Schema: File Activity
File operations and transfers including names, paths, hashes, extensions, mount operations, renames, and FTP/SFTP transfers.
16 fields available
[← Back to Schema Field Reference](schema-field-reference-guide.md)
file.directory
file.directoryDirectory path of a file involved in the finding. Populated for file-based Falco rules.
Providers: falco
file.extension
file.extensionFile extension, excluding the leading dot.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
file.hash.md5
file.hash.md5MD5 hash of the file.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
file.hash.sha1
file.hash.sha1SHA-1 hash of the file.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
file.hash.sha256
file.hash.sha256SHA-256 hash of the file.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
file.mount_source
file.mount_sourceSource device path for mount/unmount operations (e.g. block device or network share path).
Providers: crowdstrike,jamf_protect
file.name
file.nameName of the file including the extension, without the directory path.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
file.path
file.pathFull path to the file, including the file name. Windows paths use device notation (e.g., \Device\HarddiskVolume2...) or standard paths.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
file.path.original
file.path.originalFull path of the original file before a rename operation, including file name.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
file.path.rename
file.path.renameFull path to the renamed/destination file, including file name.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
file.pe.original_file_name
file.pe.original_file_nameInternal name of the file provided at compile-time (PE metadata).
Providers: crowdstrike,microsoft_defender,elastic
file.type
file.typeNumeric type identifier for the file. Values vary by provider and may include OCSF type_id codes or EDR-specific identifiers.
Providers: crowdstrike,sentinel_one,microsoft_defender
file_transfer.argument
file_transfer.argumentArgument supplied to the file transfer command, typically the remote path.
Providers: azure_event_hub,microsoft_defender
file_transfer.command
file_transfer.commandFile transfer protocol command, for example STOR, RETR or DELE.
Providers: azure_event_hub,microsoft_defender
file_transfer.status_code
file_transfer.status_codeServer reply code for the file transfer command, indicating whether it completed. Named status_code to match the OCSF FTP Activity class attribute. OCSF types these numerically; kept as String here because Defender emits the code as a string and there is no cast available in the JMESPath runtime.
Providers: azure_event_hub,microsoft_defender
file_transfer.user.name
file_transfer.user.nameAccount name presented to a file transfer service. Never contains the password.
Providers: azure_event_hub,microsoft_defender
Updated 1 day ago