Skip to content

Latest commit

 

History

History
21 lines (14 loc) · 856 Bytes

c07b5749-deda-4c7e-8e78-4a5dec1fcf4d.md

File metadata and controls

21 lines (14 loc) · 856 Bytes

Products: Cisco Systems - Ironport

Rules

Rule ID Rule Name
LEGACY-S00013 Connection to High Entropy Domain
THRESHOLD-S00026 Possible Credential Abuse
MATCH-S00835 Possible Dynamic URL Domain
OUTLIER-S00010 Spike in URL Length from IP Address

Log Mappers

Log Mapper ID Log Mapper Name
11fa489e-da9a-4982-8c99-55c600318585 Cisco Ironport MID - Custom Parser
d271ce6b-d074-4690-a72a-f5ae754d3efa Cisco Ironport SFIMS - Custom Parser
fdcfade8-8ed5-4195-b0bc-380acfcb6aa7 Cisco Ironport WSA - Custom Parser