Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Custom Log V1 | Yes 🔶 — uses type-suffixed column names |
| Ingestion API Supported | ✓ Yes |
Source: Connector definition
| Column Name | Type | Description |
|---|---|---|
| child_process_iocs_s | string | Serialized child process indicators associated with the Red Canary detection. |
| cross_process_iocs_s | string | Serialized cross-process indicators associated with the Red Canary detection. |
| detection_details_s | string | Detection details provided by Red Canary. |
| detection_headline_s | string | Headline for the Red Canary detection. |
| detection_id_s | string | Unique Red Canary detection identifier. |
| detection_severity_s | string | Severity assigned to the Red Canary detection. |
| detection_url_s | string | URL for the detection in Red Canary. |
| file_modification_iocs_s | string | Serialized file modification indicators associated with the Red Canary detection. |
| host_full_name_s | string | Fully qualified host name for the affected endpoint. |
| host_name_s | string | Host name for the affected endpoint. |
| host_os_family_s | string | Operating system family for the affected host. |
| host_os_version_s | string | Operating system version for the affected host. |
| identities_s | string | Serialized identities associated with the Red Canary detection. |
| network_connection_iocs_s | string | Serialized network connection indicators associated with the Red Canary detection. |
| process_iocs_s | string | Serialized process indicators associated with the Red Canary detection. |
| registry_modification_iocs_s | string | Serialized registry modification indicators associated with the Red Canary detection. |
| tactics_s | string | MITRE ATT&CK tactics associated with the detection. |
| TimeGenerated | datetime | The timestamp when the detection was ingested into Microsoft Sentinel. |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Red Canary Threat Detection (via Codeless Connector Framework) |
In solution Red Canary:
| Analytic Rule | Selection Criteria |
|---|---|
| Red Canary Threat Detection |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊