Skip to content

Latest commit

 

History

History
57 lines (50 loc) · 2.58 KB

LEGACY-S00108.md

File metadata and controls

57 lines (50 loc) · 2.58 KB

Rules: Threat Intel - Matched File Hash

Description

A record flagged a file hash from a threat intelligence match list

Additional Details

Detail Value
Type Match
Category Threat Intelligence
Apply Risk to Entities device_hostname, srcDevice_hostname, device_ip, device_natIp, srcDevice_ip, srcDevice_natIp, device_mac, srcDevice_mac, user_username, dns_replyIp
Signal Name Threat Intel - Matched File Hash
Summary Expression None
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema device_mac
Normalized Schema device_natIp
Normalized Schema dns_replyIp
Normalized Schema listMatches
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema srcDevice_mac
Normalized Schema srcDevice_natIp
Normalized Schema user_username