ECS Field Reference
ECS 8.17
Vulnerability
⚠️ Outdated Version: You are viewing ECS version 8.17, which is outdated. View the latest version (9.0)
ECS Version:

Vulnerability

Fields to describe the vulnerability relevant to an event.

Fields

Field Summary

FieldTypeLevelDescription
vulnerability.categorykeywordExtendedCategory of a vulnerability.
vulnerability.classificationkeywordExtendedClassification of the vulnerability.
vulnerability.descriptionkeywordExtendedDescription of the vulnerability.
vulnerability.description.textmatch_only_textExtendedDescription of the vulnerability.
vulnerability.enumerationkeywordExtendedIdentifier of the vulnerability.
vulnerability.idkeywordExtendedID of the vulnerability.
vulnerability.referencekeywordExtendedReference of the vulnerability.
vulnerability.report_idkeywordExtendedScan identification number.
vulnerability.scanner.vendorkeywordExtendedName of the scanner vendor.
vulnerability.score.basefloatExtendedVulnerability Base score.
vulnerability.score.environmentalfloatExtendedVulnerability Environmental score.
vulnerability.score.temporalfloatExtendedVulnerability Temporal score.
vulnerability.score.versionkeywordExtendedCVSS version.
vulnerability.severitykeywordExtendedSeverity of the vulnerability.

Field Details

vulnerability.category

Type: keyword

Level: Extended

Description: Category of a vulnerability.

Example: ["Firewall"]

Normalization: array

Indexed: true

vulnerability.classification

Type: keyword

Level: Extended

Description: Classification of the vulnerability.

Example: CVSS

Indexed: true

vulnerability.description

Type: keyword

Level: Extended

Description: Description of the vulnerability.

Example: In macOS before 2.12.6, there is a vulnerability in the RPC...

Indexed: true

vulnerability.description.text

Type: match_only_text

Level: Extended

Description: Description of the vulnerability.

Example: In macOS before 2.12.6, there is a vulnerability in the RPC...

Indexed: true

vulnerability.enumeration

Type: keyword

Level: Extended

Description: Identifier of the vulnerability.

Example: CVE

Indexed: true

vulnerability.id

Type: keyword

Level: Extended

Description: ID of the vulnerability.

Example: CVE-2019-00001

Indexed: true

vulnerability.reference

Type: keyword

Level: Extended

Description: Reference of the vulnerability.

Example: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6111

Indexed: true

vulnerability.report_id

Type: keyword

Level: Extended

Description: Scan identification number.

Example: 20191018.0001

Indexed: true

vulnerability.scanner.vendor

Type: keyword

Level: Extended

Description: Name of the scanner vendor.

Example: Tenable

Indexed: true

vulnerability.score.base

Type: float

Level: Extended

Description: Vulnerability Base score.

Example: 5.5

Indexed: true

vulnerability.score.environmental

Type: float

Level: Extended

Description: Vulnerability Environmental score.

Example: 5.5

Indexed: true

vulnerability.score.temporal

Type: float

Level: Extended

Description: Vulnerability Temporal score.

Indexed: true

vulnerability.score.version

Type: keyword

Level: Extended

Description: CVSS version.

Example: 2.0

Indexed: true

vulnerability.severity

Type: keyword

Level: Extended

Description: Severity of the vulnerability.

Example: Critical

Indexed: true