CEF Extension

CEF Extension Description Values Sample Value
act Type of the event.
  • Non-compliant
  • Compliant
  • Policy changed
  • Active
  • Inactive
  • Disconnected
  • Detected
  • Ended
  • Installed
  • Removed
  • Blocked
  • Prevented
  • Enabled
  • Disabled
Installed
alert_details Event details. app_hash: 9061187fbd6aa0cf978bfe9928158cf41c53c70a884f9d8b279a52e232fa3a9a
app_name Related application name, if relevant. Google Photos
app_pacakge Application package name, if relevant. com.google.photos
bssid BSSID of the attacking network. None
cat Mobile Security event category. Alert
cnt Mobile Security event ID. 1232
cs1 Device type.
  • Android_4_x
  • iPhone
iPhone
cs1Label Custom string label Device Type. DeviceType DeviceType
cs2 Phone number of the device. +44 7469 376815
cs2Label Custom string label Phone. Phone Phone
cs3 Device OS version. 15.6.1
cs3Label Custom string label OS level. OSLevel OSLevel
cs4 Model of the device. Multiple iPhone / iPhone 11
cs4Label Custom string label DeviceDetails. DeviceDetails DeviceDetails
cs5 Certificate of the attacking network.
cs5Label Custom string label NetworkCertificate NetworkCertificate NetworkCertificate
cs6 Current device risk level.
  • Unknown - cs6 = 0
  • None - cs6 = 0
  • Low - 0 < cs6 <= 0.3
  • Medium - 0.3 < cs6 <= 0.6
  • High - 0.6 < cs6 <= 1
0.6
cs6Label Custom string label Current Device Risk. Current device risk. Custom string label
deviceDirection Is ARP Poisoning network.
  • None
  • True
  • False
None
deviceExternalId Device UUID Multiple 971225
deviceInboundInterface If the device is rooted or jailbroken.
  • True
  • False
False
device_client_version Version of the client app. M.m.mm.b 4.0.2.9119
duid Device Tracking ID. AAA23C40-6577-4321-8B74-25454123457D
duser User Email. user@example.com
dvchost Host example-tenant.locsec.net
externalId Device UUID. F112343S-4123-4b69-90ff-0234DFHGHFY9
fileHash SHA256 identifier of the binary. 9061187fbd6aa0cf978bfe9928158cf41c53c70a884f9d8b279a52e232fa3a9a
fileId Application version. 6.4.469058872
filePermission Application was repackaged or not.
  • False
  • True
False
fileType Description of the app threats. The application accesses the device data. It can backup sensitive information from the device.
msg Event details. app_hash: 9061187fbd6aa0cf978bfe9928158cf41c53c70a884f9d8b279a52e232fa3a9a
resource Malicious URL blocked by Mobile Security. None
rt Event Client Timestamp. 1662318312000
sender DEPRECATED, SMS sender number. None
sms_urls DEPRECATED, URLs found in SMS. None
ssid SSID (name) of the attacking Wi-Fi network. None
start Event Received timestamp. 1662318312000
suid Network location.
  • Latitude
  • Longitude
  • None
None
suser Phone name. Jhon's iPhone
uuid Device UUID for Airwatch UEM. None