Document toolboxDocument toolbox

xdr.mandiant

Introduction

The tags beginning with xdr.mandiant identify events generated by Mandiant.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as xdr.mandiant. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Mandiant Threat Intelligence

xdr.mandiant.threatintel.dtm_alert

xdr.mandiant.threatintel.dtm_alert

For more information, read more About Devo tags.

How is the data sent to Devo?

To send logs to these tables, Devo provides a collector that retrieves the required events and sends them to your Devo domain. Check this article to learn more about the Mandiant Advantage collector.

Table structure

These are the fields displayed in this table:

xdr.mandiant.threatintel.dtm_alert

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

hostname

str

 

 

 

id

str

 

 

 

monitor_id

str

 

 

 

topic_matches__topic_id

str

join(topic_matches__topic_id_array, ',')

topic_matches__topic_id_array

 

topic_matches__value

str

join(topic_matches__value_array, ',')

topic_matches__value_array

 

topic_matches__term

str

join(topic_matches__term_array, ',')

topic_matches__term_array

 

topic_matches__offsets

str

topic_matches__offsets_array

 

created_at

timestamp

 

 

 

updated_at

timestamp

 

 

 

labels_url

str

 

 

 

topics_url

str

 

 

 

doc_url

str

 

 

 

status

str

 

 

 

alert_type

str

 

 

 

alert_summary

str

 

 

 

title

str

 

 

 

email_sent_at

str

 

 

 

severity

str

 

 

 

confidence

float8

 

 

 

monitor_version

int4

 

 

 

at_devo_environment

str

 

 

 

at_devo_pulling_id

str

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

 

✓