#[non_exhaustive]pub struct ArtifactRecord {
pub uid: String,
pub artifact_id: &'static str,
pub artifact_name: &'static str,
pub scope: DataScope,
pub os_scope: OsScope,
pub timestamp: Option<String>,
pub fields: Vec<(&'static str, ArtifactValue)>,
pub meaning: String,
pub mitre_techniques: Vec<&'static str>,
pub confidence: f32,
}Expand description
A fully decoded forensic artifact record. This is the universal output type that all consumers receive – no raw bytes, no hardcoded field names.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Non-exhaustive structs could have additional fields added in future. Therefore, non-exhaustive structs cannot be constructed in external crates using the traditional
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.uid: StringGlobally unique URI, e.g. winreg://HKCU/Software/.../value_name or
file:///path/to/file#line.
artifact_id: &'static strThe catalog entry id that produced this record.
artifact_name: &'static strHuman-readable artifact name.
scope: DataScopeData scope (User/System/…).
os_scope: OsScopeOS scope.
timestamp: Option<String>Primary timestamp in ISO 8601 UTC, if the artifact has one.
fields: Vec<(&'static str, ArtifactValue)>Ordered decoded field name-value pairs.
meaning: StringHuman-readable meaning, possibly with interpolated field values.
mitre_techniques: Vec<&'static str>MITRE ATT&CK technique IDs applicable to this record.
confidence: f32Confidence score 0.0-1.0, set by the decoder or classifier.
Trait Implementations§
Source§impl Clone for ArtifactRecord
impl Clone for ArtifactRecord
Source§fn clone(&self) -> ArtifactRecord
fn clone(&self) -> ArtifactRecord
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for ArtifactRecord
impl Debug for ArtifactRecord
Source§impl PartialEq for ArtifactRecord
impl PartialEq for ArtifactRecord
impl StructuralPartialEq for ArtifactRecord
Auto Trait Implementations§
impl Freeze for ArtifactRecord
impl RefUnwindSafe for ArtifactRecord
impl Send for ArtifactRecord
impl Sync for ArtifactRecord
impl Unpin for ArtifactRecord
impl UnsafeUnpin for ArtifactRecord
impl UnwindSafe for ArtifactRecord
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more