Skip to content

Latest commit

 

History

History
49 lines (42 loc) · 2.02 KB

LEGACY-S00111.md

File metadata and controls

49 lines (42 loc) · 2.02 KB

Rules: Threat Intel - Device IP Matched Threat Intel URL

Description

A record flagged a URL from a threat intelligence match list

Additional Details

Detail Value
Type Match
Category Threat Intelligence
Apply Risk to Entities device_hostname, srcDevice_hostname, device_ip, device_natIp, srcDevice_ip, srcDevice_natIp, device_mac, srcDevice_mac, user_username, dns_replyIp
Signal Name Threat Intel - Device IP Matched Threat Intel URL
Summary Expression None
Score/Severity Static: 4
Enabled by Default True
Prototype False
Tags

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema device_mac
Normalized Schema device_natIp
Normalized Schema dns_replyIp
Normalized Schema listMatches
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema srcDevice_mac
Normalized Schema srcDevice_natIp
Normalized Schema user_username