Skip to main content
Skip table of contents

Watchlist Hit : Binary

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification
Watchlist Hit : BinaryBase RuleWatchlist HitActivity
Watchlist Hit : Unsigned BinarySub RuleWatchlist HitActivity
Watchlist Hit : Signed BinarySub RuleWatchlist HitActivity

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData Type
severity<severity>Text/String
result<result>Text/String
result<tag1>Text/String
digsig_publisher/digsig_issuer<subject>Text/String
endpoint<dname>Text/String
file_version<version>Number
group<group>Text/String
md5<objectname>Text/String
md5<hash>Text/String
observed_filename<process>Text/String
original_filename<object>Text/String
watchlist_name<vmid>Text/String



JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.