Graph Icon Descriptions

The following icons are used throughout Cisco XDR to represent assets and observables.

Icon

Category

Description

computer-tower

Asset

endpoint, endpoint.digital-telephone-handset, endpoint.laptop, endpoint.pos-terminal, endpoint.printer, endpoint.sensor, endpoint.server, endpoint.smart meter, endpoint.smart-phone, endpoint.tablet, endpoint.workstation

git-fork

Asset

network, network.bridge, network.firewall, network.gateway, network.guard, network.hips, network.hub, network.ids, network.ips, network.modem, network.nic, network.proxy, network.router, network.security_manager, network.sense_making, network.sensor, network.switch, network.vpn, network.wap

Asset/Observable

process, process_name, process_hash

terminal-window

Asset

process,aaa-server, process.anti-virus-scanner, process.connection-scanner, process.directory-service, process.dns-server, process.email-service, process.file-scanner, process.location-service, process.network-scanner, process.remediation-service, process.reputation-service, process.sandbox, process.virtualization-server, process.vulnerability-scanner.

brackets-curly

Observable

amp_computer_guid

certificate

Observable

certificate_common_name, certificate_issuer, certificate_serial, pki_serial.

tag-chevron

Observable

cisco_cm_id, cisco_mid, cisco_uc_id.

app-window

Observable

crowdstrike_id, cybereason_id

power

Observable

device

globe

Observable

domain

envelope

Observable

email, email_messageid

envelope-open

Observable

email_subject

file

Observable

file_name, sha1, sha256

folder-notch-open

Observable

file_path

desktop

Observable

hostname

circuitry

Observable

imei, imsi

hard-drives

Observable

ip, ipv6

cpu

Observable

mac_address

hash

Observable

md5

lock

Observable

mutex

wall

Observable

ngfw_id, ngfw_name

hard-drive

Observable

odns_identity, odns_identity_label

asterisk

Observable

orbital_node_id

file-code

Observable

process_args, process_path, process_username

code-block

Observable

registry_key, registry_name, registry_path

barcode

Observable

serial_number

cloud

Observable

swc_device_id, trend_micro_id, s1_agent_id, ms_machine_id

browser

Observable

url

user

Observable

user, user_agent