google.backstory.StringToInt64MapEntry Protobuf type google.backstory.StringToInt64MapEntry
com.google.backstory.StringToInt64MapEntry.Builder Protobuf type google.backstory.StringToInt64MapEntry
com.google.backstory.SystemEventDetails Captures additional details for system-level events.
com.google.backstory.SystemEventDetails.Builder Captures additional details for system-level events.
com.google.backstory.Tags Tags are event metadata which is set by examining event contents post-parsing. For example, a UDM event may be assigned a tenant_id based on certain customer-defined parameters.
com.google.backstory.Tags.Builder Tags are event metadata which is set by examining event contents post-parsing. For example, a UDM event may be assigned a tenant_id based on certain customer-defined parameters.
com.google.backstory.TimeOff System record for leave/time-off from a Human Capital Management (HCM) system.
com.google.backstory.TimeOff.Builder System record for leave/time-off from a Human Capital Management (HCM) system.
com.google.backstory.Tls Transport Layer Security (TLS) information.
com.google.backstory.Tls.Builder Transport Layer Security (TLS) information.
com.google.backstory.Tls.Client.Builder Transport Layer Security (TLS) information associated with the client (for example, Certificate or JA3 hash).
com.google.backstory.Tls.Server Transport Layer Security (TLS) information associated with the server (for example, Certificate or JA3 hash).
com.google.backstory.Tls.Server.Builder Transport Layer Security (TLS) information associated with the server (for example, Certificate or JA3 hash).
com.google.backstory.Tracker URL Tracker.
com.google.backstory.Tracker.Builder URL Tracker.
com.google.backstory.Tunnels VPN tunnels.
com.google.backstory.Tunnels.Builder VPN tunnels.
com.google.backstory. A Unified Data Model event.
com.google.backstory.UDM.Builder A Unified Data Model event.
com.google.backstory.Udm
com.google.backstory.Uint64Sequence Uint64Sequence represents a sequence of uint64s.
com.google.backstory.Uint64Sequence.Builder Uint64Sequence represents a sequence of uint64s.
com.google.backstory.Url Url.
com.google.backstory.Url.Builder Url.
com.google.backstory.User Information about a user.
com.google.backstory.User.Builder Information about a user.
com.google.backstory.UserAssist The UserAssist extension captures details specific to Windows User Assist events.
com.google.backstory.UserAssist.Builder The UserAssist extension captures details specific to Windows User Assist events.
com.google.backstory.UsnJournal Information from the NTFS USN Journal.
com.google.backstory.UsnJournal.Builder Information from the NTFS USN Journal.
com.google.backstory.Volume Information about a storage volume.
com.google.backstory.Volume.Builder Information about a storage volume.
com.google.backstory.Vulnerabilities The Vulnerabilities extension captures details on observed/detected vulnerabilities.
com.google.backstory.Vulnerabilities.Builder The Vulnerabilities extension captures details on observed/detected vulnerabilities.
com.google.backstory.Vulnerability A vulnerability.
com.google.backstory.Vulnerability.Builder A vulnerability.
com.google.backstory.WindowsEventLog The WindowsEventLog extension captures details specific to Windows Event Log events.
com.google.backstory.WindowsEventLog.Builder The WindowsEventLog extension captures details specific to Windows Event Log events.
com.google.backstory.WindowsScheduledTask Information about a Windows scheduled task.
com.google.backstory.WindowsScheduledTask.Builder Information about a Windows scheduled task.
com.google.backstory.WindowsScheduledTask.TaskAction The task action.
com.google.backstory.WindowsScheduledTask.TaskAction.Builder The task action.
com.google.backstory.WindowsScheduledTask.TaskTrigger The trigger of the scheduled task.
com.google.backstory.WindowsScheduledTask.TaskTrigger.Builder The trigger of the scheduled task.
com.google.backstory.WmiPersistenceItem Information about a WMI persistence item.
com.google.backstory.WmiPersistenceItem.Builder Information about a WMI persistence item.
com.google.backstory. File certificate.
com.google.backstory.X509.Builder File certificate.

Interfaces

Interface Description
com.google.backstory.AnalyticsMetadataOrBuilder
com.google.backstory.AppCompatMetadataOrBuilder
com.google.backstory.ArtifactClientOrBuilder
com.google.backstory.ArtifactOrBuilder
com.google.backstory.AssetOrBuilder
com.google.backstory.AtiPrioritizationOrBuilder
com.google.backstory.AttackDetails.TacticOrBuilder
com.google.backstory.AttackDetails.TechniqueOrBuilder
com.google.backstory.AttackDetailsOrBuilder
com.google.backstory.AttributeOrBuilder
com.google.backstory.AuthenticationOrBuilder
com.google.backstory.BoolSequenceOrBuilder
com.google.backstory.Browser.CookieOrBuilder
com.google.backstory.BrowserOrBuilder
com.google.backstory.BytesSequenceOrBuilder
com.google.backstory.CertificateOrBuilder
com.google.backstory.CloudOrBuilder
com.google.backstory.CollectionOrBuilder
com.google.backstory.DNSRecordOrBuilder
com.google.backstory.DataAccessIngestionLabelOrBuilder
com.google.backstory.DataAccessLabelsOrBuilder
com.google.backstory.DataTableRowInfoOrBuilder
com.google.backstory.Dhcp.OptionOrBuilder
com.google.backstory.DhcpOrBuilder
com.google.backstory.Dns.QuestionOrBuilder
com.google.backstory.Dns.ResourceRecordOrBuilder
com.google.backstory.DnsOrBuilder
com.google.backstory.DomainOrBuilder
com.google.backstory.DoubleSequenceOrBuilder
com.google.backstory.ElementOrBuilder
com.google.backstory.EmailOrBuilder
com.google.backstory.EntityGraphEnrichmentOrBuilder
com.google.backstory.EntityMetadataOrBuilder
com.google.backstory.EntityOrBuilder
com.google.backstory.EntityRiskOrBuilder
com.google.backstory.ExifInfoOrBuilder
com.google.backstory.ExtensionsOrBuilder
com.google.backstory.FaviconOrBuilder
com.google.backstory.FileMetadataCodesignOrBuilder
com.google.backstory.FileMetadataImportsOrBuilder
com.google.backstory.FileMetadataOrBuilder
com.google.backstory.FileMetadataPEOrBuilder
com.google.backstory.FileMetadataPeResourceInfoOrBuilder
com.google.backstory.FileMetadataSectionOrBuilder
com.google.backstory.FileMetadataSignatureInfoOrBuilder
com.google.backstory.FileOrBuilder
com.google.backstory.FindingVariableOrBuilder
com.google.backstory.FtpOrBuilder
com.google.backstory.GroupOrBuilder
com.google.backstory.GroupedFieldsOrBuilder
com.google.backstory.HardwareOrBuilder
com.google.backstory.HttpOrBuilder
com.google.backstory.IdOrBuilder
com.google.backstory.Int64SequenceOrBuilder
com.google.backstory.InvestigationOrBuilder
com.google.backstory.LabelOrBuilder
com.google.backstory.LatencyMetricsOrBuilder
com.google.backstory.LinuxUtmpOrBuilder
com.google.backstory.LocationOrBuilder
com.google.backstory.MetadataOrBuilder
com.google.backstory.Metric.MeasureOrBuilder
com.google.backstory.MetricOrBuilder
com.google.backstory.NetworkOrBuilder
com.google.backstory.NounOrBuilder
com.google.backstory.NtfsFileMetadataOrBuilder
com.google.backstory.OutlookMetadataOrBuilder
com.google.backstory.PDFInfoOrBuilder
com.google.backstory.PeFileMetadataOrBuilder
com.google.backstory.PermissionOrBuilder
com.google.backstory.PlatformSoftwareOrBuilder
com.google.backstory.PopularityRankOrBuilder
com.google.backstory.PrefetchFileMetadataOrBuilder
com.google.backstory.PrevalenceOrBuilder
com.google.backstory.ProcessOrBuilder
com.google.backstory.ProxyInfoOrBuilder
com.google.backstory.ReferenceOrBuilder
com.google.backstory.RegistryOrBuilder
com.google.backstory.RelationOrBuilder
com.google.backstory.ResourceOrBuilder
com.google.backstory.ResourceUsageOrBuilder
com.google.backstory.ResponsePlatformInfoOrBuilder
com.google.backstory.RiskDeltaOrBuilder
com.google.backstory.RoleOrBuilder
com.google.backstory.SSLCertificate.AuthorityKeyIdOrBuilder
com.google.backstory.SSLCertificate.CertSignatureOrBuilder
com.google.backstory.SSLCertificate.ECOrBuilder
com.google.backstory.SSLCertificate.ExtensionOrBuilder
com.google.backstory.SSLCertificate.PublicKeyOrBuilder
com.google.backstory.SSLCertificate.RSAOrBuilder
com.google.backstory.SSLCertificate.SubjectOrBuilder
com.google.backstory.SSLCertificate.ValidityOrBuilder
com.google.backstory.SSLCertificateOrBuilder
com.google.backstory.ScheduledAnacronTaskOrBuilder
com.google.backstory.ScheduledCronTaskOrBuilder
com.google.backstory.ScheduledTaskOrBuilder
com.google.backstory.SecurityResult.AnalystVerdictOrBuilder
com.google.backstory.SecurityResult.Association.AssociationAliasOrBuilder
com.google.backstory.SecurityResult.AssociationOrBuilder
com.google.backstory.SecurityResult.IoCStatsOrBuilder
com.google.backstory.SecurityResult.ProviderMLVerdictOrBuilder
com.google.backstory.SecurityResult.SourceOrBuilder
com.google.backstory.SecurityResult.ThreatCollectionItemOrBuilder
com.google.backstory.SecurityResult.VerdictInfoOrBuilder
com.google.backstory.SecurityResult.VerdictOrBuilder
com.google.backstory.SecurityResultOrBuilder
com.google.backstory.ServiceOrBuilder
com.google.backstory.SignatureInfoOrBuilder
com.google.backstory.SignerInfoOrBuilder
com.google.backstory.SmtpOrBuilder
com.google.backstory.SoarAlertMetadataOrBuilder
com.google.backstory.SoftwareOrBuilder
com.google.backstory.SrumOrBuilder
com.google.backstory.StringSequenceOrBuilder
com.google.backstory.StringToInt64MapEntryOrBuilder
com.google.backstory.SystemEventDetailsOrBuilder
com.google.backstory.TagsOrBuilder
com.google.backstory.TimeOffOrBuilder
com.google.backstory.Tls.ClientOrBuilder
com.google.backstory.Tls.ServerOrBuilder
com.google.backstory.TlsOrBuilder
com.google.backstory.TrackerOrBuilder
com.google.backstory.TunnelsOrBuilder
com.google.backstory.UDMOrBuilder
com.google.backstory.Uint64SequenceOrBuilder
com.google.backstory.UrlOrBuilder
com.google.backstory.UserAssistOrBuilder
com.google.backstory.UserOrBuilder
com.google.backstory.UsnJournalOrBuilder
com.google.backstory.VolumeOrBuilder
com.google.backstory.VulnerabilitiesOrBuilder
com.google.backstory.VulnerabilityOrBuilder
com.google.backstory.WindowsEventLogOrBuilder
com.google.backstory.WindowsScheduledTask.TaskActionOrBuilder
com.google.backstory.WindowsScheduledTask.TaskTriggerOrBuilder
com.google.backstory.WindowsScheduledTaskOrBuilder
com.google.backstory.WmiPersistenceItemOrBuilder
com.google.backstory.X509OrBuilder

Enums

Enum Description
com.google.backstory.Asset.AssetType The role type of the asset.
com.google.backstory.Asset.DeploymentStatus Deployment status states.
com.google.backstory.Authentication.AuthType Type of system the authentication event is associated with.
com.google.backstory.Authentication.AuthenticationStatus Authentication status, can be used to describe the status of authentication for a user or particular credential.
com.google.backstory.Authentication.Mechanism Mechanism(s) used to authenticate.
com.google.backstory.Authentication.Outcome The outcome of the authentication event.
com.google.backstory.Browser.BrowserType The name of the browser.
com.google.backstory.Browser.Cookie.CookieSameSite The SameSite attribute of a cookie.
com.google.backstory.Browser.UrlVisitType The type of visit to a URL.
com.google.backstory.Browser.VisitSource The source of the visit.
com.google.backstory.Cloud.CloudEnvironment The service provider environment.
com.google.backstory.Collection.CollectionType The type of the collection which will indicate which other fields are relevant. For example, detection finding collections will populate the detection field. Findings that evolve into investigations will populate the
com.google.backstory.Collection.DetectionTimingDetails Detection timing details for the collection.
com.google.backstory.Collection.RunFrequency Run frequencies used by rule executions.
com.google.backstory.Dhcp.MessageType DHCP message type. See RFC2131, section 3.1.
com.google.backstory.Dhcp.OpCode BOOTP op code. See RFC951, section 3.
com.google.backstory.EntityGraphEnrichment.EnrichmentType Type of enrichment.
com.google.backstory.EntityMetadata.EntityType Describes the type of entity. An unknown event type.
com.google.backstory.EntityMetadata.SourceType Describes the source of an entity.
com.google.backstory.File.FileType The file type, for example Microsoft Windows executable.
com.google.backstory.FindingVariable.Type Type options for Finding variables.
com.google.backstory.FindingVariable.TypedValueCase
com.google.backstory.Id.Namespace Extracted Namespace Component
com.google.backstory.LinuxUtmp.RecordType The type of activity record from the Utmp file.
com.google.backstory.Metadata.EnrichmentState An enrichment state.
com.google.backstory.Metadata.EventTimestampAttribute Enum representing the type of timestamp that the event_timestamp field represents.
com.google.backstory.Metadata.EventType An event type. Choose event type not based on the product that generated the event but the one that logged the event itself. So, for example, an antivirus (AV)
com.google.backstory.Metric.AggregateFunction Mathematic function used to calculate the value.
com.google.backstory.Metric.Dimension Describes field used as the dimension when grouping data to calculate the aggregate metric.
com.google.backstory.Metric.MetricName The name of the precomputed analytic.
com.google.backstory.Network.ApplicationProtocol A network application protocol.
com.google.backstory.Network.ConnectionState The state of a network connection.
com.google.backstory.Network.Direction A network traffic direction.
com.google.backstory.Network.IpProtocol An IP protocol.
com.google.backstory.Noun.Platform Operating system platform.
com.google.backstory.Permission.PermissionType High level categorizations of permission type.
com.google.backstory.Priority Priority that is assigned to a Case or Alert.
com.google.backstory.Process.State The state of the process. See https://psutil.readthedocs.io/en/stable/#process-status-constants.
com.google.backstory.Process.TokenElevationType The elevation type of the process's token. See https://learn.microsoft.com/en-us/windows/win32/api/winnt/ne-winnt-token_elevation_type
com.google.backstory.Reason Reason for closing an Alert or Case in the SOAR product.
com.google.backstory.Registry.Type Type of the registry value. These values are based on the Windows Registry value types: https://learn.microsoft.com/en-us/windows/win32/sysinfo/registry-value-types
com.google.backstory.Relation.Directionality Describes the relationship model as directed or undirected.
com.google.backstory.Relation.EntityLabel Entity label of the relation.
com.google.backstory.Relation.Relationship Type of relationship between the primary entity (a) and related entity (b).
com.google.backstory.Reputation Categorization options for the usefulness of a finding.
com.google.backstory.Resource.ResourceType The type of resource.
com.google.backstory.ResponsePlatformInfo.ResponsePlatformType Available response platforms.
com.google.backstory.Role.Type Well-known system roles.
com.google.backstory.SecurityResult.Action Enum representing different possible actions taken by the product that created the event. Google SecOps classifies:
com.google.backstory.SecurityResult.AlertState The type of alerting set up for a security result.
com.google.backstory.SecurityResult.Association.AssociationType Represents different possible Association types. Can be threat or malware. Used to represent Mandiant threat intelligence.
com.google.backstory.SecurityResult.IoCStatsType Type of IoCStat based on source.
com.google.backstory.SecurityResult.ProductConfidence A level of confidence in the result.
com.google.backstory.SecurityResult.ProductPriority A product priority level.
com.google.backstory.SecurityResult.ProductSeverity Defined by the product
com.google.backstory.SecurityResult.SecurityCategory SecurityCategory is used to standardize security categories across products so one event is not categorized as "malware" and another as a "virus".
com.google.backstory.SecurityResult.ThreatCollectionType Different Types of threat collections currently supported.
com.google.backstory.SecurityResult.ThreatStatus Vendor-specific information about the status of a threat (ITW).
com.google.backstory.SecurityResult.VerdictResponse Represents different verdict types. Used to represent Mandiant threat intelligence.
com.google.backstory.SecurityResult.VerdictType Category of the verdict.
com.google.backstory.Service.ServiceType The type of service.
com.google.backstory.Service.StartupType How the service is started.
com.google.backstory.Service.State The current status of the service.
com.google.backstory.Status Describes status of a finding.
com.google.backstory.ThreatVerdict GCTI threat verdict levels.
com.google.backstory.User.AccountType User Account Type.
com.google.backstory.User.Role User system roles.
com.google.backstory.UsnJournal.Attribute File attributes from the USN record (e.g., "READ_ONLY, HIDDEN"). See https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants for more information about the attributes.
com.google.backstory.UsnJournal.Reason The reason for the USN journal entry.
com.google.backstory.Verdict Categorization options for the validity of a finding (for example, whether it reflects an actual security incident).
com.google.backstory.Vulnerability.Severity Severity of the vulnerability.
com.google.backstory.WindowsEventLog.Channel The channel specifies the source or category of the event.
com.google.backstory.WindowsScheduledTask.TaskAction.ActionType Enum representing the action type of the task.
com.google.backstory.WindowsScheduledTask.TaskLogonType Enum representing the logon type of the task.
com.google.backstory.WindowsScheduledTask.TaskState Enum representing the operation state of the task.
com.google.backstory.WindowsScheduledTask.TaskTrigger.TriggerType Enum representing the trigger type of the task. For more details, see https://learn.microsoft.com/en-us/windows/win32/api/taskschd/ne-taskschd-task_trigger_type2.