Speculus_Indicators_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (33 columns)

Source: Connector definition

Column Name Type
Activity string
Asn string
Attribution string
City string
CloudProvider dynamic
Confidence int
ConnectionType string
Country string
CountryCode string
Created datetime
Description string
FirstSeen datetime
IndicatorTypes string
IndicatorValue string
IsBlacklisted bool
IsDatacenter bool
Isp string
IsScanner bool
IsTorNode bool
IsVpnProxy bool
Labels string
LastSeen datetime
Modified datetime
Name string
Org string
Pattern string
ResidentialProxy dynamic
Risk string
RiskScore int
ScannerName string
StixId string
TimeGenerated datetime
ValidFrom datetime

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Speculus Threat Intelligence

Content Items Using This Table (3)

Analytic Rules (3)

In solution Speculus Threat Intelligence:

Analytic Rule Selection Criteria
Speculus - Network traffic to or from high-risk IP indicator
Speculus - Sign-in attempt from high-risk IP indicator
Speculus - Threat intelligence feed outage

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index