Skip to main content
Skip table of contents

V 2.0 : Inbound SEP Malicious Activity Detected

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Inbound SEP Malicious Activity DetectedBase RuleSuspicious ActivitySuspicious

V 2.0 : Inbound SEP Identified Attack Sign. Detect

Sub RuleGeneral Attack ActivityAttack

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaData Type
N/A<sip>Number
N/A<sname>String/Number/Text
N/A<dip>Number
N/A<dname>String/Number/Text
N/A<sport>String/Number/Text
N/A<dport>String/Number/Text
N/A<smac>String/Number/Text
N/A<dmac>String/Number/Text
N/A<protname>Text/String
N/A<account>Text/String
N/A<domainimpacted>Text/String
N/A<subject>Text/String
N/A<threatname>String/Number/Text
N/A<threatid>
<tag1>
String/Number/Text
N/A<hash>String/Number/Text
N/A<url>String/Number/Text
N/A<quantity>Number
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.