CEF Extension
| CEF Extension | Description | Values | Sample Value |
|---|---|---|---|
| act | Type of the event. |
|
Installed |
| alert_details | Event details. | app_hash: 9061187fbd6aa0cf978bfe9928158cf41c53c70a884f9d8b279a52e232fa3a9a | |
| app_name | Related application name, if relevant. | Google Photos | |
| app_pacakge | Application package name, if relevant. | com.google.photos | |
| bssid | BSSID of the attacking network. | None | |
| cat | Mobile Security event category. | Alert | |
| cnt | Mobile Security event ID. | 1232 | |
| cs1 | Device type. |
|
iPhone |
| cs1Label | Custom string label Device Type. | DeviceType | DeviceType |
| cs2 | Phone number of the device. | +44 7469 376815 | |
| cs2Label | Custom string label Phone. | Phone | Phone |
| cs3 | Device OS version. | 15.6.1 | |
| cs3Label | Custom string label OS level. | OSLevel | OSLevel |
| cs4 | Model of the device. | Multiple | iPhone / iPhone 11 |
| cs4Label | Custom string label DeviceDetails. | DeviceDetails | DeviceDetails |
| cs5 | Certificate of the attacking network. | ||
| cs5Label | Custom string label NetworkCertificate | NetworkCertificate | NetworkCertificate |
| cs6 | Current device risk level. |
|
0.6 |
| cs6Label | Custom string label Current Device Risk. | Current device risk. | Custom string label |
| deviceDirection | Is ARP Poisoning network. |
|
None |
| deviceExternalId | Device UUID | Multiple | 971225 |
| deviceInboundInterface | If the device is rooted or jailbroken. |
|
False |
| device_client_version | Version of the client app. | M.m.mm.b | 4.0.2.9119 |
| duid | Device Tracking ID. | AAA23C40-6577-4321-8B74-25454123457D | |
| duser | User Email. | user@example.com | |
| dvchost | Host | example-tenant.locsec.net | |
| externalId | Device UUID. | F112343S-4123-4b69-90ff-0234DFHGHFY9 | |
| fileHash | SHA256 identifier of the binary. | 9061187fbd6aa0cf978bfe9928158cf41c53c70a884f9d8b279a52e232fa3a9a | |
| fileId | Application version. | 6.4.469058872 | |
| filePermission | Application was repackaged or not. |
|
False |
| fileType | Description of the app threats. | The application accesses the device data. It can backup sensitive information from the device. | |
| msg | Event details. | app_hash: 9061187fbd6aa0cf978bfe9928158cf41c53c70a884f9d8b279a52e232fa3a9a | |
| resource | Malicious URL blocked by Mobile Security. | None | |
| rt | Event Client Timestamp. | 1662318312000 | |
| sender | DEPRECATED, SMS sender number. | None | |
| sms_urls | DEPRECATED, URLs found in SMS. | None | |
| ssid | SSID (name) of the attacking Wi-Fi network. | None | |
| start | Event Received timestamp. | 1662318312000 | |
| suid | Network location. |
|
None |
| suser | Phone name. | Jhon's iPhone | |
| uuid | Device UUID for Airwatch UEM. | None |