Pack Contributors:
- Francisco Javier Fernández Jiménez
- Timothy Roberts
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.
This Content Pack will get you up and running in no-time and provide you with the most commonly used incident & indicator fields and types.
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.
| Name | Description |
|---|---|
Mail Listener - Classifier | Classifies phishing email messages. |
Mail Listener - Incoming Mapper | Maps incoming phishing email messages fields. |
| Name | Description |
|---|---|
Suspicious Executions Found | |
Parent Process IDs | |
Log Source Name | The log source name associated with the event. |
User Block Status | |
Number of Related Incidents | |
Process SHA256 | |
Destination Network | |
Item Owner Email | |
Application Path | |
Risk Name | |
EmailCampaignCanvas | |
File Names | |
Account Name | Account Name |
Vulnerability Category | |
Org Level 2 | |
Unique Ports | |
Tenant Name | Tenant Name |
Job Family | Job Family |
Cloud Service | |
Device Username | The username of the user that owns the device |
Part of Campaign | The ID of the campaign incident of which the current incident is part of. |
Ticket Number | |
CVSS Confidentiality Requirement | The CVSS confidentiality requirement of the asset. |
IP Blocked Status | |
Is Active | Alert status |
External Category Name | |
Technique | |
Resource Type | |
Critical Assets | A table of critical assets involved in the incident, including the name and asset type. |
Country Code | |
Related Report | |
Incident Link | |
User Agent | |
Last Modified By | |
Account ID | |
Parent Process File Path | |
Password Changed Date | |
Src | Source |
Asset ID | |
Policy Remediable | |
Dest NT Domain | Destination NT Domain |
Timezone | |
Tactic | |
Report Name | |
Source Priority | |
app channel name | |
Threat Hunting Detected Hostnames | |
Approver | The person who approved or needs to approve the request. |
Destination Geolocation | The destination geolocation of the event. |
Subtype | Subtype |
Additional Indicators | |
User Groups | |
Cloud Account ID | |
Events | The events associated with the offense. |
Cloud Instance ID | Cloud Instance ID |
Source IPV6 | The source IPV6 address. |
OutgoingMirrorError | |
Device External IPs | |
App message | |
Agent Version | Reporting Agent/Sensor Version |
Surname | Surname |
Source Network | |
Destination IPV6 | The destination IPV6 address. |
First Name | First Name |
Technical User | The technical user of the asset. |
Alert Name | Alert name as received from the integration JSON |
Source Username | The username that was the source of the attack. |
Detected External IPs | Detected external IPs |
Additional Email Addresses | |
Blocked Action | Blocked Action |
Policy ID | |
Dest | Destination |
EmailCampaignSnippets | |
Objective | |
Process ID | |
CVSS Availability Requirement | The CVSS availability requirement for the asset. |
Given Name | Given Name |
Policy Recommendation | |
Mobile Phone | |
Source Updated by | |
Identity Type | |
Related Endpoints | |
Use Case Description | |
Registry Key | |
Destination MAC Address | The destination MAC address in an event. |
Affected Users | |
Description | The description of the incident |
Destination Port | The destination port used. |
Domain Registrar Abuse Email | |
Source Create time | |
End Time | The time when the offense ended. |
Dst Ports | The destination ports of the event. |
Referenced Resource ID | |
Src OS | Src OS |
MITRE Tactic ID | |
Number of similar files | |
Triggered Security Profile | Triggered Security Profile |
ASN | |
Detected Internal IPs | Detected internal IPs |
URL SSL Verification | Indicates whether the URLs passed the SSL certificate verification. |
SSDeep | |
Signature | |
Personal Email | |
Remediation SLA | The time it took since remediation of the incident began, and until it ended. |
Device OS Version | |
Attack Patterns | |
Dest Hostname | Destination hostname |
Source Created By | |
MITRE Technique Name | |
Alert URL | Alert URL as received from the integration JSON |
Employee Manager Email | The email address of the employee's manager. |
Protocols | |
Closing User | The closing user. |
Endpoints Details | |
Source MAC Address | The source MAC address in an event. |
CMD line | |
Process Creation Time | |
Process Name | |
Country Name | Country Name |
Destination IP | The IP address the impossible traveler logged in to. |
Appliance Name | Appliance name as received from the integration JSON |
Low Level Categories Events | The low level category of the event. |
Location Region | Location Region |
Last Mirrored Time Stamp | The last time the incident was mirrored in. |
similarIncidents | |
External Confidence | |
Source Geolocation | The source geolocation of the event. |
Detection Update Time | |
Appliance ID | Appliance ID as received from the integration JSON |
Domain Name | |
Org Unit | |
Destination IPs | The destination IPs of the event. |
OS Version | OS Version |
Rule Name | The name of a YARA rule |
Error Code | |
External Sub Category Name | |
Event ID | Event ID |
Custom Query Results | |
Phone Number | Phone number |
Region ID | |
Job Code | Job Code |
MD5 | MD5 |
MAC Address | MAC Address |
Manager Email Address | |
Event Type | Event Type |
Agents ID | |
Alert Malicious | Whether the alert is malicious. |
Sensor Name | |
Verdict | |
Registry Value | |
Registry Hive | |
Full Name | Person's Full Name |
Threat Name | Define the threat name such as malware/exploit/phishing/etc |
Command Line Verdict | |
SHA256 | SHA256 |
High Risky Hosts | |
Pre Nat Source IP | The source IP before NAT. |
Incident Duration | How long it took for the playbook of the incident to finish, from the moment it started. |
Pre Nat Source Port | The source port before NAT. |
App | |
Src NT Domain | Source NT Domain |
File SHA1 | |
SKU Name | |
Additional Data | |
Dsts | The destination values. |
Selected Indicators | Includes the indicators selected by the user. |
Duration | |
Device OS Name | |
Protocol - Event | The network protocol in the event. |
Parent Process | |
Scenario | |
Parent Process CMD | |
Investigation Stage | The stage of the investigation. |
User SID | |
Username | The username of the account who logged in. |
Domain Squatting Result | The result of the domain-squatting check for the attacker's email. |
Parent Process Name | |
Related Alerts | |
Hunt Results Count | |
Related Campaign | |
Process MD5 | |
Close Time | The closing time. |
Registry Value Type | |
Acquisition Hire | |
MITRE Tactic Name | |
File Hash | |
Verification Method | The method used to verify the user. |
User Id | User Id |
First Seen | |
Registration Email | |
Resource Name | |
Alert Rules | |
Last Update Time | |
Ticket Opened Date | |
CVE | |
Hostnames | The hostname in the event. |
Last Name | Last Name |
Category Count | The number of categories that are associated with the offense. |
Containment SLA | The time it took to contain the incident. |
Rendered HTML | The HTML content in a rendered form. |
Tool Usage Found | |
Device Status | |
Post Nat Source Port | The source port after NAT. |
Detection ID | |
Block Indicators Status | |
Process Paths | |
Src Ports | The source ports of the event. |
Destination Hostname | Destination hostname |
Escalation | |
Cloud Operation Type | |
Ticket Acknowledged Date | |
Detected Internal Hosts | Detected internal hosts |
Endpoint Isolation Status | |
Manager Name | Manager Name |
Changed | The user who changed this incident |
File MD5 | |
Users | |
Policy Details | |
Event Action | Action taken on user accounts - Create, Update, Deactivate, Reactivate |
CMD | |
Post Nat Destination IP | The destination IP address after NAT. |
Threat Family Name | Threat Family Name Associated with an Attacking Vector. I.E. Meterpreter as toolkit or Extortion\ֿFraud\Espionage |
Tools | |
File Access Date | |
IncomingMirrorError | |
Reporter Email Address | The email address of the user who reported the email. |
Department | Department |
User Creation Time | |
Vendor Product | |
External Category ID | |
Birthday | Person's Birthday |
Classification | Incident Classification |
File Relationships | |
Isolated | Isolated |
CVSS Integrity Requirement | The CVSS integrity requirement for the asset. |
Account Status | |
Tactic ID | |
PID | PID |
String Similarity Results | |
Rating | |
Assignment Group | |
Policy Actions | |
Bugtraq | |
Policy Severity | |
IP Reputation | |
SHA1 | SHA1 |
Alert Acknowledgement | Alert acknowledgement as received from the integration JSON |
Event Names | The event name (translated QID ) in the event. |
Cost Center Code | Cost Center Code |
Risk Score | |
Application Name | Application Name |
Srcs | The source values. |
Vulnerable Product | |
Title | Title |
Device Id | Device Id |
Threat Hunting Detected IP | |
Display Name | Display Name |
External Status | |
Device Model | Device Model |
Alert Action | Alert action as received from the integration JSON |
Source External IPs | |
Alert Attack Time | |
Agent ID | Agent ID |
Alert tags | |
Technical Owner | The technical owner of the asset. |
Referenced Resource Name | |
Cloud Resource List | |
Process CMD | |
Compliance Notes | Notes regarding the assets compliance. |
Last Modified On | |
Destination Networks | |
File SHA256 | |
Src User | Source User |
Number Of Found Related Alerts | Medium or Higher Severity Alerts |
Number Of Log Sources | The number of log sources related to the offense. |
State | State |
SKU TIER | |
Detection SLA | The time it took from incident creation until the maliciousness was determined. |
Users Details | |
ASN Name | |
Event Descriptions | The description of the event name. |
Employee Email | The email address of the employee. |
OS | The operating system. |
Detected IPs | |
Detection End Time | |
Command Line | Command Line |
UUID | UUID as received from the integration JSON |
Device Name | Device Name |
RemovedFromCampaigns | |
Alert Source | |
User Engagement Response | |
Device OU | Device's OU path in Active Directory |
CVSS Collateral Damage Potential | The CVSS collateral damage potential of the asset. |
Log Source Type | The log source type associated with the event. |
Dest OS | Destination OS |
Verification Status | The status of the user verification. |
Alert Category | The category of the alert |
External End Time | |
Usernames | The username in the event. |
SHA512 | SHA512 |
File Paths | |
External Start Time | |
External Severity | |
Child Process | |
Group ID | |
Policy Deleted | |
Cost Center | Cost Center |
CVE Published | |
Post Nat Destination Port | The destination port after NAT. |
Status Reason | |
Pre Nat Destination Port | The destination port before NAT. |
Alert ID | Alert ID as received from the integration JSON |
sAMAccountName | User sAMAAccountName |
Email Sent Successfully | Whether the email has been successfully sent. |
Country | The country from which the user logged in. |
Work Phone | |
High Risky Users | |
Device Internal IPs | |
Detected External Hosts | Detected external hosts |
High Level Categories | The high level categories in the events. |
Protocol names | |
Src Hostname | Source hostname |
Domain Updated Date | |
Traffic Direction | The direction of the traffic in the event. |
Failed Logon Events Timeframe | The timeframe which the failed logon events occurred in. |
Follow Up | True if marked for follow up. |
Risk Rating | |
Street Address | |
External Link | |
Raw Event | The unparsed event data. |
Policy Type | |
Source Port | The source port that was used |
Caller | |
Triage SLA | The time it took to investigate and enrich incident information. |
City | |
File Upload | Used to upload files to incidents in a way that would make them distinguishable from the rest of the incident files. This field can be used, for example, to execute commands on manually uploaded files with the click of an incident layout button. |
Approval Status | The status for the approval of the request. |
Assigned User | Assigned User |
User Anomaly Count | |
Failed Logon Events | The number of failed logon events in a specific timeframe. Can be used with reference to the "Failed Logon Events Timeframe" field. |
Resource URL | |
Audit Logs | |
Password Reset Successfully | Whether the password has been successfully reset. |
CVSS | |
Country Code Number | |
Endpoint | |
Cloud Region List | |
File Creation Date | |
File Size | File Size |
Org Level 3 | |
Similar incidents Dbot | |
Tags | |
URLs | |
Categories | The categories for the incident. |
Source Urgency | Source Urgency |
Mobile Device Model | |
Internal Addresses | |
EmailCampaignSummary | |
Closing Reason | The closing reason |
Source Hostname | The hostname that performed the port scan. |
Error Message | The error message that contains details about the error that occurred. |
Parent CMD line | |
Region | |
Log Source | Log Source |
Employee Display Name | The display name of the employee. |
External Sub Category ID | |
Exposure Level | |
DNS Name | The DNS name of the asset. |
External Last Updated Time | |
Suspicious Executions | |
Device External IP | Device External IP |
Item Owner | |
userAccountControl | userAccountControl |
Protocol | Protocol |
Campaign Name | |
Resource ID | |
Source Category | |
Process Path | |
EmailCampaignMutualIndicators | |
Location | Location |
Device MAC Address | |
Zip Code | Zip Code |
Last Seen | |
Technique ID | |
Asset Name | |
Detection URL | URL of the ExtraHop Reveal(x) detection |
User Risk Level | |
Sensor IP | |
File Name | |
Operation Name | |
Device Time | The time from the original logging device when the event occurred. |
Detected User | |
Account Member Of | |
File Path | |
Source IP | The IP Address that the user initially logged in from. |
Project ID | |
Device Hash | Device Hash |
Vendor ID | |
Source Networks | |
Technical Owner Contact | The contact details for the technical owner. |
Parent Process MD5 | |
OS Type | OS Type |
Start Time | The time when the offense started. |
External System ID | |
Device Local IP | Device Local IP |
Team name | |
MITRE Technique ID | |
Detected Endpoints | |
Sub Category | The sub category |
Comment | The comments related with the incident |
Macro Source Code | In case there's a macro in a Microsoft file such as docm, xlsm or pptm, this field will hold the source code of the macro. |
Job Function | Job Function |
Source IPs | The source IPs of the event. |
External ID | |
Primary Email Address | |
Source Status | |
Parent Process Path | |
Attack Mode | Attack mode as received from the integration JSON |
Alert Type ID | |
Ticket Closed Date | |
Parent Process SHA256 | |
List Of Rules - Event | The list of rules associated to an event. |
Detected Users | Detected users |
Source Id | |
Affected Hosts | |
Time to Assignment | The time it took from when the incident was created until a user was assigned to it. |
Policy Description | |
Leadership | |
Application Id | Application Id |
Policy URI | |
External Addresses | |
Process Names | |
Org Level 1 | |
Post Nat Source IP | The source IP address after NAT. |
CVE ID |
| Name | Description |
|---|---|
Vulnerability | |
Reconnaissance | |
Indicator Feed | |
Authentication | |
Policy Violation | |
Network | |
Exfiltration | |
Exploit | |
Job | |
Simulation | |
UnknownBinary | |
Lateral Movement | |
Hunt | |
Defacement | |
DoS | |
C2Communication |
| Name | Description |
|---|---|
Updated Date | |
Signature Original Name | |
OS Version | |
Source Original Severity | The original score/severity provided by the source without DBot translation. |
BIOS Version | |
Community Notes | |
Report Object References | A list of STIX IDs referenced in the report. |
Associations | Known associations to other pieces of Threat Data. |
Author | |
Reported By | The source that reported this indicator. Can be a feed, an incident, or users. |
Public Key | |
Extension | |
Processors | |
Memory | |
Description | |
Entry ID | |
Last Seen By Source | The last time the indicator was seen by the Source vendor. |
Applications | |
STIX Description | |
STIX Is Malware Family | |
SHA1 | |
Organization | |
Port | |
SSDeep | |
Hostname | |
Actor | |
Registrar Abuse Country | |
Registrant Country | |
CVSS Table | |
Organization Prevalence | The number of times the indicator is detected in the organization. |
Operating System | |
Query Language | |
Global Prevalence | The number of times the indicator is detected across all organizations. |
Subdomains | |
Office365ExpressRoute | |
Operating System Version | |
Zip Code | |
Location | |
Tags | |
CVSS3 | |
Registrant Name | |
STIX Tool Version | |
Vulnerable Products | |
Traffic Light Protocol | TLP is a set of designations used to ensure that sensitive information is shared with the appropriate audience. It employs four colors to indicate expected sharing boundaries to be applied by the recipient(s). |
Mobile Phone | |
Acquisition Hire | Whether the employee is an acquisition hire. |
Personal Email | |
Domains | |
CVE Modified | |
Published | |
Signature Algorithm | |
PEM | Certificate in PEM format. |
Service | The specific service of a feed integration from which an indicator was ingested. |
Organization Last Seen | Date and time when the indicator was last seen in the organization. |
STIX Roles | |
Manager Name | Manager Name |
STIX Secondary Motivations | |
Region | |
ASN | |
SHA256 | |
Is Malware Family | |
Action | |
Signature File Version | |
File Type | |
STIX Threat Actor Types | |
Mitre Tactics | |
City | City |
Download URL | |
imphash | |
STIX Primary Motivation. | |
Operating System Refs | |
Size | |
Samples | |
Country Name | |
Street Address | |
STIX Goals | |
CVSS Score | |
Assigned user | |
Resource Level | |
Path | |
Office365Category | |
Registrar Name | |
Account Type | |
Assigned role | |
CVSS Version | |
User ID | |
MAC Address | |
Name Servers | |
Targets | |
Campaign | |
Office365Required | |
Email Address | |
Reports | |
Job Function | |
Org Unit | |
Threat Types | The threat category associated to this indicator by the source vendor. For example, Phishing, Command \u0026 Control, TOR, etc. |
CVE Description | |
CVSS | |
Admin Email | |
Registrar Abuse Network | |
Positive Detections | Number of engines that positively detected the indicator as malicious |
Internal | |
Name Field | |
Org Level 3 | |
Certificate Names | |
Whois Records | |
Aliases | Alternative names used to identify this object |
Validity Not Before | Specifies the date on which the certificate validity period begins. |
SHA512 | |
Detection Engines | Total number of engines that checked the indicator |
STIX ID | An identifier uniquely identifies a STIX Object and MAY do so in a deterministic way |
Mitre ID | |
Validity Not After | Specifies the date on which the certificate validity period ends. |
Registrar Abuse Name | |
Implementation Languages | |
Department | Department |
Serial Number | |
Creation Date | |
Subject DN | Subject Distinguished Name |
Organization First Seen | Date and time when the indicator was first seen in the organization. |
STIX Sophistication | |
Number of subkeys | |
Rank | Used to display rank from different sources |
Threat Actor Types | |
Signature Internal Name | |
Job Code | Job Code |
Device Model | |
Country Code | |
Manager Email Address | |
Surname | Surname |
X.509 v3 Extensions | |
Job Family | |
Registrar Abuse Phone | |
Cost Center | |
Leadership | |
Malware types | |
Domain Status | |
Objective | |
Organization Type | |
Identity class | The type of entity that this Identity describes, e.g., an individual or organization. |
Definition | |
Issuer DN | Issuer Distinguished Name |
Malware Family | |
Associated File Names | |
Admin Country | |
Blocked | |
Confidence | |
Languages | Specifies the languages supported by the software. The value of each list member MUST be a language code conformant to - RFC5646. |
Quarantined | Whether the indicator is quarantined or isolated |
Secondary Motivations | |
SWID | Specifies the Software Identification (SWID) tags entry for the software |
Admin Phone | |
File Extension | |
Signed | |
Processor | |
AS Owner | |
Certificate Validation Checks | |
Kill Chain Phases | The list of Kill Chain Phases for which this object is used. |
CVSS Vector | |
Key Value | |
Admin Name | |
Vulnerabilities | |
Capabilities | |
First Seen By Source | The first time the indicator was seen by the source vendor. |
Architecture | |
Vendor | |
Cost Center Code | |
Domain Referring IPs | |
Domain Referring Subnets | |
Title | Title |
Sophistication | |
Work Phone | |
Registrant Email | |
SPKI SHA256 | SHA256 fingerprint of Subject Public Key Info |
Name | |
Goals | |
Feed Related Indicators | |
Signature Authentihash | |
Geo Location | |
Country Code Number | |
Org Level 1 | |
Expiration Date | |
Registrant Phone | |
Primary Motivation | |
Report type | |
DNS Records | |
Short Description | |
Username | |
Paths | |
Domain Name | |
Industry sectors | Industry sector is an open vocabulary that describes industrial and commercial sectors. |
Indicator Identification | |
Publications | |
Geo Country | |
Version | |
Force Sync | Whether to force user synchronization. |
STIX Aliases | Alternative names used to identify this object |
Infrastructure Types | |
Given Name | Given Name |
Tool Version | |
Subject | |
Issuer | |
IP Address | |
Commands | |
Source Priority | |
MD5 | |
Domain IDN Name | |
DHCP Server | |
Display Name | |
Is Processed | |
Location Region | |
Behavior | |
Registrar Abuse Address | |
Product | |
Subject Alternative Names | |
Signature Description | |
DNS | |
Certificates | |
CPE | Specifies the Common Platform Enumeration (CPE) entry for the software, if available. The value for this property MUST be a CPE v2.3 entry from the official NVD CPE Dictionary |
Registrar Abuse Email | |
STIX Kill Chain Phases | The list of Kill Chain Phases for which this object is used. |
Roles | |
Tool Types | |
Groups | |
State | |
Category | |
Signature Copyright | |
Organizational Unit (OU) | |
STIX Tool Types | |
STIX Malware Types | |
Certificate Signature | |
STIX Resource Level | |
Org Level 2 | |
Detections |
| Name | Description |
|---|---|
Malware Indicator | Malware Indicator Layout |
Software | Software Indicator Layout |
Intrusion Set | Intrusion Set Layout |
Mutex | Mutex indicator layout |
Course of Action | Course of Action Indicator Layout |
URL Indicator | URL Indicator Layout |
Infrastructure | Infrastructure Indicator Layout |
File Indicator | File Indicator Layout |
Registry Key Indicator | Registry Key Indicator Layout |
ASN | ASN Indicator Layout |
Attack Pattern | Attack Pattern Indicator Layout |
Report | Report Indicator Layout |
Domain Indicator | Domain Indicator Layout |
Host Indicator | Host indicator layout |
Tool Indicator | Tool Indicator Layout |
IP Indicator | IP Indicator Layout |
CVE Indicator | CVE Indicator Layout |
Threat Actor | Threat Actor Indicator Layout |
Identity | Identity indicator layout |
Email Indicator | Email Indicator Layout |
Indicator Feed Incident | |
Account Indicator | Account Indicator Layout |
Location | Location indicator layout |
Vulnerability Incident | |
Campaign | Campaign Indicator Layout |
X509 Certificate | CVE Indicator Layout |
Tactic Layout | Tactic Indicator Layout |
| Name | Description |
|---|---|
Intrusion Set | |
IP | |
IPv6CIDR | |
Account | |
CVE | |
Location | |
Tool | |
URL | |
Host | |
Threat Actor | |
Course of Action | |
CIDR | |
Tactic | |
X509 Certificate | |
File MD5 | |
Mutex | |
Attack Pattern | |
Registry Key | |
IPv6 | |
ssdeep | |
Identity | |
Infrastructure | |
Report | |
Onion Address | |
ASN | |
Software | |
File | |
File SHA-256 | |
Domain | |
File SHA-1 | |
Malware | |
DomainGlob | |
Campaign |
| Name | Description |
|---|---|
Mail Listener - Classifier | Classifies phishing email messages. |
Mail Listener - Incoming Mapper | Maps incoming phishing email messages fields. |
| Name | Description |
|---|---|
Timezone | |
Objective | |
Display Name | Display Name |
External Severity | |
Last Seen | |
Close Time | The closing time. |
Last Update Time | |
MITRE Technique ID | |
File SHA1 | |
RemovedFromCampaigns | |
Mobile Device Model | |
Log Source Type | The log source type associated with the event. |
EmailCampaignSummary | |
Detection ID | |
Device External IPs | |
Selected Indicators | Includes the indicators selected by the user. |
Related Campaign | |
Location Region | Location Region |
Suspicious Executions | |
app channel name | |
Tools | |
Attack Mode | Attack mode as received from the integration JSON |
Users Details | |
Traffic Direction | The direction of the traffic in the event. |
Registry Value Type | |
Detected Internal Hosts | Detected internal hosts |
SHA512 | SHA512 |
App message | |
Verification Method | The method used to verify the user. |
Referenced Resource ID | |
Src OS | Src OS |
Employee Email | The email address of the employee. |
Number of Related Incidents | |
Parent Process File Path | |
External Category Name | |
CVSS Availability Requirement | The CVSS availability requirement for the asset. |
First Seen | |
Country Code | |
Referenced Resource Name | |
Tactic ID | |
Org Unit | |
Policy Remediable | |
External Last Updated Time | |
Reporter Email Address | The email address of the user who reported the email. |
OS | The operating system. |
Org Level 2 | |
Approval Status | The status for the approval of the request. |
Employee Display Name | The display name of the employee. |
Policy ID | |
Process SHA256 | |
Custom Query Results | |
Similar incidents Dbot | |
Process ID | |
similarIncidents | |
Cloud Instance ID | Cloud Instance ID |
Use Case Description | |
Job Function | Job Function |
Macro Source Code | In case there's a macro in a Microsoft file such as docm, xlsm or pptm, this field will hold the source code of the macro. |
Endpoint Isolation Status | |
Region | |
Status Reason | |
Raw Event | The unparsed event data. |
Related Alerts | |
Suspicious Executions Found | |
High Risky Hosts | |
Detection URL | URL of the ExtraHop Reveal(x) detection |
External Category ID | |
Low Level Categories Events | The low level category of the event. |
Location | Location |
Process MD5 | |
File Hash | |
Tenant Name | Tenant Name |
Policy Actions | |
Parent Process SHA256 | |
Parent Process MD5 | |
Asset Name | |
Phone Number | Phone number |
Identity Type | |
Number Of Log Sources | The number of log sources related to the offense. |
Containment SLA | The time it took to contain the incident. |
First Name | First Name |
State | State |
Vulnerability Category | |
Number Of Found Related Alerts | Medium or Higher Severity Alerts |
Process CMD | |
Group ID | |
Attack Patterns | |
Domain Squatting Result | The result of the domain-squatting check for the attacker's email. |
CVE ID | |
Account ID | |
ASN Name | |
Cloud Resource List | |
Alert Malicious | Whether the alert is malicious. |
Unique Ports | |
URL SSL Verification | Indicates whether the URLs passed the SSL certificate verification. |
Detected External IPs | Detected external IPs |
Event Names | The event name (translated QID ) in the event. |
Device Time | The time from the original logging device when the event occurred. |
Alert Type ID | |
Domain Name | |
Process Names | |
Job Code | Job Code |
User SID | |
Leadership | |
Event Descriptions | The description of the event name. |
Bugtraq | |
Follow Up | True if marked for follow up. |
userAccountControl | userAccountControl |
Domain Updated Date | |
Street Address | |
Personal Email | |
Department | Department |
Approver | The person who approved or needs to approve the request. |
Device Internal IPs | |
Last Mirrored Time Stamp | The last time the incident was mirrored in. |
Signature | |
Caller | |
Ticket Closed Date | |
Item Owner | |
Cost Center Code | Cost Center Code |
Critical Assets | A table of critical assets involved in the incident, including the name and asset type. |
Parent Process Path | |
Comment | The comments related with the incident |
Source Networks | |
Duration | |
Dest OS | Destination OS |
Failed Logon Events | The number of failed logon events in a specific timeframe. Can be used with reference to the "Failed Logon Events Timeframe" field. |
User Groups | |
Vendor ID | |
Policy URI | |
Parent Process CMD | |
Manager Email Address | |
Vendor Product | |
Source Create time | |
Command Line Verdict | |
User Creation Time | |
Campaign Name | |
External System ID | |
Cloud Service | |
Device Id | Device Id |
Cloud Region List | |
File Access Date | |
Country Code Number | |
User Block Status | |
External Confidence | |
Alert Action | Alert action as received from the integration JSON |
Risk Name | |
Tool Usage Found | |
Device MAC Address | |
Pre Nat Destination Port | The destination port before NAT. |
Verification Status | The status of the user verification. |
Blocked Action | Blocked Action |
Technical Owner Contact | The contact details for the technical owner. |
Registry Hive | |
Source Urgency | Source Urgency |
Device OS Name | |
City | |
OutgoingMirrorError | |
Device Name | Device Name |
Policy Recommendation | |
Pre Nat Source Port | The source port before NAT. |
Acquisition Hire | |
Source Id | |
Process Paths | |
Last Modified On | |
External Start Time | |
Registration Email | |
Closing User | The closing user. |
sAMAccountName | User sAMAAccountName |
Additional Data | |
Destination Geolocation | The destination geolocation of the event. |
CVSS Integrity Requirement | The CVSS integrity requirement for the asset. |
Closing Reason | The closing reason |
Original Alert Name | Alert name as received from the integration JSON |
Log Source | Log Source |
Org Level 1 | |
Escalation | |
CVE | |
File Creation Date | |
Source Status | |
Event ID | Event ID |
Internal Addresses | |
External Status | |
Tactic | |
Process Creation Time | |
Full Name | Person's Full Name |
Isolated | Isolated |
Source Updated by | |
Device Hash | Device Hash |
File Relationships | |
Risk Score | |
Mobile Phone | |
Detection End Time | |
Sub Category | The sub category |
Password Reset Successfully | Whether the password has been successfully reset. |
Account Member Of | |
Zip Code | Zip Code |
CVSS | |
SSDeep | |
Alert Rules | |
Classification | Incident Classification |
User Engagement Response | |
Birthday | Person's Birthday |
Parent Process Name | |
End Time | The time when the offense ended. |
External Sub Category ID | |
EmailCampaignSnippets | |
String Similarity Results | |
Registry Key | |
Audit Logs | |
ASN | |
Last Name | Last Name |
Start Time | The time when the offense started. |
Assigned User | Assigned User |
Alert Acknowledgement | Alert acknowledgement as received from the integration JSON |
Log Source Name | The log source name associated with the event. |
Changed | The user who changed this incident |
Given Name | Given Name |
Compliance Notes | Notes regarding the assets compliance. |
Report Name | |
MITRE Technique Name | |
Related Report | |
Source Created By | |
Block Indicators Status | |
Rule Name | The name of a YARA rule |
Cloud Account ID | |
Domain Registrar Abuse Email | |
Post Nat Source Port | The source port after NAT. |
IncomingMirrorError | |
High Risky Users | |
Part of Campaign | The ID of the campaign incident of which the current incident is part of. |
Dsts | The destination values. |
CVSS Confidentiality Requirement | The CVSS confidentiality requirement of the asset. |
Manager Name | Manager Name |
Account Status | |
Additional Indicators | |
Policy Deleted | |
Technical User | The technical user of the asset. |
Title | Title |
Cost Center | Cost Center |
External End Time | |
Technique | |
Subtype | Subtype |
Team name | |
Original Alert Source | |
Source Geolocation | The source geolocation of the event. |
Additional Email Addresses | |
SKU TIER | |
Source Category | |
Operation Name | |
Affected Hosts | |
Project ID | |
Alert tags | |
Hunt Results Count | |
Endpoints Details | |
Triage SLA | The time it took to investigate and enrich incident information. |
Time to Assignment | The time it took from when the incident was created until a user was assigned to it. |
List Of Rules - Event | The list of rules associated to an event. |
Job Family | Job Family |
Password Changed Date | |
Category Count | The number of categories that are associated with the offense. |
Item Owner Email | |
Application Path | |
Resource Type | |
Threat Family Name | Threat Family Name Associated with an Attacking Vector. I.E. Meterpreter as toolkit or Extortion\ֿFraud\Espionage |
User Id | User Id |
UUID | UUID as received from the integration JSON |
Post Nat Destination IP | The destination IP address after NAT. |
Email Sent Successfully | Whether the email has been successfully sent. |
Incident Link | |
Rating | |
OS Type | OS Type |
Vulnerable Product | |
Technical Owner | The technical owner of the asset. |
Is Active | Alert status |
Agents ID | |
Resource Name | |
Error Message | The error message that contains details about the error that occurred. |
Protocol names | |
User Anomaly Count | |
Policy Details | |
IP Blocked Status | |
Original Alert ID | Alert ID as received from the integration JSON |
Registry Value | |
CVE Published | |
CVSS Collateral Damage Potential | The CVSS collateral damage potential of the asset. |
Parent Process IDs | |
MITRE Tactic ID | |
Last Modified By | |
SHA1 | SHA1 |
Ticket Number | |
Device OS Version | |
Error Code | |
File Size | File Size |
Failed Logon Events Timeframe | The timeframe which the failed logon events occurred in. |
Device Status | |
Detected Endpoints | |
Threat Name | Define the threat name such as malware/exploit/phishing/etc |
Remediation SLA | The time it took since remediation of the incident began, and until it ended. |
Resource URL | |
Original Events | The events associated with the offense. |
Original Description | The description of the incident |
EmailCampaignMutualIndicators | |
Verdict | |
Technique ID | |
Destination IPV6 | The destination IPV6 address. |
IP Reputation | |
Policy Type | |
EmailCampaignCanvas | |
Post Nat Source IP | The source IP address after NAT. |
Device OU | Device's OU path in Active Directory |
External Sub Category Name | |
Ticket Acknowledged Date | |
External Link | |
Primary Email Address | |
Agent Version | Reporting Agent/Sensor Version |
URLs | |
Org Level 3 | |
MITRE Tactic Name | |
Policy Severity | |
Post Nat Destination Port | The destination port after NAT. |
Event Action | Action taken on user accounts - Create, Update, Deactivate, Reactivate |
Triggered Security Profile | Triggered Security Profile |
Sensor IP | |
Risk Rating | |
Investigation Stage | The stage of the investigation. |
Affected Users | |
Rendered HTML | The HTML content in a rendered form. |
Source External IPs | |
Surname | Surname |
Employee Manager Email | The email address of the employee's manager. |
Asset ID | |
Scenario | |
Assignment Group | |
Work Phone | |
Source Priority | |
SKU Name | |
Destination Networks | |
Number of similar files | |
Device Model | Device Model |
Detection SLA | The time it took from incident creation until the maliciousness was determined. |
Region ID | |
Policy Description | |
Related Endpoints | |
Exposure Level | |
Pre Nat Source IP | The source IP before NAT. |
| Name | Description |
|---|---|
DoS | |
C2Communication | |
Simulation | |
Vulnerability | |
Exploit | |
Indicator Feed | |
Reconnaissance | |
Defacement | |
Lateral Movement | |
Hunt | |
Authentication | |
Exfiltration | |
Network | |
Job | |
UnknownBinary | |
Policy Violation |
| Name | Description |
|---|---|
Operating System Version | |
CVSS3 | |
Traffic Light Protocol | TLP is a set of designations used to ensure that sensitive information is shared with the appropriate audience. It employs four colors to indicate expected sharing boundaries to be applied by the recipient(s). |
Office365Required | |
Samples | |
Name Field | |
Commands | |
Org Unit | |
Subject DN | Subject Distinguished Name |
Office365Category | |
STIX Tool Types | |
Force Sync | Whether to force user synchronization. |
Registrar Abuse Network | |
Processor | |
Source Original Severity | The original score/severity provided by the source without DBot translation. |
Report type | |
Author | |
First Seen By Source | The first time the indicator was seen by the source vendor. |
Port | |
Zip Code | |
DNS | |
Domains | |
Certificate Validation Checks | |
Goals | |
MD5 | |
CVSS Vector | |
Aliases | Alternative names used to identify this object |
Location | |
Admin Phone | |
Creation Date | |
Vendor | |
CVSS Score | |
Memory | |
Mitre ID | |
Industry sectors | Industry sector is an open vocabulary that describes industrial and commercial sectors. |
Languages | Specifies the languages supported by the software. The value of each list member MUST be a language code conformant to - RFC5646. |
Assigned user | |
Secondary Motivations | |
SHA512 | |
Query Language | |
Issuer | |
Reports | |
Vulnerable Products | |
Signature Internal Name | |
Global Prevalence | The number of times the indicator is detected across all organizations. |
Extension | |
Processors | |
Domain Referring Subnets | |
Primary Motivation | |
Targets | |
Paths | |
Surname | Surname |
Hostname | |
IP Address | |
Admin Email | |
Signature File Version | |
Domain Referring IPs | |
Certificate Signature | |
DHCP Server | |
Organization Type | |
Registrar Abuse Name | |
SHA1 | |
CPE | Specifies the Common Platform Enumeration (CPE) entry for the software, if available. The value for this property MUST be a CPE v2.3 entry from the official NVD CPE Dictionary |
Registrar Abuse Address | |
Download URL | |
Capabilities | |
Username | |
Organization | |
Cost Center | |
Malware Family | |
Registrar Abuse Country | |
Short Description | |
Registrar Abuse Email | |
Leadership | |
Sophistication | |
STIX Aliases | Alternative names used to identify this object |
Is Malware Family | |
CVE Modified | |
Updated Date | |
Office365ExpressRoute | |
Street Address | |
Org Level 1 | |
Blocked | |
File Extension | |
CVSS | |
Confidence | |
Key Value | |
Cost Center Code | |
Registrant Email | |
Signature Authentihash | |
Associations | Known associations to other pieces of Threat Data. |
Manager Name | Manager Name |
DNS Records | |
Architecture | |
Community Notes | |
PEM | Certificate in PEM format. |
SWID | Specifies the Software Identification (SWID) tags entry for the software |
SHA256 | |
Is Processed | |
Vulnerabilities | |
Actor | |
STIX ID | An identifier uniquely identifies a STIX Object and MAY do so in a deterministic way |
Campaign | |
STIX Malware Types | |
Certificates | |
Name Servers | |
Geo Location | |
Implementation Languages | |
Title | Title |
Behavior | |
Organization First Seen | Date and time when the indicator was first seen in the organization. |
Domain Name | |
Acquisition Hire | Whether the employee is an acquisition hire. |
STIX Kill Chain Phases | The list of Kill Chain Phases for which this object is used. |
Validity Not After | Specifies the date on which the certificate validity period ends. |
Registrar Name | |
STIX Resource Level | |
STIX Sophistication | |
Detections | |
STIX Goals | |
Feed Related Indicators | |
Country Code | |
Region | |
Registrant Country | |
Quarantined | Whether the indicator is quarantined or isolated |
CVSS Version | |
STIX Description | |
STIX Tool Version | |
Mitre Tactics | |
Threat Actor Types | |
Version | |
Subject Alternative Names | |
Objective | |
City | City |
Signature Copyright | |
Assigned role | |
Issuer DN | Issuer Distinguished Name |
Serial Number | |
Organization Prevalence | The number of times the indicator is detected in the organization. |
Associated File Names | |
Work Phone | |
Given Name | Given Name |
Organization Last Seen | Date and time when the indicator was last seen in the organization. |
STIX Secondary Motivations | |
Publications | |
Registrant Phone | |
Expiration Date | |
Operating System | |
Country Name | |
X.509 v3 Extensions | |
Registrar Abuse Phone | |
Domain IDN Name | |
Roles | |
Personal Email | |
Signature Original Name | |
Department | Department |
Subject | |
Reported By | The source that reported this indicator. Can be a feed, an incident, or users. |
Category | |
CVE Description | |
Kill Chain Phases | The list of Kill Chain Phases for which this object is used. |
Malware types | |
STIX Roles | |
ASN | |
Last Seen By Source | The last time the indicator was seen by the Source vendor. |
Description | |
Operating System Refs | |
Account Type | |
Job Code | Job Code |
AS Owner | |
SPKI SHA256 | SHA256 fingerprint of Subject Public Key Info |
Signed | |
Product | |
Definition | |
Organizational Unit (OU) | |
Country Code Number | |
Admin Country | |
Tool Version | |
Path | |
Rank | Used to display rank from different sources |
Org Level 2 | |
Positive Detections | Number of engines that positively detected the indicator as malicious |
Service | The specific service of a feed integration from which an indicator was ingested. |
Action | |
Applications | |
STIX Threat Actor Types | |
Identity class | The type of entity that this Identity describes, e.g., an individual or organization. |
STIX Is Malware Family | |
Tags | |
Signature Algorithm | |
Mobile Phone | |
Source Priority | |
Signature Description | |
Entry ID | |
Published | |
Location Region | |
File Type | |
OS Version | |
Threat Types | The threat category associated to this indicator by the source vendor. For example, Phishing, Command \u0026 Control, TOR, etc. |
Org Level 3 | |
Domain Status | |
Registrant Name | |
BIOS Version | |
Subdomains | |
Resource Level | |
Validity Not Before | Specifies the date on which the certificate validity period begins. |
Indicator Identification | |
Report Object References | A list of STIX IDs referenced in the report. |
Number of subkeys | |
Geo Country | |
SSDeep | |
Whois Records | |
STIX Primary Motivation. | |
Internal | |
Public Key | |
Job Function | |
Tool Types | |
Size | |
Admin Name | |
Display Name | |
Name | |
Detection Engines | Total number of engines that checked the indicator |
Email Address | |
imphash | |
State | |
Manager Email Address | |
Job Family | |
User ID | |
Infrastructure Types | |
Device Model | |
Certificate Names | |
Groups | |
CVSS Table |
| Name | Description |
|---|---|
Indicator Feed Layout Rule | |
Vulnerability Layout Rule |
| Name | Description |
|---|---|
Intrusion Set | Intrusion Set Layout |
Account Indicator | Account Indicator Layout |
X509 Certificate | CVE Indicator Layout |
Host Indicator | Host indicator layout |
Course of Action | Course of Action Indicator Layout |
Tactic Layout | Tactic Indicator Layout |
Threat Actor | Threat Actor Indicator Layout |
Domain Indicator | Domain Indicator Layout |
IP Indicator | IP Indicator Layout |
Tool Indicator | Tool Indicator Layout |
ASN | ASN Indicator Layout |
Location | Location indicator layout |
File Indicator | File Indicator Layout |
Malware Indicator | Malware Indicator Layout |
CVE Indicator | CVE Indicator Layout |
Email Indicator | Email Indicator Layout |
Campaign | Campaign Indicator Layout |
Mutex | Mutex indicator layout |
Report | Report Indicator Layout |
URL Indicator | URL Indicator Layout |
Registry Key Indicator | Registry Key Indicator Layout |
Software | Software Indicator Layout |
Identity | Identity indicator layout |
Indicator Feed Incident | |
Infrastructure | Infrastructure Indicator Layout |
Attack Pattern | Attack Pattern Indicator Layout |
Vulnerability Incident |
| Name | Description |
|---|---|
Course of Action | |
File SHA-1 | |
Tool | |
ssdeep | |
Registry Key | |
Campaign | |
Attack Pattern | |
Domain | |
Threat Actor | |
File | |
Host | |
CIDR | |
Location | |
Malware | |
File MD5 | |
Identity | |
Report | |
Tactic | |
Mutex | |
Software | |
IPv6 | |
DomainGlob | |
Infrastructure | |
X509 Certificate | |
URL | |
Onion Address | |
Account | |
ASN | |
CVE | |
File SHA-256 | |
IP | |
Intrusion Set | |
IPv6CIDR |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
| Common Scripts | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
| Common Scripts | By: Cortex XSOAR |
| Cortex REST API | By: Cortex XSOAR |
ASN
Documentation and metadata improvements.
ASN Name
Documentation and metadata improvements.
Account ID
Documentation and metadata improvements.
Account Member Of
Documentation and metadata improvements.
Account Status
Documentation and metadata improvements.
Acquisition Hire
Documentation and metadata improvements.
Additional Data
Documentation and metadata improvements.
Additional Email Addresses
Documentation and metadata improvements.
Additional Indicators
Documentation and metadata improvements.
Affected Hosts
Documentation and metadata improvements.
Affected Users
Documentation and metadata improvements.
Agent Version
Documentation and metadata improvements.
Agents ID
Documentation and metadata improvements.
Alert Acknowledgement
Documentation and metadata improvements.
Alert Action
Documentation and metadata improvements.
Alert Malicious
Documentation and metadata improvements.
Alert Rules
Documentation and metadata improvements.
Alert Type ID
Documentation and metadata improvements.
Alert tags
Documentation and metadata improvements.
App message
Documentation and metadata improvements.
Application Path
Documentation and metadata improvements.
Approval Status
Documentation and metadata improvements.
Approver
Documentation and metadata improvements.
Asset ID
Documentation and metadata improvements.
Asset Name
Documentation and metadata improvements.
Assigned User
Documentation and metadata improvements.
Assignment Group
Documentation and metadata improvements.
Attack Mode
Documentation and metadata improvements.
Attack Patterns
Documentation and metadata improvements.
Audit Logs
Documentation and metadata improvements.
Birthday
Documentation and metadata improvements.
Block Indicators Status
Documentation and metadata improvements.
Blocked Action
Documentation and metadata improvements.
Bugtraq
Documentation and metadata improvements.
CVE
Documentation and metadata improvements.
CVE ID
Documentation and metadata improvements.
CVE Published
Documentation and metadata improvements.
CVSS
Documentation and metadata improvements.
CVSS Availability Requirement
Documentation and metadata improvements.
CVSS Collateral Damage Potential
Documentation and metadata improvements.
CVSS Confidentiality Requirement
Documentation and metadata improvements.
CVSS Integrity Requirement
Documentation and metadata improvements.
Caller
Documentation and metadata improvements.
Campaign Name
Documentation and metadata improvements.
Category Count
Documentation and metadata improvements.
Changed
Documentation and metadata improvements.
City
Documentation and metadata improvements.
Classification
Documentation and metadata improvements.
Close Time
Documentation and metadata improvements.
Closing Reason
Documentation and metadata improvements.
Closing User
Documentation and metadata improvements.
Cloud Account ID
Documentation and metadata improvements.
Cloud Instance ID
Documentation and metadata improvements.
Cloud Region List
Documentation and metadata improvements.
Cloud Resource List
Documentation and metadata improvements.
Cloud Service
Documentation and metadata improvements.
Command Line Verdict
Documentation and metadata improvements.
Comment
Documentation and metadata improvements.
Compliance Notes
Documentation and metadata improvements.
Containment SLA
Documentation and metadata improvements.
Cost Center
Documentation and metadata improvements.
Cost Center Code
Documentation and metadata improvements.
Country Code
Documentation and metadata improvements.
Country Code Number
Documentation and metadata improvements.
Critical Assets
Documentation and metadata improvements.
Custom Query Results
Documentation and metadata improvements.
Department
Documentation and metadata improvements.
Dest OS
Documentation and metadata improvements.
Destination Geolocation
Documentation and metadata improvements.
Destination IPV6
Documentation and metadata improvements.
Destination Networks
Documentation and metadata improvements.
Detected Endpoints
Documentation and metadata improvements.
Detected External IPs
Documentation and metadata improvements.
Detected Internal Hosts
Documentation and metadata improvements.
Detection End Time
Documentation and metadata improvements.
Detection ID
Documentation and metadata improvements.
Detection SLA
Documentation and metadata improvements.
Detection URL
Documentation and metadata improvements.
Device External IPs
Documentation and metadata improvements.
Device Hash
Documentation and metadata improvements.
Device Id
Documentation and metadata improvements.
Device Internal IPs
Documentation and metadata improvements.
Device MAC Address
Documentation and metadata improvements.
Device Model
Documentation and metadata improvements.
Device Name
Documentation and metadata improvements.
Device OS Name
Documentation and metadata improvements.
Device OS Version
Documentation and metadata improvements.
Device OU
Documentation and metadata improvements.
Device Status
Documentation and metadata improvements.
Device Time
Documentation and metadata improvements.
Display Name
Documentation and metadata improvements.
Domain Name
Documentation and metadata improvements.
Domain Registrar Abuse Email
Documentation and metadata improvements.
Domain Squatting Result
Documentation and metadata improvements.
Domain Updated Date
Documentation and metadata improvements.
Dsts
Documentation and metadata improvements.
Duration
Documentation and metadata improvements.
Documentation and metadata improvements.
Email Sent Successfully
Documentation and metadata improvements.
EmailCampaignCanvas
Documentation and metadata improvements.
EmailCampaignMutualIndicators
Documentation and metadata improvements.
EmailCampaignSnippets
Documentation and metadata improvements.
EmailCampaignSummary
Documentation and metadata improvements.
Employee Display Name
Documentation and metadata improvements.
Employee Email
Documentation and metadata improvements.
Employee Manager Email
Documentation and metadata improvements.
End Time
Documentation and metadata improvements.
Endpoint Isolation Status
Documentation and metadata improvements.
Endpoints Details
Documentation and metadata improvements.
Error Code
Documentation and metadata improvements.
Error Message
Documentation and metadata improvements.
Escalation
Documentation and metadata improvements.
Event Action
Documentation and metadata improvements.
Event Descriptions
Documentation and metadata improvements.
Event ID
Documentation and metadata improvements.
Event Names
Documentation and metadata improvements.
Exposure Level
Documentation and metadata improvements.
External Category ID
Documentation and metadata improvements.
External Category Name
Documentation and metadata improvements.
External Confidence
Documentation and metadata improvements.
External End Time
Documentation and metadata improvements.
External Last Updated Time
Documentation and metadata improvements.
External Link
Documentation and metadata improvements.
External Severity
Documentation and metadata improvements.
External Start Time
Documentation and metadata improvements.
External Status
Documentation and metadata improvements.
External Sub Category ID
Documentation and metadata improvements.
External Sub Category Name
Documentation and metadata improvements.
External System ID
Documentation and metadata improvements.
Failed Logon Events
Documentation and metadata improvements.
Failed Logon Events Timeframe
Documentation and metadata improvements.
File Access Date
Documentation and metadata improvements.
File Creation Date
Documentation and metadata improvements.
File Hash
Documentation and metadata improvements.
File Relationships
Documentation and metadata improvements.
File SHA1
Documentation and metadata improvements.
File Size
Documentation and metadata improvements.
First Name
Documentation and metadata improvements.
First Seen
Documentation and metadata improvements.
Follow Up
Documentation and metadata improvements.
Full Name
Documentation and metadata improvements.
Given Name
Documentation and metadata improvements.
Group ID
Documentation and metadata improvements.
High Risky Hosts
Documentation and metadata improvements.
High Risky Users
Documentation and metadata improvements.
Hunt Results Count
Documentation and metadata improvements.
IP Blocked Status
Documentation and metadata improvements.
IP Reputation
Documentation and metadata improvements.
Identity Type
Documentation and metadata improvements.
Incident Link
Documentation and metadata improvements.
IncomingMirrorError
Documentation and metadata improvements.
Internal Addresses
Documentation and metadata improvements.
Investigation Stage
Documentation and metadata improvements.
Is Active
Documentation and metadata improvements.
Isolated
Documentation and metadata improvements.
Item Owner
Documentation and metadata improvements.
Item Owner Email
Documentation and metadata improvements.
Job Code
Documentation and metadata improvements.
Job Family
Documentation and metadata improvements.
Job Function
Documentation and metadata improvements.
Last Mirrored Time Stamp
Documentation and metadata improvements.
Last Modified By
Documentation and metadata improvements.
Last Modified On
Documentation and metadata improvements.
Last Name
Documentation and metadata improvements.
Last Seen
Documentation and metadata improvements.
Last Update Time
Documentation and metadata improvements.
Leadership
Documentation and metadata improvements.
List Of Rules - Event
Documentation and metadata improvements.
Location
Documentation and metadata improvements.
Location Region
Documentation and metadata improvements.
Log Source
Documentation and metadata improvements.
Log Source Name
Documentation and metadata improvements.
Log Source Type
Documentation and metadata improvements.
Low Level Categories Events
Documentation and metadata improvements.
MITRE Tactic ID
Documentation and metadata improvements.
MITRE Tactic Name
Documentation and metadata improvements.
MITRE Technique ID
Documentation and metadata improvements.
MITRE Technique Name
Documentation and metadata improvements.
Macro Source Code
Documentation and metadata improvements.
Manager Email Address
Documentation and metadata improvements.
Manager Name
Documentation and metadata improvements.
Mobile Device Model
Documentation and metadata improvements.
Mobile Phone
Documentation and metadata improvements.
Number Of Found Related Alerts
Documentation and metadata improvements.
Number Of Log Sources
Documentation and metadata improvements.
Number of Related Incidents
Documentation and metadata improvements.
Number of similar files
Documentation and metadata improvements.
OS
Documentation and metadata improvements.
OS Type
Documentation and metadata improvements.
Objective
Documentation and metadata improvements.
Operation Name
Documentation and metadata improvements.
Org Level 1
Documentation and metadata improvements.
Org Level 2
Documentation and metadata improvements.
Org Level 3
Documentation and metadata improvements.
Org Unit
Documentation and metadata improvements.
OutgoingMirrorError
Documentation and metadata improvements.
Parent Process CMD
Documentation and metadata improvements.
Parent Process File Path
Documentation and metadata improvements.
Parent Process IDs
Documentation and metadata improvements.
Parent Process MD5
Documentation and metadata improvements.
Parent Process Name
Documentation and metadata improvements.
Parent Process Path
Documentation and metadata improvements.
Parent Process SHA256
Documentation and metadata improvements.
Part of Campaign
Documentation and metadata improvements.
Password Changed Date
Documentation and metadata improvements.
Password Reset Successfully
Documentation and metadata improvements.
Personal Email
Documentation and metadata improvements.
Phone Number
Documentation and metadata improvements.
Policy Actions
Documentation and metadata improvements.
Policy Deleted
Documentation and metadata improvements.
Policy Description
Documentation and metadata improvements.
Policy Details
Documentation and metadata improvements.
Policy ID
Documentation and metadata improvements.
Policy Recommendation
Documentation and metadata improvements.
Policy Remediable
Documentation and metadata improvements.
Policy Severity
Documentation and metadata improvements.
Policy Type
Documentation and metadata improvements.
Policy URI
Documentation and metadata improvements.
Post Nat Destination IP
Documentation and metadata improvements.
Post Nat Destination Port
Documentation and metadata improvements.
Post Nat Source IP
Documentation and metadata improvements.
Post Nat Source Port
Documentation and metadata improvements.
Pre Nat Destination Port
Documentation and metadata improvements.
Pre Nat Source IP
Documentation and metadata improvements.
Pre Nat Source Port
Documentation and metadata improvements.
Process CMD
Documentation and metadata improvements.
Process Creation Time
Documentation and metadata improvements.
Process ID
Documentation and metadata improvements.
Process MD5
Documentation and metadata improvements.
Process Names
Documentation and metadata improvements.
Process Paths
Documentation and metadata improvements.
Process SHA256
Documentation and metadata improvements.
Project ID
Documentation and metadata improvements.
Protocol names
Documentation and metadata improvements.
Rating
Documentation and metadata improvements.
Raw Event
Documentation and metadata improvements.
Referenced Resource ID
Documentation and metadata improvements.
Referenced Resource Name
Documentation and metadata improvements.
Region
Documentation and metadata improvements.
Region ID
Documentation and metadata improvements.
Registration Email
Documentation and metadata improvements.
Registry Hive
Documentation and metadata improvements.
Registry Key
Documentation and metadata improvements.
Registry Value
Documentation and metadata improvements.
Registry Value Type
Documentation and metadata improvements.
Related Alerts
Documentation and metadata improvements.
Related Campaign
Documentation and metadata improvements.
Related Endpoints
Documentation and metadata improvements.
Related Report
Documentation and metadata improvements.
Remediation SLA
Documentation and metadata improvements.
RemovedFromCampaigns
Documentation and metadata improvements.
Rendered HTML
Documentation and metadata improvements.
Report Name
Documentation and metadata improvements.
Reporter Email Address
Documentation and metadata improvements.
Resource Name
Documentation and metadata improvements.
Resource Type
Documentation and metadata improvements.
Resource URL
Documentation and metadata improvements.
Risk Name
Documentation and metadata improvements.
Risk Rating
Documentation and metadata improvements.
Risk Score
Documentation and metadata improvements.
Rule Name
Documentation and metadata improvements.
SHA1
Documentation and metadata improvements.
SHA512
Documentation and metadata improvements.
SKU Name
Documentation and metadata improvements.
SKU TIER
Documentation and metadata improvements.
SSDeep
Documentation and metadata improvements.
Scenario
Documentation and metadata improvements.
Selected Indicators
Documentation and metadata improvements.
Sensor IP
Documentation and metadata improvements.
Signature
Documentation and metadata improvements.
Similar incidents Dbot
Documentation and metadata improvements.
Source Category
Documentation and metadata improvements.
Source Create time
Documentation and metadata improvements.
Source Created By
Documentation and metadata improvements.
Source External IPs
Documentation and metadata improvements.
Source Geolocation
Documentation and metadata improvements.
Source Id
Documentation and metadata improvements.
Source Networks
Documentation and metadata improvements.
Source Priority
Documentation and metadata improvements.
Source Status
Documentation and metadata improvements.
Source Updated by
Documentation and metadata improvements.
Source Urgency
Documentation and metadata improvements.
Src OS
Documentation and metadata improvements.
Start Time
Documentation and metadata improvements.
State
Documentation and metadata improvements.
Status Reason
Documentation and metadata improvements.
Street Address
Documentation and metadata improvements.
String Similarity Results
Documentation and metadata improvements.
Sub Category
Documentation and metadata improvements.
Subtype
Documentation and metadata improvements.
Surname
Documentation and metadata improvements.
Suspicious Executions
Documentation and metadata improvements.
Suspicious Executions Found
Documentation and metadata improvements.
Tactic
Documentation and metadata improvements.
Tactic ID
Documentation and metadata improvements.
Team name
Documentation and metadata improvements.
Technical Owner
Documentation and metadata improvements.
Technical Owner Contact
Documentation and metadata improvements.
Technical User
Documentation and metadata improvements.
Technique
Documentation and metadata improvements.
Technique ID
Documentation and metadata improvements.
Tenant Name
Documentation and metadata improvements.
Threat Family Name
Documentation and metadata improvements.
Threat Name
Documentation and metadata improvements.
Ticket Acknowledged Date
Documentation and metadata improvements.
Ticket Closed Date
Documentation and metadata improvements.
Ticket Number
Documentation and metadata improvements.
Time to Assignment
Documentation and metadata improvements.
Timezone
Documentation and metadata improvements.
Title
Documentation and metadata improvements.
Tool Usage Found
Documentation and metadata improvements.
Tools
Documentation and metadata improvements.
Traffic Direction
Documentation and metadata improvements.
Triage SLA
Documentation and metadata improvements.
Triggered Security Profile
Documentation and metadata improvements.
URL SSL Verification
Documentation and metadata improvements.
URLs
Documentation and metadata improvements.
UUID
Documentation and metadata improvements.
Unique Ports
Documentation and metadata improvements.
Use Case Description
Documentation and metadata improvements.
User Anomaly Count
Documentation and metadata improvements.
User Block Status
Documentation and metadata improvements.
User Creation Time
Documentation and metadata improvements.
User Engagement Response
Documentation and metadata improvements.
User Groups
Documentation and metadata improvements.
User Id
Documentation and metadata improvements.
User SID
Documentation and metadata improvements.
Users Details
Documentation and metadata improvements.
Vendor ID
Documentation and metadata improvements.
Vendor Product
Documentation and metadata improvements.
Verdict
Documentation and metadata improvements.
Verification Method
Documentation and metadata improvements.
Verification Status
Documentation and metadata improvements.
Vulnerability Category
Documentation and metadata improvements.
Vulnerable Product
Documentation and metadata improvements.
Work Phone
Documentation and metadata improvements.
Zip Code
Documentation and metadata improvements.
app channel name
Documentation and metadata improvements.
sAMAccountName
Documentation and metadata improvements.
similarIncidents
Documentation and metadata improvements.
userAccountControl
Documentation and metadata improvements.
Authentication
Documentation and metadata improvements.
C2Communication
Documentation and metadata improvements.
Defacement
Documentation and metadata improvements.
DoS
Documentation and metadata improvements.
Exfiltration
Documentation and metadata improvements.
Exploit
Documentation and metadata improvements.
Hunt
Documentation and metadata improvements.
Indicator Feed
Documentation and metadata improvements.
Job
Documentation and metadata improvements.
Lateral Movement
Documentation and metadata improvements.
Network
Documentation and metadata improvements.
Policy Violation
Documentation and metadata improvements.
Reconnaissance
Documentation and metadata improvements.
Simulation
Documentation and metadata improvements.
UnknownBinary
Documentation and metadata improvements.
Vulnerability
Documentation and metadata improvements.
ASN
Documentation and metadata improvements.
Account
Documentation and metadata improvements.
Attack Pattern
Documentation and metadata improvements.
CIDR
Documentation and metadata improvements.
CVE
Documentation and metadata improvements.
Campaign
Documentation and metadata improvements.
Course of Action
Documentation and metadata improvements.
DomainGlob
Documentation and metadata improvements.
Documentation and metadata improvements.
File MD5
Documentation and metadata improvements.
File SHA-1
Documentation and metadata improvements.
File SHA-256
Documentation and metadata improvements.
Host
Documentation and metadata improvements.
IPv6CIDR
Documentation and metadata improvements.
Identity
Documentation and metadata improvements.
Infrastructure
Documentation and metadata improvements.
Intrusion Set
Documentation and metadata improvements.
Location
Documentation and metadata improvements.
Malware
Documentation and metadata improvements.
Mutex
Documentation and metadata improvements.
Onion Address
Documentation and metadata improvements.
Registry Key
Documentation and metadata improvements.
Report
Documentation and metadata improvements.
Software
Documentation and metadata improvements.
Tactic
Documentation and metadata improvements.
Threat Actor
Documentation and metadata improvements.
Tool
Documentation and metadata improvements.
X509 Certificate
Documentation and metadata improvements.
ssdeep
Documentation and metadata improvements.
Domain
Added support for the xti module.
File
Added support for the xti module.
IP
Added support for the xti module.
IPv6
Added support for the xti module.
URL
Added support for the xti module.
ASN
Documentation and metadata improvements.
Account Indicator
Documentation and metadata improvements.
Attack Pattern
Documentation and metadata improvements.
CVE Indicator
Documentation and metadata improvements.
Campaign
Documentation and metadata improvements.
Course of Action
Documentation and metadata improvements.
Domain Indicator
Documentation and metadata improvements.
Email Indicator
Documentation and metadata improvements.
File Indicator
Documentation and metadata improvements.
Host Indicator
Documentation and metadata improvements.
IP Indicator
Documentation and metadata improvements.
Identity
Documentation and metadata improvements.
Indicator Feed Incident
Documentation and metadata improvements.
Infrastructure
Documentation and metadata improvements.
Intrusion Set
Documentation and metadata improvements.
Location
Documentation and metadata improvements.
Malware Indicator
Documentation and metadata improvements.
Mutex
Documentation and metadata improvements.
Registry Key Indicator
Documentation and metadata improvements.
Report
Documentation and metadata improvements.
Software
Documentation and metadata improvements.
Tactic Layout
Documentation and metadata improvements.
Threat Actor
Documentation and metadata improvements.
Tool Indicator
Documentation and metadata improvements.
URL Indicator
Documentation and metadata improvements.
Vulnerability Incident
Documentation and metadata improvements.
X509 Certificate
Documentation and metadata improvements.
Traffic Direction
Updated the Traffic Direction incident field to associate 'Trellix Incident' type.
Alert Attack Time
Updated the Alert Attack Time incident field to associate 'Trellix Incident' type.
Vendor Product
Updated the Vendor Product incident field to associate 'Trellix Incident' type.
UUID
Updated the UUID incident field to associate 'Trellix Incident' type.
Detected External Hosts
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Vendor Product
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Last Update Time
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
UUID
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
End Time
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Display Name
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Start Time
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Source IPs
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Risk Score
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Detection ID
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
imphash incident field.ASN
Documentation and metadata improvements.
ASN Name
Documentation and metadata improvements.
Account ID
Documentation and metadata improvements.
Account Member Of
Documentation and metadata improvements.
Account Status
Documentation and metadata improvements.
Acquisition Hire
Documentation and metadata improvements.
Additional Data
Documentation and metadata improvements.
Additional Email Addresses
Documentation and metadata improvements.
Additional Indicators
Documentation and metadata improvements.
Affected Hosts
Documentation and metadata improvements.
Affected Users
Documentation and metadata improvements.
Agent Version
Documentation and metadata improvements.
Agents ID
Documentation and metadata improvements.
Alert Acknowledgement
Documentation and metadata improvements.
Alert Action
Documentation and metadata improvements.
Alert Malicious
Documentation and metadata improvements.
Alert Rules
Documentation and metadata improvements.
Alert Type ID
Documentation and metadata improvements.
Alert tags
Documentation and metadata improvements.
App message
Documentation and metadata improvements.
Application Path
Documentation and metadata improvements.
Approval Status
Documentation and metadata improvements.
Approver
Documentation and metadata improvements.
Asset ID
Documentation and metadata improvements.
Asset Name
Documentation and metadata improvements.
Assigned User
Documentation and metadata improvements.
Assignment Group
Documentation and metadata improvements.
Attack Mode
Documentation and metadata improvements.
Attack Patterns
Documentation and metadata improvements.
Audit Logs
Documentation and metadata improvements.
Birthday
Documentation and metadata improvements.
Block Indicators Status
Documentation and metadata improvements.
Blocked Action
Documentation and metadata improvements.
Bugtraq
Documentation and metadata improvements.
CVE
Documentation and metadata improvements.
CVE ID
Documentation and metadata improvements.
CVE Published
Documentation and metadata improvements.
CVSS
Documentation and metadata improvements.
CVSS Availability Requirement
Documentation and metadata improvements.
CVSS Collateral Damage Potential
Documentation and metadata improvements.
CVSS Confidentiality Requirement
Documentation and metadata improvements.
CVSS Integrity Requirement
Documentation and metadata improvements.
Caller
Documentation and metadata improvements.
Campaign Name
Documentation and metadata improvements.
Category Count
Documentation and metadata improvements.
Changed
Documentation and metadata improvements.
City
Documentation and metadata improvements.
Classification
Documentation and metadata improvements.
Close Time
Documentation and metadata improvements.
Closing Reason
Documentation and metadata improvements.
Closing User
Documentation and metadata improvements.
Cloud Account ID
Documentation and metadata improvements.
Cloud Instance ID
Documentation and metadata improvements.
Cloud Region List
Documentation and metadata improvements.
Cloud Resource List
Documentation and metadata improvements.
Cloud Service
Documentation and metadata improvements.
Command Line Verdict
Documentation and metadata improvements.
Comment
Documentation and metadata improvements.
Compliance Notes
Documentation and metadata improvements.
Containment SLA
Documentation and metadata improvements.
Cost Center
Documentation and metadata improvements.
Cost Center Code
Documentation and metadata improvements.
Country Code
Documentation and metadata improvements.
Country Code Number
Documentation and metadata improvements.
Critical Assets
Documentation and metadata improvements.
Custom Query Results
Documentation and metadata improvements.
Department
Documentation and metadata improvements.
Dest OS
Documentation and metadata improvements.
Destination Geolocation
Documentation and metadata improvements.
Destination IPV6
Documentation and metadata improvements.
Destination Networks
Documentation and metadata improvements.
Detected Endpoints
Documentation and metadata improvements.
Detected External IPs
Documentation and metadata improvements.
Detected Internal Hosts
Documentation and metadata improvements.
Detection End Time
Documentation and metadata improvements.
Detection ID
Documentation and metadata improvements.
Detection SLA
Documentation and metadata improvements.
Detection URL
Documentation and metadata improvements.
Device External IPs
Documentation and metadata improvements.
Device Hash
Documentation and metadata improvements.
Device Id
Documentation and metadata improvements.
Device Internal IPs
Documentation and metadata improvements.
Device MAC Address
Documentation and metadata improvements.
Device Model
Documentation and metadata improvements.
Device Name
Documentation and metadata improvements.
Device OS Name
Documentation and metadata improvements.
Device OS Version
Documentation and metadata improvements.
Device OU
Documentation and metadata improvements.
Device Status
Documentation and metadata improvements.
Device Time
Documentation and metadata improvements.
Display Name
Documentation and metadata improvements.
Domain Name
Documentation and metadata improvements.
Domain Registrar Abuse Email
Documentation and metadata improvements.
Domain Squatting Result
Documentation and metadata improvements.
Domain Updated Date
Documentation and metadata improvements.
Dsts
Documentation and metadata improvements.
Duration
Documentation and metadata improvements.
Documentation and metadata improvements.
Email Sent Successfully
Documentation and metadata improvements.
EmailCampaignCanvas
Documentation and metadata improvements.
EmailCampaignMutualIndicators
Documentation and metadata improvements.
EmailCampaignSnippets
Documentation and metadata improvements.
EmailCampaignSummary
Documentation and metadata improvements.
Employee Display Name
Documentation and metadata improvements.
Employee Email
Documentation and metadata improvements.
Employee Manager Email
Documentation and metadata improvements.
End Time
Documentation and metadata improvements.
Endpoint Isolation Status
Documentation and metadata improvements.
Endpoints Details
Documentation and metadata improvements.
Error Code
Documentation and metadata improvements.
Error Message
Documentation and metadata improvements.
Escalation
Documentation and metadata improvements.
Event Action
Documentation and metadata improvements.
Event Descriptions
Documentation and metadata improvements.
Event ID
Documentation and metadata improvements.
Event Names
Documentation and metadata improvements.
Exposure Level
Documentation and metadata improvements.
External Category ID
Documentation and metadata improvements.
External Category Name
Documentation and metadata improvements.
External Confidence
Documentation and metadata improvements.
External End Time
Documentation and metadata improvements.
External Last Updated Time
Documentation and metadata improvements.
External Link
Documentation and metadata improvements.
External Severity
Documentation and metadata improvements.
External Start Time
Documentation and metadata improvements.
External Status
Documentation and metadata improvements.
External Sub Category ID
Documentation and metadata improvements.
External Sub Category Name
Documentation and metadata improvements.
External System ID
Documentation and metadata improvements.
Failed Logon Events
Documentation and metadata improvements.
Failed Logon Events Timeframe
Documentation and metadata improvements.
File Access Date
Documentation and metadata improvements.
File Creation Date
Documentation and metadata improvements.
File Hash
Documentation and metadata improvements.
File Relationships
Documentation and metadata improvements.
File SHA1
Documentation and metadata improvements.
File Size
Documentation and metadata improvements.
First Name
Documentation and metadata improvements.
First Seen
Documentation and metadata improvements.
Follow Up
Documentation and metadata improvements.
Full Name
Documentation and metadata improvements.
Given Name
Documentation and metadata improvements.
Group ID
Documentation and metadata improvements.
High Risky Hosts
Documentation and metadata improvements.
High Risky Users
Documentation and metadata improvements.
Hunt Results Count
Documentation and metadata improvements.
IP Blocked Status
Documentation and metadata improvements.
IP Reputation
Documentation and metadata improvements.
Identity Type
Documentation and metadata improvements.
Incident Link
Documentation and metadata improvements.
IncomingMirrorError
Documentation and metadata improvements.
Internal Addresses
Documentation and metadata improvements.
Investigation Stage
Documentation and metadata improvements.
Is Active
Documentation and metadata improvements.
Isolated
Documentation and metadata improvements.
Item Owner
Documentation and metadata improvements.
Item Owner Email
Documentation and metadata improvements.
Job Code
Documentation and metadata improvements.
Job Family
Documentation and metadata improvements.
Job Function
Documentation and metadata improvements.
Last Mirrored Time Stamp
Documentation and metadata improvements.
Last Modified By
Documentation and metadata improvements.
Last Modified On
Documentation and metadata improvements.
Last Name
Documentation and metadata improvements.
Last Seen
Documentation and metadata improvements.
Last Update Time
Documentation and metadata improvements.
Leadership
Documentation and metadata improvements.
List Of Rules - Event
Documentation and metadata improvements.
Location
Documentation and metadata improvements.
Location Region
Documentation and metadata improvements.
Log Source
Documentation and metadata improvements.
Log Source Name
Documentation and metadata improvements.
Log Source Type
Documentation and metadata improvements.
Low Level Categories Events
Documentation and metadata improvements.
MITRE Tactic ID
Documentation and metadata improvements.
MITRE Tactic Name
Documentation and metadata improvements.
MITRE Technique ID
Documentation and metadata improvements.
MITRE Technique Name
Documentation and metadata improvements.
Macro Source Code
Documentation and metadata improvements.
Manager Email Address
Documentation and metadata improvements.
Manager Name
Documentation and metadata improvements.
Mobile Device Model
Documentation and metadata improvements.
Mobile Phone
Documentation and metadata improvements.
Number Of Found Related Alerts
Documentation and metadata improvements.
Number Of Log Sources
Documentation and metadata improvements.
Number of Related Incidents
Documentation and metadata improvements.
Number of similar files
Documentation and metadata improvements.
OS
Documentation and metadata improvements.
OS Type
Documentation and metadata improvements.
Objective
Documentation and metadata improvements.
Operation Name
Documentation and metadata improvements.
Org Level 1
Documentation and metadata improvements.
Org Level 2
Documentation and metadata improvements.
Org Level 3
Documentation and metadata improvements.
Org Unit
Documentation and metadata improvements.
Original Alert ID
Documentation and metadata improvements.
Original Alert Name
Documentation and metadata improvements.
Original Alert Source
Documentation and metadata improvements.
Original Description
Documentation and metadata improvements.
Original Events
Documentation and metadata improvements.
OutgoingMirrorError
Documentation and metadata improvements.
Parent Process CMD
Documentation and metadata improvements.
Parent Process File Path
Documentation and metadata improvements.
Parent Process IDs
Documentation and metadata improvements.
Parent Process MD5
Documentation and metadata improvements.
Parent Process Name
Documentation and metadata improvements.
Parent Process Path
Documentation and metadata improvements.
Parent Process SHA256
Documentation and metadata improvements.
Part of Campaign
Documentation and metadata improvements.
Password Changed Date
Documentation and metadata improvements.
Password Reset Successfully
Documentation and metadata improvements.
Personal Email
Documentation and metadata improvements.
Phone Number
Documentation and metadata improvements.
Policy Actions
Documentation and metadata improvements.
Policy Deleted
Documentation and metadata improvements.
Policy Description
Documentation and metadata improvements.
Policy Details
Documentation and metadata improvements.
Policy ID
Documentation and metadata improvements.
Policy Recommendation
Documentation and metadata improvements.
Policy Remediable
Documentation and metadata improvements.
Policy Severity
Documentation and metadata improvements.
Policy Type
Documentation and metadata improvements.
Policy URI
Documentation and metadata improvements.
Post Nat Destination IP
Documentation and metadata improvements.
Post Nat Destination Port
Documentation and metadata improvements.
Post Nat Source IP
Documentation and metadata improvements.
Post Nat Source Port
Documentation and metadata improvements.
Pre Nat Destination Port
Documentation and metadata improvements.
Pre Nat Source IP
Documentation and metadata improvements.
Pre Nat Source Port
Documentation and metadata improvements.
Process CMD
Documentation and metadata improvements.
Process Creation Time
Documentation and metadata improvements.
Process ID
Documentation and metadata improvements.
Process MD5
Documentation and metadata improvements.
Process Names
Documentation and metadata improvements.
Process Paths
Documentation and metadata improvements.
Process SHA256
Documentation and metadata improvements.
Project ID
Documentation and metadata improvements.
Protocol names
Documentation and metadata improvements.
Rating
Documentation and metadata improvements.
Raw Event
Documentation and metadata improvements.
Referenced Resource ID
Documentation and metadata improvements.
Referenced Resource Name
Documentation and metadata improvements.
Region
Documentation and metadata improvements.
Region ID
Documentation and metadata improvements.
Registration Email
Documentation and metadata improvements.
Registry Hive
Documentation and metadata improvements.
Registry Key
Documentation and metadata improvements.
Registry Value
Documentation and metadata improvements.
Registry Value Type
Documentation and metadata improvements.
Related Alerts
Documentation and metadata improvements.
Related Campaign
Documentation and metadata improvements.
Related Endpoints
Documentation and metadata improvements.
Related Report
Documentation and metadata improvements.
Remediation SLA
Documentation and metadata improvements.
RemovedFromCampaigns
Documentation and metadata improvements.
Rendered HTML
Documentation and metadata improvements.
Report Name
Documentation and metadata improvements.
Reporter Email Address
Documentation and metadata improvements.
Resource Name
Documentation and metadata improvements.
Resource Type
Documentation and metadata improvements.
Resource URL
Documentation and metadata improvements.
Risk Name
Documentation and metadata improvements.
Risk Rating
Documentation and metadata improvements.
Risk Score
Documentation and metadata improvements.
Rule Name
Documentation and metadata improvements.
SHA1
Documentation and metadata improvements.
SHA512
Documentation and metadata improvements.
SKU Name
Documentation and metadata improvements.
SKU TIER
Documentation and metadata improvements.
SSDeep
Documentation and metadata improvements.
Scenario
Documentation and metadata improvements.
Selected Indicators
Documentation and metadata improvements.
Sensor IP
Documentation and metadata improvements.
Signature
Documentation and metadata improvements.
Similar incidents Dbot
Documentation and metadata improvements.
Source Category
Documentation and metadata improvements.
Source Create time
Documentation and metadata improvements.
Source Created By
Documentation and metadata improvements.
Source External IPs
Documentation and metadata improvements.
Source Geolocation
Documentation and metadata improvements.
Source Id
Documentation and metadata improvements.
Source Networks
Documentation and metadata improvements.
Source Priority
Documentation and metadata improvements.
Source Status
Documentation and metadata improvements.
Source Updated by
Documentation and metadata improvements.
Source Urgency
Documentation and metadata improvements.
Src OS
Documentation and metadata improvements.
Start Time
Documentation and metadata improvements.
State
Documentation and metadata improvements.
Status Reason
Documentation and metadata improvements.
Street Address
Documentation and metadata improvements.
String Similarity Results
Documentation and metadata improvements.
Sub Category
Documentation and metadata improvements.
Subtype
Documentation and metadata improvements.
Surname
Documentation and metadata improvements.
Suspicious Executions
Documentation and metadata improvements.
Suspicious Executions Found
Documentation and metadata improvements.
Tactic
Documentation and metadata improvements.
Tactic ID
Documentation and metadata improvements.
Team name
Documentation and metadata improvements.
Technical Owner
Documentation and metadata improvements.
Technical Owner Contact
Documentation and metadata improvements.
Technical User
Documentation and metadata improvements.
Technique
Documentation and metadata improvements.
Technique ID
Documentation and metadata improvements.
Tenant Name
Documentation and metadata improvements.
Threat Family Name
Documentation and metadata improvements.
Threat Name
Documentation and metadata improvements.
Ticket Acknowledged Date
Documentation and metadata improvements.
Ticket Closed Date
Documentation and metadata improvements.
Ticket Number
Documentation and metadata improvements.
Time to Assignment
Documentation and metadata improvements.
Timezone
Documentation and metadata improvements.
Title
Documentation and metadata improvements.
Tool Usage Found
Documentation and metadata improvements.
Tools
Documentation and metadata improvements.
Traffic Direction
Documentation and metadata improvements.
Triage SLA
Documentation and metadata improvements.
Triggered Security Profile
Documentation and metadata improvements.
URL SSL Verification
Documentation and metadata improvements.
URLs
Documentation and metadata improvements.
UUID
Documentation and metadata improvements.
Unique Ports
Documentation and metadata improvements.
Use Case Description
Documentation and metadata improvements.
User Anomaly Count
Documentation and metadata improvements.
User Block Status
Documentation and metadata improvements.
User Creation Time
Documentation and metadata improvements.
User Engagement Response
Documentation and metadata improvements.
User Groups
Documentation and metadata improvements.
User Id
Documentation and metadata improvements.
User SID
Documentation and metadata improvements.
Users Details
Documentation and metadata improvements.
Vendor ID
Documentation and metadata improvements.
Vendor Product
Documentation and metadata improvements.
Verdict
Documentation and metadata improvements.
Verification Method
Documentation and metadata improvements.
Verification Status
Documentation and metadata improvements.
Vulnerability Category
Documentation and metadata improvements.
Vulnerable Product
Documentation and metadata improvements.
Work Phone
Documentation and metadata improvements.
Zip Code
Documentation and metadata improvements.
app channel name
Documentation and metadata improvements.
sAMAccountName
Documentation and metadata improvements.
similarIncidents
Documentation and metadata improvements.
userAccountControl
Documentation and metadata improvements.
Authentication
Documentation and metadata improvements.
C2Communication
Documentation and metadata improvements.
Defacement
Documentation and metadata improvements.
DoS
Documentation and metadata improvements.
Exfiltration
Documentation and metadata improvements.
Exploit
Documentation and metadata improvements.
Hunt
Documentation and metadata improvements.
Indicator Feed
Documentation and metadata improvements.
Job
Documentation and metadata improvements.
Lateral Movement
Documentation and metadata improvements.
Network
Documentation and metadata improvements.
Policy Violation
Documentation and metadata improvements.
Reconnaissance
Documentation and metadata improvements.
Simulation
Documentation and metadata improvements.
UnknownBinary
Documentation and metadata improvements.
Vulnerability
Documentation and metadata improvements.
ASN
Documentation and metadata improvements.
Account
Documentation and metadata improvements.
Attack Pattern
Documentation and metadata improvements.
CIDR
Documentation and metadata improvements.
CVE
Documentation and metadata improvements.
Campaign
Documentation and metadata improvements.
Course of Action
Documentation and metadata improvements.
DomainGlob
Documentation and metadata improvements.
Documentation and metadata improvements.
File MD5
Documentation and metadata improvements.
File SHA-1
Documentation and metadata improvements.
File SHA-256
Documentation and metadata improvements.
Host
Documentation and metadata improvements.
IPv6CIDR
Documentation and metadata improvements.
Identity
Documentation and metadata improvements.
Infrastructure
Documentation and metadata improvements.
Intrusion Set
Documentation and metadata improvements.
Location
Documentation and metadata improvements.
Malware
Documentation and metadata improvements.
Mutex
Documentation and metadata improvements.
Onion Address
Documentation and metadata improvements.
Registry Key
Documentation and metadata improvements.
Report
Documentation and metadata improvements.
Software
Documentation and metadata improvements.
Tactic
Documentation and metadata improvements.
Threat Actor
Documentation and metadata improvements.
Tool
Documentation and metadata improvements.
X509 Certificate
Documentation and metadata improvements.
ssdeep
Documentation and metadata improvements.
Domain
Added support for the xti module.
File
Added support for the xti module.
IP
Added support for the xti module.
IPv6
Added support for the xti module.
URL
Added support for the xti module.
ASN
Documentation and metadata improvements.
Account Indicator
Documentation and metadata improvements.
Attack Pattern
Documentation and metadata improvements.
CVE Indicator
Documentation and metadata improvements.
Campaign
Documentation and metadata improvements.
Course of Action
Documentation and metadata improvements.
Domain Indicator
Documentation and metadata improvements.
Email Indicator
Documentation and metadata improvements.
File Indicator
Documentation and metadata improvements.
Host Indicator
Documentation and metadata improvements.
IP Indicator
Documentation and metadata improvements.
Identity
Documentation and metadata improvements.
Indicator Feed Incident
Documentation and metadata improvements.
Infrastructure
Documentation and metadata improvements.
Intrusion Set
Documentation and metadata improvements.
Location
Documentation and metadata improvements.
Malware Indicator
Documentation and metadata improvements.
Mutex
Documentation and metadata improvements.
Registry Key Indicator
Documentation and metadata improvements.
Report
Documentation and metadata improvements.
Software
Documentation and metadata improvements.
Tactic Layout
Documentation and metadata improvements.
Threat Actor
Documentation and metadata improvements.
Tool Indicator
Documentation and metadata improvements.
URL Indicator
Documentation and metadata improvements.
Vulnerability Incident
Documentation and metadata improvements.
X509 Certificate
Documentation and metadata improvements.
Traffic Direction
Updated the Traffic Direction incident field to associate 'Trellix Incident' type.
Vendor Product
Updated the Vendor Product incident field to associate 'Trellix Incident' type.
UUID
Updated the UUID incident field to associate 'Trellix Incident' type.
Vendor Product
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Last Update Time
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
UUID
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
End Time
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Display Name
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Start Time
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Risk Score
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
Detection ID
Added the CrowdStrike Falcon NGSIEM Case, CrowdStrike Falcon NGSIEM Incident, and CrowdStrike Falcon NGSIEM Automated Lead incident types as associated types.
imphash incident field.| Certification | Certified | Read more |
| Supported By | Cortex | |
| Created | July 26, 2020 | |
| Last Release | August 10, 2026 |










































































