Schema reference
Overview¶
This is the schema reference for the data returned by the SIEM v1 API in Sophos Fusion. The SIEM API powers the siem.py tool at https://github.com/sophos/Sophos-Central-SIEM-Integration.
Event schema¶
| Field | Type | Format | Description |
|---|---|---|---|
id | String | UUID | Event ID. |
customer_id | String | UUID | Customer ID. |
severity | String | Enum | Allowed values: NONE, LOW, MEDIUM, HIGH, CRITICAL. |
source | String | For endpoint events: "n/a" (for Windows Server), or user name (such as "John Smith"), or the login associated with the user "John-PC\Administrator". | |
source_info | Object | Source Info object (see below) | |
location | String | For most events, this is the computer/server/firewall host name where the event occurred. | |
when | String | Date-time | When the event was reported. |
created_at | String | Date-time | When the event record was created. |
name | String | Event description. | |
type | String | Event type. | |
user_id | String | Identifies the user related to the event. | |
threat | String | Threat correlation ID. | |
group | String | Enum | Event group. One of: AD_SYNC, APP_REPUTATION, APPLICATION_CONTROL, BLOCKLISTED, CONNECTIVITY, CREDENTIAL_MANAGER,CSWITCH, DATA_LOSS_PREVENTION, DENC, DOWNLOAD_REPUTATION, ENDPOINT_FIREWALL, FORENSIC_SNAPSHOT, GENERAL, ISOLATION, MALWARE, MDR, MOBILES, PERIPHERALS, POLICY, PROTECTION, PUA, RUNTIME_DETECTIONS, SECURITY, SYSTEM_HEALTH, UAV, UNCATEGORIZED, UPDATING, UTM, VIRT, WEB, WIRELESS, XGEMAIL, ZTNA_AUTHENTICATION, ZTNA_GATEWAY, ZTNA_RESOURCE. |
endpoint_type | String | Enum | Endpoint type. One of: mobile, computer, server, security_vm, sensor, utm, access_point, wireless_network, mailbox, slec, xgfirewall, ztna_gateway, nta_appliance. Present only if endpoint_id is also present. |
endpoint_id | String | UUID | Endpoint ID associated with the event. |
whitelist_properties | List of objects | Endpoint Whitelist object (see below) | |
details | List of objects | Event Details object (see below) | |
core_remedy_items | Object | Core Remedy Items object (see below) | This is set only for Endpoint Core Detection events (see below). |
origin | String | Enum | This is set only for Endpoint Core Detection events (see below). The possible values are: ML_MALWARE_DETECTION, VDL_MALWARE_DETECTION, ML_PUA_DETECTION, VDL_PUA_DETECTION, HMPA_DETECTION, MTD_DETECTION, HBT_DETECTION, SCAN_NOW, SCHEDULED_SCAN, REP_MALWARE_DETECTION, REP_PUA_DETECTION, BLOCKLISTED_BY_ADMIN, AMSI_DETECTION, IPS_DETECTION, BEHAVIORAL_DETECTION, DRIVER_BLOCKLIST. |
appSha256 | String | SHA256 | SHA 256 hash of the application associated with the threat, if available. This is set only for Endpoint Core Detection events (see below). |
appCerts | List of objects | Endpoint Core Event Certificate object (see below) | |
ips_threat_data | Object | IPS Threat Data object (see below) | IPS Threat data associated with the threat, if available. This is set only for Endpoint IPS Detection events. |
amsi_threat_data | Object | AMSI Threat Data object (see below) | AMSI Threat data associated with the threat, if available. This is set only for Endpoint AMSI events. |
Source Info object¶
| Field | Type | Format | Description |
|---|---|---|---|
ip | String | IP Address | Source IP address of the endpoint. |
detection_name | String | Detection name. Present only for MDR-related events. | |
case_id | String | MDR Case ID. Present only for MDR-related events. |
Endpoint Whitelist object¶
| Field | Type | Format | Description |
|---|---|---|---|
type | String | Enum | One of: SHA_256, CERTIFICATE_SIGNER, PATH, THUMBPRINT, PROCESS_NAME, MITIGATION, or DETECTION_KEY. |
property | String | String value of the type above. |
Event Details object¶
| Field | Type | Format | Description |
|---|---|---|---|
type | String | Enum | One of: CORE_EVENT_REQUEST_ID, CORE_EVENT_RESPONSE_STATUS, HMPA_EVENT_REPORT, HMPA_EVENT_TYPE, HMPA_PROCESS_VERSION, HMPA_PROCESS_PID, HMPA_PROCESS_PATH, HOME_FAMILY_ID, HOME_SCAN_LABEL, HOME_SCAN_STATE, HOME_SCAN_CLEAN, HOME_SCAN_REBOOT, HOME_COOKIES_COUNT, HOME_COOKIES_DOMAINS, HOME_REMNANT_FAMILY, HOME_REMNANT_NAME, HOME_REMNANT_PATHS, IPS_EXECUTABLE_PATH, IPS_EXECUTABLE_PID, IPS_EXECUTABLE_VERSION, IPS_EXECUTABLE_NAME, IPS_RAW_DATA, IPS_REMOTE_IP, IPS_REMOTE_PORT, IPS_LOCAL_PORT, IPS_TECH_SUPPORT_ID, AMSI_PROCESS_NAME, AMSI_PROCESS_ID, AMSI_PROCESS_PATH, AMSI_PARENT_PROCESS_ID, AMSI_PARENT_PROCESS_PATH, AMSI_THREAT_SUB_TYPE, CORE_BEHAVIORAL_DETECTION_REPORT_SOURCE, CORE_BEHAVIORAL_DETECTION_NAME, CORE_BEHAVIORAL_DETECTION_THUMBPRINT, CORE_BEHAVIORAL_PATH, CORE_APPLICATION_PATH, CORE_APPLICATION_SHA_256. |
property | String | String value of the type above. |
Core Remedy Items object¶
| Field | Type | Format | Description |
|---|---|---|---|
items | List of objects | Core Remedy Item object (see below) | |
totalItems | Integer | Total number of Core Remedy Item objects. |
Core Remedy Item object¶
| Field | Type | Format | Description |
|---|---|---|---|
type | String | Enum | One of: file, regkey, process, thread. |
result | String | Enum | One of: NOT_APPLICABLE, SUCCESS, NOT_FOUND, DELETED, FAILED_TO_DELETE, WHITELISTED, OTHER_ERROR, FAILED_TO_DELETE_SYSTEM_PROTECTED. |
suspendResult | String | Enum | One of: NOT_APPLICABLE, SUCCESS, SUSPEND_FAILED, PROTECTED, OTHER_ERROR. |
descriptor | String | Item descriptor. | |
processPath | String | Process path. | |
sophosPid | String | Sophos PID. |
Endpoint Core Event Certificate object¶
| Field | Type | Format | Description |
|---|---|---|---|
signer | String | Certificate signer. | |
thumbprint | String | Certificate thumbprint. |
IPS Threat Data object¶
| Field | Type | Format | Description |
|---|---|---|---|
techSupportId | String | Tech support ID. | |
executablePath | String | Executable path. | |
executableVersion | String | Executable version. | |
executablePid | String | Executable PID. | |
executableName | String | Executable name. | |
rawData | String | Raw data. | |
remoteIp | String | Remote IP. | |
remotePort | String | Remote port. | |
detectionType | Integer | 0 or 1 | 0 means inbound, 1 means outbound, null means both or neither, depending upon context. |
localPort | String | Local port. |
AMSI Threat Data object¶
| Field | Type | Format | Description |
|---|---|---|---|
processName | String | Process name. | |
processId | String | Process ID. | |
processPath | String | Process path. | |
parentProcessId | String | Parent process ID. | |
parentProcessPath | String | Parent process path. |
Event types¶
Endpoint Core Detection events have the type field set to one of:
Event::Endpoint::CoreAmsiBlockedEvent::Endpoint::CoreBehavioralDetectionEvent::Endpoint::CoreBlocklistDetectionEvent::Endpoint::CoreBlocklistRemoteDetectionEvent::Endpoint::CoreDetectionEvent::Endpoint::CorePuaDetectionEvent::Endpoint::CorePuaRemoteDetectionEvent::Endpoint::CoreRemoteDetectionEvent::Endpoint::Threat::IpsInboundDetectionEvent::Endpoint::Threat::IpsOutboundDetection
Alert Schema¶
| Field | Type | Format | Description |
|---|---|---|---|
id | String | UUID | Alert ID. |
type | String | Enum | The type attribute of the event from which the alert was created. |
data | Object | Alert Data object (see below) | Alert data. |
info | Object | Alert Info object (see below) | Alert info. |
source | String | The source attribute of the event from which the alert was created. | |
location | String | The location attribute of the event from which the alert was created. | |
when | String | Date-time | When the alert was reported (same as the when attribute of the underlying event), or when the alert became visible if reporting on it was initially deferred. |
created_at | String | Date-time | When the alert object was created. |
severity | String | Enum | The alert severity. One of: none, high, medium, low. |
customer_id | String | UUID | Customer ID. |
threat_cleanable | Boolean | Whether the threat is one that the Sophos endpoint agent is normally able to clean up. Present only for Endpoint events where there is an associated threat. | |
threat | String | Threat name. Present only for Endpoint events where there is an associated threat object. | |
description | String | Alert description. | |
event_service_event_id | String | UUID | Internal ID of the underlying event object. |
Alert Data object¶
| Field | Type | Format | Description |
|---|---|---|---|
endpoint_id | String | UUID | Endpoint UUID. |
endpoint_java_id | String | UUID | Endpoint UUID in the correct UUIDv4 string representation format rather than like endpoint_id, which has successive adjacent nibbles flipped. |
endpoint_type | String | Enum | Endpoint type. One of: mobile, computer, server, security_vm, sensor, utm, access_point, wireless_network, mailbox, slec, xgfirewall, ztna_gateway, nta_appliance. Present only if endpoint_id is also present. |
endpoint_platform | String | Enum | Endpoint platform. One of: unknown, windows, mac, utm, posix, chrome, ios, android, windowsphone, slec, sve, xgfirewall. Present only if endpoint_id is also present. |
policy_type | Integer | Policy type. One of: 0 (No/Invalid policy), 1 (Automatic Updates), 2 (Malware Protection), 7 (Application Control), 15 (Data Loss Prevention), 16 (Device Control), 19 (Tamper Protection), 22 (Web Control), 24 (Network Threat Protection), 25 (Communication Service), 26 (Lockdown), 27 (Heartbeat), 28 (Update Cache), 29 (Sophos Threat Analysis), 30 (Exploit Detection), 31 (Sophos Endpoint Defense), 32 (Sophos Agent UI), 33 (Endpoint Firewall), 34 (Sophos Home), 35 (Message Relay), 36 (CORe Endpoint Plugin), 37 (CORe Customer Plugin), 38 (Virtualisation), 39 (Mobile Security), 42 (Mobile Password Plugin), 43 (Mobile Restrictions Plugin), 44 (Mobile Exchange Plugin), 45 (Mobile WiFi Plugin), 46 (Mobile Compliance Plugin), 47 (Cloud Secure Gateway Plugin), 48 (Next Gen Web Control), 51 (Email Protection), 52 (File Integrity Monitoring), 53 (Email DLP Protection), 54 (Managed Endpoint Detection Response), 55 (MTR Essentials), 56 (Live Query), 57 (Zero Trust Network Access), 58 (Connect), 70 (Device Encryption), 80 (Wireless Control), 90 (Email Secure Message), 91 (Linux Runtime Detection). | |
threat_id | String | Threat ID. Present only for Endpoint Threat events. | |
device_id | String | Peripheral ID. | |
threat_status | String | Enum | Present only for Endpoint Threat events. One of: NONE, CLEANED_UP, CLEANUPABLE_NOT_SUPPORTED, NOT_CLEANUPABLE, FULL_SCAN_REQUIRED, CLEANUPABLE, CLEANUP_IN_PROGRESS, REBOOT_REQUIRED, CLEANUP_TIMED_OUT, CLEANUP_FAILED, OUTBREAK, DISMISSED |
source_info | Object | Same as the source_info attribute of the underlying event. | |
user_match_uuid | String | UUID | UUID of the user associated with the underlying event. Present only if the event also has an associated Windows Workgroup logon username. |
case_id | String | MDR Case ID. Present only for MDR Case Created event. | |
detection_name | String | Name of the detection that led to the MDR Case being created. Present only for MDR Case Created event. |
Alert Info object¶
| Field | Type | Format | Description |
|---|---|---|---|
threat_case_link_id | String | MDR Case ID. Same as the case_id attribute in the Alert Data object (above). |
CEF extensions to API response¶
When you use the siem.py script (see Github) to pull alerts and events from Sophos Fusion, you may notice a few additional fields in the objects in the response.
| Field | Type | Format | Description |
|---|---|---|---|
datastream | String | This has the value Alert or Event to distinguish between events and alerts. | |
rt | String | Timestamp | When an event is added/uploaded to Sophos Fusion. The Sophos endpoint agent may delay sending a new event to Sophos Fusion. For example, Web Control violation events may be batched and sent later while malware detection events are sent immediately. Another scenario this is different from the time of the event is when the device where the event happens is offline. The device in question sends such events to Sophos Fusion when it comes back online. Its value is the same as created_at in the JSON object, and its CEF equivalent is also created_at. |
end | String | Timestamp | When an event is created. This matches what you see in Sophos Fusion UI. Its value is the same as when in the JSON object, and its CEF equivalent is reported_at. |
dhost | String | Destination host. | |
suser | String | Name of user signed in at the time of the event. |
Glossary¶
| Acronym / Initialism | What it stands for |
|---|---|
AMSI | Microsoft Antimalware Scan Interface |
API | Application Programming Interface |
CEF | Common Event Format |
Enum | Enumeration |
HBT | Heartbeat |
HMPA | Sophos HitmanPro.Alert |
IPS | Intrusion Prevention System |
MDR | Managed Detection and Response |
ML | Machine Learning |
PID | Process ID |
PUA | Potentially Unwanted Application |
REP | Reputation |
SHA256 | Secure Hash Algorithm (256-bit) |
SIEM | Security Information and Event Management |
UTM | Unified Threat Management |
UUID | Universally Unique IDentifier |
VDL | Virus Definition Language |
ZTNA | Zero Trust Network Access |