ZeroFox_CTI_botnet_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (21 columns)

Source: KQL validation test schema

Column Name Type
acquired_at_t datetime
anti_viruses_s string
available_keyboards_s string
bot_name_s string
breached_at datetime
c2_domain_s string
c2_ip_address_s string
country_code_s string
current_language_s string
estimated_infected_at_t datetime
file_location_s string
is_common_domain_b bool
listed_at_t datetime
location_s string
logged_at_t datetime
operating_system_s string
process_elevation_s string
tags_s string
TimeGenerated datetime
uac_s string
zip_code_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
ZeroFox CTI


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index