A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path. There is one Executable per path per Endpoint, built from the process lists the agent collects on Windows, macOS, and Linux. Each Executable keeps the peak CPU, memory, and thread count seen across its processes, plus the files and network sockets those processes were observed holding open, each with its own seen history. Use executablesSeen on the Endpoint for when each Executable was observed running.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The Executable's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
seen - SeenOnline!
|
Describes when this executable was last seen running on the Endpoint. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
endpoint - Endpoint
|
The Endpoint this Executable belongs to if available. |
path - String!
|
The full file system path of the executable. |
name - String!
|
The name of the executable file. |
cpuPercent - Float
|
The maximum CPU usage percentage observed across all processes, on a 0 to 100 scale (not a 0 to 1 fraction), e.g. 62.5 meaning 62.5%. |
memory - ProcessMemory
|
The maximum memory usage observed across all processes (by total size). |
threads - Uint64
|
The maximum thread count observed across all processes. |
openFiles - [OpenFile!]
|
Files observed open by processes of this executable. |
openFilesSeen - [SeenOpenFile!]
|
Files observed open by processes of this executable with their seen-online history. |
openSockets - [OpenSocket!]
|
Sockets observed open by processes of this executable. |
openSocketsSeen - [SeenOpenSocket!]
|
Sockets observed open by processes of this executable with their seen-online history. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
executablequery: Retrieves an Executable by its graph object id: a unique executable file seen running on an endpoint, aggregating the peak resource use of its…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.ExecutableConnectiontype: Collection payload for Executable edges with total count.ExecutableEdgetype: Edge payload for an Executable with optional seen data.ExecutablePayloadtype: Payload wrapper for a single Executable result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "xyz789",
"displayName": "xyz789",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"endpoint": Endpoint,
"path": "abc123",
"name": "xyz789",
"cpuPercent": 123.45,
"memory": ProcessMemory,
"threads": "8589934592",
"openFiles": [OpenFile],
"openFilesSeen": [SeenOpenFile],
"openSockets": [OpenSocket],
"openSocketsSeen": [SeenOpenSocket],
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}