Syslog - Malwarebytes Endpoint Security CEF
Device Details
Vendor | Malwarebytes |
---|---|
Device Type | Malwarebytes Endpoint Security |
Supported Model Name/Number | Malwarebytes Management Console (MBMC) |
Supported Software Version(s) | 1.8.0.3443 |
Collection Method | Syslog |
Configurable Log Output? | No |
Log Source Type | Syslog - Malwarebytes Endpoint Security CEF |
Log Processing Policy | LogRhythm Default |
Exceptions | N/A |
Additional Information |
Prerequisites
Endpoint configuration changes must be implemented to facilitate installation of a Malwarebytes managed client to those endpoints. Similar methods are required for the various operating systems, and they are grouped accordingly.
Windows Server Endpoint Preparation for All Supported Versions
- From the Windows Start Menu, launch the Control Panel.
- Launch Network and Sharing Center by double-clicking its icon.
- On the left side of the screen, select Change advanced sharing settings.
- Click the arrow to the right of All Networks or Domain, (dependent on network environment).
- Turn on Network discovery, File sharing and Printer sharing.
- Click Save changes.
- Close the Control Panel.
- Launch the Server Manager by clicking its Icon.
- Select Administrative Tools, Add Feature, and then .Net 3.5.
- Continue through the installation.
- WORKGROUP ONLY: Enable the built-in administrator account by opening a command prompt as administrator, and typing the following command: net user administrator /active:yes
Windows 7/8/8.1/10 Endpoint Preparation
- From the Windows Start Menu, launch the Control Panel.
- Launch Network and Sharing Center by double-clicking its icon.
- On the left side of the screen, select Change advanced sharing settings.
- Click the arrow to the right of All Networks or Domain, (dependent on network environment).
- Turn on Network discovery, File sharing and Printer sharing.
- Click Save changes.
- Close the Control Panel.
- WORKGROUP ONLY: Enable the built-in administrator account by opening a command prompt as administrator, and typing the following command: net user administrator /active:yes
Windows Vista Endpoint Preparation
- From the Windows Start Menu, launch the Control Panel.
- Launch Network and Sharing Center by double-clicking its icon.
- In the section titled Sharing and Discovery, turn on Network discovery, File sharing and Printer sharing.
- Close the Control Panel.
- WORKGROUP ONLY: Enable the built-in administrator account by opening a command prompt as administrator, and typing the following command: net user administrator /active:yes
Windows XP Endpoint Preparation
- From the Windows Start Menu, launch the Control Panel.
- Launch Network and Sharing Center by double-clicking its icon.
- Click the Exceptions tab.
- Check the checkboxes for File and Printer Sharing.
- To close the Windows Firewall screen, click OK.
- Launch Administrative Tools by double-clicking on its icon.
- Launch Local Security Policy by double-clicking on its icon.
The Local Security Settings screen opens. - In the left panel, click Local Policies.
The main panel refreshes to show relevant settings. - Scroll down to Network access: Sharing and security model for local accounts.
- Double click this setting.
- Change the value to Classic – local users authenticate as themselves.
- To save the changes, click OK.
- Close the Local Security Settings window, the Administrative Tools window, and the Control Panel.
If your company’s Internet access is controlled by a firewall or other access-limiting device, you must grant access for Malwarebytes Management Console to reach Malwarebytes services. These are:
https://data.service.malwarebytes.org/ | Port443 | outbound |
https://data-cdn.mbamupdates.com/ | Port443 | outbound |
https://hubble.mb-cosmos.com/ | Port443 | outbound |
https://*.mwbsys.com | Port443 | outbound |
https://telemetry.malwarebytes.com/ | Port443 | outbound |
Currently Supported Log Types
Type | Product Version | Supported Schema Fields |
---|---|---|
Malware Messages | 1.8.0.3443 | deviceVersion, port, process, threatName, severity, dvchost, deviceDnsDomain, deviceMacAddress, dvc, act, outcome, suser, fname, filePath, sourceServiceName |
Parsed Metadata Fields
Malwarebytes Endpoint Security CEF Field Name | LogRhythm Metadata Field | Value/Data Type |
---|---|---|
act | <action> | Text/String |
deviceDnsDomain | <domain> | Text/String |
deviceMacAddress | <smac> | Text/String |
deviceVersion | <version> | Text/String |
dvc | <sip> | Text/String |
dvchost | <sname> | Text/String |
filePath | <object> | Text/String |
fname | <objectname> | Text/String |
N/A | <threatname> | Text/String |
outcome | <result> | Text/String |
port | <sport> | Number |
process | <process> | Text/String |
severity | <severity> | Text/String |
sourceServiceName | <parentprocessname> | Text/String |
suser | <login> | Text/String |