Merge pull request #5105 from Azure/asim/update-process-schema-tests
Update ASimTester to align ProcessEvent to doc
This commit is contained in:
Коммит
56c34f0131
|
@ -580,25 +580,22 @@ ActingProcessSHA1,string,Optional,ProcessEvent,SHA1,,
|
|||
ActingProcessSHA256,string,Optional,ProcessEvent,SHA256,,
|
||||
ActingProcessSHA512,string,Optional,ProcessEvent,SHA521,,
|
||||
ActingProcessTokenElevation,string,Optional,ProcessEvent,,,
|
||||
ActorOriginalUserType,string,Optional,ProcessEvent,,,
|
||||
ActorSessionId,string,Optional,ProcessEvent,,,
|
||||
ActorUserId,string,Recommended,ProcessEvent,,,
|
||||
ActorUserIdType,string,Conditional,ProcessEvent,Enumerated,SID|UIS|AADID|OktaId|AWSId|MD4IoTid,ActorUserId
|
||||
ActorUsername,string,Mandatory,ProcessEvent,,,
|
||||
ActorUsernameType,string,Conditional,ProcessEvent,Enumerated,UPN|Windows|DN|Simple,ActorUsername
|
||||
ActorUserType,string,Optional,ProcessEvent,Enumerated,Regular|Machine|Admin|System|Application| Service Principal|Other,
|
||||
ActorOriginalUserType,string,Optional,ProcessEvent,,,
|
||||
AdditionalFields,dynamic,Optional,ProcessEvent,,,
|
||||
CommandLine,string,Alias,ProcessEvent,,,TargetProcessCommandLine
|
||||
Dvc,string,Mandatory,ProcessEvent,Hostname,,
|
||||
DvcAction,string,Optional,ProcessEvent,,,
|
||||
DvcDescription,string,Optional,ProcessEvent,,,
|
||||
SrcDescription,string,Optional,ProcessEvent,,,
|
||||
DstDescription,string,Optional,ProcessEvent,,,
|
||||
DvcDomain,string,Recommended,ProcessEvent,Domain,,
|
||||
DvcDomainType,string,Recommended,ProcessEvent,Enumerated,Windows|FQDN|ResourceGroup,
|
||||
DvcFQDN,string,Optional,ProcessEvent,FQDN,,
|
||||
DvcHostname,string,Recommended,ProcessEvent,Hostname,,
|
||||
DvcHostname,string,Recommended,ProcessEvent,Hostname,,
|
||||
DvcId,string,Optional,ProcessEvent,,,
|
||||
DvcIdType,string,Optional,ProcessEvent,Enumerated,AzureResourceId|MDEid|MD4IoTid|VMConnectionId|AwsVpcId|VectraId|AppGateId|Other,
|
||||
DvcInterface,string,Optional,ProcessEvent,,,
|
||||
|
@ -613,7 +610,7 @@ EventCount,int,Mandatory,ProcessEvent,,,
|
|||
EventEndTime,datetime,Mandatory,ProcessEvent,,,
|
||||
EventMessage,string,Optional,ProcessEvent,,,
|
||||
EventOriginalResultDetails,string,Optional,ProcessEvent,,,
|
||||
EventOriginalResultDetails,string,Optional,ProcessEvent,,,
|
||||
EventOriginalSeverity,string,Optional,ProcessEvent,,,
|
||||
EventOriginalSubType,string,Optional,ProcessEvent,,,
|
||||
EventOriginalType,string,Optional,ProcessEvent,,,
|
||||
EventOriginalUid,string,Optional,ProcessEvent,,,
|
||||
|
@ -622,8 +619,9 @@ EventProductVersion,string,Optional,ProcessEvent,,,
|
|||
EventReportUrl,string,Optional,ProcessEvent,URL,,
|
||||
EventResult,string,Mandatory,ProcessEvent,Enumerated,Success|Failure|Partial|NA,
|
||||
EventResultDetails,string,Optional,ProcessEvent,,,
|
||||
EventSchema,string,Mandatory,ProcessEvent,,ProcessEvent,
|
||||
EventSchema,string,Recommended,ProcessEvent,,ProcessEvent,
|
||||
EventSchemaVersion,string,Mandatory,ProcessEvent,SchemaVersion,,
|
||||
EventSeverity,string,Optional,ProcessEvent,Enumerated,Informational|Low|Medium|High,
|
||||
EventStartTime,datetime,Mandatory,ProcessEvent,,,
|
||||
EventSubType,string,Optional,ProcessEvent,,,
|
||||
EventType,string,Mandatory,ProcessEvent,Enumerated,ProcessCreated|ProcessTerminated,
|
||||
|
@ -675,9 +673,8 @@ TargetUserIdType,string,Conditional,ProcessEvent,Enumerated,SID|UIS|AADID|OktaId
|
|||
TargetUsername,string,Mandatory,ProcessEvent,,,
|
||||
TargetUsernameType,string,Conditional,ProcessEvent,Enumerated,UPN|Windows|DN|Simple,TargetUsername
|
||||
TargetUserSessionId,string,Optional,ProcessEvent,,,
|
||||
TargetUserType,string,Optional,ProcessEvent,Enumerated,Regular|Machine|Admin|System|Application|Service Principal|Other,
|
||||
TimeGenerated,datetime,Mandatory,ProcessEvent,,,
|
||||
Type,string,Recommended,ProcessEvent,,,
|
||||
User,string,Alias,ProcessEvent,Username,,TaregetUsername
|
||||
TimeGenerated,datetime,Mandatory,RegistryEvent,,,
|
||||
_ResourceId,string,Recommended,RegistryEvent,,,
|
||||
Type,string,Recommended,RegistryEvent,,,
|
||||
|
@ -726,5 +723,5 @@ RegistryValue,string,Recommended,RegistryEvent,,,
|
|||
RegistryValueData,string,Recommended,RegistryEvent,,,
|
||||
RegistryValueType,string,Recommended,RegistryEvent,,,
|
||||
User,string,Alias,RegistryEvent,Username,,ActorUsername
|
||||
ActorUserType,string,Optional,ProcessEvent,Enumerated,Regular|Machine|Admin|System|Application| Service Principal|Other,
|
||||
ActorOriginalUserType,string,Optional,ProcessEvent,,,
|
||||
Type,string,Recommended,ProcessEvent,,,
|
||||
User,string,Alias,ProcessEvent,Username,,TaregetUsername
|
||||
|
|
|
Загрузка…
Ссылка в новой задаче