Maps FireEye EX alerts.
FireEye Common Fields
- Details
 - Content
 - Dependencies
 - Version History
 
FireEye common fields concentrates all of the mutual content entities for the FireEye integrations.
| Name | Description | 
|---|---|
FireEye EX - Incoming Mapper  | |
FireEye NX Alert - Incoming Mapper v2  | Maps FireEye NX alerts.  | 
FireEye NX IPS Alert - Incoming Mapper v2  | Maps FireEye NX IPS alerts.  | 
| Name | Description | 
|---|---|
FireEye Download At  | |
FireEye C2 Host  | |
FireEye Infection ID  | |
FireEye Malware Information  | |
FireEye Match Count  | |
FireEye Alert Malicious  | |
FireEye Submitted At  | |
FireEye Signature Revision  | |
FireEye Domain Name  | |
FireEye Signature ID  | |
FireEye Malware Info  | |
FireEye Alert Vlan  | |
FireEye Matched Time  | |
FireEye C2 Address  | |
FireEye Alert Infection ID  | |
FireEye C2 Channel  | |
FireEye Infection URL  | |
FireEye C2 Protocol  | |
FireEye Email Source Domain  | |
FireEye Email Queue ID  | |
FireEye Signature  | |
FireEye C2 Port  | 
| Name | Description | 
|---|---|
FireEye EX - Incoming Mapper  | Maps FireEye EX alerts.  | 
FireEye NX Alert - Incoming Mapper v2  | Maps FireEye NX alerts.  | 
FireEye NX IPS Alert - Incoming Mapper v2  | Maps FireEye NX IPS alerts.  | 
| Name | Description | 
|---|---|
FireEye C2 Channel  | |
FireEye Matched Time  | |
FireEye C2 Address  | |
FireEye Alert Infection ID  | |
FireEye Infection URL  | |
FireEye Alert Vlan  | |
FireEye Email Queue ID  | |
FireEye Email Source Domain  | |
FireEye Signature Revision  | |
FireEye C2 Host  | |
FireEye Signature ID  | |
FireEye Infection ID  | |
FireEye Download At  | |
FireEye Submitted At  | |
FireEye Malware Info  | |
FireEye Alert Malicious  | |
FireEye Malware Information  | |
FireEye Match Count  | 
| Pack Name | Pack By | 
|---|---|
| Base | By: Cortex XSOAR  | 
| Pack Name | Pack By | 
|---|---|
| Common Types | By: Cortex XSOAR  | 
| FireEye Email Security (EX) | By: Cortex XSOAR  | 
| FireEye HX | By: Cortex XSOAR  | 
| FireEye Network Security (NX) | By: Cortex XSOAR  | 
| Malware Core | By: Cortex XSOAR  | 
| Phishing | By: Cortex XSOAR  | 
| PhishingAlerts | By: Cortex XSOAR  | 
| Pack Name | Pack By | 
|---|---|
| Base | By: Cortex XSOAR  | 
Incident Fields
- FireEye C2 Protocol
 - FireEye Domain Name
 
Incident Fields
- FireEye Signature
 
Incident Fields
FireEye C2 Port
    - Maintenance and stability enhancements.
Mappers
FireEye EX - Incoming Mapper
- Added mapping for Phishing Alerts incident type.
 
Incident Fields
- FireEye Malware Information
 
Incident Fields
- FireEye C2 Protocol
 - FireEye Domain Name
 
Incident Fields
FireEye C2 Port
    - Maintenance and stability enhancements.
Mappers
FireEye EX - Incoming Mapper
- Added mapping for Phishing Alerts incident type.
 
Incident Fields
- FireEye Malware Information
 
FireEye common fields concentrates all of the mutual content entities for the FireEye integrations.
PUBLISHER
PLATFORMS
INFO
| Certification | Certified | Read more | 
| Supported By | Cortex | |
| Created | June 11, 2021 | |
| Last Release | March 26, 2025 | 
WORKS WITH THE FOLLOWING INTEGRATIONS:




