Samsung_Knox_System_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (57 columns)

Source: KQL validation test schema

Column Name Type
ArpDevice string
AvbBootPatchLevel string
AvbBootState string
AvbDeviceLocked string
AvbOsPatchLevel string
AvbOsVersion string
AvbVendorPatchLevel string
AvbVerityMode string
BLBuildId string
BLBuildType string
BLBuildVersion string
BLEvent string
BLEventTarget string
BLMode string
BLRP string
CCModeState string
CustomCount string
DeviceImei1 string
DeviceImei2 string
DeviceModel string
DeviceSerialNumber string
DeviceWifimac string
EDLCount string
EmFuseHistory string
EmStatus string
EmTokens string
EventGuid long
FOTACount string
FrpState string
ImgStatus string
KernelBuildId string
KernelBuildType string
KernelRP string
KernelState string
KGFuse string
KGState string
MDMState string
MitreTtp dynamic
Name string
ODINCount string
PrimaryImei string
Profile string
RebootReason string
RPMBState string
SecureBoot string
Severity string
SystemBuildId0 string
SystemBuildId1 string
SystemBuildId2 string
SystemRP string
TimeGenerated datetime
UnlockCount string
VbMetaType string
Version string
WbFuse string
WbReason string
WpState string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Samsung Knox Asset Intelligence

Content Items Using This Table (5)

Analytic Rules (3)

In solution Samsung Knox Asset Intelligence:

Analytic Rule Selection Criteria
Samsung Knox - Mobile Device Boot Compromise Events
Samsung Knox - Peripheral Access Detection with Camera Events
Samsung Knox - Peripheral Access Detection with Mic Events

Workbooks (2)

In solution Samsung Knox Asset Intelligence:

Workbook Selection Criteria
SamsungKnoxAssetIntelligence

GitHub Only:

Workbook Selection Criteria
SamsungKnoxAssetIntelligence

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index