Skip to main content
Skip table of contents

V 2.0 : Sandbox Detection Event

Vendor Documentation

Classification

Rule Name

Rule Type

Classification

Common Event

V 2.0 : Sandbox Detection EventBase RuleActivityGeneral Threat Message

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
Header (logVer)N/AN/ACEF format version
Header (vendor)N/AN/AAppliance vendor
Header (pname)N/AN/AAppliance product
Header (pver)N/AN/AAppliance version
Header (eventid)<vmid>Text/StringDevice event class ID
Header (eventName)N/AN/AEvent name
Header (severity)N/AN/ASeverity
deviceExternalIdN/AN/AID
rtN/AN/ALog generation time in UTC
deviceFacilityN/AN/AProduct type
dvchostN/AN/AServer name
dhost<dname>Text/String/NumberEndpoint name
dst<dip>IP AddressEndpoint IPv4 address
c6a3N/AN/AEndpoint IPv6 address
appN/AN/AEntry channel
sourceServiceNameN/AN/ASource
destinationServiceNameN/AN/ADestination
sproc<process>Text/StringProcess name
fileHash<hash>Text/String/NumberFile SHA-1 hash
fname<object>Text/StringFile name
request<url>Text/String/NumberURL
cs1LabelN/AN/ACorresponding label for the "cs1" field
cs1<threatname>Text/StringThe name of the security threat determined by Virtual Analyzer
cn1LabelN/AN/ACorresponding label for the "cn1" field
cn1<severity>Number0: No risk
1: Low risk
2: Medium risk
3: High risk
9999: Unknown
cs2LabelN/AN/ACorresponding label for the "cs2" field
cs2<subject>Text/StringDisplays the security threat type
cs3LabelN/AN/ACorresponding label for the "cs3" field
cs3N/AN/ACloud storage vendor
Google Drive
Dropbox
Box
Google Drive
Microsoft OneDrive
SugarSync
Hightail
Evernote
Microsoft Exchange Online
Microsoft SharePoint Online
Unknown
N/A
reason<reason>Text/StringCritical Threat Type
A: Known Advanced Persistent Threat (APT)
B: Social engineering attack
C: Vulnerability attack
D: Lateral movement
E: Unknown threats
F: C&C callback
G: Ransomware
deviceNtDomainN/AN/AActive Directory domain
dntdomN/AN/AApex One domain hierarchy
TMCMLogDetectedHostN/AN/AEndpoint name where the log event occurred
TMCMLogDetectedIPN/AN/AIP address where the log event occurred
ApexCentralHostN/AN/AApex Central host name
devicePayloadIdN/AN/AUnique message GUID
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.