An enumeration of the different types of security graph objects.
Values
| Enum Value | Description |
|---|---|
|
|
The AccountPolicy graph object type. |
|
|
The ActiveDirectory graph object type. |
|
|
The AdministrativeTemplatesWindows graph object type. |
|
|
The Application graph object type. |
|
|
The ApplicationInstall graph object type. |
|
|
The ApplicationInstallUserSettings graph object type. |
|
|
The ArpTableEntry graph object type. |
|
|
The AuditPolicy graph object type. |
|
|
The Device graph object type. |
|
|
The DeviceManufacturer graph object type. |
|
|
The DeviceModel graph object type. |
|
|
The Disk graph object type. |
|
|
The DiskMount graph object type. |
|
|
The Endpoint graph object type. |
|
|
The EndpointGroup graph object type. |
|
|
The EndpointPath graph object type. |
|
|
The EndpointUser graph object type. |
|
|
The Executable graph object type. |
|
|
The Finding graph object type. |
|
|
The Interface graph object type. |
|
|
The Issue graph object type. |
|
|
The LocalPolicies graph object type. |
|
|
The Location graph object type. |
|
|
The LogonSession graph object type. |
|
|
The Network graph object type. |
|
|
The NetworkPrefix graph object type. |
|
|
The OpenPort graph object type. |
|
|
The PositionSeen graph object type. |
|
|
The Route graph object type. |
|
|
The Rule graph object type. |
|
|
The Security graph object type. |
|
|
The Service graph object type. |
|
|
The SoftwareUpdatePreferences graph object type. |
|
|
The SystemService graph object type. |
|
|
The SystemSettings graph object type. |
|
|
Unrecognized graph object type. |
|
|
The UserSystemSettings graph object type. |
|
|
The WlanInterface graph object type. |
|
|
The WlanInterfaceConnection graph object type. |
|
|
The WlanNetwork graph object type. |
|
|
The WlanAccessPoint graph object type. |
Used by
AccountPolicytype: The local account password and lockout policy in effect on an Endpoint.ActiveDirectorytype: The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.AdministrativeTemplatesWindowstype: The Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.Applicationtype: A software product as an identity shared across an organization, independent of any one computer.ApplicationInstalltype: One installed copy of an application on one Endpoint.ApplicationInstallUserSettingstype: The settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.ArpTableEntrytype: One entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…AuditPolicytype: The security event auditing configuration of an Endpoint.Devicetype: A physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…DeviceManufacturertype: A hardware vendor that made one or more discovered Device objects in an organization.DeviceModeltype: A specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.Disktype: A physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…DiskMounttype: A file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.EndpointGrouptype: An operating system or domain group observed on an Endpoint.EndpointPathtype: The single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…EndpointUsertype: An operating system or domain user account observed on an Endpoint.Executabletype: A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.Findingtype: The record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.Interfacetype: A network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…Issuetype: The triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.LocalPoliciestype: The local security policy settings of an Endpoint.Locationtype: A physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.LogonSessiontype: A user logon session observed on an Endpoint, identified by the username and the time the session started.Networktype: An IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…NetworkPrefixtype: A specific IP address together with its subnet prefix length (e.g.OpenPorttype: One TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…PositionSeentype: A geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.Routetype: One entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.Securitytype: The security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.Servicetype: A network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…SoftwareUpdatePreferencestype: The operating system update configuration of an Endpoint and the updates currently available to it.SystemServicetype: A background service or daemon configured on an Endpoint.SystemSettingstype: The machine-wide operating system configuration of an Endpoint.UserSystemSettingstype: The per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.WlanAccessPointtype: A Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…WlanInterfacetype: A wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.WlanNetworktype: A Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.GraphObjectTypeInfotype: Describes a single graph object type: its enum value, the relationships it participates in, and the properties available for use in search query…GraphObjectTypesInputinput: Input for selecting which graph object types are returned by a graph object types query.
And 10 more.
Related types
AccountPolicyThe local account password and lockout policy in effect on an Endpoint.ActiveDirectoryThe Active Directory (AD) domain membership and directory-binding configuration of an Endpoint.AdministrativeTemplatesWindowsThe Group Policy Administrative Templates (ADMX) settings applied to a Windows Endpoint, read from the policy registry values those templates write.ApplicationA software product as an identity shared across an organization, independent of any one computer.ApplicationInstallOne installed copy of an application on one Endpoint.ApplicationInstallUserSettingsThe settings one EndpointUser has configured for one ApplicationInstall, so there is at most one object per user and install on an Endpoint.ArpTableEntryOne entry in an Endpoint's neighbor cache: the IPv4 Address Resolution Protocol (ARP) table and, where the operating system reports it, the IPv6…AuditPolicyThe security event auditing configuration of an Endpoint.DeviceA physical or virtual device that does not run the Wartiva endpoint application but is visible on the network to a managed Endpoint, such as…DeviceManufacturerA hardware vendor that made one or more discovered Device objects in an organization.DeviceModelA specific product model, made by a DeviceManufacturer, that one or more discovered Device objects in an organization are instances of.DiskA physical disk drive attached to an Endpoint, identified on that Endpoint by its operating-system drive ID (for example \\.\PhysicalDrive0 on…DiskMountA file system mounted on an Endpoint, identified by its device and mount point (for example C: on Windows or / on Linux and macOS).EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.EndpointGroupAn operating system or domain group observed on an Endpoint.EndpointPathThe single graph object a PathSensor produces on an Endpoint, so an Endpoint has one EndpointPath per sensor that has reported data from it; list…EndpointUserAn operating system or domain user account observed on an Endpoint.ExecutableA unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.FindingThe record of a policy Rule evaluating FAIL against one graph object, such as an Endpoint, Device, or network service.InterfaceA network interface (physical, virtual, loopback, or tunnel) on an Endpoint, collected from Windows, macOS, and Linux endpoints as part of the…IssueThe triage record for a policy violation: a security concern on one graph object that needs remediation or a decision.LocalPoliciesThe local security policy settings of an Endpoint.LocationA physical place identified by its global plus code (Open Location Code), with a street address resolved by reverse geocoding.LogonSessionA user logon session observed on an Endpoint, identified by the username and the time the session started.NetworkAn IP network (subnet) that a managed Endpoint has been attached to, identified by its address range in CIDR notation and, for networks outside a…NetworkPrefixA specific IP address together with its subnet prefix length (e.g.OpenPortOne TCP or UDP port at one IP address on a discovered Device, found by managed endpoints port-scanning the devices on their local networks and by…PositionSeenA geographic coordinate (latitude and longitude) where a managed Endpoint was observed, and the times it was seen there.RouteOne entry in an Endpoint's IP routing table, collected from Windows, macOS, and Linux endpoints as part of the periodic network inventory.SecurityThe security posture of an Endpoint: its firewall, anti-malware and disk encryption state, summarized as per-component health ratings in Health.ServiceA network service identified on a discovered Device: one protocol (such as HTTP, TLS, SSH, SMB, DNS, SNMP, IPP, mDNS, or UPnP) acting as a client or…SoftwareUpdatePreferencesThe operating system update configuration of an Endpoint and the updates currently available to it.SystemServiceA background service or daemon configured on an Endpoint.SystemSettingsThe machine-wide operating system configuration of an Endpoint.UserSystemSettingsThe per-user operating system configuration of one user account on an Endpoint, complementing the machine-wide SystemSettings.WlanAccessPointA Wi-Fi access point radio, identified by the network name (SSID) it broadcasts and its BSSID, as heard by managed endpoints scanning for nearby…WlanInterfaceA wireless LAN (Wi-Fi) adapter on an Endpoint, collected from Windows, macOS, and Linux endpoints by the periodic Wi-Fi inventory.WlanNetworkA Wi-Fi network identified by its network name (SSID), visible to managed endpoints when they scan for nearby networks on Windows, macOS, or Linux.
Example
Example
"ACCOUNT_POLICY"