Cortex XDR Attribute Reference
This reference lists the attributes that Device Security collects from Cortex XDR,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with Cortex XDR, it imports endpoint
and host inventory data to enrich the device inventory with telemetry from the Cortex
platform. The attributes in this reference cover endpoints, host inventory records,
application inventory, interfaces, knowledge base entries, and vulnerability (CVE)
findings.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Endpoint Attributes
Device Security collects endpoint attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
domain | cortex_xdr.domain | AD Domain | Domain |
active_directory | cortex_xdr.active_directory | AD Join Status | Active directory |
users | cortex_xdr.users | AD Username | Users |
endpoint_status | cortex_xdr.endpoint_status | Endpoint Protection | Endpoint status |
"Cortex XDR" | — | Endpoint Protection Vendor | "cortex xdr" |
first_seen | cortex_xdr.first_seen | First Seen | First seen |
endpoint_name | cortex_xdr.endpoint_name | hostname | Endpoint name |
last_seen | cortex_xdr.last_seen | Last Activity | Last seen |
os_version | cortex_xdr.os_version | OS Version | OS version |
public_ip | cortex_xdr.public_ip | public_ip_address | Public IP |
operating_system | cortex_xdr.operating_system | raw_os | Operating system |
assigned_extensions_policy | cortex_xdr.assigned_extensions_policy | — | Assigned extensions policy |
assigned_prevention_policy | cortex_xdr.assigned_prevention_policy | — | Assigned prevention policy |
content_release_timestamp | cortex_xdr.content_release_timestamp | — | Content release timestamp |
content_status | cortex_xdr.content_status | — | Content status |
content_version | cortex_xdr.content_version | — | Content version |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_version | cortex_xdr.endpoint_version | — | Endpoint version |
group_name | cortex_xdr.group_name | — | Name of the group the device belongs to |
is_isolated | cortex_xdr.is_isolated | — | Is isolated |
isolated_date | cortex_xdr.isolated_date | — | Isolated date |
last_content_update_time | cortex_xdr.last_content_update_time | — | Last content update time |
mac_address | cortex_xdr.mac_address | — | MAC address |
operational_status | cortex_xdr.operational_status | — | Operational status |
scan_status | cortex_xdr.scan_status | — | Scan status |
tag_list | cortex_xdr.tags | — | Tag list |
tags.endpoint_tags | cortex_xdr.tags.endpoint_tags | — | Endpoint tags |
tags.server_tags | cortex_xdr.tags.server_tags | — | Server tags |
Host Inventory Attributes
Device Security collects host inventory attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_domain | — | domain | Endpoint domain |
endpoint_name | — | hostname | Endpoint name |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
mac_address | cortex_xdr.mac_address | MAC Address; id | MAC address |
build_number | cortex_xdr.build_number | OS Build Number | Build number |
major_version | cortex_xdr.major_version | OS Version | Major version |
model | cortex_xdr.model | raw_model | Model of the device |
os_caption | — | raw_os | OS caption |
serial_number | cortex_xdr.serial_number | Serial Number | Serial number |
manufacturer | cortex_xdr.manufacturer | Vendor | Manufacturer of the device |
chassis_sku_number | cortex_xdr.chassis_sku_number | — | Chassis sku number |
csdversion | cortex_xdr.csdversion | — | Csdversion |
endpoint_alias | cortex_xdr.endpoint_alias | — | Endpoint alias |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
hardware_uuid | cortex_xdr.hardware_uuid | — | Hardware UUID |
minor_version | cortex_xdr.minor_version | — | Minor version |
physical_memory | cortex_xdr.physical_memory | — | Physical memory |
platform | cortex_xdr.platform | — | Platform |
processor_architecture | cortex_xdr.processor_architecture | — | Processor architecture |
product_type | cortex_xdr.product_type | — | Product type |
report_timestamp | cortex_xdr.report_timestamp | — | Report timestamp |
swap_memory | cortex_xdr.swap_memory | — | Swap memory |
system_type | cortex_xdr.system_type | — | System type |
Application Attributes
Device Security collects application attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_name | — | hostname | Endpoint name |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
mac_address | cortex_xdr.mac_address | MAC Address; id | MAC address |
installed_software | — | third_party_learned_installed_software | Installed software |
endpoint_alias | cortex_xdr.endpoint_alias | — | Endpoint alias |
endpoint_domain | cortex_xdr.endpoint_domain | — | Endpoint domain |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
platform | cortex_xdr.platform | — | Platform |
Endpoint Attributes (Legacy)
Device Security collects endpoint attributes (legacy) from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_name | cortex_xdr.endpoint_name | hostname | Endpoint name |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
kernel_version | cortex_xdr.kernel_version | latest_firmware_version | Kernel version |
mac_address | cortex_xdr.mac_address | MAC Address; id | MAC address |
os_type | cortex_xdr.os_type | os_type | Operating system type of the device |
operating_system | cortex_xdr.operating_system | raw_os | Operating system |
architecture | cortex_xdr.architecture | — | Architecture |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_status | cortex_xdr.endpoint_status | — | Endpoint status |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
group_names | cortex_xdr.group_names | — | Group names |
last_calculation_time | cortex_xdr.last_calculation_time | — | Last calculation time |
last_report_time | cortex_xdr.last_report_time | — | Last report time |
severity | cortex_xdr.severity | — | Severity |
severity_score | cortex_xdr.severity_score | — | Severity score |
Knowledge Base Attributes
Device Security collects knowledge base attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
endpoint_name | — | hostname | Endpoint name |
mac_address | cortex_xdr.mac_address | id | MAC address |
ip_address | cortex_xdr.ip_address | IP Address | IP address |
endpoint_alias | cortex_xdr.endpoint_alias | — | Endpoint alias |
endpoint_domain | cortex_xdr.endpoint_domain | — | Endpoint domain |
endpoint_id | cortex_xdr.endpoint_id | — | Endpoint ID |
endpoint_type | cortex_xdr.endpoint_type | — | Endpoint type |
platform | cortex_xdr.platform | — | Platform |
Endpoint Interface Attributes
Device Security collects endpoint interface attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
mac_address | — | third_party_learned_network_interfaces; id; MAC Address | MAC address |
Endpoint Interface Attributes (Legacy)
Device Security collects endpoint interface attributes (legacy) from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
ip_address | — | IP Address | IP address |
mac_address | — | third_party_learned_network_interfaces; id; MAC Address | MAC address |
CVE Attributes
Device Security collects cve attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
mac_address | — | id | MAC address |
ip_address | — | IP Address | IP address |
* Only some attributes map to a Device Security Common Attribute.