Watchlist Hit : Binary Storage

Vendor Documentation

Classification

Rule Name

Rule Type

Common Event

Classification

Watchlist Hit : Binary Storage

Base Rule

Watchlist Hit

Activity

Watchlist Hit : Unsigned Binary Storage

Sub Rule

Watchlist Hit

Activity

Watchlist Hit : Signed Binary Storage

Sub Rule

Watchlist Hit

Activity

Mapping with LogRhythm Schema

Device Key in Log Message

LogRhythm Schema

Data Type

publisher/issuer

<subject>

Text/String

digsig_result

<result>

Text/String

digsig_result

<tag1>

Text/String

endpoint

<dname>

Text/String

file_version

<version>

Number

group

<group>

Text/String

md5

<objectname>

Text/String

md5

<hash>

Text/String

observed_filename

<process>

Text/String

original_filename

<object>

Text/String

watchlist_name

<vmid>

Text/String