macOS安全性警示和記錄檔字典參考

Jamf Protect 說明文件

Solution
Application
Content Type
技術說明文件
Utilities & Services
ft:locale
zh-TW
注意:

本節內容適用於 macOS 安全性的舊版威脅防護策略。舊版策略將在未來的 macOS 安全性版本中棄用。有關配置威脅防護策略的資訊和說明,請參閱 macOS 的威脅防護策略

一般事件欄位

每個事件都包含許多事件欄位,且本概覽中的欄位名稱對於所有事件類型皆通用。

#欄位名稱說明資料類型範例值
1input.eventType定義事件類型字串GPFSEvent
2input.host.ipsIP位址字串192.168.1.2
3input.host.serial序號字串C02TL0WGGAAA
4input.host.hostnameHostname (主機名稱)字串Jon’s MacBook Pro
5input.match{}.tags{}資訊標籤 字串MITRE TTPs
6input.match{}.uuid UUID警示字串237BF758-408B-402A-87C2-64BCCFF7D0A2
7input.match{}.event.timestamp 警示時間 整數1635055240.016535
8input.match{}.facts{}.name警示名稱 字串SpearphishOfficeWritesExecutableResearch
9input.match{}.facts{}.human警示說明字串當Office建立可執行檔時發生。
10input.match{}.actions{}.name 基於事件的動作 字串Log
11input.match{}.custom自訂分析識別碼布林false
12input.match{}.context其他中繼資料字串
[ 
{ "name": "ItemName", "value": "jamf", "valueType": "String" }, 
{ 
"name": "Label", 
"value": "com.jamfsoftware.task.checkForTasks", 
"valueType": "String" 
}, 
{ 
"name": "Args", 
"value": "/usr/local/jamf/bin/jamf manage -rebootIfNeeded -deleteLaunchdTask", 
"valueType": "String" 
}, 
{ 
"name": "Name", 
"value": "com.jamfsoftware.task.checkForTasks.plist", 
"valueType": "String" 
}, 
{ 
"name": "ItemBinary", 
"value": "/usr/local/jamf/bin/jamf", 
"valueType": "Binary" 
} 
] 
13input.match{}.severity警示嚴重性整數
  • 0=資訊
  • 1=低
  • 2=中
  • 3=高
14input.related{}.users{}事件使用者陣列整數、字串
"binaries": [
      {
        "gid": 0,
        "uid": 0,
        "fsid": 16777225,
        "mode": 33261,
        "path": "/Library/PrivilegedHelperTools/com.microsoft.autoupdate.helper",
        "size": 293136,
        "inode": 19220446,
        "xattrs": [],
        "changed": 1698151132,
        "created": 1698151132,
        "sha1hex": "63182f5bda15fd2e262b512bf20104497b723b77",
        "accessed": 1698917972,
        "modified": 1698151132,
        "sha256hex": "f1ff86c81b106a4dc9445f01f2e62940fcca9117437941da99b0131dd98bb9e5",
        "isDownload": false,
        "objectType": "GPSystemObject",
        "isAppBundle": false,
        "isDirectory": false,
        "signingInfo": {
          "appid": "com.microsoft.autoupdate.helper",
          "cdhash": "l+/pmKVmSUighiu5PFt6q4t4pfs=",
          "status": 0,
          "teamid": "UBF8T346G9",
          "signerType": 2,
          "authorities": [
            "Developer ID Application: Microsoft Corporation (UBF8T346G9)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ],
          "entitlements": [],
          "statusMessage": "No error.",
          "informationStage": "extended"
        },
        "isScreenShot": false
      }
    ]
15input.related{}.groups{}事件群組陣列陣列
 "groups": [
      {
        "gid": 0,
        "name": "wheel",
        "uuid": "Z2C23RW4DY0"
      },
      {
        "gid": 33,
        "name": "_appstore",
        "uuid": "Z2C23RW4DY21"
      }
    ]
16input.related{}.binaries{}事件二進位資訊陣列1整數、字串
      {
        "gid": 0,
        "uid": 0,
        "fsid": 16777230,
        "mode": 35273,
        "path": "/usr/libexec/security_authtrampoline",
        "size": 134768,
        "inode": 1152921500312504800,
        "xattrs": [],
        "changed": 1694870910,
        "created": 1694870910,
        "sha1hex": "82e899cb1c8a42b74653b05ca526d5feae92b9f6",
        "accessed": 1694870910,
        "modified": 1694870910,
        "sha256hex": "7528368ce03bd25fb22520923f366e364ea40ae90b22dac79fba90f2152c3d32",
        "isDownload": false,
        "objectType": "GPSystemObject",
        "isAppBundle": false,
        "isDirectory": false,
        "signingInfo": {
          "appid": "com.apple.security_authtrampoline",
          "cdhash": "rbIoddPMz9MoMMZl1ATihY8wlMk=",
          "status": 0,
          "teamid": "",
          "signerType": 0,
          "authorities": [
            "Software Signing",
            "Apple Code Signing Certification Authority",
            "Apple Root CA"
          ],
          "entitlements": [],
          "statusMessage": "No error.",
          "informationStage": "extended"
        },
        "isScreenShot": false
      }
17input.related{}.binaries{}.uid檔案擁有者使用者識別碼整數501
18input.related{}.binaries{}.gid檔案擁有者群組識別碼整數80
19input.related{}.binaries{}.path二進位路徑1字串/Applications/iMyFone iBypasser.app/Contents/MacOS/iMyFone iBypasser
20input.related{}.binaries{}.sha1hex SHA-1雜湊檔十六進位字串字串39655008a0a72cabf6d488cd0dcfb37e9883e0b8
21input.related{}.binaries{}.sha256hex SHA-256雜湊檔十六進位字串字串d2d07ceb1e637c555786d68b65f7b8913c8d52c5e4348881632aea0fa91c1643
22input.related{}.binaries{}.xattrs{}檔案延伸功能屬性陣列字串["com.dropbox.attrs", "com.jamf.protect.quarantined"]
23input.related{}.binaries{}.isDownload網際網路下載的檔案驗證布林true
24input.related{}.binaries{}.isAppBundleApp套件目錄檔驗證 布林true
25input.related{}.binaries{}.isDirectory目錄檔驗證布林true
26input.related{}.binaries{}.isScreenShot截圖圖像檔驗證布林true
27input.related{}.binaries{}.signingInfo{} 二進位簽署資訊陣列1字串
"signingInfo": {
          "appid": "com.microsoft.autoupdate.helper",
          "cdhash": "l+/pmKVmSUighiu5PFt6q4t4pfs=",
          "status": 0,
          "teamid": "UBF8T346G9",
          "signerType": 2,
          "authorities": [
            "Developer ID Application: Microsoft Corporation (UBF8T346G9)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ],
          "entitlements": [],
          "statusMessage": "No error.",
          "informationStage": "extended"
        }
28input.related{}.binaries{}.signingInfo.appid二進位識別碼1字串com.jamf.protect.security-extension
29input.related{}.binaries{}.signingInfo.cdhash 二進位代碼目錄雜湊1字串XeQsQOHD7J3vTAuYYZTMQP2mwm0=
30input.related{}.binaries{}.signingInfo.teamid二進位開發團隊簽署者識別碼1字串483DWKW443
31input.related{}.binaries{}.signingInfo.signerType簽署類型和二進位隱含信任級別1整數2
32input.related{}.binaries{}.signingInfo.authorities簽名簽署授權陣列字串
[
            "Developer ID Application: JAMF Software (483DWKW443)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ]
33input.related{}.binaries{}.signingInfo.entitlements二進位授與的權利陣列1 字串
[
            "com.apple.private.responsibility.set-to-self",
            "com.apple.private.responsibility.set-to-other",
            "com.apple.private.security.storage.InstallerSandboxes",
            "com.apple.private.responsibility.set-hosted-properties"
          ]
34input.related{}.binaries{}.signingInfo.statusMessage簽署資訊擷取翻譯的狀態碼字串No error.
35input.related{}.processes{}.uid有效使用者執行程序識別碼整數501
36input.related{}.processes{}.gid有效群組執行程序識別碼整數20
37input.related{}.processes{}.ppid父程序識別碼整數1
38input.related{}.processes{}.pgid程序群組識別碼整數1
39input.related{}.processes{}.ruid真實使用者執行程序識別碼整數501
40input.related{}.processes{}.rgid真實群組執行程序識別碼整數20
41input.related{}.processes{}.pid程序識別碼(程序)整數772
42input.related{}.processes{}.responsiblePID負責程序識別碼整數19678
43input.related{}.processes{}.originalParentPID父程序識別碼整數55064
44input.related{}.processes{}.args{}將可選引數陣列傳遞至的程序字串
[ 
"mv", 
"Slack.app", 
"/Users/ada.powers/Applications" 
] 
45input.related{}.processes{}.name程序名稱字串Snap Camera
46input.related{}.processes{}.path程序路徑字串/Applications/Snap Camera.app/Contents/MacOS/Snap Camera
47input.related{}.processes{}.exitCode程序結束程式代碼整數0
48input.related{}.process{}.signingInfo{}程序簽署資訊陣列 字串
"signingInfo": {
          "appid": "com.microsoft.autoupdate.helper",
          "cdhash": "l+/pmKVmSUighiu5PFt6q4t4pfs=",
          "status": 0,
          "teamid": "UBF8T346G9",
          "signerType": 2,
          "authorities": [
            "Developer ID Application: Microsoft Corporation (UBF8T346G9)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ],
          "entitlements": [],
          "statusMessage": "No error.",
          "informationStage": "extended"
        }
49input.related{}.process{}.signingInfo.appid套件識別碼(程序)字串MF.iMyFone iBypasser
50input.related{}.process{}.signingInfo.cdhash程序代碼目錄雜湊字串XeQsQOHD7J3vTAuYYZTMQP2mwm0=
51input.related{}.process{}.signingInfo.teamid 程序開發團隊簽署識別碼字串483DWKW443
52input.related{}.process{}.signingInfo.signerType簽署類型和二進位隱含信任級別1整數2
53input.related{}.process{}.signingInfo.authorities簽名簽署授權陣列字串
[
            "Developer ID Application: JAMF Software (483DWKW443)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ]
54input.related{}.process{}.signingInfo.entitlements程序授與的權利陣列字串com.apple.rootless.restricted-block-devices
55input.related{}.binaries{}.signingInfo.statusMessage簽署資訊擷取翻譯的狀態碼字串No error.
56input.related{}.process{}.startTimetamp程序開始時間戳記整數1657114862
1任何與事件相關的二進位,而不是Jamf二進位。

GPClickEvent

合成點選事件
#欄位名稱說明資料類型範例值
1input.match{}.event{}.gid合成點選群組識別碼整數20
2input.match{}.event{}.pid合成點選程序識別碼(PID)整數96657
3input.match{}.event{}.uid合成點選使用者識別碼整數501
4input.match{}.event{}.clickType點選類型整數
  • 0 = Other
  • 1 = Left Down
  • 2 = Left Up
  • 3 = Right Down
  • 4 = Right Up
5input.match{}.event{}.targetpid合成點選目標程序識別碼(PID)整數4456

GPDownloadEvent

監控從網際網路下載的檔案。

#欄位名稱 說明資料類型範例值
1input.match{}.event.path下載的檔案路徑字串/Library/LaunchDaemons/com.jamfsoftware.task.checkForTasks.plist
2input.related{}.files{}.gid檔案群組識別碼整數20
3input.related{}.files{}.uid檔案擁有者使用者識別碼整數501
4input.related{}.files{}.fsid檔案系統ID(FSID)整數16777234
5input.related{}.files{}.mode檔案類型和模式整數33188
6input.related{}.files{}.path檔案路徑字串/Library/LaunchDaemons/com.jamfsoftware.task.checkForTasks.plist
7input.related{}.files{}.size檔案大小整數35249769
8input.related{}.files{}.inode檔案inode識別碼整數7174457
9input.related{}.files{}.xattrs檔案延伸功能屬性陣列字串["com.apple.macl", "com.apple.metadata:kMDItemDownloadedDate", "com.apple.metadata:kMDItemWhereFroms", "com.apple.quarantine"]
10input.related{}.files{}.changed檔案變更日期整數1632496484
11input.related{}.files{}.created檔案建立日期 整數1632496484
12input.related{}.files{}.sha1hex SHA-1雜湊檔十六進位字串字串39655008a0a72cabf6d488cd0dcfb37e9883e0b8
13input.related{}.files{}.accessed檔案上次存取日期整數1632496484
14input.related{}.files{}.modified檔案上次修改日期 整數1632496484
15input.related{}.files{}.sha256hexSHA-256雜湊檔十六進位字串字串ca43054c05867b673d980bbcc97215d7ebaed5465ad1266eea4c776188bbd385
16input.related{}.files{}.isDownload網際網路下載的檔案驗證 布林true
17input.related{}.files{}.isAppBundleApp套件目錄檔驗證 布林true
18input.related{}.files{}.isDirectory目錄檔驗證 布林true
19input.related{}.files{}.signingInfo{}檔案簽署資訊陣列整數、字串
{ 
"status": -67062, 
"authorities": [], 
"teamid": "", 
"signerType": 4, 
"statusMessage": "code object is not signed at all", 
"entitlements": [], 
"appid": "" 
}, 
20input.related{}.files{}.signingInfo.appid檔案識別碼字串GoogleChrome-97.0.4692.99-GGRO
21input.related{}.files{}.signingInfo.cdhash檔案代碼目錄雜湊字串WApZMfx1x99D8eRQhUFeID4YZDY=
22input.related{}.files{}.signingInfo.teamid開發團隊簽署者識別碼字串EQHXZ8M8AV
23input.related{}.files{}.signingInfo.signerType物件簽名類型和隱含信任級別整數2
24input.related{}.files{}.signingInfo.authorities簽名簽署授權陣列字串["Developer ID Application: Google, Inc. (EQHXZ8M8AV)", "Developer ID Certification Authority", "Apple Root CA"]
25input.related{}.files{}.signingInfo.entitlements檔案授與的權利陣列字串com.apple.rootless.restricted-block-devices
26input.related{}.files{}.isScreenShot截圖圖像檔驗證 布林true
27input.related{}.files{}.downloadedFrom檔案下載位置陣列字串https://files.jamf.com

GPFSEvent

檔案系統事件
#欄位名稱說明資料類型範例值
1input.match{}.event.dev檔案系統事件裝置ID 整數16777233
2input.match{}.event.gid檔案群組識別碼 整數0
3input.match{}.event.pid檔案程序識別碼(PID) 整數96657
4input.match{}.event.uid檔案使用者識別碼 整數0
5input.match{}.event.path檔案路徑 字串/Library/LaunchDaemons/com.jamfsoftware.task.checkForTasks.plist
6input.match{}.event.type檔案系統事件整數
  • 0=已建立
  • 1=已刪除
  • 3 =已重新命名
  • 4=已修改
  • 7 =已建立目錄
7input.match{}.event.iNode檔案inode識別碼整數3493490
8input.match{}.event.eventID檔案系統事件識別碼 整數62816
9input.match{}.event.prevFile檔案重新命名操作先前的路徑 字串/Library/LaunchDaemons/.dat.nosync7991.BW4gMk
10input.related{}.files{}.gid檔案系統操作群組識別碼整數0
11input.related{}.files{}.uid檔案系統操作使用者識別碼整數0
12input.related{}.files{}.fsid檔案FSID整數16777234
13input.related{}.files{}.mode檔案類型和模式整數33188
14input.related{}.files{}.path檔案路徑字串/Library/LaunchDaemons/com.jamfsoftware.task.checkForTasks.plist
15input.related{}.files{}.size檔案大小整數0
16input.related{}.files{}.inode檔案inode識別碼整數7174457
17input.related{}.files{}.xattrs檔案延伸功能屬性陣列字串["com.apple.quarantine"]
18input.related{}.files{}.changed檔案變更日期整數1632496484
19input.related{}.files{}.created檔案建立日期整數1632496484
20input.related{}.files{}.sha1hex SHA-1雜湊檔十六進位字串字串39655008a0a72cabf6d488cd0dcfb37e9883e0b8
21input.related{}.files{}.accessed檔案存取日期整數1632496484
22input.related{}.files{}.modified檔案修改日期整數1632496484
23input.related{}.files{}.sha256hex SHA-256雜湊檔十六進位字串字串ca43054c05867b673d980bbcc97215d7ebaed5465ad1266eea4c776188bbd385"
24input.related{}.files{}.isDownload網際網路下載的檔案驗證 布林false
25input.related{}.files{}.isAppBundleApp套件目錄檔驗證布林false
26input.related{}.files{}.isDirectory目錄檔驗證 布林false
27input.related{}.files{}.signingInfo{}檔案簽署資訊陣列陣列
{ 
"status": -67062, 
"authorities": [], 
"teamid": "", 
"signerType": 4, 
"statusMessage": "code object is not signed at all", 
"entitlements": [], 
"appid": "" 
}, 
28input.related{}.files{}.signingInfo.appid檔案識別碼字串com.googlecode.iterm2
29input.related{}.files{}.signingInfo.cdhash檔案代碼目錄雜湊字串JmJW/m4Oafwj3PRZh8QspKxDUYw=
30input.related{}.files{}.signingInfo.teamid開發團隊簽署者識別碼字串AQPZ6F3ASY
31input.related{}.files{}.signingInfo.signerType物件簽名類型和隱含信任級別整數
  • 0 = Apple
  • 1 = App Store
  • 2=開發者
  • 3=臨時許用
  • 4=未簽署
32input.related{}.files{}.signingInfo.authorities簽名簽署授權陣列陣列
[
            "Software Signing",
            "Apple Code Signing Certification Authority",
            "Apple Root CA"
          ]
33input.related{}.files{}.signingInfo.entitlements檔案權利陣列陣列com.apple.private.security.clear-library-validation
34input.related{}.files{}.isScreenShot截圖圖像檔驗證 布林true
35input.related{}.files{}.downloadedFrom檔案下載位置陣列 字串 https://files.jamf.com

GPProcessEvent

監控在電腦上啟動或終止的程序。

#欄位名稱說明資料類型範例值
1input.match{}.event.pid程序事件識別碼整數 96657
2input.match{},event.type程序活動整數 1
3input.match{},event.subType詳細程序活動整數23

GPKeylogRegisterEvent

透過 macOS 上的核心圖形架構來監視新的「事件點擊」註冊。某些類型的鍵盤記錄和輔助功能軟體經常使用核心圖形事件點擊。

#欄位名稱說明資料類型範例值
1input.match{}.event{}.options註冊記錄檔的密鑰輕點時設定的選項。字串
  • defaultTap =預設輕點
  • listenOnly =僅監聽
2input.match{}.event{}.sourcePID來源程序ID(記錄檔的密鑰輕點註冊請求)整數86939
3input.match{}.event{}.destinationPID目的地程序ID(記錄檔的密鑰輕點註冊請求)整數0

GPGatekeeperEvent

監控來自 Gatekeeper 的動作和記錄檔,這是 Apple 的內建功能,用於執行代碼簽署並在開啟下載的應用程式之前對其進行驗證。

#欄位名稱說明資料類型範例值
1input.match{}.event{}.pid程序ID(門禁事件) 整數39357
2input.match{}.event{}.name 事件名稱字串CrashReporter
3input.match{}.event{}.path程序路徑(門禁事件) 字串/Library/LaunchDaemons/com.jamfsoftware.task.checkForTasks.plist
4input.match{}.event{}.sender記錄檔訊息寄件人字串AppleSystemPolicy
5input.match{}.event{}.process記錄檔訊息寄件人程序字串kernel
6input.match{}.event{}.category記錄類別字串XPEvent.structured
7input.match{}.event{}.subsystem記錄子系統字串com.apple.XProtectFramework.PluginAPI
8input.match{}.event{}.composedMessage記錄檔訊息字串
ASP: Security policy would not allow process: 30659, /Applications/JamfComplianceReporter.app/Contents/Helpers/JamfComplianceReporterAgent.app/Contents/MacOS/JamfComplianceReporterAgent
9input.match{}.event{}.senderImagePath圖片路徑(記錄檔訊息寄件人)字串/System/Library/Extensions/AppleSystemPolicy.kext/Contents/MacOS/AppleSystemPolicy
10input.match{}.event{}.processImagePath程序路徑(記錄檔訊息寄件人)字串/kernel
11input.match{}.event{}.processIdentifier程序ID(記錄檔訊息寄件人)整數0
12input.match{}.facts{}.name警示名稱 字串GatekeeperBlockedSigned

GPMRTEvent

監控來自惡意軟體移除工具(MRT)的動作和記錄檔,MRT是Apple的內建應用程式,負責從macOS中移除目標檔案。

#欄位名稱說明資料類型範例值
1input.match{}.event{}.pid程序ID(門禁事件)整數96657
2input.match{}.event{}.name事件名稱字串JamfComplianceReporterAgent
3input.match{}.event{}.path程序路徑(門禁事件) 字串/Library/LaunchDaemons/com.jamfsoftware.task.checkForTasks.plist
4input.match{}.event{}.sender記錄檔訊息寄件人字串AppleSystemPolicy
5input.match{}.event{}.process記錄檔訊息寄件人程序字串kernel
6input.match{}.event{}.category記錄類別字串XPEvent.structured
7input.match{}.event{}.subsystem記錄子系統字串com.apple.XProtectFramework.PluginAPI
8input.match{}.event{}.composedMessage記錄檔訊息字串 ASP: Security policy would not allow process: 30659, /Applications/JamfComplianceReporter.app/Contents/Helpers/JamfComplianceReporterAgent.app/Contents/MacOS/JamfComplianceReporterAgent"
9input.match{}.event{}.senderImagePath圖片路徑(記錄檔訊息寄件人)字串/System/Library/Extensions/AppleSystemPolicy.kext/Contents/MacOS/AppleSystemPolicy
10input.match{}.event{}.processImagePath程序路徑(記錄檔訊息寄件人)字串/kernel
11input.match{}.event{}.processIdentifier程序ID(記錄檔訊息寄件人)整數0
12input.match{}.facts{}.nameSpearphishOfficeWritesExecutableResearch字串LaunchDaemon

GPPreventedExecutionEvent

自訂防止清單事件
#欄位名稱說明資料類型範例值
1input.match{}.event{}.blockedApp被封鎖布林true
2input.match{}.event{}.matchType比對方法字串signingID
3input.match{}.event{}.matchValue阻止的App名稱字串scriptingosx.desktoppr
4input.match{}.event{}.process{}.gid程序有效群組識別碼整數20
5input.match{}.event{}.process{}.pid程序識別碼(程序)整數40990
6input.match{}.event{}.process{}.uid程序有效使用者識別碼 整數501
7input.match{}.event{}.process{}.args程序陣列傳遞的可能引數字串
[
          "/tmp/PKInstallSandbox.nVjzpr/Scripts/com.jamf.ce.Wallpaper.43ZvSw/desktoppr",
          "/Library/Desktop Pictures/wallpaper.heic"
        ]
          "/tmp/PKInstallSandbox.nVjzpr/Scripts /com.jamf.ce.Wallpaper.43ZvSw/desktoppr",
          "/Library/Desktop Pictures/wallpaper.heic"
        ]
8input.match{}.event{}.process{}.name程序名稱字串desktoppr
9input.match{}.event{}.process{}.path程序路徑字串/tmp/PKInstallSandbox.nVjzpr/Scripts/com.jamf.ce.Wallpaper.43ZvSw/desktoppr
10input.match{}.event{}.process{}.pgid程序群組識別碼整數40990
11input.match{}.event{}.process{}.rgid程序真實群組識別碼整數20
12input.match{}.event{}.process{}.ruid程序真實使用者識別碼整數501
13input.match{}.event{}.process{}.uuid事件唯一識別碼字串ade83c7a-2eaa-4bd3-b468-d1643483746f
14input.match{}.event{}.process{}.signingInfo{}程序簽署資訊陣列整數、字串
[
          "appid": "com.scriptingosx.desktoppr",
          "cdhash": "oA74w5FQMn1N1G7k1Ar0lyClqu8=",
          "status": 0,
          "teamid": "JME5BW3F3R",
          "signerType": 2,
          "authorities": [
            "Developer ID Application: Jon Smith (JME5BW3F3R)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ]
15input.match{}.event{}.process{}.signingInfo{}.appid識別碼(程序)字串com.scriptingosx.desktoppr
16input.match{}.event{}.process{}.signingInfo{}.cdhash程序代碼目錄雜湊字串oA74w5FQMn1N1G7k1Ar0lyClqu8=
17input.match{}.event{}.process{}.signingInfo{}.status簽署資訊擷取狀態整數
  • 0 = Apple
  • 1 = App Store
  • 2=開發者
  • 3=臨時許用
  • 4=未簽署
18input.match{}.event{}.process{}.signingInfo{}.teamid程序開發團隊簽署者識別碼字串JME5BW3F3R
19input.match{}.event{}.process{}.signingInfo{}.signerType簽名類型和隱含信任級別整數
  • 0 = Apple
  • 1 = App Store
  • 2=開發者
  • 3=臨時許用
  • 4=未簽署
20input.match{}.event{}.process{}.signingInfo{}.authorities簽名簽署授權陣列字串
[
            "Developer ID Application: Jon Smith (JME5BW3F3R)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ]
21input.match{}.event{}.process{}.signingInfo{}.entitlements程序授與的權利陣列字串com.apple.private.security.clear-library-validation
22input.match{}.event{}.process{}.signingInfo{}.statusMessage簽署資訊擷取狀態碼字串No error.
23input.match{}.event{}.process{}.startTimestamp程序開始時間戳記整數1668431165
24input.match{}.event{}.process{}.orginalParentPID父程序識別碼整數1

GPThreatMatchExecEvent

威脅預防事件
#欄位名稱說明資料類型範例值
1input.match{}.event{}.blocked威脅被封鎖布林true
2input.match{}.event{}.matchType資料庫比對字串Threat Signature
3input.match{}.event{}.matchValue威脅名稱字串applejeus_jmt_a
4input.match{}.event{}.scriptPath工序指令路徑字串/tmp/CrashReporter.sh
5input.match{}.event{}.process{}.gid有效群組執行程序識別碼整數0
6input.match{}.event{}.process{}.pid程序識別碼(程序)整數39356
7input.match{}.event{}.process{}.uid有效使用者執行程序識別碼整數0
8input.match{}.event{}.process{}.args將可選引數陣列傳遞至的程序字串
[
          "/Library/JMTTrader/CrashReporter",
          "Maintain"
        ]
9input.match{}.event{}.process{}.name程序名稱字串CrashReporter
10input.match{}.event{}.process{}.path程序路徑字串/Library/radar/CrashReporter
11input.match{}.event{}.process{}.pgid程序群組識別碼整數39356
12input.match{}.event{}.process{}.rgid真實群組執行程序識別碼整數0
13input.match{}.event{}.process{}.ruid真實使用者執行程序識別碼整數0
14input.match{}.event{}.process{}.uuid事件唯一識別碼字串3a842375-29f4-4516-8c8e-aca148c3ab32
15input.match{}.event{}.process{}.signingInfo{}程序簽署資訊陣列整數、字串
{
          "appid": "com.microsoft.autoupdate.helper",
          "cdhash": "l+/pmKVmSUighiu5PFt6q4t4pfs=",
          "status": 0,
          "teamid": "UBF8T346G9",
          "signerType": 2,
          "authorities": [
            "Developer ID Application: Microsoft Corporation (UBF8T346G9)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ],
          "entitlements": [],
          "statusMessage": "No error.",
          "informationStage": "extended"
        }
16input.match{}.event{}.process{}.signingInfo{}.appid識別碼(程序)字串com.scriptingosx.desktoppr
17input.match{}.event{}.process{}.signingInfo{}.cdhash程序代碼目錄雜湊字串oA74w5FQMn1N1G7k1Ar0lyClqu8=
18input.match{}.event{}.process{}.signingInfo{}.status簽署資訊擷取狀態整數-67068
19input.match{}.event{}.process{}.signingInfo{}.teamid 程序開發團隊簽署識別碼字串JME5BW3F3R
20input.match{}.event{}.process{}.signingInfo{}.signerType物件簽名類型和隱含信任級別整數
  • 0 = Apple
  • 1 = App Store
  • 2=開發者
  • 3=臨時許用
  • 4=未簽署
21input.match{}.event{}.process{}.signingInfo{}.authorities簽名簽署授權陣列字串
[
            "Developer ID Application: Jon Smith (JME5BW3F3R)",
            "Developer ID Certification Authority",
            "Apple Root CA"
          ]
22input.match{}.event{}.process{}.signingInfo{}.entitlements程序授與的權利陣列字串com.apple.private.security.clear-library-validation
23input.match{}.event{}.process{}.signingInfo{}.statusMessage簽署資訊擷取翻譯的狀態碼字串cannot find code object on disk
24input.match{}.event{}.process{}.startTimestamp程序開始時間戳記整數1668430737
25input.match{}.event{}.process{}.orginalParentPID父程序識別碼整數1
26input.match.facts{}.version端點威脅預防版本整數11568

GPUnifiedLogEvent

統一記錄檔事件
#欄位名稱說明資料類型範例值
1input.match{}.event{}.sender記錄檔訊息寄件人字串XProtectRadarSecurity
2input.match{}.event{}.process記錄檔訊息寄件人程序字串XProtectRadarSecurity
3input.match{}.event{}.category記錄類別字串XPEvent.structured
4input.match{}.event{}.subsystem記錄子系統字串com.apple.XProtectFramework.PluginAPI
5input.match{}.event{}.composedMessage記錄檔訊息字串{\"caused_by\":[],\"status_message\":\"NoThreatDetected\",\"status_code\":20,\"execution_duration\":0.7135159969329834}
6input.match{}.event{}.senderImagePath 記錄檔訊息寄件人圖像路徑字串/Library/Apple/System/Library/CoreServices/XProtect.app/Contents/MacOS/XProtectRadarSecurity
7input.match{}.event{}.processImagePath 記錄檔訊息寄件人程序路徑字串/Library/Apple/System/Library/CoreServices/XProtect.app/Contents/MacOS/XProtectRLibrary/Apple/System/Library/CoreServices/XProtect.app/Contents/MacOS/XProtectRadarSecurity
8input.match{}.event{}.processIdentifier記錄檔訊息寄件人程序ID整數6925

GPUSBEvent

監控插入電腦的 USB 裝置。

#欄位名稱說明資料類型範例值
1input.match.typeUSB事件類型整數
  • 0 =已插入裝置
  • 1=已移除裝置
2input.match.usbAddressUSB 位址整數6
3input.match{}.device{}.mediaPath媒體路徑字串IODeviceTree:/PCI0@0/RP05@1C,4/UPSB@0/DSB2@2/XHC2@0/@1:0
4input.match{}.device{}.protocolProtocol (通訊協定)字串USB
5input.match{}.device{}.deviceModel機型字串Ultra USB 3.0
6input.match{}.device{}.isRemovable卸除式布林true
7input.match{}.device{}.mediaName媒體名稱字串SanDisk Ultra USB 3.0 Media
8input.match{}.device{}.bsdMinorBSD次要整數11
9input.match{}.device{}.vendorNameUSB裝置供應商字串Apple Inc.
10input.match{}.device{}.isWhole整數布林false
11input.match{}.device{}.unit單位整數1
12input.match{}.device{}.deviceSubclassUSB裝置子類別整數0
13input.match{}.device{}.serialNumberUSB裝置序號字串FM79997PJ3VYB7+SET
14input.match{}.device{}.bsdUnitBSD單位整數2
15input.match{}.device{},busPath匯流排路徑字串IODeviceTree:/PCI0@0/RP05@1C,4/UPSB@0/DSB2@2/XHC2@0
16input.match{}.device{}.isLeaf布林true
17input.match{}.device{}.isInternal內部布林true
18input.match{}.device{}.busNamebusName字串XHC2
19input.match{}.device{}.bsdMajorBSD主要整數1
20input.match{}.device{}.isEjectable可退出布林true
21input.match{}.device{}.isEncrypted已加密布林true
22input.match{}.device{}.devicePath裝置路徑字串IOService:/AppleACPIPlatformExpert/PCI0@0/AppleACPIPCI/RP05@1C,4/IOPP/UPSB@0/IOPP/DSB2@2/IOPP/XHC2@0/XHC2@00000000/SSP1@00100000/Ultra USB 3.0@00100000/IOUSBHostInterface@0/IOUSBMassStorageInterfaceNub/IOUSBMassStorageDriverNub/IOUSBMassStorageDriver/IOSCSILogicalUnitNub@0/IOSCSIPeripheralDeviceType00/IOBlockStorageServices
23input.match{}.device{}.bsdNameBSD名稱字串disk2
24input.match{}.device{}.vendorIdUSB裝置供應商識別碼字串0x05ac
25input.match{}.device{}.content裝置內容字串GUID_partition_scheme
26input.match{}.device{}.revision裝置修訂版字串1.00
27input.match{}.device{}.size裝置大小整數15376000000
28input.match{}.device{}.isNetworkVolume網路量布林true
29input.match{}.device{}.blocksize區塊大小整數512
30input.match{}.device{}.productNameUSB產品名稱字串Apple Internal Keyboard / Trackpad
31input.match{}.device{}.mediaKind媒體種類字串IOMedia
32input.match{}.device{}.isWritable裝置可寫入布林true
33input.match{}.device{}.productIdUSB裝置產品識別碼字串0x027b
34input.match{}.device{}.deviceClassUSB裝置類別整數0
35input.match{}.device{}.encryptionDetail加密詳細資訊整數0