Job Export Fields

Single Job Export Report Fields

Field TitleDescriptionField FormatEndpointNetworkEmailDNSProtected TheaterCaptive IOC
Job IDID of the Job that was runInteger
Job StepOrder of the Job that was runInteger
VIDValidation Identifier of the JobString
Action NameName of the ActionString
Action DescriptionDescription of the ActionText
Attack LocationLocation where the Action will attack fromString

Attack Vector

Method the Security Validation Platform used to process the ActionString
Behavior TypeType of behavior the Action will processString
Stage of AttackAttack lifecycle stage the Action belongs toString
TagsTag(s) that categorize the ActionString
User ProfileUser profile of user created for use with the ActionText
Blocked?Indicates whether Action was blocked (shows Yes or No)Boolean
Events?Indicates whether there were events detectedBoolean
Host EventsIndicates whether there were events detected from the integrationText



Source ActorIndicates source Actor (IP address of source Actor)String
Destination ActorIndicates destination Actor (IP address of destination ActorString
Target StatusStatus of targetHash/Object with key/value pairs
Attacker StatusStatus of attackerString
Proxied?Indicates whether the Actoris a proxy (shows Yes or No)Boolean
Start Run TimeWhen Job report was startedBoolean
Stop Run TimeWhen Job report stoppedString
Action Port NumbersAttack portsString
Run Time ParametersParameters specific to the ActionString
DevicesDevice(s) the Action was run onText



Correlation RulesRules or conditions that act as a trigger to take specific actions if a particular event occursString





FilenameFilename of the ActionText




SHA256Password verification for the ActionInteger




Host CLI LogHost CLI log fileText



Cloud Action LogCloud Action log fileText





Simple Jobs Export Report Fields

Field TitleDescriptionField Format
Job IDIDs of the Jobs that were run

Integer

Job NameNames of the Jobs that were runString
TimeTime that Jobs were runString
TimestampTimestamp for when Jobs were runString
ProgressProgress of Jobs reports, per Job (for example, Completed Group)String
StatusStatus of Jobs reports, per Job (for example, Completed)String
UserUser who ran Jobs ReportString
DescriptionDescription of JobText

Job Action Report Fields

Field TitleDescriptionField Format
Job IDID of Jobs that were runInteger that could be a string
Job StepOrder of the Jobs that were runInteger
Job NameNames of Jobs that were runString
TimestampTimestamp for when Jobs were runString
ProgressProgress of Jobs reports, per Job (for example, value could be Completed Group)String
BlockedWhether Actions were blocked (value is TRUE, FALSE, or other message)Boolean
DetectedWhether Actions were detected (value is TRUE or FALSE, or other message)Boolean
StatusStatus of Jobs reports, per Job (for example, Completed)String
UserUser who ran Jobs reportString
Action NameName of Action, per JobString
VIDVID of Action, per JobString
Action DescriptionDescription of Action, per JobText
DescriptionDescription of what the Action will do and other information, per JobText
Action TypeType of ActionString
FilenameFilename of the Action, per JobString
SHA256Password verification for the ActionString
Action TagsAny tags used by the ActionString
User TagsAny tags used by the userString
Target StatusTarget status for ActionString
Attacker StatusStatus of Attacker, per JobString
Host CLI LogHost CLI log file, per JobText
<Integration> EventsEvents listed per Integration (for example, Azure Sentinel, Elasticsearch)Text of events, each separated by a new line
Host CLI EventsIndicates whether there were events detected from the integration, per JobText of events, each separated by a new line
  • May 20, 2022
  • September 21, 2023
In This Article