Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Ingestion API Supported | ✓ Yes |
Source: KQL validation test schema
| Column Name | Type |
|---|---|
| explanation | string |
| factors | string |
| feedNames | string |
| indicator | string |
| indicatorType | string |
| isAnonymizer | bool |
| isBruteforce | bool |
| isC2 | bool |
| isMalware | bool |
| isPhishing | bool |
| isScanner | bool |
| isSpam | bool |
| isThreat | bool |
| isTor | bool |
| lastSeen | datetime |
| threatLevel | string |
| threatScore | real |
| threatSources | int |
| TimeGenerated | datetime |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
In solution Whisper:
| Analytic Rule | Selection Criteria |
|---|---|
| Whisper Security - C2 Communication Detection | |
| Whisper Security - Co-Hosted Malware Cluster Detection | |
| Whisper Security - Tor Exit Node Communication |
In solution Whisper:
In solution Whisper:
| Workbook | Selection Criteria |
|---|---|
| InfrastructureThreatLandscape |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊