@@ -27,20 +27,20 @@ Learn more about [strong and weak identifiers](entities.md#strong-and-weak-ident
27
27
| [ ** Host** ] ( #host ) | DnsDomain<br >NTDomain<br >HostName<br >* FullName \* * <br >NetBiosName<br >AzureID<br >OMSAgentID<br >OSFamily<br >OSVersion<br >IsDomainJoined | HostName+NTDomain<br >HostName+DnsDomain<br >NetBiosName+NTDomain<br >NetBiosName+DnsDomain<br >AzureID<br >OMSAgentID | HostName<br >NetBiosName |
28
28
| [ ** IP** ] ( #ip ) | Address<br >AddressScope | Address [ \*\* ] ( #strong-identifiers-of-an-ip-entity ) <br >Address+AddressScope [ \*\* ] ( #strong-identifiers-of-an-ip-entity ) | |
29
29
| [ ** URL** ] ( #url ) | Url | Url * (if absolute URL)* [ \*\* ] ( #strong-identifiers-of-a-url-entity ) | Url * (if relative URL)* [ \*\* ] ( #strong-identifiers-of-a-url-entity ) |
30
- | [ ** AzureResource ** ] ( #azure-resource ) | ResourceId | ResourceId | |
30
+ | [ ** Azure resource ** ] ( #azure-resource ) < br > * (AzureResource) * | ResourceId | ResourceId | |
31
31
| [ ** Cloud application** ] ( #cloud-application ) <br >* (CloudApplication)* | AppId<br >Name<br >InstanceName | AppId<br >Name<br >AppId+InstanceName<br >Name+InstanceName | |
32
- | [ ** DNS Resolution ** ] ( #dns-resolution ) | DomainName | DomainName+* DnsServerIp* +* HostIpAddress* | DomainName+* HostIpAddress* |
32
+ | [ ** DNS resolution ** ] ( #dns-resolution ) < br > * (DNS) * | DomainName | DomainName+* DnsServerIp* +* HostIpAddress* | DomainName+* HostIpAddress* |
33
33
| [ ** File** ] ( #file ) | Directory<br >Name | Directory+Name | |
34
34
| [ ** File hash** ] ( #file-hash ) <br >* (FileHash)* | Algorithm<br >Value | Algorithm+Value | |
35
35
| [ ** Malware** ] ( #malware ) | Name<br >Category | Name+Category | |
36
36
| [ ** Process** ] ( #process ) | ProcessId<br >CommandLine<br >ElevationToken<br >CreationTimeUtc | * Host* +ProcessID+CreationTimeUtc<br >* Host* +* ParentProcessId* +<br >  ;  ;  ; CreationTimeUtc+CommandLine<br >* Host* +ProcessId+<br >  ;  ;  ; CreationTimeUtc+* ImageFile* <br >* Host* +ProcessId+<br >  ;  ;  ; CreationTimeUtc+* ImageFile* +<br >  ;  ;  ; * FileHash* | ProcessId+CreationTimeUtc+<br >  ;  ;  ; CommandLine (no Host)<br >ProcessId+CreationTimeUtc+<br >  ;  ;  ; * ImageFile* (no Host) |
37
- | [ ** Registry key** ] ( #registry-key ) | Hive<br >Key | Hive+Key | |
38
- | [ ** Registry value** ] ( #registry-value ) | Name<br >Value<br >ValueType<br > | * Key* +Name | Name (no Key) |
39
- | [ ** Security group** ] ( #security-group ) | DistinguishedName<br >SID<br >ObjectGuid | DistinguishedName<br >SID<br >ObjectGuid | |
37
+ | [ ** Registry key** ] ( #registry-key ) < br > * (RegistryKey) * | Hive<br >Key | Hive+Key | |
38
+ | [ ** Registry value** ] ( #registry-value ) < br > * (RegistryValue) * | Name<br >Value<br >ValueType<br > | * Key* +Name | Name (no Key) |
39
+ | [ ** Security group** ] ( #security-group ) < br > * (SecurityGroup) * | DistinguishedName<br >SID<br >ObjectGuid | DistinguishedName<br >SID<br >ObjectGuid | |
40
40
| [ ** Mailbox** ] ( #mailbox ) | MailboxPrimaryAddress<br >DisplayName<br >Upn<br >ExternalDirectoryObjectId<br >RiskLevel | MailboxPrimaryAddress | |
41
- | [ ** Mail cluster** ] ( #mail-cluster ) | NetworkMessageIds<br >CountByDeliveryStatus<br >CountByThreatType<br >CountByProtectionStatus<br >Threats<br >Query<br >QueryTime<br >MailCount<br >IsVolumeAnomaly<br >Source<br >* ClusterSourceIdentifier \* * <br >* ClusterSourceType \* * <br >* ClusterQueryStartTime \* * <br >* ClusterQueryEndTime \* * <br >* ClusterGroup \* * | Query+Source | |
42
- | [ ** Mail message** ] ( #mail-message ) | Recipient<br >Urls<br >Threats<br >Sender<br >* P1Sender \* * <br >* P1SenderDisplayName \* * <br >* P1SenderDomain \* * <br >SenderIP<br >* P2Sender \* * <br >* P2SenderDisplayName \* * <br >* P2SenderDomain \* * <br >ReceivedDate<br >NetworkMessageId<br >InternetMessageId<br >Subject<br >* BodyFingerprintBin1 \* * <br >* BodyFingerprintBin2 \* * <br >* BodyFingerprintBin3 \* * <br >* BodyFingerprintBin4 \* * <br >* BodyFingerprintBin5 \* * <br >AntispamDirection<br >DeliveryAction<br >DeliveryLocation<br >* Language \* * <br >* ThreatDetectionMethods \* * | NetworkMessageId+Recipient | |
43
- | [ ** Submission mail** ] ( #submission-mail ) | NetworkMessageId<br >Timestamp<br >Recipient<br >Sender<br >SenderIp<br >Subject<br >ReportType<br >SubmissionId<br >SubmissionDate<br >Submitter | SubmissionId+NetworkMessageId+<br >  ;  ;  ; Recipient+Submitter | |
41
+ | [ ** Mail cluster** ] ( #mail-cluster ) < br > * (MailCluster) * | NetworkMessageIds<br >CountByDeliveryStatus<br >CountByThreatType<br >CountByProtectionStatus<br >Threats<br >Query<br >QueryTime<br >MailCount<br >IsVolumeAnomaly<br >Source<br >* ClusterSourceIdentifier \* * <br >* ClusterSourceType \* * <br >* ClusterQueryStartTime \* * <br >* ClusterQueryEndTime \* * <br >* ClusterGroup \* * | Query+Source | |
42
+ | [ ** Mail message** ] ( #mail-message ) < br > * (MailMessage) * | Recipient<br >Urls<br >Threats<br >Sender<br >* P1Sender \* * <br >* P1SenderDisplayName \* * <br >* P1SenderDomain \* * <br >SenderIP<br >* P2Sender \* * <br >* P2SenderDisplayName \* * <br >* P2SenderDomain \* * <br >ReceivedDate<br >NetworkMessageId<br >InternetMessageId<br >Subject<br >* BodyFingerprintBin1 \* * <br >* BodyFingerprintBin2 \* * <br >* BodyFingerprintBin3 \* * <br >* BodyFingerprintBin4 \* * <br >* BodyFingerprintBin5 \* * <br >AntispamDirection<br >DeliveryAction<br >DeliveryLocation<br >* Language \* * <br >* ThreatDetectionMethods \* * | NetworkMessageId+Recipient | |
43
+ | [ ** Submission mail** ] ( #submission-mail ) < br > * (SubmissionMail) * | NetworkMessageId<br >Timestamp<br >Recipient<br >Sender<br >SenderIp<br >Subject<br >ReportType<br >SubmissionId<br >SubmissionDate<br >Submitter | SubmissionId+NetworkMessageId+<br >  ;  ;  ; Recipient+Submitter | |
44
44
| [ ** Sentinel entities** ] ( #sentinel-entities ) | Entities | Entities | |
45
45
46
46
** Table footnotes:**
@@ -65,7 +65,7 @@ The following section contains a more in-depth look at the full schemas of each
65
65
- [ Process] ( #process )
66
66
- [ Cloud application] ( #cloud-application )
67
67
- [ DNS resolution] ( #dns-resolution )
68
- - [ AzureResource ] ( #azure-resource )
68
+ - [ Azure resource ] ( #azure-resource )
69
69
- [ File hash] ( #file-hash )
70
70
- [ Registry key] ( #registry-key )
71
71
- [ Registry value] ( #registry-value )
@@ -175,6 +175,8 @@ The following section contains a more in-depth look at the full schemas of each
175
175
176
176
### IP
177
177
178
+ * Entity name: IP*
179
+
178
180
| Field | Type | Description |
179
181
| ----- | ---- | ----------- |
180
182
| ** Type** | String | 'ip' |
0 commit comments