Schema: Process Execution

Process and script execution details including command lines, hashes, parent-child relationships, code signatures, and script content.

43 fields available

[← Back to Schema Field Reference](schema-field-reference-guide.md)


parent.process.command_line

Full command line that started the parent process.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


parent.process.file.hash.sha256

SHA-256 hash of the parent process executable.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


parent.process.file.path

Absolute path to the parent process executable.

Providers: jamf_protect,sentinel_one,microsoft_defender,elastic


parent.process.name

Name of the parent process executable.

Providers: crowdstrike,jamf_protect,sentinel_one,microsoft_defender,elastic


parent.process.pid

OS-assigned parent process identifier (PPID). OCSF: process.parent_process.pid.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


parent.process.uid

Unique identifier for the parent process instance. Format varies by provider.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


parent.process.user.group.name

Name of the group associated with the parent process user.

Providers: crowdstrike,sentinel_one,jamf_protect


parent.process.user.group.uid

Unique identifier for the group of the parent process user (Unix GID).

Providers: crowdstrike,sentinel_one,jamf_protect


parent.process.user.name

Short name or login of the user running the parent process.

Providers: crowdstrike,sentinel_one,jamf_protect


parent.process.user.uid

Unique identifier of the user running the parent process (e.g., Unix UID or Windows SID).

Providers: crowdstrike,sentinel_one,jamf_protect


process.args

Array of process arguments passed at launch.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


process.command_line

Full command line that started the process, including the executable and all arguments.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


process.file.hash.md5

MD5 hash of the process executable.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


process.file.hash.sha1

SHA-1 hash of the process executable.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


process.file.hash.sha256

SHA-256 hash of the process executable.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


process.file.path

Absolute path to the process executable. Windows uses device path notation (\Device\HarddiskVolume2...).

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


process.file.signature.certificate.subject

Subject name or signing identifier of the certificate used to sign the process binary. On macOS this is the Signing ID (e.g., com.apple.bioutil); on Windows it is the certificate subject (e.g., Microsoft Corporation). Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event. CrowdStrike only populates this on macOS; Microsoft Defender and Jamf Protect populate on both platforms.

Providers: crowdstrike,microsoft_defender,jamf_protect


process.file.signature.developer_uid

Developer or team identifier on the certificate that signed the binary (OCSF: digital_signature.developer_uid). Maps Apple TeamId and Elastic team_id. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event. CrowdStrike only populates this on macOS.

Providers: crowdstrike,jamf_protect


process.file.signature.digest.algorithm_id

Digest hash algorithm identifier (OCSF: digital_signature.digest.algorithm_id). 4=Authenticode per OCSF Algorithm enum. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.

Providers: Not specified


process.file.signature.digest.value

Code signature digest hash value (OCSF: digital_signature.digest.value). Windows: AuthenticodeHash; macOS: cdhash. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.

Providers: Not specified


process.file.signature.exists

Boolean indicating whether a code signature is present on the process binary. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected by the EDR provider for this event. When populated with 'true' the binary has a signature. Do not treat 'false' or Null as evidence of unsigned or malicious on its own.

Providers: microsoft_defender,elastic,crowdstrike


process.file.signature.flags

Code signing flags providing detailed signature attributes. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.

Providers: microsoft_defender


process.file.signature.is_platform_binary

Apple platform binary indicator derived from CS_PLATFORM_BINARY codesigning flag (NOCSF extension; macOS only).

Providers: jamf_protect


process.file.signature.signer_type

Signing authority classification indicating the signer category (NOCSF extension). Maps MDE InitiatingProcessSignerType. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.

Providers: microsoft_defender


process.file.signature.state

Signature validation state (Valid/Invalid/Expired/Revoked/Self-Signed/Unknown). Derived from signature validation flags. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.

Providers: microsoft_defender


process.file.signature.state_id

Normalized signature state identifier (OCSF: digital_signature.state_id). 0=Unknown 1=Valid 2=Expired 3=Revoked 4=Suspended 5=Pending 99=Other. Note: Null/empty does not mean the binary is unsigned - it means signature data was not collected for this event.

Providers: sentinel_one


process.name

Name of the process executable.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


process.pe.original_file_name

Internal name of the process file provided at compile-time (PE metadata).

Providers: azure_event_hub,crowdstrike,microsoft_defender,elastic


process.pid

OS-assigned process identifier (PID). OCSF: process.pid.

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


process.uid

Unique identifier for the process instance. Format varies by provider (e.g., large numeric ID from CrowdStrike, UUID from Jamf).

Providers: crowdstrike,sentinel_one,microsoft_defender,jamf_protect,elastic


process.user.domain

user.domain

Providers: microsoft_defender


process.user.group.name

Name of the group associated with the process user.

Providers: crowdstrike,sentinel_one,jamf_protect


process.user.group.uid

Unique identifier for the group on the system/platform (Unix GID).

Providers: crowdstrike,sentinel_one,jamf_protect


process.user.name

Short name or login of the user running the process. Note: some provider mappings may produce incorrect data in this field.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


process.user.uid

Note good mapping wrong data it seems Short name or login of the user.

Providers: crowdstrike,sentinel_one,microsoft_defender,elastic


script.file.name

Script file name. OCSF: script.file.name. CS: FileName.

Providers: crowdstrike


script.file.path

Script file path (if file-based, not fileless). OCSF: script.file.path. CS: TargetFileName.

Providers: crowdstrike


script.hashes.sha256

SHA256 hash of script content. OCSF: script.hashes. MDE: SHA256. S1: cmdScript.sha256. CS: SHA256HashData.

Providers: crowdstrike,microsoft_defender,sentinel_one


script.is_complete

Whether script content capture is complete (may be truncated for large scripts). NOCSF extension. S1: cmdScript.isComplete.

Providers: sentinel_one


script.name

Script or macro name, or engine identifier. OCSF: script.name. S1: cmdScript.applicationName.

Providers: sentinel_one


script.type

Script type name (PowerShell, Unix Shell, Python, etc.). OCSF: script.type.

Providers: microsoft_defender


script.type_id

Normalized script type ID per OCSF (0=Unknown, 1=Windows Cmd, 2=PowerShell, 3=Python, 4=JavaScript, 5=VBScript, 6=Unix Shell, 7=VBA, 99=Other). OCSF: script.type_id.

Providers: microsoft_defender


script.uid

Unique script execution ID (e.g., PowerShell ScriptBlockId). OCSF: script.uid.

Providers: microsoft_defender



Did this page help you?