Skip to content

Schema reference

Overview

This is the schema reference for the data returned by the SIEM v1 API in Sophos Fusion. The SIEM API powers the siem.py tool at https://github.com/sophos/Sophos-Central-SIEM-Integration.

Event schema

Field Type Format Description
id String UUID Event ID.
customer_id String UUID Customer ID.
severity String Enum Allowed values: NONE, LOW, MEDIUM, HIGH, CRITICAL.
source String For endpoint events: "n/a" (for Windows Server), or user name (such as "John Smith"), or the login associated with the user "John-PC\Administrator".
source_info Object Source Info object (see below)
location String For most events, this is the computer/server/firewall host name where the event occurred.
when String Date-time When the event was reported.
created_at String Date-time When the event record was created.
name String Event description.
type String Event type.
user_id String Identifies the user related to the event.
threat String Threat correlation ID.
group String Enum Event group. One of: AD_SYNC, APP_REPUTATION, APPLICATION_CONTROL, BLOCKLISTED, CONNECTIVITY, CREDENTIAL_MANAGER,CSWITCH, DATA_LOSS_PREVENTION, DENC, DOWNLOAD_REPUTATION, ENDPOINT_FIREWALL, FORENSIC_SNAPSHOT, GENERAL, ISOLATION, MALWARE, MDR, MOBILES, PERIPHERALS, POLICY, PROTECTION, PUA, RUNTIME_DETECTIONS, SECURITY, SYSTEM_HEALTH, UAV, UNCATEGORIZED, UPDATING, UTM, VIRT, WEB, WIRELESS, XGEMAIL, ZTNA_AUTHENTICATION, ZTNA_GATEWAY, ZTNA_RESOURCE.
endpoint_type String Enum Endpoint type. One of: mobile, computer, server, security_vm, sensor, utm, access_point, wireless_network, mailbox, slec, xgfirewall, ztna_gateway, nta_appliance. Present only if endpoint_id is also present.
endpoint_id String UUID Endpoint ID associated with the event.
whitelist_properties List of objects Endpoint Whitelist object (see below)
details List of objects Event Details object (see below)
core_remedy_items Object Core Remedy Items object (see below) This is set only for Endpoint Core Detection events (see below).
origin String Enum This is set only for Endpoint Core Detection events (see below). The possible values are: ML_MALWARE_DETECTION, VDL_MALWARE_DETECTION, ML_PUA_DETECTION, VDL_PUA_DETECTION, HMPA_DETECTION, MTD_DETECTION, HBT_DETECTION, SCAN_NOW, SCHEDULED_SCAN, REP_MALWARE_DETECTION, REP_PUA_DETECTION, BLOCKLISTED_BY_ADMIN, AMSI_DETECTION, IPS_DETECTION, BEHAVIORAL_DETECTION, DRIVER_BLOCKLIST.
appSha256 String SHA256 SHA 256 hash of the application associated with the threat, if available. This is set only for Endpoint Core Detection events (see below).
appCerts List of objects Endpoint Core Event Certificate object (see below)
ips_threat_data Object IPS Threat Data object (see below) IPS Threat data associated with the threat, if available. This is set only for Endpoint IPS Detection events.
amsi_threat_data Object AMSI Threat Data object (see below) AMSI Threat data associated with the threat, if available. This is set only for Endpoint AMSI events.

Source Info object

Field Type Format Description
ip String IP Address Source IP address of the endpoint.
detection_name String Detection name. Present only for MDR-related events.
case_id String MDR Case ID. Present only for MDR-related events.

Endpoint Whitelist object

Field Type Format Description
type String Enum One of: SHA_256, CERTIFICATE_SIGNER, PATH, THUMBPRINT, PROCESS_NAME, MITIGATION, or DETECTION_KEY.
property String String value of the type above.

Event Details object

Field Type Format Description
type String Enum One of: CORE_EVENT_REQUEST_ID, CORE_EVENT_RESPONSE_STATUS, HMPA_EVENT_REPORT, HMPA_EVENT_TYPE, HMPA_PROCESS_VERSION, HMPA_PROCESS_PID, HMPA_PROCESS_PATH, HOME_FAMILY_ID, HOME_SCAN_LABEL, HOME_SCAN_STATE, HOME_SCAN_CLEAN, HOME_SCAN_REBOOT, HOME_COOKIES_COUNT, HOME_COOKIES_DOMAINS, HOME_REMNANT_FAMILY, HOME_REMNANT_NAME, HOME_REMNANT_PATHS, IPS_EXECUTABLE_PATH, IPS_EXECUTABLE_PID, IPS_EXECUTABLE_VERSION, IPS_EXECUTABLE_NAME, IPS_RAW_DATA, IPS_REMOTE_IP, IPS_REMOTE_PORT, IPS_LOCAL_PORT, IPS_TECH_SUPPORT_ID, AMSI_PROCESS_NAME, AMSI_PROCESS_ID, AMSI_PROCESS_PATH, AMSI_PARENT_PROCESS_ID, AMSI_PARENT_PROCESS_PATH, AMSI_THREAT_SUB_TYPE, CORE_BEHAVIORAL_DETECTION_REPORT_SOURCE, CORE_BEHAVIORAL_DETECTION_NAME, CORE_BEHAVIORAL_DETECTION_THUMBPRINT, CORE_BEHAVIORAL_PATH, CORE_APPLICATION_PATH, CORE_APPLICATION_SHA_256.
property String String value of the type above.

Core Remedy Items object

Field Type Format Description
items List of objects Core Remedy Item object (see below)
totalItems Integer Total number of Core Remedy Item objects.

Core Remedy Item object

Field Type Format Description
type String Enum One of: file, regkey, process, thread.
result String Enum One of: NOT_APPLICABLE, SUCCESS, NOT_FOUND, DELETED, FAILED_TO_DELETE, WHITELISTED, OTHER_ERROR, FAILED_TO_DELETE_SYSTEM_PROTECTED.
suspendResult String Enum One of: NOT_APPLICABLE, SUCCESS, SUSPEND_FAILED, PROTECTED, OTHER_ERROR.
descriptor String Item descriptor.
processPath String Process path.
sophosPid String Sophos PID.

Endpoint Core Event Certificate object

Field Type Format Description
signer String Certificate signer.
thumbprint String Certificate thumbprint.

IPS Threat Data object

Field Type Format Description
techSupportId String Tech support ID.
executablePath String Executable path.
executableVersion String Executable version.
executablePid String Executable PID.
executableName String Executable name.
rawData String Raw data.
remoteIp String Remote IP.
remotePort String Remote port.
detectionType Integer 0 or 1 0 means inbound, 1 means outbound, null means both or neither, depending upon context.
localPort String Local port.

AMSI Threat Data object

Field Type Format Description
processName String Process name.
processId String Process ID.
processPath String Process path.
parentProcessId String Parent process ID.
parentProcessPath String Parent process path.

Event types

Endpoint Core Detection events have the type field set to one of:

  • Event::Endpoint::CoreAmsiBlocked
  • Event::Endpoint::CoreBehavioralDetection
  • Event::Endpoint::CoreBlocklistDetection
  • Event::Endpoint::CoreBlocklistRemoteDetection
  • Event::Endpoint::CoreDetection
  • Event::Endpoint::CorePuaDetection
  • Event::Endpoint::CorePuaRemoteDetection
  • Event::Endpoint::CoreRemoteDetection
  • Event::Endpoint::Threat::IpsInboundDetection
  • Event::Endpoint::Threat::IpsOutboundDetection

Alert Schema

Field Type Format Description
id String UUID Alert ID.
type String Enum The type attribute of the event from which the alert was created.
data Object Alert Data object (see below) Alert data.
info Object Alert Info object (see below) Alert info.
source String The source attribute of the event from which the alert was created.
location String The location attribute of the event from which the alert was created.
when String Date-time When the alert was reported (same as the when attribute of the underlying event), or when the alert became visible if reporting on it was initially deferred.
created_at String Date-time When the alert object was created.
severity String Enum The alert severity. One of: none, high, medium, low.
customer_id String UUID Customer ID.
threat_cleanable Boolean Whether the threat is one that the Sophos endpoint agent is normally able to clean up. Present only for Endpoint events where there is an associated threat.
threat String Threat name. Present only for Endpoint events where there is an associated threat object.
description String Alert description.
event_service_event_id String UUID Internal ID of the underlying event object.

Alert Data object

Field Type Format Description
endpoint_id String UUID Endpoint UUID.
endpoint_java_id String UUID Endpoint UUID in the correct UUIDv4 string representation format rather than like endpoint_id, which has successive adjacent nibbles flipped.
endpoint_type String Enum Endpoint type. One of: mobile, computer, server, security_vm, sensor, utm, access_point, wireless_network, mailbox, slec, xgfirewall, ztna_gateway, nta_appliance. Present only if endpoint_id is also present.
endpoint_platform String Enum Endpoint platform. One of: unknown, windows, mac, utm, posix, chrome, ios, android, windowsphone, slec, sve, xgfirewall. Present only if endpoint_id is also present.
policy_type Integer Policy type. One of: 0 (No/Invalid policy), 1 (Automatic Updates), 2 (Malware Protection), 7 (Application Control), 15 (Data Loss Prevention), 16 (Device Control), 19 (Tamper Protection), 22 (Web Control), 24 (Network Threat Protection), 25 (Communication Service), 26 (Lockdown), 27 (Heartbeat), 28 (Update Cache), 29 (Sophos Threat Analysis), 30 (Exploit Detection), 31 (Sophos Endpoint Defense), 32 (Sophos Agent UI), 33 (Endpoint Firewall), 34 (Sophos Home), 35 (Message Relay), 36 (CORe Endpoint Plugin), 37 (CORe Customer Plugin), 38 (Virtualisation), 39 (Mobile Security), 42 (Mobile Password Plugin), 43 (Mobile Restrictions Plugin), 44 (Mobile Exchange Plugin), 45 (Mobile WiFi Plugin), 46 (Mobile Compliance Plugin), 47 (Cloud Secure Gateway Plugin), 48 (Next Gen Web Control), 51 (Email Protection), 52 (File Integrity Monitoring), 53 (Email DLP Protection), 54 (Managed Endpoint Detection Response), 55 (MTR Essentials), 56 (Live Query), 57 (Zero Trust Network Access), 58 (Connect), 70 (Device Encryption), 80 (Wireless Control), 90 (Email Secure Message), 91 (Linux Runtime Detection).
threat_id String Threat ID. Present only for Endpoint Threat events.
device_id String Peripheral ID.
threat_status String Enum Present only for Endpoint Threat events. One of: NONE, CLEANED_UP, CLEANUPABLE_NOT_SUPPORTED, NOT_CLEANUPABLE, FULL_SCAN_REQUIRED, CLEANUPABLE, CLEANUP_IN_PROGRESS, REBOOT_REQUIRED, CLEANUP_TIMED_OUT, CLEANUP_FAILED, OUTBREAK, DISMISSED
source_info Object Same as the source_info attribute of the underlying event.
user_match_uuid String UUID UUID of the user associated with the underlying event. Present only if the event also has an associated Windows Workgroup logon username.
case_id String MDR Case ID. Present only for MDR Case Created event.
detection_name String Name of the detection that led to the MDR Case being created. Present only for MDR Case Created event.

Alert Info object

Field Type Format Description
threat_case_link_id String MDR Case ID. Same as the case_id attribute in the Alert Data object (above).

CEF extensions to API response

When you use the siem.py script (see Github) to pull alerts and events from Sophos Fusion, you may notice a few additional fields in the objects in the response.

Field Type Format Description
datastream String This has the value Alert or Event to distinguish between events and alerts.
rt String Timestamp When an event is added/uploaded to Sophos Fusion. The Sophos endpoint agent may delay sending a new event to Sophos Fusion. For example, Web Control violation events may be batched and sent later while malware detection events are sent immediately. Another scenario this is different from the time of the event is when the device where the event happens is offline. The device in question sends such events to Sophos Fusion when it comes back online. Its value is the same as created_at in the JSON object, and its CEF equivalent is also created_at.
end String Timestamp When an event is created. This matches what you see in Sophos Fusion UI. Its value is the same as when in the JSON object, and its CEF equivalent is reported_at.
dhost String Destination host.
suser String Name of user signed in at the time of the event.

Glossary

Acronym / Initialism What it stands for
AMSI Microsoft Antimalware Scan Interface
API Application Programming Interface
CEF Common Event Format
Enum Enumeration
HBT Heartbeat
HMPA Sophos HitmanPro.Alert
IPS Intrusion Prevention System
MDR Managed Detection and Response
ML Machine Learning
PID Process ID
PUA Potentially Unwanted Application
REP Reputation
SHA256 Secure Hash Algorithm (256-bit)
SIEM Security Information and Event Management
UTM Unified Threat Management
UUID Universally Unique IDentifier
VDL Virus Definition Language
ZTNA Zero Trust Network Access