Skip to content

Latest commit

 

History

History
50 lines (40 loc) · 1.54 KB

File metadata and controls

50 lines (40 loc) · 1.54 KB

file-read

Description

A file was opened/read

Parameters

Parameter Value
Subject file
Activity read
Activity Type file-read
Pretty Name File Read

Legacy Names

Success Fail
file-read
usb-read
file-read
usb-read

Fields

The possible fields for this activity type will vary depending on whether the activity was a success or a fail.

file-read:success

Field Core Detection Informational
is_dok
is_peripheral_storage
device_pid
storage_account
device_vid
cid

file-read:fail

Field Core Detection Informational
failure_code
is_dok
failure_reason
storage_account
cid