System Events
Overview
AlphaSOC normalizes system event telemetry from various sources into the Open Cybersecurity Schema Framework (OCSF) format, enabling you to write consistent Sigma detection rules across different endpoint security tools and platforms. For complete field definitions and semantics, refer to the linked OCSF class schema pages.
System: Process Activity
OCSF Category: System Activity
OCSF Class: Process Activity
OCSF Fields
activity_idactivity_nameactor.process.cmd_lineactor.process.created_timeactor.process.file.hashes.0.algorithm_idactor.process.file.hashes.0.valueactor.process.file.hashes.1.algorithm_idactor.process.file.hashes.1.valueactor.process.file.hashes.2.algorithm_idactor.process.file.hashes.2.valueactor.process.file.nameactor.process.file.pathactor.process.nameactor.process.parent_process.cmd_lineactor.process.parent_process.created_timeactor.process.parent_process.file.hashes.0.algorithm_idactor.process.parent_process.file.hashes.0.valueactor.process.parent_process.file.hashes.1.algorithm_idactor.process.parent_process.file.hashes.1.valueactor.process.parent_process.file.hashes.2.algorithm_idactor.process.parent_process.file.hashes.2.valueactor.process.parent_process.file.nameactor.process.parent_process.file.pathactor.process.parent_process.nameactor.process.parent_process.pidactor.process.parent_process.user.nameactor.process.pidactor.process.user.nameactor.user.namecategory_namecategory_uidclass_nameclass_uiddevice.ipdevice.macdevice.os.namedevice.os.typedevice.os.type_iddevice.uidmetadata.product.namemetadata.versionprocess.cmd_lineprocess.created_timeprocess.file.hashes.0.algorithm_idprocess.file.hashes.0.valueprocess.file.hashes.1.algorithm_idprocess.file.hashes.1.valueprocess.file.hashes.2.algorithm_idprocess.file.hashes.2.valueprocess.file.nameprocess.file.pathprocess.nameprocess.pidprocess.user.nameseverityseverity_idtimetype_nametype_uid