Skip to main content
Skip table of contents

V 2.0 : C&C Callback Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 : C&C Callback EventBase RuleActivityGeneral Threat Message
V 2.0 : C&C Callback : UnknownSub RuleActivityGeneral Threat Message
V 2.0 : C&C Callback : PassSub RuleMalwareDetected Malware Activity
V 2.0 : C&C Callback : BlockSub RuleFailed ActivityThreat Blocked
V 2.0 : C&C Callback : MonitorSub RuleMalwareDetected Malware Activity
V 2.0 : C&C Callback : DeleteSub RuleFailed ActivityThreat Deleted
V 2.0 : C&C Callback : QuarantineSub RuleActivityQuarantine
V 2.0 : C&C Callback : WarnSub RuleMalwareDetected Malware Activity
V 2.0 : C&C Callback : Warn & ContinueSub RuleMalwareDetected Malware Activity
V 2.0 : C&C Callback : OverrideSub RuleMalwareDetected Malware Activity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AAppliance vendor
Header (pname)N/AN/AAppliance product
Header (pver)N/AN/AAppliance version
Header (eventid)N/AN/ACnC:Action
Header (eventName)<vmid>Text/StringName
Header (severity)N/AN/ASeverity
deviceExternalIdN/AN/AID
rtN/AN/ALog generation time in UTC
catN/AN/ALog type
deviceFacilityN/AN/AProduct
cs2LabelN/AN/ACorresponding label for the "cs2" field
cs2N/AN/AProduct version
shostN/AN/AEndpoint host name
src<sip>IP AddressEndpoint IPv4 address
c6a2LabelN/AN/ACorresponding label for the "c6a2" field
c6a2<sip>IP AddressEndpoint IPv6 address
cs3LabelN/AN/ACorresponding label for the "cs3" field
cs3<domainorigin>Text/StringDomain name
cs4LabelN/AN/ACorresponding label for the "cs4" field
cs4<policy>Text/StringPolicy name
act<action>
<tag1>
Text/StringAction
0: Unknown
1: Pass
2: Block
3: Monitor
4: Delete
5: Quarantine
6: Warn
7: Warn and continue
8: Override
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1<severity>NumberC&C risk level
0: SLF_CCCA_RISKLEVEL_UNKNOWN
1: SLF_CCCA_RISKLEVEL_LOW
2: SLF_CCCA_RISKLEVEL_MEDIUM
3: SLF_CCCA_RISKLEVEL_HIGH
cn2LabelN/AN/ACorresponding label for the "cn2" field
cn2N/AN/AC&C list source
0: SLF_CCCA_GLOBAL_LIST
1: SLF_CCCA_CUSTOM_LIST
2: SLF_CCCA_CUSTOM_LIST_USER_DEFINED
cn3LabelN/AN/ACorresponding label for the "cn3" field
cn3N/AN/ACallback address format
0: IP
1: IP
2: HTTP
3: SMTP
request<url>Text/String/NumberURL
cs5LabelN/AN/ACorresponding label for the "cs5" field
cs5N/AN/ACallback URL address
dst<dip>IP AddressCallback IPv4 address
c6a3LabelN/AN/ACorresponding label for the "c6a3" field
c6a3<dip>IP AddressCallback IPv6 address
deviceProcessName<process>Text/StringProcess name
deviceNtDomainN/AN/AActive Directory domain
dntdomN/AN/AApex One domain hierarchy
dvchostN/AN/AHost name
TMCMLogDetectedHost<dname>Text/StringEndpoint name where the log event occurred
TNCNKigDetectedIP<dip>IP AddressIP address where the log event occurred
ApexCentralHostN/AN/AApex Central host name
devicePayloadIdN/AN/AUnique message GUID
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.