Field Name
|
Type
|
General Field
|
Description
|
Example
|
Products
|
actResult
|
string[] |
-
|
The action result
|
Success |
Collaboration Sensor
|
actionName
|
string |
-
|
The user or service action
|
UserLoggedIn |
Collaboration Sensor
|
applicationId
|
string |
-
|
The application ID
|
8ee8fdad-f234-4243-8f3b-15c294843740 |
Collaboration Sensor
|
attachmentFileHashSha256s
|
string[] |
FileSHA2
|
The secure hash algorithm 256-bit (SHA-256) hash of the email attachment
|
|
|
attachmentFileHashes
|
string[] |
FileSHA1
|
The SHA-1 hash of the email attachment
|
|
|
attachmentFileName
|
string[] |
FileName
|
The file name of the email attachment
|
|
|
attachmentFileTlshes
|
string[] |
-
|
The Trend Micro locality sensitive hashing (TLSH) hash detected by Trend Micro Anti-Spam
Engine
|
-
|
|
attachmentMd5
|
string[] |
FileMD5
|
The message-digest algorithm 5 (MD5) hash of the email attachment
|
|
|
attachmentSha1
|
string[] |
FileSHA1
|
The SHA-1 hash of the email attachment
|
|
|
attachmentSha256
|
string[] |
FileSHA2
|
The SHA-256 hash of the email attachment
|
|
|
attachmentSize
|
int64[] |
-
|
The attachment file size
|
-
|
|
attachmentSource
|
string[] |
-
|
The attachment source
|
|
|
attachmentTlsh
|
string[] |
-
|
The TLSH hash detected by Trend Micro Anti-Spam Engine
|
|
|
attachmentUrls
|
object_AttachmentUrl[] |
-
|
The uniform resource locators (URLs) and URL sources extracted from the email attachment
|
-
|
|
clientIp
|
string |
|
The client internet protocol (IP)
|
|
Collaboration Sensor
|
cloudStorageId
|
string |
-
|
The file or folder location ID
|
3d8752ef-a57b-4c7e-8b07-0d7deeb90eb9 |
Collaboration Sensor
|
cloudStorageName
|
string |
-
|
The file or folder URL
|
https://test.sharepoint.com/sites/FILA |
Collaboration Sensor
|
correlationId
|
string |
-
|
The correlation ID
|
7f545dec-5f3b-443f-9f2e-282499deaaef |
Collaboration Sensor
|
eventId
|
enum_MESSAGING_EVENT_ID |
-
|
The event ID
|
|
|
eventName
|
string |
-
|
The event type
|
COLLABORATION_ACTIVITY |
Collaboration Sensor
|
eventSubName
|
string |
-
|
The event type sub-name
|
|
Collaboration Sensor
|
eventTime
|
int64 |
-
|
The time the agent detected the event
|
1657135700000 |
|
extraInfo
|
string[] |
-
|
The additional information about the sharing action
|
<ClientType>SPHomePagesWeb</ClientType> |
Collaboration Sensor
|
fileExt
|
string |
-
|
The file extension (If the object is a folder, this field has no value.)
|
jpg |
Collaboration Sensor
|
fileName
|
string |
FileName
|
The file or folder name
|
test.pdf |
Collaboration Sensor
|
filterRiskLevel
|
string |
-
|
The top-level risk level of the event
|
|
Security Analytics Engine
|
isExternalAccess
|
bool |
-
|
Whether an external user ran the cmdlet (True=external user, False=internal user
in your organization)
|
true |
Collaboration Sensor
|
isSensitiveInfo
|
bool |
-
|
Whether the event contains sensitive information
|
true |
Collaboration Sensor
|
logReceivedTime
|
int64 |
-
|
The time when the extended detection and response (XDR) log was received
|
1656324260000 |
Security Analytics Engine
|
mExternalUid
|
string |
-
|
The unique ID of the email
|
|
|
mailAttachmentHash
|
string |
FileMD5
|
The hash value of the email attachment
|
|
|
mailBccAddresses
|
string[] |
EmailRecipient
|
The blind carbon copy (BCC) address in the email header
|
|
|
mailCacheId
|
string |
-
|
The internal email cache ID to identify emails in the same group
|
<CAAQw8Mj0mFrshPQwS5dwEtFHwdEp2MJfFmMVxe@mail.gmail.com> |
|
mailCcAddresses
|
string[] |
EmailRecipient
|
The carbon copy (CC) address in the email header
|
|
|
mailDirection
|
int32 |
-
|
The email traffic direction
|
|
|
mailEurekaRuleIds
|
string[] |
-
|
The list of rule IDs scanned by Eureka and detected by Trend Micro Anti-Spam Engine
|
|
|
mailFeatureId
|
int64[] |
-
|
The email protocol detected by Trend Micro Anti-Spam Engine
|
-
|
|
mailFolder
|
string |
-
|
The email folder name
|
|
|
mailFromAddresses
|
string[] |
EmailSender
|
The From address in the email header
|
|
|
mailHeaderHash
|
string |
-
|
The email header hash detected by Trend Micro Anti-Spam Engine
|
|
|
mailHelo
|
string |
-
|
The HELO command detected by Trend Micro Anti-Spam Engine
|
|
|
mailMetaText
|
string |
-
|
The postman meta text detected by Trend Micro Anti-Spam Engine
|
|
|
mailMetaTraceId
|
string |
-
|
The trace ID generated by Trend Micro Feedback Engine
|
|
|
mailMsgId
|
string |
EmailMessageID
|
The email ID
|
|
|
mailMsgSubject
|
string |
EmailSubject
|
The email subject
|
|
|
mailReplyToAddresses
|
string[] |
-
|
The Reply To address detected by Trend Micro Anti-Spam Engine
|
|
|
mailRuleId
|
string[] |
-
|
The rule ID of the matched rule detected by Trend Micro Anti-Spam Engine
|
|
|
mailScore
|
int64 |
-
|
The score assigned to the email by Trend Micro Anti-Spam Engine
|
-
|
|
mailSenderIp
|
string |
-
|
The email sender IP address
|
|
|
mailSmtpFromAddresses
|
string[] |
-
|
The sender email address
|
|
|
mailSmtpOriginalRecipients
|
string[] |
-
|
The original email recipients in the simple mail transfer protocol (SMTP) envelope
|
|
|
mailSmtpRecipients
|
string[] |
-
|
The email recipients in the SMTP envelope after scanning
|
|
|
mailSmtpTls
|
string |
-
|
The SMTP transport layer security (TLS) version number
|
|
|
mailSourceDomain
|
string |
-
|
The sender email domain
|
|
|
mailTagHash
|
string |
-
|
The email tag hash detected by Trend Micro Anti-Spam Engine
|
|
|
mailTagHashRawSignature
|
string |
-
|
The raw signature hash of the email
|
|
|
mailTextHash
|
string |
-
|
The email text hash detected by Trend Micro Anti-Spam Engine
|
|
|
mailThreatType
|
string |
-
|
The type of email detected by Trend Micro Anti-Spam Engine
|
|
|
mailToAddresses
|
string[] |
EmailRecipient
|
The Mail To address in the email header
|
|
|
mailUrlHash
|
string |
-
|
The email URL hash detected by Trend Micro Anti-Spam Engine
|
|
|
mailUrlsOriginalLink
|
string[] |
-
|
The original URL extracted from the email content
|
|
|
mailUrlsRealLink
|
string[] |
URL
|
The URL extracted from the email content
|
|
|
mailUrlsVisibleLink
|
string[] |
URL
|
The URL extracted from the email content
|
|
|
mailUserAgent
|
string |
-
|
The user agent
|
|
|
mailWantedHeaderName
|
string[] |
-
|
The WantedHeader key name detected by Trend Micro Anti-Spam Engine
|
|
|
mailWantedHeaderValue
|
string[] |
-
|
The WantedHeader key value detected by Trend Micro Anti-Spam Engine
|
|
|
mailWholeHeader
|
string[] |
-
|
The name and email address of the sender in the From header detected by Trend Micro
Anti-Spam Engine
|
|
|
mailXMailer
|
string |
-
|
The X-Mailer header of the email
|
|
|
mailbox
|
string |
-
|
The primary email address
|
|
|
msgUuid
|
string |
-
|
The internal email universally unique identifier (UUID) to identify each email message
|
|
|
msgUuidChain
|
string |
-
|
The internal UUID chain for each email in Trend Micro Feedback Engine
|
|
|
orgId
|
string |
-
|
The organization ID
|
|
|
orgName
|
string |
-
|
The tenant name
|
test.onmicrosoft.com |
Collaboration Sensor
|
originatingServer
|
string |
-
|
The server where the operation originated
|
TY0PR03MB6449 (15.20.5746.023) |
Collaboration Sensor
|
parameters
|
string |
-
|
The names and values of all parameters used in the cmdlet identified in the Operations
property
|
[{"Name": "AlwaysDeleteOutlookRulesBlob","Value": "False"},{"Name" : "Force","Value":
"False"}] |
Collaboration Sensor
|
pname
|
string |
-
|
The internal product code (deprecated)
|
|
|
policyTreePath
|
string |
-
|
The policy tree path (endpoint only)
|
policyname1/policyname2/policyname3 |
Security Analytics Engine
|
principalName
|
string |
UserAccount
|
The User Principal Name
|
clark@company.com |
Collaboration Sensor
|
productCode
|
string |
-
|
The product code of the product that sent the log
|
|
Security Analytics Engine
|
recordType
|
int32 |
-
|
The operation type
|
|
Collaboration Sensor
|
scanTs
|
int64 |
-
|
The time the email was scanned
|
1657135700000 |
|
scanType
|
string |
-
|
The manual or real-time scan type
|
|
|
service
|
string |
-
|
The Microsoft 365 service where the activity occurred
|
|
Collaboration Sensor
|
tags
|
string[] |
-
|
The detected technique ID based on the alert filter
|
|
Security Analytics Engine
|
target
|
string |
-
|
The object accessed by a user or application
|
|
Collaboration Sensor
|
targetType
|
string |
-
|
The type of object that was accessed or modified
|
File |
Collaboration Sensor
|
userAgent
|
string |
-
|
The user agent
|
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0
Safari/537.36 |
Collaboration Sensor
|
userSessionId
|
string |
-
|
The user session ID
|
d45aa435-d768-4f13-9d54-cd8f596d2641 |
Collaboration Sensor
|
userType
|
string |
-
|
The user type
|
|
Collaboration Sensor
|
uuid
|
string |
-
|
The unique key of the log entry
|
|
Security Analytics Engine
|
Views: