# Active Defence (Deception)

Version 1.0

\\

| **Field Name**                       | **Data Type** |
| ------------------------------------ | :-----------: |
| ads.service.app\_language            |      text     |
| ads.service.app\_remote              |      text     |
| ads.service.arch\_remote             |      text     |
| ads.service.audit\_action            |      text     |
| ads.service.client\_remote           |      text     |
| ads.service.client\_response         |      text     |
| ads.service.command                  |      text     |
| ads.service.command\_args            |      text     |
| ads.service.community\_string        |      text     |
| ads.service.database\_name           |      text     |
| ads.service.filename                 |      text     |
| ads.service.host\_domain             |      text     |
| ads.service.host\_remote             |      text     |
| ads.service.log\_msg                 |      text     |
| ads.service.name\_local              |      text     |
| ads.service.name\_remote             |      text     |
| ads.service.opcode                   |      text     |
| ads.service.repo\_name               |      text     |
| ads.service.request\_call\_id        |      text     |
| ads.service.request\_contact         |      text     |
| ads.service.request\_content\_length |      int      |
| ads.service.request\_cseq            |      text     |
| ads.service.request\_from            |      text     |
| ads.service.request\_max\_forwards   |      int      |
| ads.service.request\_mime\_type      |      text     |
| ads.service.request\_oid             |      text     |
| ads.service.request\_to              |      text     |
| ads.service.request\_via             |      text     |
| ads.service.server\_address          |      text     |
| ads.service.server\_challenge        |      text     |
| ads.service.session\_id              |      text     |
| ads.service.share\_filename          |      text     |
| ads.service.share\_name              |      text     |
| ads.service.status                   |      text     |
| ads.service.transfer\_mode           |      text     |
| ads.service.url\_domain              |      text     |
| ads.service.url\_path                |      text     |
| ads.service.user\_agent              |      text     |
| ads.service.user\_name               |      text     |
| ads.service.user\_password           |      text     |
| ads.service.version\_local           |      text     |
| ads.service.version\_remote          |      text     |
| ads.service.web\_module              |      text     |
| ads.token.auth                       |      text     |
| ads.token.channel                    |      text     |
| ads.token.id                         |      text     |
| ads.token.manage\_url                |      text     |
| ads.token.reminder\_text             |      text     |
| ads.token.text                       |      text     |
| ads.token.type                       |      text     |
| ads.token.user\_agent                |      text     |
| agent.hostname                       |      text     |
| agent.type                           |      text     |
| destination.as.number                |      text     |
| destination.as.organization.name     |      text     |
| destination.geo.city\_name           |      text     |
| destination.geo.continent\_code      |      text     |
| destination.geo.country\_code        |      text     |
| destination.geo.country\_name        |      text     |
| destination.geo.location.lat         |    geopoint   |
| destination.geo.location.lon         |    geopoint   |
| destination.geo.region\_name         |      text     |
| destination.ip                       |       ip      |
| destination.locality                 |      text     |
| destination.port                     |      int      |
| event.action                         |      text     |
| event.category                       |     array     |
| event.code                           |      int      |
| event.created                        |   date/time   |
| event.dataset                        |      text     |
| event.kind                           |      text     |
| event.module                         |      text     |
| event.original                       |      text     |
| event.provider                       |      text     |
| event.type                           |     array     |
| file.directory                       |      text     |
| file.path                            |      text     |
| http.request.body.content            |      text     |
| http.request.lang                    |      text     |
| http.request.method                  |      text     |
| http.request.mime\_type              |      text     |
| http.response.status\_code           |      int      |
| input.type                           |      text     |
| log.file.path                        |      text     |
| message                              |      text     |
| network.community.id                 |      text     |
| node.name                            |      text     |
| observer.as.number                   |      text     |
| observer.as.organization.name        |      text     |
| observer.geo.city\_name              |      text     |
| observer.geo.continent\_code         |      text     |
| observer.geo.country\_code           |      text     |
| observer.geo.country\_name           |      text     |
| observer.geo.location.lat            |    geopoint   |
| observer.geo.location.lon            |    geopoint   |
| observer.geo.region\_name            |      text     |
| observer.hostname                    |      text     |
| observer.interface                   |      text     |
| observer.ip                          |       ip      |
| observer.locality                    |      text     |
| observer.mac                         |      text     |
| observer.type                        |      text     |
| observer.version                     |      text     |
| organization.id                      |      text     |
| related.hash                         |     array     |
| related.hosts                        |     array     |
| related.ip                           |     array     |
| related.user                         |     array     |
| sensor.id                            |      text     |
| service.address                      |       ip      |
| service.name                         |      text     |
| service.type                         |      text     |
| source.as.number                     |      text     |
| source.as.organization.name          |      text     |
| source.geo.city\_name                |      text     |
| source.geo.continent\_code           |      text     |
| source.geo.country\_code             |      text     |
| source.geo.country\_name             |      text     |
| source.geo.location.lat              |    geopoint   |
| source.geo.location.lon              |    geopoint   |
| source.geo.region\_name              |      text     |
| source.ip                            |       ip      |
| source.locality                      |      text     |
| source.port                          |      int      |
| threat.indicator.lookup              |      text     |
| threat.indicator.type                |       ip      |
| threatintel.days                     |      int      |
| threatintel.entity                   |      text     |
| threatintel.event\_data              |      text     |
| threatintel.lookup                   |      text     |
| threatintel.malware.malware          |      text     |
| threatintel.malware.timestamp        |   date/time   |
| threatintel.severity                 |      text     |
| threatintel.tags                     |      text     |
| threatintel.white\_list              |      text     |
| url.domain                           |      text     |
| url.path                             |      text     |
| user.name                            |      text     |
| user.password                        |      text     |
| user\_agent.original                 |      text     |
| uuid                                 |      text     |


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.blusapphire.io/taxonomy/active-defence-deception.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
