FileInspectionEvent

FileInspectionEvent
File Inspection Event

File Inspection Event.

JSON Example
{
    "inspection_time": 0,
    "server": {
        "vm_id": "string",
        "ip_address": "string",
        "fqdn": "string"
    },
    "client": {
        "vm_id": "string",
        "ip_address": "string",
        "fqdn": "string"
    },
    "sha256": "string",
    "file_name": "string",
    "inspection_status": "string",
    "threat_score": 0,
    "verdict": "string",
    "error_message": "string",
    "error_code": "string",
    "is_blocked": false,
    "is_excluded": false,
    "node_type": "string",
    "node_id": "string",
    "gateway_id": "string"
}
inspection_time
Optional

Timestamp in milliseconds since epoch.

server
Optional

Details about the Virtual Machine.

client
Optional

Details about the Virtual Machine.

string
sha256
Optional

SHA256 hash of the file.

string
file_name
Optional

Name of the file as observed in this instance of inspection.

inspection_status
Optional

Denotes the current analysis status of the inspection event.

Enumeration: IN_PROGRESS, COMPLETED, ERROR
integer
threat_score
Optional

Threat score assigned to this inspection event. Threat score in the range of 0 to 100 for known verdict. A score of 100 is considered high potential threat. Score -1 indicates the verdict is UNINSPECTED because file is excluded. Any score outside the range of -1 to 100 will mean that verdict is UNKNOWN.

verdict
Optional

This property describes the behavior of the file at runtime. Following is the meaning of each verdict:

  • BENIGN: File with no malicious code.
  • TRUSTED: Behavioural analysis or prevalence indicates a trusted file.
  • HIGHLY_TRUSTED: File from a highly trusted source. For example, Microsoft published the file.
  • SUSPICIOUS: File contains suspicious code and on execution can turn out to be a malware.
  • MALICIOUS: File is a malicious file containing malware or bad code that can harm the system.
  • UNKNOWN: File behavior is UNKNOWN at this point in time or there is some error in the analysis pipeline and verdict could not be concluded.
  • UNINSPECTED: File is marked as excluded and hence was not inspected by the analysis pipeline.
Enumeration: BENIGN, TRUSTED, HIGHLY_TRUSTED, SUSPICIOUS, MALICIOUS, UNKNOWN, UNINSPECTED
string
error_message
Optional

Error message corresponding to this inspection event. This field will be populated only when there is some error in the inspection.

string
error_code
Optional

Error code corresponding to this inspection event. This field will be populated only when there is some error in the inspection.

boolean
is_blocked
Optional

This field conveys if the file is blocked by Malware Prevention Service.

boolean
is_excluded
Optional

A value of true implies the file is present in the exclusion list. An excluded file is not inspected.

node_type
Optional

Type of node on which endpoint or network activity is reported.

Enumeration: HOST, GATEWAY, SENSOR, INVALID
node_id
Optional

ID of the node from which event was generated. A node could be hypervisor host, NSX Edge or Sensor.

string
gateway_id
Optional

ID of the Tier0 or Tier1 gateway on which this file is detected. Tier0 or Tier1 gateway are logical routers of NSX-T topology.