V 2.0 : Outbound SEP Malicious Activity Detected 1

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

V 2.0 : Outbound SEP Malicious Activity Detected

Base Rule

General Attack Activity

Attack

V 2.0 : Outbound SEP Identified Attack Sign. Detect

Sub Rule

General Attack Activity

Attack

Mapping with LogRhythm Schema  

Device Key in Log Message

LogRhythm Schema

Data Type

SymantecServer

 <sname>

Text/String

Event Description

<subject>
<tag1>

Text/String/Number

Local

<sip>

Number

Local

<smac>

Number

Remote

<dname>

Text/String

Remote

<dip>

Number

Remote

<dmac>

Number

Outbound

<protname>

Text/String

Occurrences

<quantity>

Number

User

<login>

Text/String

Domain

<domainorigin>

Number

Local Port

<sport>

Number

Remote Port

<dport>

Number

Signature ID

<threatid>
<tag2>

Number

Signature string

<threatname>

Text/String/Number

Intrusion Url

<url>

Text/String

SHA-256:

MD-5:

<hash>

Text/String/Number