threatintel.external
Introduction
The tags beginning with threatintel.external
identify events generated by products to detect external threats.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as threatintel.external
. The third level identifies the product and the fourth indicates the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Threat Compass (formerly Blueliv Threat Compass) |
|
|
|
| |
|
| |
|
| |
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in these tables:
threatintel.external.blueliv.attackingips
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
attackType |
|
|
destination_ip |
|
|
destination_port |
|
|
destination_serviceName |
|
|
destination_latitude |
|
|
destination_longitude |
|
|
destination_city |
|
|
destination_country |
|
|
destination_countryName |
|
|
source_ip |
|
|
source_port |
|
|
source_latitude |
|
|
source_longitude |
|
|
source_city |
|
|
source_country |
|
|
source_countryName |
|
|
lastEvent |
|
|
updatedAt |
|
|
createdAt |
|
|
firstEvent |
|
|
numEvents |
|
|
_id |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
threatintel.external.blueliv.credentials
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
id |
|
|
userName |
|
|
userPassword |
|
|
portalUrl |
|
|
botIp |
|
|
type |
|
|
isEmail |
|
|
reportedAt |
|
|
classification |
|
|
stolenAt |
|
|
botLongitude |
|
|
botLatitude |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
threatintel.external.blueliv.credentialsettings
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
asset |
|
|
action |
|
|
assetype |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
threatintel.external.blueliv.crimeservers
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
url |
|
|
type |
|
|
subType |
|
|
country |
|
|
countryName |
|
|
city |
|
|
status |
|
|
host |
|
|
latitude |
|
|
longitude |
|
|
ip |
|
|
updatedAt |
|
|
asnId |
|
|
lastSeenAt |
|
|
confidence |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |
threatintel.external.blueliv.malware
Field | Type | Extra fields |
---|---|---|
eventdate |
|
|
malwareType |
|
|
filename |
|
|
md5 |
|
|
sha1 |
|
|
sha256 |
|
|
fileType |
|
|
confidence |
|
|
contentType |
|
|
architecture |
|
|
fileSize |
|
|
firstSeenAt |
|
|
analyzedAt |
|
|
severityOneCount |
|
|
severityOneList |
|
|
severityTwoCount |
|
|
severityTwoList |
|
|
severityThreeCount |
|
|
severityThreeList |
|
|
severityFourCount |
|
|
severityFourList |
|
|
severityFiveCount |
|
|
severityFiveList |
|
|
severitySixCount |
|
|
severitySixList |
|
|
hostchain |
| ✓ |
tag |
| ✓ |
rawMessage |
| ✓ |