Event Structure
| Field | Description | Values | Sample Value |
|---|---|---|---|
| URL | Source tenant URL | HM tenant URL | dashboardurl.locsec.net |
| AttackVector | Attack vector |
|
Application |
| Product | Name of reporting product. | Mobile Security | Mobile Security |
| Threat Factors | Type of the threat. | See Threat Factor List. | Backup Tool |
| EventType | Type of the event. |
|
Removed |
| RiskLevel | Risk level of the event. |
|
Info |
| DeviceID | Internal Mobile Security device ID. | 1111 | |
| Client | Client application. | Mobile Security Protect | Mobile Security Protect |
| Device Client Version | Version of the client application. | M.m.mm.b | 3.2.0.3986 |
| DeviceOwner | Name of the device owner. | testUser | |
| DeviceEmail | Email of the device owner. | email@example.com | |
| DeviceNumber | Phone number of the device. | 9720000000 | |
| DeviceType | Device type. | Android_4_x, iPhone | Android_4_x |
| DeviceOSLevel | Device OS version. | 6.0.1 | |
| DeviceModel | Model of the device. | Multiple | samsung / SM-G930F |
| DeviceRiskLevel | Current device risk level. |
cs6 is the custom string label for current device risk level. |
0.0 |
| Event ID | Internal ID of the event. | 13 | |
| Event Timestamp | Event received timestamp. | 1586078275000 | |
| Event Client Timestamp | Event occurred timestamp. | 1586078274000 | |
| Device Tracking ID | 3c55d882-f2c8-48ac-ba3a-91a1afab3f5e | ||
| Host Type | Type of the endpoint. | Mobile | Mobile |
| APP name | Name of the application, if the Attack Vector is Application. | Photos | |
| APP package | Application package name. | com.google.android.apps.photos | |
| APP Threat summary | Description of the app threats. | The application accesses the device data. It can backup sensitive information from the device | |
| APP SHA256 | SHA256 identifier of the binary. | 382c9be98a2e63539dc8.... | |
| App version | Application version. | 1.1/24 | |
| App repackaged | App was repackaged or not. |
|
False |
| APP Developer | Developer of the app. | None | |
| APP Developer Certificate | Certificate of the app. | None | |
| System APP | If system app or not. | None | |
| APP Link | Link to the official app store. | None | |
| Network bssid | BSSID of the attacking network. | None | |
| Network Certificate | Certificate of the attacking network. | None | |
| sms_urls | DEPRECATED, URLs found in SMS. | None | |
| Sender | DEPRECATED, SMS sender number. | None | |
| Location | Geo location of attacking network. | None | |
| ssid | SSID (name) of the attacking Wi-Fi network. | None | |
| Devicerootedjailbroken | If the device is rooted or jailbroken. |
|
False |
| Network Resource | Malicious URL blocked by Mobile Security. | None |