File path sensors · GraphQL type

EndpointPathEntryStats type

The stat record of one file a PathSensor discovered, stored as alternate data on the owning EndpointPath object and retrieved with endpointPathEntryStats.

Fields

Field Name Description
path - String! The file's absolute path as reported by the endpoint.
mode - PosixFileMode! The file's permission bits decoded into octal, symbolic, per-class, and special-bit forms.
isDirectory - Boolean! True when this entry is a directory. Derived cross-platform from the file mode (and, on Windows, the DIRECTORY file attribute).
isSymlink - Boolean! True when this entry is a symbolic link. Populated on Linux and macOS (endpoints that lstat the file).
symlinkTarget - String The path a symbolic link points at, or null when this entry is not a symlink. Linux and macOS only.
isHardLink - Boolean! True when this entry is a regular file with more than one hard link (link count > 1). Linux and macOS only.
hardLinkCount - Int The file's POSIX hard-link count (st_nlink), or null on Windows where it is not collected.
inode - Int64 The file's inode number (st_ino). Together with deviceId it identifies the underlying inode, so files that are hard links of one another can be correlated. Null on Windows.
deviceId - Int64 The device id (st_dev) of the filesystem holding the file. Pairs with inode. Null on Windows.
ownerUid - Int The file's POSIX owner UID, or null on Windows (which has no POSIX ownership).
ownerGid - Int The file's POSIX owner GID, or null on Windows.
owner - EndpointUser The EndpointUser that owns this file, resolved from ownerUid on the same endpoint. Null on Windows or when no matching user has been observed.
group - EndpointGroup The EndpointGroup that owns this file, resolved from ownerGid on the same endpoint. Null on Windows or when no matching group has been observed.
size - Int64! File size in bytes.
modifiedAt - Time File modification time reported by the endpoint. Null when the endpoint reported no modification time — e.g. a file reported deleted (its mtime is no longer observable) or a report where the file could not be stat'd.
checksum - String! Checksum of the file on disk (xxh3-128, lowercase hex), or empty when none is available. It is populated when the sensor's collectChecksum is enabled (the endpoint hashes up to the sensor's checksumMaxBytes of the file, regardless of how much content was collected), or when contents were collected and covered the whole file (the server then hashes the stream with the same scheme). When contents were collected but truncated to contentMaxBytes and collectChecksum was not enabled, this is empty. See contentTruncated for whether the stored contents are a prefix.
hasContents - Boolean! True if file contents are stored for this file.
deleted - Boolean! True if this file was reported deleted on the endpoint. The stat record is retained and marked, not removed, so the deletion remains visible; the file's collected bytes are removed when the deletion is reported. A later sighting of the same path clears the marker.
deletedAt - Time When the endpoint reported this file as deleted, if it has been. Null for files still present.
renamedTo - String The path this file was renamed to, set only on deleted entries whose deletion was observed as a rename. The entry stays at the original path; the new path appears as its own entry when a sensor covers it. Null when the file was not renamed away.
executedAt - Time Set when the report this entry came from observed an open-for-execution of the file (execve, not an interpreter read) since the path's previous report; the timestamp is the report's collection time, not the exact exec time. Null when the covering report saw no execution.
contentTruncated - Boolean! True when the collected contents are only the first contentMaxBytes of a larger file (a prefix), rather than the whole file. Meaningful only when hasContents is true. When true, the blob behind the entry's contentsUrl and the bytes from its contentsAsString are a prefix, not the complete file. This is independent of checksum, which (when collectChecksum is enabled) reflects the file hashed up to the sensor's checksumMaxBytes regardless of how much content was stored — see checksum.
collectedAt - Time! When the endpoint collected this stat record.
osSpecific - EndpointPathOsSpecific OS-specific fields for this file. The concrete type depends on the endpoint platform.
creationTime - Time File creation time reported by the endpoint, when available.
lastWriteTime - Time Last write time reported by the endpoint, when available.
lastAccessTime - Time Last access time reported by the endpoint, when available.
lastChangeTime - Time Last metadata change time (Unix ctime) reported by the endpoint, when available.
lastStatusChangeTime - Time Last status change time reported by the endpoint, when available.

Returned by

  • endpointPathEntryStats query: Retrieves the stat record (mode, ownership, sizes, timestamps, and OS-specific attributes) of one file path discovered by an EndpointPath — list…

Used by

Related types

  • EndpointGroup An operating system or domain group observed on an Endpoint.
  • EndpointUser An operating system or domain user account observed on an Endpoint.

Example

Example

{
  "path": "xyz789",
  "mode": PosixFileMode,
  "isDirectory": true,
  "isSymlink": false,
  "symlinkTarget": "abc123",
  "isHardLink": true,
  "hardLinkCount": 123,
  "inode": "-8589934592",
  "deviceId": "-8589934592",
  "ownerUid": 987,
  "ownerGid": 123,
  "owner": EndpointUser,
  "group": EndpointGroup,
  "size": "-8589934592",
  "modifiedAt": "2021-10-07T18:23:25.829Z",
  "checksum": "xyz789",
  "hasContents": true,
  "deleted": true,
  "deletedAt": "2021-10-07T18:23:25.829Z",
  "renamedTo": "xyz789",
  "executedAt": "2021-10-07T18:23:25.829Z",
  "contentTruncated": true,
  "collectedAt": "2021-10-07T18:23:25.829Z",
  "osSpecific": EndpointPathWindows,
  "creationTime": "2021-10-07T18:23:25.829Z",
  "lastWriteTime": "2021-10-07T18:23:25.829Z",
  "lastAccessTime": "2021-10-07T18:23:25.829Z",
  "lastChangeTime": "2021-10-07T18:23:25.829Z",
  "lastStatusChangeTime": "2021-10-07T18:23:25.829Z"
}