Schema: Process Execution
Process and script execution details including command lines, hashes, parent-child relationships, code signatures, and script content.
43 fields available
[← Back to Schema Field Reference](schema-field-reference-guide.md)
parent.process.command_line
parent.process.command_lineFull command line that started the parent process.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
parent.process.file.hash.sha256
parent.process.file.hash.sha256SHA-256 hash of the parent process executable.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
parent.process.file.path
parent.process.file.pathAbsolute path to the parent process executable.
Providers: jamf_protect,sentinel_one,microsoft_defender,elastic
parent.process.name
parent.process.nameName of the parent process executable.
Providers: crowdstrike,jamf_protect,sentinel_one,microsoft_defender,elastic
parent.process.pid
parent.process.pidOS-assigned parent process identifier (PPID). OCSF: process.parent_process.pid.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
parent.process.uid
parent.process.uidUnique identifier for the parent process instance. Format varies by provider.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
parent.process.user.group.name
parent.process.user.group.nameName of the group associated with the parent process user.
Providers: crowdstrike,sentinel_one,jamf_protect
parent.process.user.group.uid
parent.process.user.group.uidUnique identifier for the group of the parent process user (Unix GID).
Providers: crowdstrike,sentinel_one,jamf_protect
parent.process.user.name
parent.process.user.nameShort name or login of the user running the parent process.
Providers: crowdstrike,sentinel_one,jamf_protect
parent.process.user.uid
parent.process.user.uidUnique identifier of the user running the parent process (e.g., Unix UID or Windows SID).
Providers: crowdstrike,sentinel_one,jamf_protect
process.args
process.argsArray of process arguments passed at launch.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
process.command_line
process.command_lineFull command line that started the process, including the executable and all arguments.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
process.file.hash.md5
process.file.hash.md5MD5 hash of the process executable.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
process.file.hash.sha1
process.file.hash.sha1SHA-1 hash of the process executable.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
process.file.hash.sha256
process.file.hash.sha256SHA-256 hash of the process executable.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
process.file.path
process.file.pathAbsolute path to the process executable. Windows uses device path notation (\Device\HarddiskVolume2...).
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
process.file.signature.certificate.subject
process.file.signature.certificate.subjectSubject name or signing identifier of the certificate used to sign the process binary. On macOS this is the Signing ID (e.g., com.apple.bioutil); on Windows it is the certificate subject (e.g., Microsoft Corporation). Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event. CrowdStrike only populates this on macOS; Microsoft Defender and Jamf Protect populate on both platforms.
Providers: crowdstrike,microsoft_defender,jamf_protect
process.file.signature.developer_uid
process.file.signature.developer_uidDeveloper or team identifier on the certificate that signed the binary (OCSF: digital_signature.developer_uid). Maps Apple TeamId and Elastic team_id. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event. CrowdStrike only populates this on macOS.
Providers: crowdstrike,jamf_protect
process.file.signature.digest.algorithm_id
process.file.signature.digest.algorithm_idDigest hash algorithm identifier (OCSF: digital_signature.digest.algorithm_id). 4=Authenticode per OCSF Algorithm enum. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.
Providers: Not specified
process.file.signature.digest.value
process.file.signature.digest.valueCode signature digest hash value (OCSF: digital_signature.digest.value). Windows: AuthenticodeHash; macOS: cdhash. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.
Providers: Not specified
process.file.signature.exists
process.file.signature.existsBoolean indicating whether a code signature is present on the process binary. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected by the EDR provider for this event. When populated with 'true' the binary has a signature. Do not treat 'false' or Null as evidence of unsigned or malicious on its own.
Providers: microsoft_defender,elastic,crowdstrike
process.file.signature.flags
process.file.signature.flagsCode signing flags providing detailed signature attributes. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.
Providers: microsoft_defender
process.file.signature.is_platform_binary
process.file.signature.is_platform_binaryApple platform binary indicator derived from CS_PLATFORM_BINARY codesigning flag (NOCSF extension; macOS only).
Providers: jamf_protect
process.file.signature.signer_type
process.file.signature.signer_typeSigning authority classification indicating the signer category (NOCSF extension). Maps MDE InitiatingProcessSignerType. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.
Providers: microsoft_defender
process.file.signature.state
process.file.signature.stateSignature validation state (Valid/Invalid/Expired/Revoked/Self-Signed/Unknown). Derived from signature validation flags. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.
Providers: microsoft_defender
process.file.signature.state_id
process.file.signature.state_idNormalized signature state identifier (OCSF: digital_signature.state_id). 0=Unknown 1=Valid 2=Expired 3=Revoked 4=Suspended 5=Pending 99=Other. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.
Providers: sentinel_one
process.name
process.nameName of the process executable.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
process.pe.original_file_name
process.pe.original_file_nameInternal name of the process file provided at compile-time (PE metadata).
Providers: azure_event_hub,crowdstrike,microsoft_defender,elastic
process.pid
process.pidOS-assigned process identifier (PID). OCSF: process.pid.
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
process.uid
process.uidUnique identifier for the process instance. Format varies by provider (e.g., large numeric ID from CrowdStrike, UUID from Jamf).
Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic
process.user.domain
process.user.domainuser.domain
Providers: microsoft_defender
process.user.group.name
process.user.group.nameName of the group associated with the process user.
Providers: crowdstrike,sentinel_one,jamf_protect
process.user.group.uid
process.user.group.uidUnique identifier for the group on the system/platform (Unix GID).
Providers: crowdstrike,sentinel_one,jamf_protect
process.user.name
process.user.nameShort name or login of the user running the process. Note: some provider mappings may produce incorrect data in this field.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
process.user.uid
process.user.uidNote good mapping wrong data it seems Short name or login of the user.
Providers: crowdstrike,sentinel_one,microsoft_defender,elastic
script.file.name
script.file.nameScript file name. OCSF: script.file.name. CS: FileName.
Providers: crowdstrike
script.file.path
script.file.pathScript file path (if file-based, not fileless). OCSF: script.file.path. CS: TargetFileName.
Providers: crowdstrike
script.hashes.sha256
script.hashes.sha256SHA256 hash of script content. OCSF: script.hashes. MDE: SHA256. S1: cmdScript.sha256. CS: SHA256HashData.
Providers: crowdstrike,microsoft_defender,sentinel_one
script.is_complete
script.is_completeWhether script content capture is complete (may be truncated for large scripts). NOCSF extension. S1: cmdScript.isComplete.
Providers: sentinel_one
script.name
script.nameScript or macro name, or engine identifier. OCSF: script.name. S1: cmdScript.applicationName.
Providers: sentinel_one
script.type
script.typeScript type name (PowerShell, Unix Shell, Python, etc.). OCSF: script.type.
Providers: microsoft_defender
script.type_id
script.type_idNormalized script type ID per OCSF (0=Unknown, 1=Windows Cmd, 2=PowerShell, 3=Python, 4=JavaScript, 5=VBScript, 6=Unix Shell, 7=VBA, 99=Other). OCSF: script.type_id.
Providers: microsoft_defender
script.uid
script.uidUnique script execution ID (e.g., PowerShell ScriptBlockId). OCSF: script.uid.
Providers: microsoft_defender
Updated 1 day ago