Schema: Software

Installed software and browser extensions including names, versions, vendors, permissions, installation methods, and product codes.

14 fields available

[← Back to Schema Field Reference](schema-field-reference-guide.md)


product.name

Name of the product (browser name). CrowdStrike: Human-readable browser name (Chrome, Edge, Firefox, Safari) translated from internal codes. Only populated in software_info_extension events that track browser security context. 'Unknown' with path 'no-extension-available' indicates browser extension info could not be collected. Not the process name - use process.name for execution context.

Providers: crowdstrike


product.path

Path to the product executable. CrowdStrike: Full filesystem path to browser binary (e.g. /Applications/Google Chrome.app/Contents/MacOS/Google Chrome, C:\Program Files\Google\Chrome\Application\chrome.exe). Only populated in software_info_extension events. 'no-extension-available' indicates browser path could not be determined. Not the process path - use process.file.path for execution context.

Providers: crowdstrike


product.version

Version of the product. CrowdStrike: Browser version string (e.g. 144.0.7559.60). Only populated in software_info_extension events that track which browser version loaded extensions. Not the process version - use process.pe.file_version or similar for process metadata.

Providers: crowdstrike


software.architecture

Architecture or manifest version of the software. Browser extensions: Manifest V2, Manifest V3, Safari App. OS-level software: CPU architecture (x64, arm64, x86) where reported.

Providers: crowdstrike


software.enabled

Whether the software or extension is currently enabled

Providers: crowdstrike


software.install_method

Installation method of the software. Browser extensions: Browser default, Webstore, GPO, Sideloaded. OS-level software: free-text install method as reported by the source (e.g. msi, pkg, deb, rpm, brew, snap, app_store).

Providers: crowdstrike


software.install_source

High-level provenance of the install. Known values: os_installer (msiexec, pkg installer, dpkg/rpm), package_manager (npm, pip, gem, cargo, brew, apt, yum), app_store (Microsoft Store, Mac App Store, Google Play), extension_store (Chrome Web Store, Firefox add-ons), sideloaded, unknown.

Providers: crowdstrike


software.name

Name of the software or extension

Providers: crowdstrike


software.path

Installation path of the software

Providers: crowdstrike


software.permissions

Permissions requested by the software (e.g. browser extension permissions)

Providers: crowdstrike


software.product_code

Stable identifier for the installed product distinct from software.uid. Windows: MSI ProductCode GUID. macOS: bundle id (e.g. com.apple.Safari). Linux: package manager identifier (e.g. nginx-core for dpkg, kernel-default for rpm). Used as a join key for vulnerability and configuration data.

Providers: crowdstrike


software.publisher

Publisher / signer subject of the software. Distinct from software.vendor_name (which records the package author or scope) — publisher is the entity that signed the installer or package, when available. Used by im-software_inventory and im-software_install for OS-level installs (MSI publisher, macOS pkg signer, Linux package signer).

Providers: crowdstrike


software.vendor_name

Vendor or author of the software. Browser extensions: author email or scope. OS-level software: vendor / publisher / package author as reported by the package metadata.

Providers: crowdstrike


software.version

Version string of the software. Browser extensions: extension version (CrowdStrike software_info_extension). OS-level software inventory: installed package version (CrowdStrike InstalledApplication).

Providers: crowdstrike



Did this page help you?