Rules: Threat Intel - Device IP Matched Threat Intel URL
A record flagged a URL from a threat intelligence match list
Detail | Value |
---|---|
Type | Match |
Category | Threat Intelligence |
Apply Risk to Entities | device_hostname, srcDevice_hostname, device_ip, device_natIp, srcDevice_ip, srcDevice_natIp, device_mac, srcDevice_mac, user_username, dns_replyIp |
Signal Name | Threat Intel - Device IP Matched Threat Intel URL |
Summary Expression | None |
Score/Severity | Static: 4 |
Enabled by Default | True |
Prototype | False |
Tags |
- CheckPoint - URL Filtering
- Cisco Systems - Meraki
- Cisco Systems - Umbrella
- Fortinet - Fortigate
- Google - Google Cloud Platform
- Imperva - Imperva Incapsula
- Netskope - Security Cloud
- Palo Alto Networks - Next Generation Firewall
- Proofpoint - Targeted Attack Protection
- Squid - Squid Proxy
- Symantec - Web Security Service
- Zscaler - Nanolog Streaming Service
Origin | Field |
---|---|
Normalized Schema | device_hostname |
Normalized Schema | device_ip |
Normalized Schema | device_mac |
Normalized Schema | device_natIp |
Normalized Schema | dns_replyIp |
Normalized Schema | listMatches |
Normalized Schema | srcDevice_hostname |
Normalized Schema | srcDevice_ip |
Normalized Schema | srcDevice_mac |
Normalized Schema | srcDevice_natIp |
Normalized Schema | user_username |