An open file snapshot and when it was last observed.
Fields
| Field Name | Description |
|---|---|
value - OpenFile!
|
The observed open file. |
seen - SeenOnline!
|
When this value was observed. |
Used by
Executabletype: A unique executable file observed running on an Endpoint, aggregating data across all observed processes that share the same file system path.
Example
Example
{
"value": OpenFile,
"seen": SeenOnline
}