CyfirmaASOpenPortsAlerts_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (28 columns)

Source: KQL validation test schema

Column Name Type
alert_object_uid string
Alert_title string
alert_uid string
asset_comments string
category string
description string
first_seen datetime
ip string
is_third_party bool
last_seen datetime
notes dynamic
open_ports dynamic
risk_score int
safe_flag_comments string
safe_flag_marked_by string
safe_flag_marked_date string
severity string
software string
status string
sub_category string
sub_domain string
TimeGenerated datetime
top_domain string
uid string
use_cases string
web_app_firewall string
web_server string
web_server_version string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
CYFIRMA Attack Surface

Content Items Using This Table (2)

Analytic Rules (2)

In solution Cyfirma Attack Surface:

Analytic Rule Selection Criteria
CYFIRMA - Attack Surface - Open Ports High Rule
CYFIRMA - Attack Surface - Open Ports Medium Rule

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index