Feed : Binary Storage Hit

Vendor Documentation


Classification

Rule Name

Rule Type

Common Event

Classification

Feed : Binary Storage Hit

Base Rule

Watchlist Hit

Activity

Feed Hit : Unsigned Binary Storage

Sub Rule

Watchlist Hit

Activity

Feed Hit : Signed Binary Storage

Sub Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

alliance_link_

<url>

Text/String

CVE

<cve>
<sender>

Text/String

digsig_publisher/issuer

<subject>

Text/String

digsig_result

<result>
<tag1>

Text/String

md5

<hash>

Text/String