CyfirmaASConfigurationAlerts_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (44 columns)

Source: KQL validation test schema

Column Name Type
alert_object_uid string
Alert_title string
alert_uid string
asset_comment string
category string
click_jacking_defence bool
content_security_policy bool
cookie_xss_protection bool
data_injection_defence bool
description string
dmarc string
dns_sec string
domain_expiry dynamic
domain_status string
first_seen datetime
ip string
is_third_party bool
last_seen datetime
missing_epp_codes dynamic
notes dynamic
open_relay string
risk_score int
safe_flag_comments string
safe_flag_marked_by string
safe_flag_marked_date string
secure_cookie bool
server string
server_version string
set_cookie_https_only bool
severity string
software string
spf string
status string
strict_transport_Security bool
sub_category string
sub_domain string
TimeGenerated datetime
top_domain string
uid string
use_cases string
web_app_firewall string
x_frame_options bool
x_xss_protection bool
zone_transfer string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
CYFIRMA Attack Surface

Content Items Using This Table (2)

Analytic Rules (2)

In solution Cyfirma Attack Surface:

Analytic Rule Selection Criteria
CYFIRMA - Attack Surface - Configuration High Rule
CYFIRMA - Attack Surface - Configuration Medium Rule

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index