The Cloud object describes the cloud computing environment where an event or finding originated. It provides comprehensive context about the cloud infrastructure, including the cloud service provider, account or subscription details, organizational structure, geographic regions, availability zones, and logical partitions.
Attributes
Section titled “Attributes”provider
- Type:
string_t - Requirement: required
The unique name of the Cloud services provider where the event or finding was created, such as AWS, MS Azure, GCP, etc.
region
- Type:
string_t - Requirement: recommended
The cloud region where the event or finding was created, as defined by the cloud provider.
Examples:
- AWS: Region where the event occurred (
us-east-1,eu-west-1) - Azure: Region where the event occurred (
East US,West Europe) - GCP: Region where the event occurred (
us-central1,europe-west1) - Oracle Cloud: Region where the event occurred (
us-ashburn-1,uk-london-1)
account
- Type:
account - Requirement: optional
The Account object containing details about the cloud account, subscription, or billing unit where the event or finding was created. This object includes properties such as the account name, unique identifier, type, labels, and tags.
Examples:
- AWS: Account object with
name,uid(Account ID),type, and other account properties - Azure: Subscription object with
name,uid(Subscription ID),type, and subscription metadata - GCP: Project object with
name,uid(Project ID),type, and project attributes - Oracle Cloud: Compartment object with
name,uid(Tenancy OCID),type, and compartment details
cloud_partition
- Type:
string_t - Requirement: optional
The logical grouping or isolated segment within a cloud provider’s infrastructure where the event or finding was created, often used for compliance, governance, or regional separation.
Examples:
- AWS: Partition where the event occurred (
aws,aws-cn,aws-us-gov) - Azure: Cloud environment where the event occurred (
AzureCloud,AzureUSGovernment,AzureChinaCloud)
org
- Type:
organization - Requirement: optional
The Organization object containing details about the organizational unit or management structure that governs the account, subscription, or project where the event or finding was created. This object includes properties such as the organization name, unique identifier, type, and other organizational metadata.
Examples:
- AWS: Organization object with
name,uid(Organization ID),type, and other organizational properties - Azure: Management Group object with
name,uid(Management Group ID),type, and management group metadata - GCP: Organization object with
name,uid(Organization ID),type, and organizational attributes - Oracle Cloud: Tenancy object with
name,uid(Tenancy OCID),type, and tenancy details
project_uid
- Type:
string_t - Requirement: optional
The unique identifier of a Cloud project.
zone
- Type:
string_t - Requirement: optional
The availability zone in the cloud region where the event or finding was created, as defined by the cloud provider.
Examples:
- AWS: Availability zone where the event occurred (
us-east-1a,us-east-1b) - Azure: Availability zone where the event occurred (
1,2,3within a region) - GCP: Availability zone where the event occurred (
us-central1-a,us-central1-b) - Oracle Cloud: Availability zone where the event occurred (
AD-1,AD-2,AD-3)
Used By
Section titled “Used By”account_changeadmin_group_queryairborne_broadcast_activityapi_activityapplication_errorapplication_lifecycleapplication_security_posture_findingauthenticationauthorize_sessionbase_eventcloud_resources_inventory_infocompliance_findingconfig_statedata_security_findingdatastore_activitydetection_findingdevice_config_state_changedhcp_activitydns_activitydrone_flights_activityemail_activityemail_file_activityemail_url_activityentity_managementevent_log_actvityevidence_infofile_activityfile_hostingfile_queryfile_remediation_activityfolder_queryftp_activitygroup_managementhttp_activityiam_analysis_findingincident_findinginventory_infojob_querykernel_activitykernel_extension_activitykernel_object_querymemory_activitymodule_activitymodule_querynetwork_activitynetwork_connection_querynetwork_file_activitynetwork_remediation_activitynetworks_queryntp_activityosint_inventory_infopatch_stateperipheral_activityperipheral_device_queryprocess_activityprocess_queryprocess_remediation_activityrdp_activityremediation_activityscan_activityscheduled_job_activityscript_activitysecurity_findingservice_querysession_querysmb_activitysoftware_infossh_activitystartup_item_querytunnel_activityuser_accessuser_inventoryuser_queryvulnerability_findingweb_resource_access_activityweb_resources_activitywin/prefetch_querywin/registry_key_activitywin/registry_key_querywin/registry_value_activitywin/registry_value_querywin/windows_resource_activitywin/windows_service_activity