Schema: File Activity

File operations and transfers including names, paths, hashes, extensions, mount operations, renames, and FTP/SFTP transfers.

16 fields available

[← Back to Schema Field Reference](schema-field-reference-guide.md)


file.directory

Directory path of a file involved in the finding. Populated for file-based Falco rules.

Providers: falco


file.extension

File extension, excluding the leading dot.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


file.hash.md5

MD5 hash of the file.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


file.hash.sha1

SHA-1 hash of the file.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


file.hash.sha256

SHA-256 hash of the file.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


file.mount_source

Source device path for mount/unmount operations (e.g. block device or network share path).

Providers: crowdstrike,jamf_protect


file.name

Name of the file including the extension, without the directory path.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


file.path

Full path to the file, including the file name. Windows paths use device notation (e.g., \Device\HarddiskVolume2...) or standard paths.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


file.path.original

Full path of the original file before a rename operation, including file name.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


file.path.rename

Full path to the renamed/destination file, including file name.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


file.pe.original_file_name

Internal name of the file provided at compile-time (PE metadata).

Providers: crowdstrike,microsoft_defender,elastic


file.type

Numeric type identifier for the file. Values vary by provider and may include OCSF type_id codes or EDR-specific identifiers.

Providers: crowdstrike,sentinel_one,microsoft_defender


file_transfer.argument

Argument supplied to the file transfer command, typically the remote path.

Providers: azure_event_hub,microsoft_defender


file_transfer.command

File transfer protocol command, for example STOR, RETR or DELE.

Providers: azure_event_hub,microsoft_defender


file_transfer.status_code

Server reply code for the file transfer command, indicating whether it completed. Named status_code to match the OCSF FTP Activity class attribute. OCSF types these numerically; kept as String here because Defender emits the code as a string and there is no cast available in the JMESPath runtime.

Providers: azure_event_hub,microsoft_defender


file_transfer.user.name

Account name presented to a file transfer service. Never contains the password.

Providers: azure_event_hub,microsoft_defender



Did this page help you?