|
4226 | 4226 | ignore_above: 1024 |
4227 | 4227 | description: 'Use the `os.type` field to categorize the operating system into one of the broad commercial families. |
4228 | 4228 |
|
4229 | | - One of these following values should be used (lowercase): linux, macos, unix, windows. |
4230 | | -
|
4231 | | - If the OS you''re dealing with is not in the list, the field should not be populated. Please let us know by opening an issue with ECS, to propose its addition.' |
| 4229 | + If the OS you''re dealing with is not listed as an expected value, the field should not be populated. Please let us know by opening an issue with ECS, to propose its addition.' |
4232 | 4230 | example: macos |
4233 | 4231 | default_field: false |
4234 | 4232 | - name: os.version |
|
5480 | 5478 | default_field: false |
5481 | 5479 | - name: env_vars |
5482 | 5480 | level: extended |
5483 | | - type: object |
5484 | | - description: 'Environment variables (`env_vars`) set at the time of the event. May be filtered to protect sensitive information. |
| 5481 | + type: keyword |
| 5482 | + ignore_above: 1024 |
| 5483 | + description: 'Array of environment variable bindings. Captured from a snapshot of the environment at the time of execution. |
5485 | 5484 |
|
5486 | | - The field should not contain nested objects. All values should use `keyword`.' |
5487 | | - example: '{"USER": "elastic","LANG": "en_US.UTF-8","HOME": "/home/elastic"}' |
| 5485 | + May be filtered to protect sensitive information.' |
| 5486 | + example: '["PATH=/usr/local/bin:/usr/bin", "USER=ubuntu"]' |
5488 | 5487 | default_field: false |
5489 | 5488 | - name: executable |
5490 | 5489 | level: extended |
|
8534 | 8533 | level: extended |
8535 | 8534 | type: keyword |
8536 | 8535 | ignore_above: 1024 |
8537 | | - description: "Traffic Light Protocol sharing markings. Recommended values are:\n * WHITE\n * GREEN\n * AMBER\n * RED" |
8538 | | - example: White |
| 8536 | + description: Traffic Light Protocol sharing markings. |
| 8537 | + example: WHITE |
8539 | 8538 | default_field: false |
8540 | 8539 | - name: enrichments.indicator.modified_at |
8541 | 8540 | level: extended |
|
8631 | 8630 | level: extended |
8632 | 8631 | type: keyword |
8633 | 8632 | ignore_above: 1024 |
8634 | | - description: "Type of indicator as represented by Cyber Observable in STIX 2.0. Recommended values:\n * autonomous-system\n * artifact\n * directory\n * domain-name\n * email-addr\n * file\n * ipv4-addr\n * ipv6-addr\n * mac-addr\n * mutex\n * port\n * process\n * software\n * url\n * user-account\n * windows-registry-key\n * x509-certificate" |
| 8633 | + description: Type of indicator as represented by Cyber Observable in STIX 2.0. |
8635 | 8634 | example: ipv4-addr |
8636 | 8635 | default_field: false |
8637 | 8636 | - name: enrichments.indicator.url.domain |
|
8776 | 8775 | level: extended |
8777 | 8776 | type: keyword |
8778 | 8777 | ignore_above: 1024 |
8779 | | - description: List of country (C) codes |
| 8778 | + description: List of country \(C) codes |
8780 | 8779 | example: US |
8781 | 8780 | default_field: false |
8782 | 8781 | - name: enrichments.indicator.x509.issuer.distinguished_name |
|
8879 | 8878 | level: extended |
8880 | 8879 | type: keyword |
8881 | 8880 | ignore_above: 1024 |
8882 | | - description: List of country (C) code |
| 8881 | + description: List of country \(C) code |
8883 | 8882 | example: US |
8884 | 8883 | default_field: false |
8885 | 8884 | - name: enrichments.indicator.x509.subject.distinguished_name |
|
9012 | 9011 | level: extended |
9013 | 9012 | type: keyword |
9014 | 9013 | ignore_above: 1024 |
9015 | | - description: "Identifies the vendor-neutral confidence rating using the None/Low/Medium/High scale defined in Appendix A of the STIX 2.1 framework. Vendor-specific confidence scales may be added as custom fields.\nExpected values are:\n * Not Specified\n * None\n * Low\n * Medium\n * High" |
| 9014 | + description: Identifies the vendor-neutral confidence rating using the None/Low/Medium/High scale defined in Appendix A of the STIX 2.1 framework. Vendor-specific confidence scales may be added as custom fields. |
9016 | 9015 | example: Medium |
9017 | 9016 | default_field: false |
9018 | 9017 | - name: indicator.description |
|
9915 | 9914 | level: extended |
9916 | 9915 | type: keyword |
9917 | 9916 | ignore_above: 1024 |
9918 | | - description: "Traffic Light Protocol sharing markings.\nRecommended values are:\n * WHITE\n * GREEN\n * AMBER\n * RED" |
| 9917 | + description: Traffic Light Protocol sharing markings. |
9919 | 9918 | example: WHITE |
9920 | 9919 | default_field: false |
9921 | 9920 | - name: indicator.modified_at |
|
10012 | 10011 | level: extended |
10013 | 10012 | type: keyword |
10014 | 10013 | ignore_above: 1024 |
10015 | | - description: "Type of indicator as represented by Cyber Observable in STIX 2.0.\nRecommended values:\n * autonomous-system\n * artifact\n * directory\n * domain-name\n * email-addr\n * file\n * ipv4-addr\n * ipv6-addr\n * mac-addr\n * mutex\n * port\n * process\n * software\n * url\n * user-account\n * windows-registry-key\n * x509-certificate" |
| 10014 | + description: Type of indicator as represented by Cyber Observable in STIX 2.0. |
10016 | 10015 | example: ipv4-addr |
10017 | 10016 | default_field: false |
10018 | 10017 | - name: indicator.url.domain |
|
10157 | 10156 | level: extended |
10158 | 10157 | type: keyword |
10159 | 10158 | ignore_above: 1024 |
10160 | | - description: List of country (C) codes |
| 10159 | + description: List of country \(C) codes |
10161 | 10160 | example: US |
10162 | 10161 | default_field: false |
10163 | 10162 | - name: indicator.x509.issuer.distinguished_name |
|
10260 | 10259 | level: extended |
10261 | 10260 | type: keyword |
10262 | 10261 | ignore_above: 1024 |
10263 | | - description: List of country (C) code |
| 10262 | + description: List of country \(C) code |
10264 | 10263 | example: US |
10265 | 10264 | default_field: false |
10266 | 10265 | - name: indicator.x509.subject.distinguished_name |
|
10322 | 10321 | level: extended |
10323 | 10322 | type: keyword |
10324 | 10323 | ignore_above: 1024 |
10325 | | - description: "The platforms of the software used by this threat to conduct behavior commonly modeled using MITRE ATT&CK®.\nRecommended Values:\n * AWS\n * Azure\n * Azure AD\n * GCP\n * Linux\n * macOS\n * Network\n * Office 365\n * SaaS\n * Windows\n\nWhile not required, you can use a MITRE ATT&CK® software platforms." |
| 10324 | + description: "The platforms of the software used by this threat to conduct behavior commonly modeled using MITRE ATT&CK®.\nWhile not required, you can use MITRE ATT&CK® software platform values." |
10326 | 10325 | example: '[ "Windows" ]' |
10327 | 10326 | default_field: false |
10328 | 10327 | - name: software.reference |
|
10336 | 10335 | level: extended |
10337 | 10336 | type: keyword |
10338 | 10337 | ignore_above: 1024 |
10339 | | - description: "The type of software used by this threat to conduct behavior commonly modeled using MITRE ATT&CK®.\nRecommended values\n * Malware\n * Tool\n\n While not required, you can use a MITRE ATT&CK® software type." |
| 10338 | + description: "The type of software used by this threat to conduct behavior commonly modeled using MITRE ATT&CK®.\nWhile not required, you can use a MITRE ATT&CK® software type." |
10340 | 10339 | example: Tool |
10341 | 10340 | default_field: false |
10342 | 10341 | - name: tactic.id |
|
0 commit comments