Detections GraphQL API types
Every named type reachable from a query or mutation in this schema, grouped by kind.
Jump to: Objects · Interfaces · Enums · Unions · Input objects · Scalars
Objects
AccountCompromiseDetectorDetail
Fields
| Field | Type | Description |
user_name | String | |
AggregationKeys
Fields
| Field | Type | Description |
key | String! | |
value | String! | |
AggregationResponse
Fields
| Field | Type | Description |
key | String | DEPRECATED. Use keys instead Deprecated: use keys instead for the broken out name/value pairs. |
value | Float | |
keys | [AggregationKeys!] | |
Alert2
Base schema for an alert.
Implements: Node
Fields
| Field | Type | Description |
id | ID! | |
group_key | [String!] | Alert group key |
metadata | AlertsMetadata | Alert metadata |
visibility | Visibility | |
attack_technique_ids | [String!] | List of attack technique IDs |
tenant_id | String | Tenant ID associated with alert Deprecated: being replaced with Tenant field. |
tenant | TenantV4 | Tenant associated with alert |
parent_tenant_id | String | Parent Tenant ID of the tenant associated with this alert |
mdr_provider | String | MDR Provider for Tenant |
suppressed | Boolean | Was this rule suppressed. True or false |
suppression_rules | [AlertRuleReference!] | Suppression rules associated wiht alert |
alerting_rules | [AlertRuleReference!] | Rules associated with alert |
status | ResolutionStatus | Alert resolution status |
resolution_reason | String | Alert resolution reason |
resolution_history | [ResolutionMetadata!] | |
severity_history | [SeverityUpdate!] | |
tuning_history | [TuningUpdate!] | Tuning history will contain the rule id of the tuning rule, the field being tuned and the value it was tuned to. Tuning rules include suppression rules and can tune severity, origin, or suppress alerts. |
tags | [String!] | List of tags associated to alert |
sensor_types | [String!] | Sensor types associated with alert |
entities | EntityRelationships | All entities that are associated with an alert |
key_entities | [EntityMetadata!] | |
source_entities | [StructuredEntity!] | All source entities that are associated with an alert |
target_entities | [StructuredEntity!] | All target entities that are associated with an alert |
event_ids | [AuxiliaryEvent!] | All event IDs that are associated with an alert |
observation_ids | [Observation!] | All observation IDs that are associated with an alert |
investigation_ids | [Investigation!] | All investigation IDs that are associated with an alert |
collection_ids | [Collection!] | |
enrichment_details | [EnrichmentDetail!] | Specific detectors may provide additional context to explain why the alert triggered or information to help an analyst review the alert. |
third_party_details | [ThirdPartyDetail!] | Alert third party details |
reference_details | [ReferenceDetail!] | List of detailed alert references provided by detector or watchlist rule |
priority | AlertPriority | |
threat_score | Float32 | Threat score mappings for observations and alerts (OLD) |
threat_score_v2 | Float32 | Threat score mappings for alerts |
vids | [Int] | Vulnerability IDs associated with the alert |
events_metadata | AlertEventMetadata | |
observation | Boolean | True when severity is info, low or medium. False when severity is high or critical Deprecated: use threat_score_v2 value instead. |
AlertEventMetadata includes metadata about contributing events
Fields
| Field | Type | Description |
updated_at | Timestamp | The timestamp of this alert events metadata update |
began_at | Timestamp | The timestamp of the first event contributing to an alert; replaces metadata.began_at |
ended_at | Timestamp | The timestamp of the latest event contributing to an alert; replaces metadata.ended_at |
first_event_id | String | The first event_id contributing to an alert |
last_event_id | String | The most recent event_id contributing to an alert |
total_events | Int | The total number of events contributing to an alert |
AlertPriority
Fields
| Field | Type | Description |
value | Float | |
prioritizer | String | |
version | String | |
model_name | String | |
model_version | String | |
evidence | [String!] | |
applied_time | Timestamp | |
AlertRuleReference
Fields
| Field | Type | Description |
id | String | |
version | String | |
AlertsAggregateResponse
Fields
AlertsAggregateResponse_AlertsAggregation
Fields
AlertsAggregateResponse_AlertsAggregation_Severity
Fields
| Field | Type | Description |
info | Int | |
low | Int | |
medium | Int | |
high | Int | |
critical | Int | |
AlertsCountByTenantResponse
Fields
AlertsCountByTenantResponseItem
Fields
| Field | Type | Description |
count | Int! | Number of alerts for this tenant |
tenant | TenantV4! | |
AlertsInvestigationInfo
Fields
| Field | Type | Description |
alert_resource_id | String | |
initial_access_vector_info | [InitialAccessVectorInfo!] | Deprecated: data no longer exists. |
AlertsList
List of alerts and associated request metadata.
Fields
| Field | Type | Description |
list | [Alert2!] | List of Alert types |
total_results | Int | Total results available for request |
next_offset | Int | |
previous_offset | Int | |
last_offset | Int | |
first_offset | Int | |
total_parts | Int | Total parts of the result set |
part | Int | Part number of returned result set |
group_by | [AggregationResponse!] | Aggregation response, if the initial request included an aggregation |
Alert metadata information
Fields
| Field | Type | Description |
creator | Creator | Alert creator |
engine | Engine | Alert engine |
severity | Float32 | Alert severity - can be from 0 - 1 |
severity_updated_at | Timestamp | |
confidence | Float32 | Alert confidence - can be from 0 - 1 |
title | String | Alert title - limit of 1024 characters, may be automatically truncated |
full_title | String | If the Alert title is truncated, the complete title. Otherwise empty. |
description | String | Alert description |
descriptions | [Description] | Translated descriptions |
began_at | Timestamp | When the behavior associated with the alert began at |
ended_at | Timestamp | When the behavior associated with the alert ended at |
created_at | Timestamp | When the alert was created |
inserted_at | Timestamp | When the alert was inserted into the database; this should be very close in time to created_at |
updated_at | Timestamp | Last time alert was updated; feedback, investigations |
first_seen_at | Timestamp | When the events triggering the alert were first seen. This is set by specific ingests based on data provided by the data source. |
first_investigated_at | Timestamp | When the alert first had an investigation associated with it |
first_resolved_at | Timestamp | When the alert was first resolved |
origin | Origin | Who created the event which generated this alert |
read_only | Boolean | Whether the alert is read only or not |
AlertsResponse
Fields
| Field | Type | Description |
status | RPCResponseStatus | |
reason | String | |
alerts | AlertsList | |
search_id | String | Search ID can be used to request additional parts for search results containing more than 10k requested results |
queryId | String | Is the unique identifier within the search system for the query that generated this response |
AuthScanDetail
Fields
AuthScanLogonAttempt
Fields
| Field | Type | Description |
target_user_name | String | User attempting login |
has_logon_success | Boolean | DEPRECATED. See list in successful_logon_attempts Deprecated: see list in successful_logon_attempts. |
num_attempts | Int | Number of login attempts |
AuxiliaryEvent
Used by Nautilus to resolve the Red Cloak TDR asset model.
Implements: Node
Fields
| Field | Type | Description |
id | ID! | |
BruteForceAuth
Fields
| Field | Type | Description |
win_event_id | String | |
action | String | |
domain | String | |
target_username | String | |
event_timestamp | Int | |
resource_record_identifier | String | |
BruteForceDetails
Fields
BulkInvestigationsResponse
Fields
BusinessEmailCompromiseDetail
Fields
| Field | Type | Description |
source_address | String | |
source_address_geo_summary | GeoSummary | |
user_name | String | |
Collection
Used by Nautilus to resolve the Red Cloak TDR asset model.
Implements: Node
Fields
| Field | Type | Description |
id | ID! | |
CreationRule
Fields
| Field | Type | Description |
rule_id | String | |
version | String | |
Creator
The Detector that created the alert.
Fields
DDosIpAddressOccurrenceCount
Fields
| Field | Type | Description |
ip_address | String | |
count | Int | |
DDosIpCount
Fields
| Field | Type | Description |
date | Timestamp | |
count | Int | |
DDosSourceIpCountDetail
Fields
| Field | Type | Description |
hour_partition | String | Detector compares historical netflow data occuring within this hour. |
sensor_id | String | ID of Sensor providing netflow data. |
host_id | String | Endpoint Host ID |
event_observable_count | Int | The number of unique source IPs observed in the device's network connections in the current hour. |
event_observable_count_std_dev | Float | A comparison of the current count of unique source IPs to the Base Mean. |
baseline_observable_count_std_dev | Float | The variability, or spread, of the number of unique source IPs for this reporting device. A low standard deviation means the count of unique sources is consistent over time (a tall bell curve). A high standard deviation means the count varies greatly over time (a short bell curve). |
baseline_observable_count_mean | Float | The average number of unique source IPs, counted on an hourly basis, observed in the historical data for this reporting device. |
baseline_observable_count_median | Int | The midpoint value for the range of unique source IPs counted in the historical data for this reporting device. |
baseline_num_days | Int | The number of historical days considered in this alert. Days in which the device did not report connections are not included. |
analytic_observable_std_dev_threshold | Float | The minimum value for Standard Deviation Above Mean, which must be at least the value of the Standard Deviation Threshold in order to trigger an alert. |
analytic_observable_min_count | Int | The minimum number of unique source IPs that must be observed in the current hour in order to trigger an alert. Source IP Addresses is always at least this number. |
analytic_time_threshold | Int | Threshold time limit for detector to observe netflow activity. |
historical_ip_counts | [DDosIpCount!] | Historical count of unique source IPs per hour window. |
top_destination_ips | [DDosIpAddressOccurrenceCount!] | Top Destination IPs by occurence. |
Description
Fields
| Field | Type | Description |
locale | Locale | Locale for language description is in |
description | String | Translated description |
Detector
Information about the Detector that is associated with alert.
Fields
| Field | Type | Description |
detector_id | String | |
detector_name | String | |
version | String | |
DnsExfilEnrichment
Fields
| Field | Type | Description |
num_queries | Int | Estimated count of the number of DNS requests made by the host. |
Engine
Alert engine
Fields
| Field | Type | Description |
name | String | |
version | String | |
EnrichmentDetail
Specific detectors can provide additional context to help explain why it generated to alert or information to help an analyst review the alert.
Fields
EntityApplication
Fields
| Field | Type | Description |
property_type | String | |
app_id | String | |
app_name | String | |
app_type | String | |
app_vendor | String | |
app_version | String | |
file_path | String | |
full_url | String | |
EntityAuthDomain
Fields
| Field | Type | Description |
property_type | String | |
auth_domain | String | |
EntityCertificate
Fields
| Field | Type | Description |
property_type | String | |
cert_issuer | String | |
cert_serial_number | String | |
cert_issuer_c | String | |
cert_issuer_cn | String | |
cert_issuer_e | String | |
cert_issuer_l | String | |
cert_issuer_o | String | |
cert_issuer_order | String | |
cert_issuer_ou | String | |
cert_issuer_s | String | |
cert_ja3 | String | |
cert_ja3s | String | |
cert_subject | String | |
cert_subject_c | String | |
cert_subject_cn | String | |
cert_subject_e | String | |
cert_subject_l | String | |
cert_subject_o | String | |
cert_subject_order | String | |
cert_subject_ou | String | |
cert_subject_s | String | |
cert_valid_from | String | |
cert_valid_through | String | |
EntityCloudObject
Fields
| Field | Type | Description |
property_type | String | |
cloud_object_bucket | String | |
cloud_object_key | String | |
cloud_object_prefix | String | |
EntityCloudResource
Fields
| Field | Type | Description |
property_type | String | |
cloud_resource_account_id | String | |
cloud_resource_id | String | |
cloud_resource_type | String | |
EntityCloudUser
Fields
| Field | Type | Description |
property_type | String | |
cloud_user_id | String | |
cloud_user_name | String | |
cloud_user_type | String | |
EntityDnsServer
Fields
| Field | Type | Description |
property_type | String | |
host_id | String | |
ip_address | String | |
ip_address_type | String | |
ip_classification | String | |
EntityDomainName
Fields
| Field | Type | Description |
property_type | String | |
domain_name | String | |
threat_intel_hits_csv | String | |
threat_intel_score | Float | |
threat_intel_updated_at_usec | Int64 | |
EntityEmail
Fields
| Field | Type | Description |
property_type | String | |
email_message_id | String | |
email_message_size | Int | |
email_quarantine_reason | String | |
reply_to_email_address | String | |
vendor_alert_url | String | |
vendor_email_spam_score | Int | |
EntityEmailAddress
Fields
| Field | Type | Description |
property_type | String | |
email_address | String | |
EntityFile
Fields
| Field | Type | Description |
property_type | String | |
file_name | String | |
file_path | String | |
host_id | String | |
email_attachment_sandbox_status | String | |
file_create_time | Int | |
file_group_owner | String | |
file_modified_time | Int | |
file_owner | String | |
file_size | Int | |
file_type | String | |
file_type_detected | String | |
hash_md5 | String | |
hash_sha1 | String | |
hash_sha256 | String | |
hash_sha512 | String | |
email_message_id | String | |
EntityFileHash
Fields
| Field | Type | Description |
property_type | String | |
hash_type | String | |
hash_value | String | |
threat_intel_hits_csv | String | |
threat_intel_score | Float | |
threat_intel_updated_at_usec | Int64 | |
EntityFunction
Fields
| Field | Type | Description |
property_type | String | |
function_name | String | |
host_id | String | |
EntityHost
Fields
| Field | Type | Description |
property_type | String | |
computer_name | String | |
host_id | String | |
hostname | String | |
hostname_fqdn | String | |
mac_address | String | |
os | String | |
os_arch | String | |
sensor_id | String | |
sensor_type | String | |
serial_number | String | |
system_type | String | |
vendor_agent_device_id | String | |
vendor_agent_device_score | Int | |
EntityIpAddress
Fields
| Field | Type | Description |
property_type | String | |
host_id | String | |
ip_address | String | |
asn | Int | |
hostname | String | |
ip_address_type | String | |
ip_classification | String | |
is_nat_ip | Boolean | |
ip_geo_auto_system_org | String | |
ip_geo_city_name | String | |
ip_geo_continent_code | String | |
ip_geo_country_code | String | |
ip_geo_country_geoname_id | Int | |
ip_geo_hash | String | |
ip_geo_latitude | Float | |
ip_geo_longitude | Float | |
threat_intel_hits_csv | String | |
threat_intel_score | Float | |
threat_intel_updated_at_usec | Int64 | |
Fields
| Field | Type | Description |
entity | String | |
label | String | |
EntityProcess
Fields
| Field | Type | Description |
property_type | String | |
process_correlation_id | String | |
process_id | String | |
process_name | String | |
process_uuid | String | |
host_id | String | |
process_create_time | Int | |
process_image_path | String | |
process_is_admin | Boolean | |
hash_md5 | String | |
hash_sha1 | String | |
hash_sha256 | String | |
hash_sha512 | String | |
EntityRegistryKey
Fields
| Field | Type | Description |
property_type | String | |
host_id | String | |
registry_path | String | |
EntityRelationships
List of Entity Relationships extracted from the alert's associated events.
Fields
| Field | Type | Description |
entities | [String!] | List of entities. Entities are formatted as <type>:<value>. |
relationships | [Relationship!] | How entities are related based on events associated to the alert. |
EntityScheduledTask
Fields
| Field | Type | Description |
property_type | String | |
host_id | String | |
task_name | String | |
EntityScript
Fields
| Field | Type | Description |
property_type | String | |
hash_value | String | |
host_id | String | |
script_name | String | |
interpreter | String | |
is_truncated | Boolean | |
EntityService
Fields
| Field | Type | Description |
property_type | String | |
host_id | String | |
service_dll | String | |
service_main | String | |
service_name | String | |
service_start_type | Int | |
service_type | Int | |
EntityTaskAction
Fields
| Field | Type | Description |
property_type | String | |
host_id | String | |
task_action_id | String | |
task_action_path | String | |
task_action_args | String | |
task_action_class_id | String | |
task_action_type | String | |
task_action_working_directory | String | |
EntityUrl
Fields
| Field | Type | Description |
property_type | String | |
full_url | String | |
uri_scheme | String | |
uri_host | String | |
uri_path | String | |
uri_query | String | |
uri_fragment | String | |
uri_port | String | |
uri_userinfo | String | |
EntityUser
Fields
| Field | Type | Description |
property_type | String | |
auth_domain | String | |
computer_name | String | |
domain_name | String | |
group | String | |
host_id | String | |
user_id | String | |
user_name | String | |
cloud_user_type | String | |
original_user_name | String | |
user_is_admin | Boolean | |
identity_types_csv | String | |
EvictResponse
Response from an alertsServiceEvict mutation.
Fields
FileAnalysisDetail
Fields
GenericDetail
Fields
| Field | Type | Description |
name | String | External source providing this data. |
generic | KeyValuePairsIndexed | Key value pairs that were indexed. |
GeoSummary
Fields
GeoSummary_ASN
Fields
| Field | Type | Description |
autonomous_system_no | Int | |
autonomous_system_org | String | |
GeoSummary_City
Fields
GeoSummary_Continent
Fields
| Field | Type | Description |
geoname_id | Int | |
code | String | |
GeoSummary_Country
Fields
| Field | Type | Description |
geoname_id | Int | |
iso_code | String | |
code | String | |
confidence | Int | |
GeoSummary_Location
Fields
| Field | Type | Description |
radius | Int | |
latitude | Float | |
longitude | Float | |
us_metro_code | Int | |
timezone | String | |
gmt_offset | Int | |
metro_code | Int | |
GeographicIp
IP Address Geolocation data. This is populated at time of alert generation.
Fields
| Field | Type | Description |
ip_address | String | |
latitude | Float | Relative Geographic Latitude of IP Address. |
longitude | Float | Relative Geographic Longitude of IP Address. |
radius | Float | IP Address Geolocation Accurate within this radius of the lat/long. |
geohash | String | https://en.wikipedia.org/wiki/Geohash. |
country_code_iso | String | Country ISO code of the Geolocation. |
asn | Int | Autonomous System Number of IP Address. |
HandsOnKeyboardDetails
Fields
| Field | Type | Description |
matched_process | [HandsOnKeyboardDetails_MatchedProcess!] | |
total_num_events | Int | |
matched_num_events | Int | |
num_admin_events | Int | |
common_parent_image_path | String | |
host_id | String | |
username | String | |
HandsOnKeyboardDetails_Commandline
Fields
| Field | Type | Description |
commandline | String | |
matched_features | [String!] | |
HandsOnKeyboardDetails_Image
Fields
| Field | Type | Description |
image_path | String | |
matched_features | [String!] | |
HandsOnKeyboardDetails_MatchedProcess
Fields
ImprobableLogonDetail
Fields
InitialAccessVectorInfo
Fields
| Field | Type | Description |
created_at | Timestamp | |
updated_at | Timestamp | |
investigation_ids | String | |
tenant_id | String | |
name | String | |
Investigation
Used by Nautilus to resolve the Red Cloak TDR asset model.
Implements: Node
Fields
| Field | Type | Description |
id | ID! | |
GenesisAlertsFlag | String | Deprecated: not in use anymore. |
Kerberoasting
Fields
| Field | Type | Description |
user | String | User perpetrating the kerberoasting attack. This is the username performing the requests. |
user_baseline | Int | Number of days where the user made weakly encrypted (RC4, etc.) Ticket Granting Service (TGS) requests. |
user_avg_requests | Float | The average daily number of weakly encrypted Ticket Granting Service Requests this user generated in their baseline profile. |
user_max_requests | Int | The maximum daily number of weakly encrypted Ticket Granting Service Requests this user generated in their baseline profile. |
total_spns | Int | Total number of Service Principal Names found in the tenant's historical data. |
suspicious_num_requests | Int | Count of weakly encrypted Ticket Granting Service Requests made by the user. |
percentage_accessed | Float | The percentage of the tenant's total Service Principal Names that were accessed during the suspicious session. |
spns_accessed | [String!] | The list of exact names of the Service Principal Names that were accessed during the suspicious session. |
source_address | String | TGS service tickets requested by this IP Address. |
hostname | String | The Kerberos Key Distribution Center (KDC) which validates the user's authentication request (the 4769 call). |
KeyAndValues
Fields
| Field | Type | Description |
key | String | |
values | [String!] | |
KeyValuePairsIndexed
Fields
KeyValueRecordIndexed
Fields
| Field | Type | Description |
key | String | |
value | String | |
LoginFailureDetail
Fields
| Field | Type | Description |
host | String | Host causing authentication failures. |
user | String | User authentication failures are occurring against. |
source_address | String | Source IP Address that authentication attempts are originating from. |
target_address | String | Destination IP Address that authentication attempts are being sent to. |
successful_auth_event | String | Reference ID to sample of successful authentication. |
failed_auth_event | String | Reference ID to sample of failed authentication. |
LogonAnomaly
Fields
| Field | Type | Description |
feature_value | String | |
feature_frequency_in_org | Float | |
feature_frequency_in_user | Float | |
approximate_count_in_user | Int | |
min_allowed_user_percentage | Float | |
min_allowed_org_percentage | Float | |
MatchDetails
Fields
| Field | Type | Description |
list_name | String | IOC List Name |
reason | String | Details about the IOC List. |
attacks | [String!] | MITRE ATT&CK Techniques associated with list. |
MatchedYaraRule
Fields
| Field | Type | Description |
rule_name | String | |
rule_description | String | |
classification | String | |
confidence | Float32 | |
severity | Float32 | |
rule_created_date | Timestamp | |
attack_technique_ids | [String!] | |
vid | String | |
MitreAttackDetails
Details for the Mitre ATT&CK technique associated with the alert.
Fields
| Field | Type | Description |
technique_id | String | |
technique | String | |
tactics | [String!] | |
type | String | |
description | String | |
platform | [String!] | |
system_requirements | [String!] | |
url | String | |
data_sources | [String!] | |
defence_bypassed | [String!] | |
contributors | [String!] | |
version | String | |
NetworkConnection
Fields
| Field | Type | Description |
source_ip | String | |
destination_ip | String | |
Observation
Used by Nautilus to resolve the Red Cloak TDR asset model.
Implements: Node
Fields
| Field | Type | Description |
id | ID! | |
PasswordSprayAffectedUser
Fields
| Field | Type | Description |
target_user_name | String | |
target_domain_name | String | |
user_had_auth_success | Boolean | |
PasswordSprayDetail
Fields
| Field | Type | Description |
source_address | String | IP Address performing authentication attempts. |
num_auth_failures | Int | Count of authentication failures observed. |
num_auth_successes | Int | Count of successful authentications observed. |
all_affected_users | [PasswordSprayAffectedUser!] | List of usernames with failed or successful logins. |
RareProgramRareIpDetail
Fields
| Field | Type | Description |
host | String | Host executing observed programs and connections. |
programs | [String!] | List of rare programs. |
connections | [NetworkConnection!] | List of rare network connections. Note that network connections are not explicitly correlated to the rare program executed. |
Reference
Fields
| Field | Type | Description |
type | String | |
url | String | |
description | String | |
ReferenceDetail
Fields
Relationship
Relationships between entities contained in the alert.
Fields
| Field | Type | Description |
from_entity | String | |
to_entity | String | |
relationship | String | |
type | String | |
Fields
| Field | Type | Description |
id | String | |
user_id | String | Legacy user ID |
timestamp | Timestamp | |
status | ResolutionStatus | |
reason | String | |
num_alerts_affected | Int | |
uuid_user_id | String | Provider independent user ID |
SeverityUpdate
Fields
StolenCredsTravelFeatures
Travel features for Stolen Credentials Detector.
Fields
| Field | Type | Description |
accurate_geo | Boolean | Geolocation data is considered accurate. |
foreign_travel | Boolean | Did this travel cross international borders? |
long_distance_travel | Boolean | Did this travel occur over a long distance? |
travel_hours | Float | How many travel hours occurred between the two login locations. |
travel_km_min | Float | Minimum distance travelled between two points, and the radius of accuracy from geolocation data (GeographicIp.radius) is used to calculate this distance. |
travel_km_h_min | Float | Travel speed in km/hr. Min here denotes the speed calculated based on minimum distance; based on the radius of accuracy from geolocation data (GeographicIp.radius). |
travel_speed_impossible | Boolean | Is the travel speed impossible? |
username | String | The user who logged in from both locations. |
current_location | GeographicIp | Second location user logged in from. The user travelled to this location. |
prior_location | GeographicIp | First location user logged in from. The user travels from this location. |
StolenCredsTrustFeatures
Trust features for Stolen Credentials Detector. These are used to set priority of the alert.
Fields
| Field | Type | Description |
network_unknown_asn | Boolean | When true, the detector has not seen this ASN before across all tenants. |
network_unknown_ip | Boolean | When true, the detector has not seen this IP before across all tenants. |
user_unknown_ip | Boolean | When true, the detector has not seen this IP before for this username. |
user_unknown_asn | Boolean | When true, the detector has not seen this ASN before for this username. |
prior_event_time_sec | Int | Login time in seconds for the first login. |
current_event_time_sec | Int | Login time in seconds for the second login. |
prior_event_id | String | Reference ID of the first login. |
current_event_id | String | Reference ID of the second login. |
username | String | The user who logged in from both locations. |
location | GeographicIp | Geographic location of the second login. |
StructuredEntity
Fields
| Field | Type | Description |
id | String! | |
perspective | EntityPerspective! | |
identifiers | [String!]! | |
properties | Properties! | |
display_name | String! | |
subtype | String! | |
TacticGraphDetail
Details from Tactic Graphs Detector. This contains the tactic observed and the related events it was observed in.
Fields
TenantV4
Implements: Node
Fields
| Field | Type | Description |
id | ID! | |
ThirdPartyDetail
Available third party details of alert.
Fields
Timestamp
Fields
| Field | Type | Description |
seconds | Int! | |
nanos | Int! | |
TuningUpdate
Fields
| Field | Type | Description |
id | String | |
field_name | String | |
severity_value | Float32 | |
origin_value | Origin | |
suppressed_value | Boolean | |
changed_at | Timestamp | |
UpdateInvestigationResponse
Internal Type
Fields
UpdateResolutionResponse
Response for an alertsServiceUpdateResolutionInfo mutation.
Fields
UpdateThreatScoreResponse
Fields
UserLogonBaseline
Fields
| Field | Type | Description |
feature_value | String | |
feature_frequency_in_org | Float | |
feature_frequency_in_user | Float | |
approximate_count_in_user | Int | |
days_in_baseline | Int | Number of days baseline was established |
WatchlistMatches
Details about the watchlist that produced the alert.
Fields
| Field | Type | Description |
entity | String | Entity matching the Indicator of Compromise. |
details | [MatchDetails!] | IOC Watchlist details. |
WhoisSimple
Domain WHOIS Information
Fields
| Field | Type | Description |
domainName | String | WHOIS information was fetched for this domain. |
registrarName | String | |
contactEmail | String | |
whoisServer | String | |
nameServers | String | |
createdDate | String | |
updatedDate | String | |
expiresDate | String | |
standardRegCreatedDate | String | |
standardRegUpdatedDate | String | |
standardRegExpiresDate | String | |
status | String | |
Audit_auditUpdatedDate | String | |
registrant_email | String | |
registrant_name | String | |
registrant_organization | String | |
registrant_street1 | String | |
registrant_street2 | String | |
registrant_street3 | String | |
registrant_street4 | String | |
registrant_city | String | |
registrant_state | String | |
registrant_postalCode | String | |
registrant_country | String | |
registrant_fax | String | |
registrant_faxExt | String | |
registrant_telephone | String | |
registrant_telephoneExt | String | |
administrativeContact_email | String | |
administrativeContact_name | String | |
administrativeContact_organization | String | |
administrativeContact_street1 | String | |
administrativeContact_street2 | String | |
administrativeContact_street3 | String | |
administrativeContact_street4 | String | |
administrativeContact_city | String | |
administrativeContact_state | String | |
administrativeContact_postalCode | String | |
administrativeContact_country | String | |
administrativeContact_fax | String | |
administrativeContact_faxExt | String | |
administrativeContact_telephone | String | |
administrativeContact_telephoneExt | String | |
reg_created_date_usec | Int | |
reg_updated_date_usec | Int | |
reg_expires_date_usec | Int | |
Interfaces
Node
Fields
| Field | Type | Description |
id | ID! | |
Enums
Fields that can be grouped by in an AggregateAlertsBySeverity query.
Values
| Value | Description |
DOMAIN | |
WATCHLIST | |
HOSTNAME | |
DETECTOR | |
USER | |
AlertsSeverity
Enum of alert severity levels.
Values
| Value | Description |
INFO | |
LOW | |
MEDIUM | |
HIGH | |
CRITICAL | |
Internal Type
Values
| Value | Description |
UNKNOWN | |
ALERTS_V1 | |
ALERTS_V2 | |
EntityPerspective
Perspective of the entity
Values
| Value | Description |
UNKNOWN | |
SOURCE | |
TARGET | |
BOUNDARY | |
BOTH | |
ImprobableLogonDetail_FeatureName
Values
| Value | Description |
UNKNOWN | |
COUNTRY | |
CITY | |
ASN | |
InvestigationOperation
Type of investigation operation; either update or delete.
Values
| Value | Description |
UPDATE | |
DELETE | |
Locale
Supported locales for translated descriptions
Values
| Value | Description |
en | |
fr | |
de | |
pt | |
ko | |
ja | |
it | |
es | |
zh_CN | |
zh_TW | |
Origin
Alert origin
Values
| Value | Description |
INTERNAL | |
CUSTOMER | |
EXTERNAL | |
PARTNER | |
RPCResponseStatus
Internal Type
Values
| Value | Description |
OK | |
INVALID_REQUEST | |
TRANSACTION_ERROR | |
ResolutionStatus
Enum of alert resolution statuses.
Values
| Value | Description |
OPEN | |
TRUE_POSITIVE_BENIGN | |
TRUE_POSITIVE_MALICIOUS | |
FALSE_POSITIVE | |
NOT_ACTIONABLE | |
OTHER | |
SUPPRESSED | |
AUTO_CLOSE | |
DISMISSED | |
ResponseStatus
Status of alerts operations.
Values
| Value | Description |
SUCCESS | |
FAILED | |
Visibility
Values
| Value | Description |
DEPLOYED | |
RESEARCH | |
Unions
Properties
Possible types
Fields
Fields
| Field | Type | Description |
ql_query | String! | Taegis Query Language (QL) query |
tenant_service_filters | [String!] | Filters alerts on tenants that have the specified services. The tenants scope comprises the one specified in the X-Tenant-Context header and its children. |
Fields
| Field | Type | Description |
query | String | Taegis XDR Query Language query |
investigation_id | String | |
genesis_alerts | [String!] | DEPRECATED: Used to flag specific alerts as the genesis of the investigation. Deprecated: used to flag specific alerts as the genesis of the investigation. |
alerts | [String!] | List of Alert IDs |
tenant | String | |
Fields
| Field | Type | Description |
search_id | String | |
Fields
| Field | Type | Description |
iDs | [String!] | |
Fields
| Field | Type | Description |
search_id | String | |
part_id | Int | DEPRECATED: part id is advanced transparently with each new call. not needed. Deprecated: part id is advanced transparently with each new call now. |
Fields
| Field | Type | Description |
cql_query | String | Taegis XDR Query Language query |
offset | Int | Result set returned from this offset + limit requested. If your query has 500 total_results and you want the last 100; use offset:400 limit:100 |
limit | Int | Result set limit. Note: limits larger than 10000 are broken into multiple parts. Additional parts can be fetched by search_id. |
search_id | String | Next page reference returned with the last search response. If this is passed, offset and limit are ignored. Preferred way to paginate over large result sets as it is faster and more consistent. |
metadata | Map | Allows the caller to include metadata that is stored with the received query. |
tenant_service_filters | [String!] | Filters alerts on tenants that have the specified services. The tenants scope comprises the one specified in the X-Tenant-Context header and its children. |
locale | Locale | The locale for what language descriptions and text based fields should be retrieved for |
Fields
| Field | Type | Description |
seconds | Int | Epoch Time in seconds |
nanos | Int | Epoch Time in nano-seconds |
Fields
| Field | Type | Description |
investigation_id | String | |
genesis_alerts | [String!] | DEPRECATED: was used to flag specific alerts as the genesis of the investigation. Deprecated: was used to flag specific alerts as the genesis of the investigation. |
alerts | [String!] | |
tenant | String | |
operation | InvestigationOperation | |
caller | CallerInformation | |
requested_at | TimestampInput | |
user_id | String | Legacy user ID |
uuid_user_id | String | Provider independent user ID |
Fields
| Field | Type | Description |
alert_ids | [String!] | |
resolution_status | ResolutionStatus | |
reason | String | |
caller | CallerInformation | |
requested_at | TimestampInput | |
user_id | String | Legacy user ID |
uuid_user_id | String | Provider independent user ID |
tenant | String | |
UpdateThreatScoreEntry
Fields
| Field | Type | Description |
alert_id | String! | |
threat_score | Float32 | Optional. Overrides the threat score to update for this one alert only. Will automatically adjust threat_score_v2 |
Fields
| Field | Type | Description |
alert_ids | [UpdateThreatScoreEntry!]! | |
threat_score | Float32 | Default threat score to apply to the given alerts. Will automatically adjust threat_score_v2 |
UpdateThreatScoreV2Entry
Fields
| Field | Type | Description |
alert_id | String! | |
threat_score_v2 | Float32 | Optional. Overrides the adjusted threat score to update for this one alert only. Will automatically adjust threat_score |
Fields
| Field | Type | Description |
alert_ids | [UpdateThreatScoreV2Entry!]! | |
threat_score_v2 | Float32 | Default adjusted threat score to apply to the given alerts. Will automatically adjust threat_score |
Scalars
Float32
Int64
Map