HoneyLabs TI Map IP Entity to CommonSecurityLog

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


'Identifies source-IP matches in CommonSecurityLog (firewall, proxy and other CEF sources) against IP indicators from HoneyLabs honeypot telemetry. A match means a source IP that ran exploit or loader commands against HoneyLabs sensors also appeared as a source in your own logs. Only the structured SourceIP field is matched; destination IPs and IPs merely mentioned inside the free-text Message are ignored, because those are frequently unrelated and generate false positives. Indicator Confidence

Attribute Value
Type Analytic Rule
Solution HoneyLabs
ID c7061f05-d0ed-40e1-862e-bc52e454e3a1
Severity Medium
Kind Scheduled
Tactics InitialAccess, CommandAndControl
Techniques T1190, T1071
Required Connectors ThreatIntelligenceTaxii, CEF
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CommonSecurityLog ✓ ✓ ✓
ThreatIntelIndicators ✓ ✓ ✗

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to HoneyLabs