Cortex XDR Attribute Reference
This reference lists the attributes that Device Security collects from Cortex XDR,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with Cortex XDR, it imports endpoint
and host inventory data to enrich the device inventory with telemetry from the Cortex
platform. The attributes in this reference cover endpoints, host inventory records,
application inventory, interfaces, knowledge base entries, and vulnerability (CVE)
findings.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Endpoints Get Endpoints Attributes
Device Security collects endpoints get endpoints attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
domain | cortex_xdr.domain | AD Domain | Domain |
active_directory | cortex_xdr.active_directory | AD Join Status | Active directory |
users | cortex_xdr.users | AD Username | Users |
endpoint_status | cortex_xdr.endpoint_status | Endpoint Protection | Endpoint status |
"Cortex XDR" | — | Endpoint Protection Vendor | "Cortex XDR" |
first_seen | cortex_xdr.first_seen | First Seen | First seen |
endpoint_name | cortex_xdr.endpoint_name | hostname | Endpoint name |
last_seen | cortex_xdr.last_seen | Last Activity | Last seen |
os_version | cortex_xdr.os_version | OS Version | Os version |
public_ip | cortex_xdr.public_ip | public_ip_address | Public ip |
operating_system | cortex_xdr.operating_system | raw_os | Operating system |
assigned_extensions_policy | cortex_xdr.assigned_extensions_policy | — | Assigned extensions policy |
assigned_prevention_policy | cortex_xdr.assigned_prevention_policy | — | Assigned prevention policy |
content_release_timestamp | cortex_xdr.content_release_timestamp | — | Content release timestamp |
content_status | cortex_xdr.content_status | — | Content status |
content_version | cortex_xdr.content_version | — | Content version |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_version | cortex_xdr.endpoint_version | — | Endpoint version |
group_name | cortex_xdr.group_name | — | Name of the group the device belongs to |
is_isolated | cortex_xdr.is_isolated | — | Is isolated |
isolated_date | cortex_xdr.isolated_date | — | Isolated date |
last_content_update_time | cortex_xdr.last_content_update_time | — | Last content update time |
mac_address | cortex_xdr.mac_address | — | Mac address |
operational_status | cortex_xdr.operational_status | — | Operational status |
scan_status | cortex_xdr.scan_status | — | Scan status |
tag_list | cortex_xdr.tags | — | Tag list |
tags.endpoint_tags | cortex_xdr.tags.endpoint_tags | — | Endpoint tags |
tags.server_tags | cortex_xdr.tags.server_tags | — | Server tags |
Xql Query Host Inventory Attributes
Device Security collects xql query host inventory attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_domain | — | domain | Endpoint domain |
endpoint_name | — | hostname | Endpoint name |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
mac_address | cortex_xdr.mac_address | MAC; id | Mac address |
build_number | cortex_xdr.build_number | OS Build Number | Build number |
major_version | cortex_xdr.major_version | OS Version | Major version |
model | cortex_xdr.model | raw_model | Model of the device |
os_caption | — | raw_os | Os caption |
serial_number | cortex_xdr.serial_number | Serial Number | Serial number |
manufacturer | cortex_xdr.manufacturer | Vendor | Manufacturer of the device |
chassis_sku_number | cortex_xdr.chassis_sku_number | — | Chassis sku number |
csdversion | cortex_xdr.csdversion | — | Csdversion |
endpoint_alias | cortex_xdr.endpoint_alias | — | Endpoint alias |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
hardware_uuid | cortex_xdr.hardware_uuid | — | Hardware uuid |
minor_version | cortex_xdr.minor_version | — | Minor version |
physical_memory | cortex_xdr.physical_memory | — | Physical memory |
platform | cortex_xdr.platform | — | Platform |
processor_architecture | cortex_xdr.processor_architecture | — | Processor architecture |
product_type | cortex_xdr.product_type | — | Product type |
report_timestamp | cortex_xdr.report_timestamp | — | Report timestamp |
swap_memory | cortex_xdr.swap_memory | — | Swap memory |
system_type | cortex_xdr.system_type | — | System type |
Xql Query Host Inventory Applications Attributes
Device Security collects xql query host inventory applications attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_name | — | hostname | Endpoint name |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
mac_address | cortex_xdr.mac_address | MAC; id | Mac address |
installed_software | — | third_party_learned_installed_software | Installed software |
endpoint_alias | cortex_xdr.endpoint_alias | — | Endpoint alias |
endpoint_domain | cortex_xdr.endpoint_domain | — | Endpoint domain |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
platform | cortex_xdr.platform | — | Platform |
Xql Query Host Inventory Endpoints Attributes
Device Security collects xql query host inventory endpoints attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_name | cortex_xdr.endpoint_name | hostname | Endpoint name |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
kernel_version | cortex_xdr.kernel_version | latest_firmware_version | Kernel version |
mac_address | cortex_xdr.mac_address | MAC; id | Mac address |
os_type | cortex_xdr.os_type | os_type | Operating system type of the device |
operating_system | cortex_xdr.operating_system | raw_os | Operating system |
architecture | cortex_xdr.architecture | — | Architecture |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_status | cortex_xdr.endpoint_status | — | Endpoint status |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
group_names | cortex_xdr.group_names | — | Group names |
last_calculation_time | cortex_xdr.last_calculation_time | — | Last calculation time |
last_report_time | cortex_xdr.last_report_time | — | Last report time |
severity | cortex_xdr.severity | — | Severity |
severity_score | cortex_xdr.severity_score | — | Severity score |
Xql Query Host Inventory Kbs Attributes
Device Security collects xql query host inventory kbs attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_name | — | hostname | Endpoint name |
mac_address | cortex_xdr.mac_address | id | Mac address |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
endpoint_alias | cortex_xdr.endpoint_alias | — | Endpoint alias |
endpoint_domain | cortex_xdr.endpoint_domain | — | Endpoint domain |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
platform | cortex_xdr.platform | — | Platform |
Endpoints Get Endpoints Interfaces Attributes
Device Security collects endpoints get endpoints interfaces attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
mac_address | — | third_party_learned_network_interfaces; id; MAC | Mac address |
Xql Query Host Inventory Endpoints Interfaces Attributes
Device Security collects xql query host inventory endpoints interfaces attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
ip_address | — | IP Address | IP address |
mac_address | — | third_party_learned_network_interfaces; id; MAC | Mac address |
Xql Query Host Inventory Endpoints Cves Attributes
Device Security collects xql query host inventory endpoints cves attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
mac_address | — | id | Mac address |
ip_address | — | IP Address | IP address |
* Only some attributes map to a Device Security Common Attribute.