singularity platform

May 20, 2025 · View on GitHub

Expression

product = "singularity platform"

Fields

FieldCoreDetectionInformational
process_name
bytes
domain
user_sid
fallback_user_name
domain_user_name
user

Activity Types

Activity TypeFieldStatusCoreDetectionInformational
alert-triggerfile_pathLegacy
file_ext
agent_id
file_nameLegacy
process_nameLegacy
dest_ipLegacy
file_dirLegacy
dest_hostLegacy
app-activitysrc_ipDefault
src_macDefault
additional_infoDefault
hash_md5Default
dns-requestprocess_id
hash_sha1
agent_id
alert_severity
process_dir
src_hostLegacy
alert_type
hash_sha256
process_name
alert_id
hash_md5
event_name
process_path
alert_name
user_agent
dns-responseprocess_id
hash_sha1
agent_id
alert_severity
process_dir
alert_type
hash_sha256
process_name
alert_id
hash_md5
event_name
process_path
alert_name
user_agent
file-deletesrc_ip
dest_ip
event_name
file-readsrc_ip
agent_id
alert_severity
dest_ip
alert_id
src_hostLegacy
alert_name
alert_type
file-writesrc_ip
dest_ip
event_name
http-sessionagent_idDefault
process_nameDefault
alert_idDefault
malware_urlDefault
src_hostDefault
network-trafficagent_idDefault
process_nameDefault
alert_severityDefault
alert_idDefault
dest_hostDefault
event_nameDefault
process_dirDefault
process_pathDefault
alert_nameDefault
alert_typeDefault
process-createsrc_ipDefault
hash_sha256Default
process_signedDefault
agent_idDefault
dest_ipDefault
objectDefault
registry-modifysrc_ip
agent_id
process_name
alert_severity
dest_ip
alert_id
alert_name
alert_type
object
scheduled_task-createsrc_ip
hash_sha256
process_idLegacy
hash_sha1
process_nameLegacy
dest_ip
hash_md5
event_name
process_dirLegacy
process_pathLegacy
process_command_line
user_agent