ids.attivo
Introduction
The tags beginning with ids.attivo
identify events generated by Attivo.
Valid tags and data tables
The full tag must have 3 levels. The first two are fixed as ids.attivo
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Attivo BOTsink |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in this table:
ids.attivo.botsink
Field | Type | Extra fields |
---|---|---|
eventdate |
| Â |
Severity |
| Â |
Attacker_IP |
| Â |
Target_Host |
| Â |
Target_IP |
| Â |
Target_OS |
| Â |
Description |
| Â |
Details |
| Â |
Phase |
| Â |
Service |
| Â |
VLANID |
| Â |
Forwarder |
| Â |
Attacker_IP_Domain |
| Â |
Target_IP_Domain |
| Â |
Attacker_HostName |
| Â |
Attacker_UserNames |
| Â |
TargetIP_List |
| Â |
Target_Ports |
| Â |
Target_IP_Ports |
| Â |
Forwarder_IP |
| Â |
Dest_UserName |
| Â |
subscriberName |
| Â |
Attacker_MAC |
| Â |
Attivo_AlertID |
| Â |
MITRE_Technique_ID |
| Â |
MITRE_Technique_Name |
| Â |
MITRE_Tactic_Name |
| Â |
VTSummaryResult |
| Â |
WebRootReputation |
| Â |
rawMessage |
|  ✓ |
hostchain |
| ✓ |
tag |
|  ✓ |