A single extended attribute (xattr) entry. The raw bytes are preserved verbatim; if the bytes form valid UTF-8, the decoded string is also provided as a convenience.
Fields
| Field Name | Description |
|---|---|
keyRaw - Binary!
|
Raw xattr key bytes as collected from the filesystem. |
keyString - String
|
UTF-8 decoded form of keyRaw. Null when keyRaw is not valid UTF-8. |
valueRaw - Binary!
|
Raw xattr value bytes as collected from the filesystem. |
valueString - String
|
UTF-8 decoded form of valueRaw. Null when valueRaw is not valid UTF-8. |
Used by
EndpointPathLinuxtype: Linux-specific EndpointPath fields.EndpointPathMacOStype: macOS-specific EndpointPath fields.
Example
Example
{
"keyRaw": Binary,
"keyString": "xyz789",
"valueRaw": Binary,
"valueString": "xyz789"
}