Skip to main content
Skip table of contents

V 2.0 : Cylance Protect : Memory Exploit Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
V 2.0 : Cylance Protect : Memory Exploit EventsBase RuleGeneral Threat MessageActivity
V 2.0 : Cylance Protect : Exploit AllowedSub RuleGeneral Attack ActivityAttack
V 2.0 : Cylance Protect : Exploit BlockedSub RuleFailed General Attack ActivityFailed Attack
V 2.0 : Cylance Protect : Exploit AlertSub RuleGeneral Attack ActivityAttack
V 2.0 : Cylance Protect : Exploit TerminatedSub RuleFailed General Attack ActivityFailed Attack

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/AN/AN/ADevice Product
ActionN/AN/APossible Values: Allowed, Blocked, None, and Terminated.
Device Name<dname>Text/StringThe name of the device.
Event Type<vmid>Text/String
ExploitAttempt
Event Name<action>, <tag1>Text/String
Possible Values: Allowed, Blocked, None, and Terminated.
IP Address<dip>IP AddressThe IP address or IP addresses for the device.
Process ID<processid>NumberThe process ID for the event.
Process Name<process>Text/String
The fully qualified path of the process.
User Name<login>Text/String
The name of the user currently logged in to the device.
Violation Type<threatname>Text/StringPossible Values: DyldInjection, LsassRead, MaliciousPayload, OutOfProcessAllocation, OutOfProcessApc, OutOfProcessCreateThread, OutOfProcessMap, OutOfProcessOverwriteCode, OutOfProcessUnmapMemory, OutOfProcessWrite, OutOfProcessWritePe, OverwriteCode, StackPivot, StackProject, TrackDataRead, and ZeroAllocate.
Zone NamesN/AN/AThe zone names to which the device belongs.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.