ImportantThis data source query method is no longer available after February 2, 2026. For more
information on the currently available data sources for use in XDR Data Explorer queries,
go to https://trendmicro.github.io/tm-v1-schema/pages/index.
|
|
General Field
|
Corresponding Fields
|
Example
|
||
|
Endpoint Activity Data
|
Network Activity Data
|
Detection Data
|
||
|
AccountDomain
|
|
|
|
-
|
|
CLICommand
|
|
|
|
"C:\Program Files
(x86)\Google\Chrome\Application\chrome.exe" --type=utility --lang=en-US --no-sandbox
|
|
DomainName
|
|
|
|
self.events.data.microsoft.com
|
|
EmailMessageID
|
|
|
|
<rRzmIhBrXbgjvr4uhIwCcbtE6BnmgNTtAU51qWmqY@example.online>
|
|
EmailRecipient
|
|
|
|
john_doe@example.com
|
|
EmailSender
|
|
|
|
john_doe@example.com
|
|
EmailSubject
|
|
|
|
Subject: From the desk of the Nigerian Prince
|
|
EndpointID
|
|
|
|
e3c49595-09b9-47a3-a43f-6c21aa52e54f
|
|
EndpointName
|
|
|
|
hr-johndoe1
|
|
FileFullPath
|
|
|
|
C:\Program Files (x86)\temp\Application\test.exe
|
|
FileMd5
|
|
|
|
46CFB4E38C6299983048DE39012FD08F
|
|
FileName
|
|
|
|
example.exe
|
|
FileSHA1
|
|
|
|
98A9A1C8F69373B211E5F1E303BA8762F44BC898
|
|
FileSHA2
|
|
|
|
16e4e8b57e82159a16f5d7d898da9e2a4fbe90c17cd95c02074e75226337c90a
|
|
HostDomain
|
|
|
|
-
|
|
IPv4
|
|
|
|
192.0.2.0
|
|
IPv6
|
|
|
|
2001:0db8:85a3:0000:0000:8a2e:0370:7334
|
|
Port
|
|
|
|
8080
|
|
ProcessFullPath
|
|
|
|
C:\Program Files
(x86)\temp\Application\test.exe
|
|
ProcessName
|
|
|
|
-
|
|
RegistryKey
|
|
|
|
hklm\software\wow6432node\microsoft\windows\currentversion\run
|
|
RegistryValue
|
|
|
|
its_ie_settings
|
|
RegistryValueData
|
|
|
|
wscript "C:\Program Files
(x86)\JNJ\ITS_IE_PREF\IE_Preferences.vbs"
|
|
Tactic
|
|
|
|
TA0008
|
|
Technique
|
|
|
|
T1210
|
|
URL
|
|
|
|
https://www.example.com
|
|
UserAccount
|
|
|
|
john_doe
|
