ContrastADRAttackEvents_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (79 columns)

Source: Connector definition

Column Name Type
agentVersion string
application dynamic
application_agentLanguage string
application_id string
application_name string
applicationId string
applicationMetadata dynamic
associatedAt datetime
attackPayload dynamic
attackPayload_attackerInput dynamic
attackPayload_attackerInput_applicableAttack bool
attackPayload_attackerInput_confirmedAttack bool
attackPayload_attackerInput_documentPath string
attackPayload_attackerInput_documentType string
attackPayload_attackerInput_effectiveAttack bool
attackPayload_attackerInput_filters dynamic
attackPayload_attackerInput_inputType string
attackPayload_attackerInput_name string
attackPayload_attackerInput_patternsMatched dynamic
attackPayload_attackerInput_type string
attackPayload_url string
attackPayload_value string
codeLocation_file string
codeLocation_method string
codeLocation_stack dynamic
detectedTime long
environment string
eventUuid string
host dynamic
host_hostname string
host_isDocker bool
host_isKubernetes bool
host_operatingSystem string
host_runtimePath string
host_runtimeVersion string
incidentId string
issueId string
mitreTactics dynamic
nativeId string
observationId string
observationType string
organizationUuid string
parameters dynamic
request dynamic
request_body string
request_headers_accept dynamic
request_headers_accept_encoding dynamic
request_headers_connection dynamic
request_headers_content_length dynamic
request_headers_content_type dynamic
request_headers_contrasttraceparent dynamic
request_headers_cookie dynamic
request_headers_host dynamic
request_headers_referer dynamic
request_headers_user_agent dynamic
request_headers_x_forwarded_host dynamic
request_headers_x_forwarded_port dynamic
request_headers_x_forwarded_proto dynamic
request_headers_x_forwarded_scheme dynamic
request_headers_x_real_ip dynamic
request_headers_x_request_id dynamic
request_headers_x_scheme dynamic
request_method string
request_protocol string
request_protocolVersion string
request_queryString string
result string
rule string
ruleUuid string
server dynamic
server_id real
server_name string
severity string
sourceIp string
TimeGenerated datetime
timestamp datetime
url string
vectorAnalysis_callLocation string
vectorAnalysis_vectorFields dynamic

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Contrast ADR Push Connector

Content Items Using This Table (11)

Analytic Rules (5)

In solution ContrastADR:

Analytic Rule Selection Criteria
Contrast ADR - DLP SQL Injection Correlation
Contrast ADR - EDR Alert Correlation
Contrast ADR - Exploited Attack Event
Contrast ADR - Exploited Attack in Production
Contrast ADR - WAF Alert Correlation

Workbooks (6)

In solution ContrastADR:

Workbook Selection Criteria
ContrastADR_Command_Injection_Workbook
ContrastADR_JNDI_Injection_Workbook
ContrastADR_Path_Traversal_Workbook
ContrastADR_SQL_Injection_Workbook
ContrastADR_Untrusted_Deserialization_Workbook
ContrastADR_XML External_Entity_Injection_Injection_Workbook

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
ContrastADR ContrastADR

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index