Event Structure

Field Description Values Sample Value
URL Source tenant URL HM tenant URL dashboardurl.locsec.net
AttackVector Attack vector
  • Application
  • Cellular network
  • WIFI network
  • Device OS
  • Exploits iOS profiles
  • Network Security
Application
Product Name of reporting product. Mobile Security Mobile Security
Threat Factors Type of the threat. See Threat Factor List. Backup Tool
EventType Type of the event.
  • Non-compliant
  • Compliant
  • Policy changed
  • Active
  • Inactive
  • Disconnected
  • Detected
  • Ended
  • Installed
  • Removed
  • Blocked
  • Prevented
  • Enabled
  • Disabled
Removed
RiskLevel Risk level of the event.
  • None
  • Low
  • Medium
  • High
  • Info
Info
DeviceID Internal Mobile Security device ID. 1111
Client Client application. Mobile Security Protect Mobile Security Protect
Device Client Version Version of the client application. M.m.mm.b 3.2.0.3986
DeviceOwner Name of the device owner. testUser
DeviceEmail Email of the device owner. email@example.com
DeviceNumber Phone number of the device. 9720000000
DeviceType Device type. Android_4_x, iPhone Android_4_x
DeviceOSLevel Device OS version. 6.0.1
DeviceModel Model of the device. Multiple samsung / SM-G930F
DeviceRiskLevel Current device risk level.
  • Unknown - cs6 = 0
  • None - cs6 = 0
  • Low - 0 < cs6 <= 0.3
  • Medium - 0.3 < cs6 <= 0.6
  • High - 0.6 < cs6 <= 1

cs6 is the custom string label for current device risk level.

0.0
Event ID Internal ID of the event. 13
Event Timestamp Event received timestamp. 1586078275000
Event Client Timestamp Event occurred timestamp. 1586078274000
Device Tracking ID 3c55d882-f2c8-48ac-ba3a-91a1afab3f5e
Host Type Type of the endpoint. Mobile Mobile
APP name Name of the application, if the Attack Vector is Application. Photos
APP package Application package name. com.google.android.apps.photos
APP Threat summary Description of the app threats. The application accesses the device data. It can backup sensitive information from the device
APP SHA256 SHA256 identifier of the binary. 382c9be98a2e63539dc8....
App version Application version. 1.1/24
App repackaged App was repackaged or not.
  • False
  • True
False
APP Developer Developer of the app. None
APP Developer Certificate Certificate of the app. None
System APP If system app or not. None
APP Link Link to the official app store. None
Network bssid BSSID of the attacking network. None
Network Certificate Certificate of the attacking network. None
sms_urls DEPRECATED, URLs found in SMS. None
Sender DEPRECATED, SMS sender number. None
Location Geo location of attacking network. None
ssid SSID (name) of the attacking Wi-Fi network. None
Devicerootedjailbroken If the device is rooted or jailbroken.
  • False
  • True
False
Network Resource Malicious URL blocked by Mobile Security. None