Skip to main content
Skip table of contents

V 2.0 : Cylance Protect : Script Control Events

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
V 2.0 : Cylance Protect : Script Control EventsBase RuleGeneral Threat MessageActivity
V 2.0 : Cylance Protect : Script AllowedSub RuleApplication Control DetectionActivity
V 2.0 : Cylance Protect : Script BlockedSub RuleApplication BlockedFailed Activity
V 2.0 : Cylance Protect : Script AlertSub RuleApplication Control DetectionActivity
V 2.0 : Cylance Protect : Script UnknownSub RuleGeneral SecurityOther Security

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
N/AN/AText/StringDevice Product
Device Name<dname>Text/StringThe name of the device.
Event Type<vmid>Text/String
ScriptControl
Event Name

<action>, <tag1>

Text/String
Possible Values: Alert, Blocked, None, and Unknown.
File Path<object>Text/StringThe path to the file.
InterpreterN/AN/AActiveScript, MacroScript, Powershell
Interpreter VersionN/AN/AThe version number of the interpreter.
Zone NamesN/AN/AThe names of the zones to which the device belongs.
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.