Cortex XDR Attribute Reference
Focus
Focus
Device Security

Cortex XDR Attribute Reference

Table of Contents

Cortex XDR Attribute Reference

This reference lists the attributes that Device Security collects from Cortex XDR, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Cortex XDR, it imports endpoint and host inventory data to enrich the device inventory with telemetry from the Cortex platform. The attributes in this reference cover endpoints, host inventory records, application inventory, interfaces, knowledge base entries, and vulnerability (CVE) findings.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Endpoints Get Endpoints Attributes

Device Security collects endpoints get endpoints attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
domain
cortex_xdr.domain
AD Domain
Domain
active_directory
cortex_xdr.active_directory
AD Join Status
Active directory
users
cortex_xdr.users
AD Username
Users
endpoint_status
cortex_xdr.endpoint_status
Endpoint Protection
Endpoint status
"Cortex XDR"
Endpoint Protection Vendor
"Cortex XDR"
first_seen
cortex_xdr.first_seen
First Seen
First seen
endpoint_name
cortex_xdr.endpoint_name
hostname
Endpoint name
last_seen
cortex_xdr.last_seen
Last Activity
Last seen
os_version
cortex_xdr.os_version
OS Version
Os version
public_ip
cortex_xdr.public_ip
public_ip_address
Public ip
operating_system
cortex_xdr.operating_system
raw_os
Operating system
assigned_extensions_policy
cortex_xdr.assigned_extensions_policy
Assigned extensions policy
assigned_prevention_policy
cortex_xdr.assigned_prevention_policy
Assigned prevention policy
content_release_timestamp
cortex_xdr.content_release_timestamp
Content release timestamp
content_status
cortex_xdr.content_status
Content status
content_version
cortex_xdr.content_version
Content version
endpoint_id
cortex_xdr.endpoint_id
Endpoint ID
endpoint_version
cortex_xdr.endpoint_version
Endpoint version
group_name
cortex_xdr.group_name
Name of the group the device belongs to
ip
cortex_xdr.ip
Ip
ipv6
cortex_xdr.ipv6
Ipv6
is_isolated
cortex_xdr.is_isolated
Is isolated
isolated_date
cortex_xdr.isolated_date
Isolated date
last_content_update_time
cortex_xdr.last_content_update_time
Last content update time
mac_address
cortex_xdr.mac_address
Mac address
operational_status
cortex_xdr.operational_status
Operational status
scan_status
cortex_xdr.scan_status
Scan status
tag_list
cortex_xdr.tags
Tag list
tags.endpoint_tags
cortex_xdr.tags.endpoint_tags
Endpoint tags
tags.server_tags
cortex_xdr.tags.server_tags
Server tags

Xql Query Host Inventory Attributes

Device Security collects xql query host inventory attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
endpoint_domain
domain
Endpoint domain
endpoint_name
hostname
Endpoint name
ip_address
cortex_xdr.ip_address
IP Address
IP address
mac_address
cortex_xdr.mac_address
MAC; id
Mac address
build_number
cortex_xdr.build_number
OS Build Number
Build number
major_version
cortex_xdr.major_version
OS Version
Major version
model
cortex_xdr.model
raw_model
Model of the device
os_caption
raw_os
Os caption
serial_number
cortex_xdr.serial_number
Serial Number
Serial number
manufacturer
cortex_xdr.manufacturer
Vendor
Manufacturer of the device
chassis_sku_number
cortex_xdr.chassis_sku_number
Chassis sku number
csdversion
cortex_xdr.csdversion
Csdversion
endpoint_alias
cortex_xdr.endpoint_alias
Endpoint alias
endpoint_id
cortex_xdr.endpoint_id
Endpoint ID
endpoint_type
cortex_xdr.endpoint_type
Endpoint type
hardware_uuid
cortex_xdr.hardware_uuid
Hardware uuid
minor_version
cortex_xdr.minor_version
Minor version
physical_memory
cortex_xdr.physical_memory
Physical memory
platform
cortex_xdr.platform
Platform
processor_architecture
cortex_xdr.processor_architecture
Processor architecture
product_type
cortex_xdr.product_type
Product type
report_timestamp
cortex_xdr.report_timestamp
Report timestamp
swap_memory
cortex_xdr.swap_memory
Swap memory
system_type
cortex_xdr.system_type
System type

Xql Query Host Inventory Applications Attributes

Device Security collects xql query host inventory applications attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
endpoint_name
hostname
Endpoint name
ip_address
cortex_xdr.ip_address
IP Address
IP address
mac_address
cortex_xdr.mac_address
MAC; id
Mac address
installed_software
third_party_learned_installed_software
Installed software
endpoint_alias
cortex_xdr.endpoint_alias
Endpoint alias
endpoint_domain
cortex_xdr.endpoint_domain
Endpoint domain
endpoint_id
cortex_xdr.endpoint_id
Endpoint ID
endpoint_type
cortex_xdr.endpoint_type
Endpoint type
platform
cortex_xdr.platform
Platform

Xql Query Host Inventory Endpoints Attributes

Device Security collects xql query host inventory endpoints attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
endpoint_name
cortex_xdr.endpoint_name
hostname
Endpoint name
ip_address
cortex_xdr.ip_address
IP Address
IP address
kernel_version
cortex_xdr.kernel_version
latest_firmware_version
Kernel version
mac_address
cortex_xdr.mac_address
MAC; id
Mac address
os_type
cortex_xdr.os_type
os_type
Operating system type of the device
operating_system
cortex_xdr.operating_system
raw_os
Operating system
architecture
cortex_xdr.architecture
Architecture
endpoint_id
cortex_xdr.endpoint_id
Endpoint ID
endpoint_status
cortex_xdr.endpoint_status
Endpoint status
endpoint_type
cortex_xdr.endpoint_type
Endpoint type
group_names
cortex_xdr.group_names
Group names
last_calculation_time
cortex_xdr.last_calculation_time
Last calculation time
last_report_time
cortex_xdr.last_report_time
Last report time
severity
cortex_xdr.severity
Severity
severity_score
cortex_xdr.severity_score
Severity score

Xql Query Host Inventory Kbs Attributes

Device Security collects xql query host inventory kbs attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
endpoint_name
hostname
Endpoint name
mac_address
cortex_xdr.mac_address
id
Mac address
ip_address
cortex_xdr.ip_address
IP Address
IP address
kbs
OS KB Articles
Kbs
endpoint_alias
cortex_xdr.endpoint_alias
Endpoint alias
endpoint_domain
cortex_xdr.endpoint_domain
Endpoint domain
endpoint_id
cortex_xdr.endpoint_id
Endpoint ID
endpoint_type
cortex_xdr.endpoint_type
Endpoint type
platform
cortex_xdr.platform
Platform

Endpoints Get Endpoints Interfaces Attributes

Device Security collects endpoints get endpoints interfaces attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
ip
IP Address
Ip
mac_address
third_party_learned_network_interfaces; id; MAC
Mac address

Xql Query Host Inventory Endpoints Interfaces Attributes

Device Security collects xql query host inventory endpoints interfaces attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
ip_address
IP Address
IP address
mac_address
third_party_learned_network_interfaces; id; MAC
Mac address

Xql Query Host Inventory Endpoints Cves Attributes

Device Security collects xql query host inventory endpoints cves attributes from Cortex XDR. The following table lists each Cortex XDR attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Cortex XDR Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cves
cve
Cves
mac_address
id
Mac address
ip_address
IP Address
IP address
* Only some attributes map to a Device Security Common Attribute.