Schema: Software
Installed software and browser extensions including names, versions, vendors, permissions, installation methods, and product codes.
14 fields available
[← Back to Schema Field Reference](schema-field-reference-guide.md)
product.name
product.nameName of the product (browser name). CrowdStrike: Human-readable browser name (Chrome, Edge, Firefox, Safari) translated from internal codes. Only populated in software_info_extension events that track browser security context. 'Unknown' with path 'no-extension-available' indicates browser extension info could not be collected. Not the process name - use process.name for execution context.
Providers: crowdstrike
product.path
product.pathPath to the product executable. CrowdStrike: Full filesystem path to browser binary (e.g. /Applications/Google Chrome.app/Contents/MacOS/Google Chrome, C:\Program Files\Google\Chrome\Application\chrome.exe). Only populated in software_info_extension events. 'no-extension-available' indicates browser path could not be determined. Not the process path - use process.file.path for execution context.
Providers: crowdstrike
product.version
product.versionVersion of the product. CrowdStrike: Browser version string (e.g. 144.0.7559.60). Only populated in software_info_extension events that track which browser version loaded extensions. Not the process version - use process.pe.file_version or similar for process metadata.
Providers: crowdstrike
software.architecture
software.architectureArchitecture or manifest version of the software. Browser extensions: Manifest V2, Manifest V3, Safari App. OS-level software: CPU architecture (x64, arm64, x86) where reported.
Providers: crowdstrike
software.enabled
software.enabledWhether the software or extension is currently enabled
Providers: crowdstrike
software.install_method
software.install_methodInstallation method of the software. Browser extensions: Browser default, Webstore, GPO, Sideloaded. OS-level software: free-text install method as reported by the source (e.g. msi, pkg, deb, rpm, brew, snap, app_store).
Providers: crowdstrike
software.install_source
software.install_sourceHigh-level provenance of the install. Known values: os_installer (msiexec, pkg installer, dpkg/rpm), package_manager (npm, pip, gem, cargo, brew, apt, yum), app_store (Microsoft Store, Mac App Store, Google Play), extension_store (Chrome Web Store, Firefox add-ons), sideloaded, unknown.
Providers: crowdstrike
software.name
software.nameName of the software or extension
Providers: crowdstrike
software.path
software.pathInstallation path of the software
Providers: crowdstrike
software.permissions
software.permissionsPermissions requested by the software (e.g. browser extension permissions)
Providers: crowdstrike
software.product_code
software.product_codeStable identifier for the installed product distinct from software.uid. Windows: MSI ProductCode GUID. macOS: bundle id (e.g. com.apple.Safari). Linux: package manager identifier (e.g. nginx-core for dpkg, kernel-default for rpm). Used as a join key for vulnerability and configuration data.
Providers: crowdstrike
software.publisher
software.publisherPublisher / signer subject of the software. Distinct from software.vendor_name (which records the package author or scope) — publisher is the entity that signed the installer or package, when available. Used by im-software_inventory and im-software_install for OS-level installs (MSI publisher, macOS pkg signer, Linux package signer).
Providers: crowdstrike
software.vendor_name
software.vendor_nameVendor or author of the software. Browser extensions: author email or scope. OS-level software: vendor / publisher / package author as reported by the package metadata.
Providers: crowdstrike
software.version
software.versionVersion string of the software. Browser extensions: extension version (CrowdStrike software_info_extension). OS-level software inventory: installed package version (CrowdStrike InstalledApplication).
Providers: crowdstrike
Updated 2 days ago