| GitHub Repository |
Client Classes
Client classes are the main entry point to using a package. They contain several variations of Java methods for each of the API's methods.
| Client | Description |
|---|---|
| com. |
Entity or software accessing or utilizing network resources. |
| com. |
Transport Layer Security (TLS) information associated with the client (for example, Certificate or JA3 hash). |
Classes
| Class | Description |
|---|---|
| com. |
Stores information about an analytics metric used in a rule. |
| com. |
Stores information about an analytics metric used in a rule. |
| com. |
Windows AppCompatCache (Application Compatibility) metadata. |
| com. |
Windows AppCompatCache (Application Compatibility) metadata. |
| com. |
Information about an artifact. The artifact can only be an IP. |
| com. |
Information about an artifact. The artifact can only be an IP. |
| com. |
Entity or software accessing or utilizing network resources. |
| com. |
Information about a compute asset such as a workstation, laptop, phone, virtual desktop, or VM. |
| com. |
Information about a compute asset such as a workstation, laptop, phone, virtual desktop, or VM. |
| com. |
AtiPrioritization contains various fields used to calculate a priority score for an entity identified as a threat. |
| com. |
AtiPrioritization contains various fields used to calculate a priority score for an entity identified as a threat. |
| com. |
MITRE ATT&CK details. |
| com. |
MITRE ATT&CK details. |
| com. |
Tactic information related to an attack or threat. |
| com. |
Tactic information related to an attack or threat. |
| com. |
Technique information related to an attack or threat. |
| com. |
Technique information related to an attack or threat. |
| com. |
Attribute is a container for generic entity attributes including common attributes across core entities (such as, user or asset). For example, Cloud is a generic entity attribute since it can apply to an asset (for example, a |
| com. |
Attribute is a container for generic entity attributes including common attributes across core entities (such as, user or asset). For example, Cloud is a generic entity attribute since it can apply to an asset (for example, a |
| com. |
The Authentication extension captures details specific to authentication events. General guidelines for authentication events: |
| com. |
The Authentication extension captures details specific to authentication events. General guidelines for authentication events: |
| com. |
BoolSequence represents a sequence of bools. |
| com. |
BoolSequence represents a sequence of bools. |
| com. |
Information about an entry in the web browser's local history database. |
| com. |
Information about an entry in the web browser's local history database. |
| com. |
Browser cookie. |
| com. |
Browser cookie. |
| com. |
BytesSequence represents a sequence of bytes. |
| com. |
BytesSequence represents a sequence of bytes. |
| com. |
Certificate information |
| com. |
Certificate information |
| com. |
Metadata related to the cloud environment. |
| com. |
Metadata related to the cloud environment. |
| com. |
Collection represents a container of objects (such as events, entity context metadata, detection finding metadata) and state (such as investigation details). |
| com. |
Collection represents a container of objects (such as events, entity context metadata, detection finding metadata) and state (such as investigation details). |
| com. |
|
| com. |
DNS record. |
| com. |
DNS record. |
| com. |
|
| com. |
Label used in data access for ingestion. |
| com. |
Label used in data access for ingestion. |
| com. |
Label used in data access. |
| com. |
Label used in data access. |
| com. |
DataTableRowInfo captures information about a data table row including the name of the data table. |
| com. |
DataTableRowInfo captures information about a data table row including the name of the data table. |
| com. |
DHCP information. |
| com. |
DHCP information. |
| com. |
DHCP options. |
| com. |
DHCP options. |
| com. |
DNS information. |
| com. |
DNS information. |
| com. |
DNS Questions. See RFC1035, section 4.1.2. |
| com. |
DNS Questions. See RFC1035, section 4.1.2. |
| com. |
DNS Resource Records. See RFC1035, section 4.1.3. |
| com. |
DNS Resource Records. See RFC1035, section 4.1.3. |
| com. |
Information about a domain. |
| com. |
Information about a domain. |
| com. |
DoubleSequence represents a sequence of doubles. |
| com. |
DoubleSequence represents a sequence of doubles. |
| com. |
Protobuf type google.backstory.Element |
| com. |
Protobuf type google.backstory.Element |
| com. |
Email info. |
| com. |
Email info. |
| com. |
An Entity provides additional context about an item in a UDM event. For example, a PROCESS_LAUNCH event describes that user 'abc@example.corp' launched process 'shady.exe'. |
| com. |
An Entity provides additional context about an item in a UDM event. For example, a PROCESS_LAUNCH event describes that user 'abc@example.corp' launched process 'shady.exe'. |
| com. |
EntityGraphEnrichment contains the data table name and the enrichment applied to the entity. |
| com. |
EntityGraphEnrichment contains the data table name and the enrichment applied to the entity. |
| com. |
Information about the Entity and the product where the entity was created. |
| com. |
Information about the Entity and the product where the entity was created. |
| com. |
|
| com. |
Stores information related to the risk score of an entity. |
| com. |
Stores information related to the risk score of an entity. |
| com. |
|
| com. |
Exif information. |
| com. |
Exif information. |
| com. |
Extensions to a UDM event. |
| com. |
Extensions to a UDM event. |
| com. |
Difference hash and MD5 hash of the domain's favicon. |
| com. |
Difference hash and MD5 hash of the domain's favicon. |
| com. |
Information about a file. |
| com. |
Information about a file. |
| com. |
Metadata about a file. Place metadata about different file types here, for example data from the Microsoft Windows VersionInfo block or digital signer details. |
| com. |
Metadata about a file. Place metadata about different file types here, for example data from the Microsoft Windows VersionInfo block or digital signer details. |
| com. |
File metadata from the codesign utility. |
| com. |
File metadata from the codesign utility. |
| com. |
File metadata imports. |
| com. |
File metadata imports. |
| com. |
Metadata about the Portable Executable (PE) file. |
| com. |
Metadata about the Portable Executable (PE) file. |
| com. |
File metadata for PE resource. |
| com. |
File metadata for PE resource. |
| com. |
File metadata section. |
| com. |
File metadata section. |
| com. |
Signature information. |
| com. |
Signature information. |
| com. |
A structure that holds the value and associated metadata for values extracted while producing a Finding. |
| com. |
A structure that holds the value and associated metadata for values extracted while producing a Finding. |
| com. |
FTP info. |
| com. |
FTP info. |
| com. |
Information about an organizational group. |
| com. |
Information about an organizational group. |
| com. |
Grouped fields are aliases for groups of related UDM fields. All fields grouped together are of type string. |
| com. |
Grouped fields are aliases for groups of related UDM fields. All fields grouped together are of type string. |
| com. |
Hardware specification details for a resource, including both physical and virtual hardware. |
| com. |
Hardware specification details for a resource, including both physical and virtual hardware. |
| com. |
Specify the full URL of the HTTP request within "target". Also specify any uploaded or downloaded file information within "source" or "target". |
| com. |
Specify the full URL of the HTTP request within "target". Also specify any uploaded or downloaded file information within "source" or "target". |
| com. |
Identifier to identify a UDM object like a UDM event, Entity, Collection. The full identifier for persistence is created by setting the 32 most significant bits as the Id.Namespace enum This is a convenience wrapper to |
| com. |
Identifier to identify a UDM object like a UDM event, Entity, Collection. The full identifier for persistence is created by setting the 32 most significant bits as the Id.Namespace enum This is a convenience wrapper to |
| com. |
|
| com. |
Int64Sequence represents a sequence of int64s. |
| com. |
Int64Sequence represents a sequence of int64s. |
| com. |
Represents the aggregated state of an investigation such as categorization, severity, and status. Can be expanded to include analyst assignment details and more. |
| com. |
Represents the aggregated state of an investigation such as categorization, severity, and status. Can be expanded to include analyst assignment details and more. |
| com. |
Key value labels. |
| com. |
Key value labels. |
| com. |
LatencyMetrics contains relevant timestamps for measuring latency per event variable. These metrics are calculated from ALL of the events that contribute to the detection, not just the sampled ones. |
| com. |
LatencyMetrics contains relevant timestamps for measuring latency per event variable. These metrics are calculated from ALL of the events that contribute to the detection, not just the sampled ones. |
| com. |
The LinuxUtmp extension captures details specific to Linux Utmp events. |
| com. |
The LinuxUtmp extension captures details specific to Linux Utmp events. |
| com. |
Information about a location. |
| com. |
Information about a location. |
| com. |
General information associated with a UDM event. |
| com. |
General information associated with a UDM event. |
| com. |
Stores precomputed aggregated analytic data for an entity. |
| com. |
Stores precomputed aggregated analytic data for an entity. |
| com. |
Describes the precomputed measure. |
| com. |
Describes the precomputed measure. |
| com. |
A network event. |
| com. |
A network event. |
| com. |
The Noun type is used to represent the different entities in an event: principal, src, target, observer, intermediary, and about. It stores attributes known about the entity. For example, if the entity is a device |
| com. |
The Noun type is used to represent the different entities in an event: principal, src, target, observer, intermediary, and about. It stores attributes known about the entity. For example, if the entity is a device |
| com. |
NTFS-specific file metadata. |
| com. |
NTFS-specific file metadata. |
| com. |
Microsoft Outlook specific metadata. |
| com. |
Microsoft Outlook specific metadata. |
| com. |
Information about the PDF file structure. See https://developers.virustotal.com/reference/pdf_info |
| com. |
Information about the PDF file structure. See https://developers.virustotal.com/reference/pdf_info |
| com. |
Metadata about a Microsoft Windows Portable Executable. |
| com. |
Metadata about a Microsoft Windows Portable Executable. |
| com. |
System permission for resource access and modification. |
| com. |
System permission for resource access and modification. |
| com. |
Platform software information about an operating system. |
| com. |
Platform software information about an operating system. |
| com. |
Domain's position in popularity ranks for sources such as Alexa, Quantcast, or Statvoo. |
| com. |
Domain's position in popularity ranks for sources such as Alexa, Quantcast, or Statvoo. |
| com. |
Windows Prefetch file metadata. |
| com. |
Windows Prefetch file metadata. |
| com. |
The prevalence of a resource within the customer's environment. This measures how common it is for assets to access the resource. |
| com. |
The prevalence of a resource within the customer's environment. This measures how common it is for assets to access the resource. |
| com. |
Information about a process. |
| com. |
Information about a process. |
| com. |
Proxy information. |
| com. |
Proxy information. |
| com. |
Reference to model primatives including event and entity. As support is added for fast retrieval of objects by identifiers, this will be expanded to include ID references rather than full object copies. |
| com. |
Reference to model primatives including event and entity. As support is added for fast retrieval of objects by identifiers, this will be expanded to include ID references rather than full object copies. |
| com. |
Information about a registry key or value. |
| com. |
Information about a registry key or value. |
| com. |
Defines the relationship between the entity (a) and another entity (b). |
| com. |
Defines the relationship between the entity (a) and another entity (b). |
| com. |
Information about a resource such as a task, Cloud Storage bucket, database, disk, logical policy, or something similar. |
| com. |
Information about a resource such as a task, Cloud Storage bucket, database, disk, logical policy, or something similar. |
| com. |
The ResourceUsage extension captures details about what is using a resource. |
| com. |
The ResourceUsage extension captures details about what is using a resource. |
| com. |
Related info of an Alert in customer's SOAR platform. |
| com. |
Related info of an Alert in customer's SOAR platform. |
| com. |
Describes the difference in risk score between two points in time. |
| com. |
Describes the difference in risk score between two points in time. |
| com. |
System role for resource access and modification. |
| com. |
System role for resource access and modification. |
| com. |
SSL certificate. |
| com. |
Identifies the public key to be used to verify the signature on this certificate or CRL. |
| com. |
Identifies the public key to be used to verify the signature on this certificate or CRL. |
| com. |
SSL certificate. |
| com. |
Certificate's signature and algorithm. |
| com. |
Certificate's signature and algorithm. |
| com. |
EC public key information. |
| com. |
EC public key information. |
| com. |
Certificate's extensions. |
| com. |
Certificate's extensions. |
| com. |
Subject public key info. |
| com. |
Subject public key info. |
| com. |
RSA public key information. |
| com. |
RSA public key information. |
| com. |
Subject data. |
| com. |
Subject data. |
| com. |
Defines certificate's validity period. |
| com. |
Defines certificate's validity period. |
| com. |
Information about a scheduled anacron task. |
| com. |
Information about a scheduled anacron task. |
| com. |
Information about a scheduled cron task. |
| com. |
Information about a scheduled cron task. |
| com. |
Deprecated: use WindowsScheduledTask for Windows scheduled tasks or ScheduledCronTask for cron jobs. Information about a scheduled task. |
| com. |
Deprecated: use WindowsScheduledTask for Windows scheduled tasks or ScheduledCronTask for cron jobs. Information about a scheduled task. |
| com. |
Security related metadata for the event. A security result might be something like "virus detected and quarantined," "malicious connection blocked," or "sensitive data included in document foo.doc." Each security result, of which |
| com. |
Verdict provided by the human analyst. These fields are used to model Mandiant sources. |
| com. |
Verdict provided by the human analyst. These fields are used to model Mandiant sources. |
| com. |
Associations represents different metadata about malware and threat actors involved with an IoC. |
| com. |
Association Alias used to represent Mandiant Threat Intelligence. |
| com. |
Association Alias used to represent Mandiant Threat Intelligence. |
| com. |
Associations represents different metadata about malware and threat actors involved with an IoC. |
| com. |
Security related metadata for the event. A security result might be something like "virus detected and quarantined," "malicious connection blocked," or "sensitive data included in document foo.doc." Each security result, of which |
| com. |
Information about the threat intelligence source. These fields are used to model Mandiant sources. |
| com. |
Information about the threat intelligence source. These fields are used to model Mandiant sources. |
| com. |
Deprecated. MLVerdict result provided from threat providers, like Mandiant. These fields are used to model Mandiant sources. |
| com. |
Deprecated. MLVerdict result provided from threat providers, like Mandiant. These fields are used to model Mandiant sources. |
| com. |
Deprecated. Information about the threat intelligence source. These fields are used to model Mandiant sources. |
| com. |
Deprecated. Information about the threat intelligence source. These fields are used to model Mandiant sources. |
| com. |
Threat Collection that is either a threat campaign or a threat report. |
| com. |
Threat Collection that is either a threat campaign or a threat report. |
| com. |
Deprecated. Encapsulates the threat verdict provided by human analysts and ML models. These fields are used to model Mandiant sources. |
| com. |
Deprecated. Encapsulates the threat verdict provided by human analysts and ML models. These fields are used to model Mandiant sources. |
| com. |
Describes the threat verdict provided by human analysts and machine learning models. These fields are used to model Mandiant sources. |
| com. |
Describes the threat verdict provided by human analysts and machine learning models. These fields are used to model Mandiant sources. |
| com. |
Information about a Windows service. |
| com. |
Information about a Windows service. |
| com. |
File signature information extracted from different tools. |
| com. |
File signature information extracted from different tools. |
| com. |
File metadata related to the signer information. |
| com. |
File metadata related to the signer information. |
| com. |
SMTP info. See RFC 2821. |
| com. |
SMTP info. See RFC 2821. |
| com. |
Metadata fields of alerts coming from other SIEM systems. |
| com. |
Metadata fields of alerts coming from other SIEM systems. |
| com. |
Information about a software package or application. |
| com. |
Information about a software package or application. |
| com. |
The Srum extension captures details specific to Windows System Resource Usage Monitor (SRUM) events. |
| com. |
The Srum extension captures details specific to Windows System Resource Usage Monitor (SRUM) events. |
| com. |
StringSequence represents a sequence of string. |
| com. |
StringSequence represents a sequence of string. |
| com. |
Protobuf type google.backstory.StringToInt64MapEntry |
| com. |
Protobuf type google.backstory.StringToInt64MapEntry |
| com. |
Captures additional details for system-level events. |
| com. |
Captures additional details for system-level events. |
| com. |
Tags are event metadata which is set by examining event contents post-parsing. For example, a UDM event may be assigned a tenant_id based on certain customer-defined parameters. |
| com. |
Tags are event metadata which is set by examining event contents post-parsing. For example, a UDM event may be assigned a tenant_id based on certain customer-defined parameters. |
| com. |
System record for leave/time-off from a Human Capital Management (HCM) system. |
| com. |
System record for leave/time-off from a Human Capital Management (HCM) system. |
| com. |
Transport Layer Security (TLS) information. |
| com. |
Transport Layer Security (TLS) information. |
| com. |
Transport Layer Security (TLS) information associated with the client (for example, Certificate or JA3 hash). |
| com. |
Transport Layer Security (TLS) information associated with the server (for example, Certificate or JA3 hash). |
| com. |
Transport Layer Security (TLS) information associated with the server (for example, Certificate or JA3 hash). |
| com. |
URL Tracker. |
| com. |
URL Tracker. |
| com. |
VPN tunnels. |
| com. |
VPN tunnels. |
| com. |
A Unified Data Model event. |
| com. |
A Unified Data Model event. |
| com. |
|
| com. |
Uint64Sequence represents a sequence of uint64s. |
| com. |
Uint64Sequence represents a sequence of uint64s. |
| com. |
Url. |
| com. |
Url. |
| com. |
Information about a user. |
| com. |
Information about a user. |
| com. |
The UserAssist extension captures details specific to Windows User Assist events. |
| com. |
The UserAssist extension captures details specific to Windows User Assist events. |
| com. |
Information from the NTFS USN Journal. |
| com. |
Information from the NTFS USN Journal. |
| com. |
Information about a storage volume. |
| com. |
Information about a storage volume. |
| com. |
The Vulnerabilities extension captures details on observed/detected vulnerabilities. |
| com. |
The Vulnerabilities extension captures details on observed/detected vulnerabilities. |
| com. |
A vulnerability. |
| com. |
A vulnerability. |
| com. |
The WindowsEventLog extension captures details specific to Windows Event Log events. |
| com. |
The WindowsEventLog extension captures details specific to Windows Event Log events. |
| com. |
Information about a Windows scheduled task. |
| com. |
Information about a Windows scheduled task. |
| com. |
The task action. |
| com. |
The task action. |
| com. |
The trigger of the scheduled task. |
| com. |
The trigger of the scheduled task. |
| com. |
Information about a WMI persistence item. |
| com. |
Information about a WMI persistence item. |
| com. |
File certificate. |
| com. |
File certificate. |
Interfaces
Enums
| Enum | Description |
|---|---|
| com. |
The role type of the asset. |
| com. |
Deployment status states. |
| com. |
Type of system the authentication event is associated with. |
| com. |
Authentication status, can be used to describe the status of authentication for a user or particular credential. |
| com. |
Mechanism(s) used to authenticate. |
| com. |
The outcome of the authentication event. |
| com. |
The name of the browser. |
| com. |
The SameSite attribute of a cookie. |
| com. |
The type of visit to a URL. |
| com. |
The source of the visit. |
| com. |
The service provider environment. |
| com. |
The type of the collection which will indicate which other fields are relevant. For example, detection finding collections will populate the detection field. Findings that evolve into investigations will populate the |
| com. |
Detection timing details for the collection. |
| com. |
Run frequencies used by rule executions. |
| com. |
DHCP message type. See RFC2131, section 3.1. |
| com. |
BOOTP op code. See RFC951, section 3. |
| com. |
Type of enrichment. |
| com. |
Describes the type of entity. An unknown event type. |
| com. |
Describes the source of an entity. |
| com. |
The file type, for example Microsoft Windows executable. |
| com. |
Type options for Finding variables. |
| com. |
|
| com. |
Extracted Namespace Component |
| com. |
The type of activity record from the Utmp file. |
| com. |
An enrichment state. |
| com. |
Enum representing the type of timestamp that the event_timestamp field represents. |
| com. |
An event type. Choose event type not based on the product that generated the event but the one that logged the event itself. So, for example, an antivirus (AV) |
| com. |
Mathematic function used to calculate the value. |
| com. |
Describes field used as the dimension when grouping data to calculate the aggregate metric. |
| com. |
The name of the precomputed analytic. |
| com. |
A network application protocol. |
| com. |
The state of a network connection. |
| com. |
A network traffic direction. |
| com. |
An IP protocol. |
| com. |
Operating system platform. |
| com. |
High level categorizations of permission type. |
| com. |
Priority that is assigned to a Case or Alert. |
| com. |
The state of the process. See https://psutil.readthedocs.io/en/stable/#process-status-constants. |
| com. |
The elevation type of the process's token. See https://learn.microsoft.com/en-us/windows/win32/api/winnt/ne-winnt-token_elevation_type |
| com. |
Reason for closing an Alert or Case in the SOAR product. |
| com. |
Type of the registry value. These values are based on the Windows Registry value types: https://learn.microsoft.com/en-us/windows/win32/sysinfo/registry-value-types |
| com. |
Describes the relationship model as directed or undirected. |
| com. |
Entity label of the relation. |
| com. |
Type of relationship between the primary entity (a) and related entity (b). |
| com. |
Categorization options for the usefulness of a finding. |
| com. |
The type of resource. |
| com. |
Available response platforms. |
| com. |
Well-known system roles. |
| com. |
Enum representing different possible actions taken by the product that created the event. Google SecOps classifies: |
| com. |
The type of alerting set up for a security result. |
| com. |
Represents different possible Association types. Can be threat or malware. Used to represent Mandiant threat intelligence. |
| com. |
Type of IoCStat based on source. |
| com. |
A level of confidence in the result. |
| com. |
A product priority level. |
| com. |
Defined by the product |
| com. |
SecurityCategory is used to standardize security categories across products so one event is not categorized as "malware" and another as a "virus". |
| com. |
Different Types of threat collections currently supported. |
| com. |
Vendor-specific information about the status of a threat (ITW). |
| com. |
Represents different verdict types. Used to represent Mandiant threat intelligence. |
| com. |
Category of the verdict. |
| com. |
The type of service. |
| com. |
How the service is started. |
| com. |
The current status of the service. |
| com. |
Describes status of a finding. |
| com. |
GCTI threat verdict levels. |
| com. |
User Account Type. |
| com. |
User system roles. |
| com. |
File attributes from the USN record (e.g., "READ_ONLY, HIDDEN"). See https://learn.microsoft.com/en-us/windows/win32/fileio/file-attribute-constants for more information about the attributes. |
| com. |
The reason for the USN journal entry. |
| com. |
Categorization options for the validity of a finding (for example, whether it reflects an actual security incident). |
| com. |
Severity of the vulnerability. |
| com. |
The channel specifies the source or category of the event. |
| com. |
Enum representing the action type of the task. |
| com. |
Enum representing the logon type of the task. |
| com. |
Enum representing the operation state of the task. |
| com. |
Enum representing the trigger type of the task. For more details, see https://learn.microsoft.com/en-us/windows/win32/api/taskschd/ne-taskschd-task_trigger_type2. |