ECS::LogEntry::Dll::CodeSignature
Inherits JSON::Serializable < Struct < Value < Object
Constructors
Instance methods
dll.code_signature.exists
Boolean to capture if a signature is present.
Level: Core Type: Boolean Example:
true
dll.code_signature.exists
Boolean to capture if a signature is present.
Level: Core Type: Boolean Example:
true
dll.code_signature.status
Additional information about the certificate status.
This is useful for logging cryptographic errors with the certificate validity or trust status. Leave unpopulated if the validity or trust of the certificate was unchecked.
Level: Extended Type: Keyword Example:
ERROR_UNTRUSTED_ROOT
dll.code_signature.status
Additional information about the certificate status.
This is useful for logging cryptographic errors with the certificate validity or trust status. Leave unpopulated if the validity or trust of the certificate was unchecked.
Level: Extended Type: Keyword Example:
ERROR_UNTRUSTED_ROOT
dll.code_signature.subject_name
Subject name of the code signer
Level: Core Type: Keyword Example:
Microsoft Corporation
dll.code_signature.subject_name
Subject name of the code signer
Level: Core Type: Keyword Example:
Microsoft Corporation
dll.code_signature.trusted
Stores the trust status of the certificate chain.
Validating the trust of the certificate chain may be complicated, and this field should only be populated by tools that actively check the status.
Level: Extended Type: Boolean Example:
true
dll.code_signature.trusted
Stores the trust status of the certificate chain.
Validating the trust of the certificate chain may be complicated, and this field should only be populated by tools that actively check the status.
Level: Extended Type: Boolean Example:
true
dll.code_signature.valid
Boolean to capture if the digital signature is verified against the binary content.
Leave unpopulated if a certificate was unchecked.
Level: Extended Type: Boolean Example:
true
dll.code_signature.valid
Boolean to capture if the digital signature is verified against the binary content.
Leave unpopulated if a certificate was unchecked.
Level: Extended Type: Boolean Example:
true