file-write

September 3, 2025 · View on GitHub

Description

A file was created or edited

Parameters

ParameterValue
Subjectfile
Activitywrite
Activity Typefile-write
Pretty NameFile Write

Legacy Names

SuccessFail
file-write
usb-write
file-write
usb-write

Fields

The possible fields for this activity type will vary depending on whether the activity was a success or a fail.

file-write:success

FieldCoreDetectionInformational
is_dok
is_peripheral_storage
device_pid
device_vid
cid

file-write:fail

FieldCoreDetectionInformational
failure_code
is_dok
failure_reason
cid