Networks, devices, and sensors · GraphQL type

ArpTableEntryDuplicate type

Another ARP table entry claiming the same IP address as the entry that records it, with a different MAC address — an address conflict, and the shape ARP spoofing and cache poisoning take in the cache.

This is recorded on the entry rather than reached through a relationship so that the conflict can be read, and evaluated by a policy rule, from the entry alone.

Fields

Field Name Description
id - ID The identifier of the conflicting ArpTableEntry on the security graph. Null when that entry is no longer present on the graph, which happens once it ages out of retention while this record of the conflict survives.
mac - Mac! The MAC address the conflicting entry claims for the address. Carried here so the conflict — and what each side of it claims — reads without resolving the other entry.
isActive - Boolean! Whether this conflict was present in the most recent observation of the endpoint's ARP table. False means the conflict resolved and this is a record of the past.
firstSeen - Time! When this conflict was first observed.
lastSeen - Time! When this conflict was last observed. For an active conflict this is the most recent ARP table update.

Used by

  • ArpTableEntry type: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…

Related types

  • ArpTableEntry One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…

Example

Example

{
  "id": 4,
  "mac": "f0:18:98:14:8e:80",
  "isActive": true,
  "firstSeen": "2021-10-07T18:23:25.829Z",
  "lastSeen": "2021-10-07T18:23:25.829Z"
}