Turbine Schema Reference (AI SOC)
Turbine Schema was formerly known as Turbine Extensible Data Schema, or TEDS.
This document describes the Turbine Schema objects used by the AI SOC Solution. For general concepts, best practices, and troubleshooting, see Working with Turbine SchemaWorking with Turbine Schema.
For additional Turbine Schema objects used across solutions (Observable, Enrichment, File, File Hash, Header, MIME Part, Detection Rule, Attack, Tactic, Technique, Status, Error, Content, User, and Cloud Storage Query Input), see Turbine Schema Reference (Classic SOC)Turbine Schema Reference (Classic SOC).
For AI SOC interface contracts (Alert to Alert, Alert Search Params, Email Search Params, and Alert Triage Ingestion), see AI SOC InterfacesAI SOC Interfaces.
Alert Object
The AI SOC Alert object captures security events and incidents from SIEM, XDR, and EDR systems. It includes fields for alert identification, severity and priority, host and user context, MITRE ATT&CK and D3FEND mappings, observables, and supporting evidence.
Name | Key | Type | Requirement | Description |
|---|---|---|---|---|
Alert UID | alert_uid | String | Required | Unique identifier for the alert |
Title | alert_title | String | Recommended | Name or title of the alert |
Description | alert_description | String | Recommended | Brief summary of the alert, detailing the nature and significance of the event |
Severity | alert_severity | String | Recommended | Alert severity level (for example, High, Medium, Low) |
Priority | alert_priority | String | Optional | Alert priority, distinct from severity, used for triage ordering |
Category | alert_categories | String Array | Optional | Classification of the alert (for example, "Phishing," "Malware," "Unauthorized Access") |
Created Timestamp | alert_created_timestamp | Datetime | Recommended | Date and time when the alert was first generated |
Start Timestamp | alert_start_timestamp | Datetime | Recommended | When the triggering activity began |
End Timestamp | alert_end_timestamp | Datetime | Recommended | When the triggering activity ended |
Ingested Timestamp | alert_ingested_timestamp | Datetime | Recommended | When the alert was ingested into the system |
Provider | alert_provider | String | Optional | Tool or service that generated the alert |
Organization | alert_organization | String | Optional | Organization impacted by the alert |
Organization ID | alert_organization_id | String | Optional | Unique identifier for the impacted organization |
Permalink | alert_permalink | String | Optional | Direct link to the alert in the source system |
Risk Score | alert_risk_score | Integer | Optional | Risk score as determined by the alerting system |
Detection Rules | alert_rules | Detection Rule Array | Recommended | Rules that triggered the alert |
MITRE ATT&CK Tactic/Technique | alert_mitre_attack_tactic_technique | Array | Optional | MITRE ATT&CK tactics and techniques associated with the alert |
MITRE D3FEND Techniques | mitre_d3fend_techniques | String Array | Optional | MITRE D3FEND defensive techniques applicable to the alert |
Impacted Hostnames | alert_impacted_hostnames | String Array | Optional | Hostnames of devices affected by the alert |
Impacted IP Addresses | alert_impacted_ip_addresses | IP Address Array | Optional | IP addresses associated with impacted devices |
Impacted Usernames | alert_impacted_usernames | String Array | Optional | Usernames of users impacted by the alert |
Host ID | alert_host_id | String | Optional | Unique identifier of the affected host |
Host Criticality | alert_host_criticality | String | Optional | Criticality level of the affected host (for example, Critical, High, Medium, Low) |
Host Data Raw | alert_host_data_raw | String | Optional | Raw host data from the alerting system |
User Data Raw | alert_user_data_raw | String | Optional | Raw user data from the alerting system |
Command Line Commands | alert_command_line_commands | String | Optional | Command line commands associated with the alert activity |
Supporting Evidence | alert_supporting_evidence | String | Optional | Additional evidence supporting the alert determination |
Entities | alert_entities | Object Array | Optional | Structured entities associated with the alert (for example, processes, registry keys, network connections) |
Originating Files | alert_originating_files | File Array | Optional | Files involved in the alert |
Observables | observables | Observable Array | Recommended | Indicators of compromise (IOCs) linked to the alert |
Raw Alert | raw_alert | JSON | Required | Raw JSON format of the alert as received from the source |
Alert Object Example
{
"alert_uid": "crowdstrike-detection-20260115-001234",
"alert_title": "Suspicious PowerShell Execution Detected",
"alert_description": "PowerShell script executed with encoded commands on host WORKSTATION-01",
"alert_severity": "High",
"alert_priority": "P1",
"alert_created_timestamp": "2026-01-15T10:30:00Z",
"alert_start_timestamp": "2026-01-15T10:28:15Z",
"alert_end_timestamp": "2026-01-15T10:30:00Z",
"alert_ingested_timestamp": "2026-01-15T10:30:05Z",
"alert_provider": "CrowdStrike Falcon",
"alert_organization": "Acme Corporation",
"alert_organization_id": "org-acme-001",
"alert_categories": ["Malware", "Execution"],
"alert_impacted_hostnames": ["WORKSTATION-01"],
"alert_impacted_ip_addresses": ["192.168.1.100"],
"alert_impacted_usernames": ["jdoe"],
"alert_host_id": "host-abc123",
"alert_host_criticality": "High",
"alert_host_data_raw": "{\"os\": \"Windows 11\", \"agent_version\": \"7.04\"}",
"alert_user_data_raw": "{\"department\": \"Engineering\", \"role\": \"Developer\"}",
"alert_command_line_commands": "powershell.exe -EncodedCommand SQBuAHYAbwBrAGU...",
"alert_supporting_evidence": "Process tree analysis shows parent cmd.exe spawned by suspicious macro in document.docx",
"alert_entities": [
{
"entity_type": "process",
"entity_name": "powershell.exe",
"entity_id": "pid-4521"
}
],
"alert_risk_score": 85,
"alert_permalink": "https://falcon.crowdstrike.com/detections/001234",
"alert_rules": [
{
"rule_id": "CS-DET-001",
"rule_name": "Suspicious PowerShell Execution",
"rule_description": "Detects PowerShell execution with base64 encoded commands",
"rule_type": "behavioral"
}
],
"alert_mitre_attack_tactic_technique": [
{
"tactics": [
{
"uid": "TA0002",
"name": "Execution"
}
],
"technique": {
"uid": "T1059.001",
"name": "PowerShell"
},
"version": "14.1"
}
],
"mitre_d3fend_techniques": [
"D3-PSA",
"D3-SEA"
],
"observables": [
{
"observable_type": "sha256",
"observable_value": "a3b5c7d9e1f2a3b5c7d9e1f2a3b5c7d9e1f2a3b5c7d9e1f2a3b5c7d9e1f2a3b5"
}
],
"raw_alert": {
"detection_id": "ldt:abc123:456",
"severity": 85,
"tactic": "Execution",
"technique": "PowerShell"
}
}Email Object
The AI SOC Email object captures email metadata for phishing triage and email-based threat analysis. It includes fields for message content, recipients, email authentication (SPF, DMARC, DKIM), sender analysis, and MITRE D3FEND mappings.
Name | Key | Type | Requirement | Description |
|---|---|---|---|---|
Message ID | email_message_id | String | Required | The Message-ID header value |
From Address | email_from_address | Email Address | Required | Email address in the From header |
To Addresses | email_to_addresses | Email Address Array | Required | Email recipients in the To header |
CC Addresses | email_cc_addresses | Email Address Array | Optional | CC recipients |
BCC Addresses | email_bcc_addresses | Email Address Array | Optional | BCC recipients |
Reply-To Addresses | email_reply_to_addresses | Email Address Array | Optional | Reply-To addresses |
Subject | email_subject | String | Recommended | The Subject header |
Body | email_body | String | Recommended | Email body (HTML version if available, otherwise text) |
HTML Body | email_html_body | String | Optional | HTML part of the email |
Text Body | email_text_body | String | Optional | Plain text part of the email |
Origination Timestamp | email_origination_timestamp | Datetime | Required | Time from the Date header when the email was sent |
Delivery Timestamp | email_delivery_timestamp | Datetime | Optional | Delivery time of the email |
Organization | email_organization | String | Optional | Recipient organization |
Headers | email_headers | Header Array | Optional | All email headers as key/value pairs |
MIME Parts | email_mime_parts | MIME Part Array | Optional | Non-multipart MIME parts of the email |
SPF Check | email_spf_check | String | Optional | SPF (Sender Policy Framework) authentication check result (for example, "pass," "fail," "softfail") |
SPF Results | email_spf_results | String | Optional | Detailed SPF check results |
DMARC Check | email_dmarc_check | String | Optional | DMARC (Domain-based Message Authentication) check result |
DMARC Results | email_dmarc_results | String | Optional | Detailed DMARC check results |
DKIM Check | email_dkim_check | String | Optional | DKIM (DomainKeys Identified Mail) authentication check result |
DKIM Results | email_dkim_results | String | Optional | Detailed DKIM check results |
Return Path | email_return_path | String | Optional | Email Return-Path header value |
MTA | email_mta | String | Optional | Mail Transfer Agent that handled the email |
Sender | email_sender | String | Optional | Sender identity (may differ from From address) |
Sender Domain | email_sender_domain | String | Optional | Domain of the sender |
Sender IP | email_sender_ip | String | Optional | IP address of the sending mail server |
Top-Level Content Type | email_top_level_content_type | String | Optional | Top-level MIME content type of the email (for example, "multipart/mixed") |
Additional Information | email_additional_information | String | Optional | Additional context or information about the email |
MITRE D3FEND Techniques | mitre_d3fend_techniques | String Array | Optional | MITRE D3FEND defensive techniques applicable to this email |
Observables | observables | Observable Array | Recommended | Indicators of compromise within the email |
Raw Email | raw_email | String | Recommended | Raw email content as received by the server |
Email Object Example
{
"email_message_id": "<[email protected]>",
"email_from_address": "[email protected]",
"email_to_addresses": ["[email protected]"],
"email_cc_addresses": [],
"email_bcc_addresses": [],
"email_reply_to_addresses": ["[email protected]"],
"email_subject": "Urgent: Action Required on Your Account",
"email_body": "<html><body>Click here to verify your account...</body></html>",
"email_html_body": "<html><body>Click here to verify your account...</body></html>",
"email_text_body": "Click here to verify your account: http://phishing-site.com/verify",
"email_origination_timestamp": "2026-01-15T09:00:00Z",
"email_delivery_timestamp": "2026-01-15T09:00:15Z",
"email_organization": "Example Corp",
"email_spf_check": "fail",
"email_spf_results": "v=spf1 -all: sender 203.0.113.1 not permitted",
"email_dmarc_check": "fail",
"email_dmarc_results": "p=reject; dkim=fail; spf=fail",
"email_dkim_check": "fail",
"email_dkim_results": "signature verification failed",
"email_return_path": "[email protected]",
"email_mta": "mail.malicious-domain.com",
"email_sender": "[email protected]",
"email_sender_domain": "malicious-domain.com",
"email_sender_ip": "203.0.113.1",
"email_top_level_content_type": "multipart/mixed",
"email_additional_information": "Email flagged by gateway filter for suspicious URL patterns",
"mitre_d3fend_techniques": [
"D3-MFA",
"D3-EAL"
],
"email_headers": [
{
"header_key": "Received",
"header_value": "from mail.malicious-domain.com ([203.0.113.1])"
},
{
"header_key": "Authentication-Results",
"header_value": "spf=fail; dkim=fail; dmarc=fail"
}
],
"observables": [
{
"observable_type": "url",
"observable_value": "http://phishing-site.com/verify",
"observable_primary_provider": "URLHaus",
"observable_primary_verdict": "Malicious"
},
{
"observable_type": "ipv4_public",
"observable_value": "203.0.113.1",
"observable_primary_provider": "Recorded Future",
"observable_primary_verdict": "Suspicious"
}
],
"raw_email": "Return-Path: <[email protected]>..."
}Additional Turbine Schema Objects
The following Turbine Schema objects are used within the AI SOC Solution as sub-objects of Alerts, Emails, and other structures. Refer to Turbine Schema Reference (Classic SOC)Turbine Schema Reference (Classic SOC) for their complete field definitions:
- Observable -- security-relevant entities (IP addresses, domains, file hashes, URLs)
- Enrichment -- threat intelligence context added to observables
- File -- file metadata and content
- File Hash -- hash algorithm and value pairs
- Header -- HTTP or email header key/value pairs
- MIME Part -- email MIME part data
- Detection Rule -- rules that trigger alerts
- Attack -- MITRE ATT&CK technique and tactic mappings
- Tactic -- individual ATT&CK tactic identifiers
- Technique -- individual ATT&CK technique identifiers
- Content -- file-like content or attachments
- Error -- error tracking objects
- Status -- tool or service status objects
- User -- user account information
- Simple Observable -- lightweight observable without enrichment data
- Cloud Storage Query Input -- cloud storage search parameters