Graph search · GraphQL enum

GraphObjectType enum

An enumeration of the different types of security graph objects.

Values

Enum Value Description

ACCOUNT_POLICY

The AccountPolicy graph object type.

ACTIVE_DIRECTORY

The ActiveDirectory graph object type.

ADMINISTRATIVE_TEMPLATES_WINDOWS

The AdministrativeTemplatesWindows graph object type.

APPLICATION

The Application graph object type.

APPLICATION_INSTALL

The ApplicationInstall graph object type.

APPLICATION_INSTALL_USER_SETTINGS

The ApplicationInstallUserSettings graph object type.

ARP_TABLE_ENTRY

The ArpTableEntry graph object type.

AUDIT_POLICY

The AuditPolicy graph object type.

DEVICE

The Device graph object type.

DEVICE_MANUFACTURER

The DeviceManufacturer graph object type.

DEVICE_MODEL

The DeviceModel graph object type.

DISK

The Disk graph object type.

DISK_MOUNT

The DiskMount graph object type.

ENDPOINT

The Endpoint graph object type.

ENDPOINT_GROUP

The EndpointGroup graph object type.

ENDPOINT_PATH

The EndpointPath graph object type.

ENDPOINT_USER

The EndpointUser graph object type.

EXECUTABLE

The Executable graph object type.

FINDING

The Finding graph object type.

INTERFACE

The Interface graph object type.

ISSUE

The Issue graph object type.

LOCAL_POLICIES

The LocalPolicies graph object type.

LOCATION

The Location graph object type.

LOGON_SESSION

The LogonSession graph object type.

NETWORK

The Network graph object type.

NETWORK_PREFIX

The NetworkPrefix graph object type.

OPEN_PORT

The OpenPort graph object type.

POSITION_SEEN

The PositionSeen graph object type.

ROUTE

The Route graph object type.

RULE

The Rule graph object type.

SECURITY

The Security graph object type.

SERVICE

The Service graph object type.

SOFTWARE_UPDATE_PREFERENCES

The SoftwareUpdatePreferences graph object type.

SYSTEM_SERVICE

The SystemService graph object type.

SYSTEM_SETTINGS

The SystemSettings graph object type.

UNRECOGNIZED

Unrecognized graph object type.

USER_SYSTEM_SETTINGS

The UserSystemSettings graph object type.

WLAN_INTERFACE

The WlanInterface graph object type.

WLAN_INTERFACE_CONNECTION

The WlanInterfaceConnection graph object type.

WLAN_NETWORK

The WlanNetwork graph object type.

WLAN_ACCESS_POINT

The WlanAccessPoint graph object type.

Used by

  • AccountPolicy type: The local account password and lockout policy in effect on an Endpoint.
  • ActiveDirectory type: The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.
  • AdministrativeTemplatesWindows type: The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.
  • Application type: A software product as an identity shared across an organization, independent of any one computer.
  • ApplicationInstall type: One installed copy of an application on one Endpoint.
  • ApplicationInstallUserSettings type: The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
  • ArpTableEntry type: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…
  • AuditPolicy type: The security event auditing configuration of an Endpoint.
  • Device type: A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • DeviceManufacturer type: A hardware vendor that made one or more discovered Device objects in an organization.
  • DeviceModel type: A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.
  • Disk type: A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…
  • DiskMount type: A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).
  • Endpoint type: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointGroup type: An operating system or domain group observed on an Endpoint.
  • EndpointPath type: The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…
  • EndpointUser type: An operating system or domain user account observed on an Endpoint.
  • Executable type: A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.
  • Finding type: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
  • Interface type: A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…
  • Issue type: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
  • LocalPolicies type: The local security policy settings of an Endpoint.
  • Location type: A physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.
  • LogonSession type: A user logon session observed on an Endpoint, identified by the username and the time the session started.
  • Network type: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • NetworkPrefix type: A specific IP address together with its subnet prefix length (e.g.
  • OpenPort type: One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
  • PositionSeen type: A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
  • Route type: One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.
  • Security type: The security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.
  • Service type: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
  • SoftwareUpdatePreferences type: The operating system update configuration of an Endpoint and the updates currently available to it.
  • SystemService type: A background service or daemon configured on an Endpoint.
  • SystemSettings type: The machine-wide operating system configuration of an Endpoint.
  • UserSystemSettings type: The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
  • WlanAccessPoint type: A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…
  • WlanInterface type: A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
  • WlanNetwork type: A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.
  • GraphObjectTypeInfo type: Describes a single graph object type: its enum value, the relationships it participates in, and the properties available for use in search query…
  • GraphObjectTypesInput input: Input for selecting which graph object types are returned by a graph object types query.

And 10 more.

Related types

  • AccountPolicy The local account password and lockout policy in effect on an Endpoint.
  • ActiveDirectory The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.
  • AdministrativeTemplatesWindows The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.
  • Application A software product as an identity shared across an organization, independent of any one computer.
  • ApplicationInstall One installed copy of an application on one Endpoint.
  • ApplicationInstallUserSettings The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.
  • ArpTableEntry One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…
  • AuditPolicy The security event auditing configuration of an Endpoint.
  • Device A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…
  • DeviceManufacturer A hardware vendor that made one or more discovered Device objects in an organization.
  • DeviceModel A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.
  • Disk A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…
  • DiskMount A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).
  • Endpoint A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
  • EndpointGroup An operating system or domain group observed on an Endpoint.
  • EndpointPath The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…
  • EndpointUser An operating system or domain user account observed on an Endpoint.
  • Executable A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.
  • Finding The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.
  • Interface A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…
  • Issue The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.
  • LocalPolicies The local security policy settings of an Endpoint.
  • Location A physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.
  • LogonSession A user logon session observed on an Endpoint, identified by the username and the time the session started.
  • Network An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…
  • NetworkPrefix A specific IP address together with its subnet prefix length (e.g.
  • OpenPort One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…
  • PositionSeen A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.
  • Route One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.
  • Security The security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.
  • Service A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…
  • SoftwareUpdatePreferences The operating system update configuration of an Endpoint and the updates currently available to it.
  • SystemService A background service or daemon configured on an Endpoint.
  • SystemSettings The machine-wide operating system configuration of an Endpoint.
  • UserSystemSettings The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.
  • WlanAccessPoint A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…
  • WlanInterface A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.
  • WlanNetwork A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.

Example

Example

"ACCOUNT_POLICY"