diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index 9f5911521f3..e768edc9ede 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -20774,16 +20774,6 @@ Module for parsing Cisco AMP logs. The timestamp in Epoch nanoseconds. -type: date - --- - -*`cisco.amp.date`*:: -+ --- -The timestamp in ISO8601 format. - - type: date -- @@ -21244,7 +21234,7 @@ type: keyword When the threat hunt finalized or closed. -type: keyword +type: date -- @@ -21254,7 +21244,7 @@ type: keyword When the threat hunt was initiated. -type: keyword +type: date -- diff --git a/filebeat/docs/modules/cisco.asciidoc b/filebeat/docs/modules/cisco.asciidoc index b76e7a996db..f6d03b364d3 100644 --- a/filebeat/docs/modules/cisco.asciidoc +++ b/filebeat/docs/modules/cisco.asciidoc @@ -14,7 +14,7 @@ This is a module for Cisco network device's logs and Cisco Umbrella. It includes filesets for receiving logs over syslog or read from a file: - `asa` fileset: supports Cisco ASA firewall logs. -- `amp` fileset: supports Cisco Umbrella logs. +- `amp` fileset: supports Cisco AMP API logs. - `ftd` fileset: supports Cisco Firepower Threat Defense logs. - `ios` fileset: supports Cisco IOS router and switch logs. - `nexus` fileset: supports Cisco Nexus switch logs. @@ -448,9 +448,9 @@ Maximum duration before AWS API request will be interrupted. Default to be 120 s [float] ==== `amp` fileset settings -The Cisco AMP fileset focuses on collecting events from your Cisco AMP/Cisco Securi Endpoint API. +The Cisco AMP fileset focuses on collecting events from your Cisco AMP/Cisco Secure Endpoint API. -To configure the Cisco AMP fileset you will need to retrieve your client_id and client_key from the AMP dashboard. +To configure the Cisco AMP fileset you will need to retrieve your `client_id` and `api_key` from the AMP dashboard. For more information on how to retrieve these credentials, please reference the https://api-docs.amp.cisco.com/api_resources?api_host=api.amp.cisco.com&api_version=v1[Cisco AMP API documentation]. The URL configured for the API depends on which region your AMP is located, currently there is 3 choices: @@ -488,12 +488,13 @@ It is also possible to select how often Filebeat will check the Cisco AMP API. A var.first_interval: 200h var.interval: 60m var.request_timeout: 120s + var.limit: 100 ---- *`var.input`*:: -The input from which messages are read. Supports httpjson(default) and file. +The input from which messages are read. Supports httpjson. *`var.url`*:: @@ -516,6 +517,10 @@ timeout value for each request sent by Filebeat. How far back you would want to collect events the first time the Filebeat module starts up. Supports amount in hours. +*`var.limit`*:: + +This value controls how many events are returned by the Cisco AMP API per page. + :has-dashboards!: :fileset_ex!: diff --git a/x-pack/filebeat/module/cisco/_meta/docs.asciidoc b/x-pack/filebeat/module/cisco/_meta/docs.asciidoc index 181d101e352..7dbc483128e 100644 --- a/x-pack/filebeat/module/cisco/_meta/docs.asciidoc +++ b/x-pack/filebeat/module/cisco/_meta/docs.asciidoc @@ -9,7 +9,7 @@ This is a module for Cisco network device's logs and Cisco Umbrella. It includes filesets for receiving logs over syslog or read from a file: - `asa` fileset: supports Cisco ASA firewall logs. -- `amp` fileset: supports Cisco Umbrella logs. +- `amp` fileset: supports Cisco AMP API logs. - `ftd` fileset: supports Cisco Firepower Threat Defense logs. - `ios` fileset: supports Cisco IOS router and switch logs. - `nexus` fileset: supports Cisco Nexus switch logs. @@ -443,9 +443,9 @@ Maximum duration before AWS API request will be interrupted. Default to be 120 s [float] ==== `amp` fileset settings -The Cisco AMP fileset focuses on collecting events from your Cisco AMP/Cisco Securi Endpoint API. +The Cisco AMP fileset focuses on collecting events from your Cisco AMP/Cisco Secure Endpoint API. -To configure the Cisco AMP fileset you will need to retrieve your client_id and client_key from the AMP dashboard. +To configure the Cisco AMP fileset you will need to retrieve your `client_id` and `api_key` from the AMP dashboard. For more information on how to retrieve these credentials, please reference the https://api-docs.amp.cisco.com/api_resources?api_host=api.amp.cisco.com&api_version=v1[Cisco AMP API documentation]. The URL configured for the API depends on which region your AMP is located, currently there is 3 choices: @@ -483,12 +483,13 @@ It is also possible to select how often Filebeat will check the Cisco AMP API. A var.first_interval: 200h var.interval: 60m var.request_timeout: 120s + var.limit: 100 ---- *`var.input`*:: -The input from which messages are read. Supports httpjson(default) and file. +The input from which messages are read. Supports httpjson. *`var.url`*:: @@ -511,6 +512,10 @@ timeout value for each request sent by Filebeat. How far back you would want to collect events the first time the Filebeat module starts up. Supports amount in hours. +*`var.limit`*:: + +This value controls how many events are returned by the Cisco AMP API per page. + :has-dashboards!: :fileset_ex!: diff --git a/x-pack/filebeat/module/cisco/amp/_meta/fields.yml b/x-pack/filebeat/module/cisco/amp/_meta/fields.yml index 58dcbfa14a5..de20fe61484 100644 --- a/x-pack/filebeat/module/cisco/amp/_meta/fields.yml +++ b/x-pack/filebeat/module/cisco/amp/_meta/fields.yml @@ -10,11 +10,6 @@ description: > The timestamp in Epoch nanoseconds. - - name: date - type: date - description: > - The timestamp in ISO8601 format. - - name: event_type_id type: keyword description: > @@ -241,12 +236,12 @@ The id of the related incident for the threat hunting activity. - name: threat_hunting.incident_end_time - type: keyword + type: date description: > When the threat hunt finalized or closed. - name: threat_hunting.incident_start_time - type: keyword + type: date description: > When the threat hunt was initiated. diff --git a/x-pack/filebeat/module/cisco/amp/config/config.yml b/x-pack/filebeat/module/cisco/amp/config/config.yml index dd8218bcd3f..9148979bd35 100644 --- a/x-pack/filebeat/module/cisco/amp/config/config.yml +++ b/x-pack/filebeat/module/cisco/amp/config/config.yml @@ -18,7 +18,7 @@ request.transforms: default: '[[ formatDate (now (parseDuration "-{{ .first_interval }}")) "2006-01-02T15:04:05-07:00" ]]' - set: target: url.params.limit - value: 100 + value: {{ .limit }} request.rate_limit.limit: '[[ .last_response.header.Get "X-RateLimit-Limit" ]]' request.rate_limit.reset: '[[ .last_response.header.Get "X-RateLimit-Reset" ]]' request.rate_limit.remaining: '[[ .last_response.header.Get "X-RateLimit-Remaining" ]]' @@ -68,4 +68,4 @@ processors: - add_fields: target: '' fields: - ecs.version: 1.6.0 + ecs.version: 1.7.0 diff --git a/x-pack/filebeat/module/cisco/amp/ingest/pipeline.yml b/x-pack/filebeat/module/cisco/amp/ingest/pipeline.yml index 352dc28f4dd..bf0227c6107 100644 --- a/x-pack/filebeat/module/cisco/amp/ingest/pipeline.yml +++ b/x-pack/filebeat/module/cisco/amp/ingest/pipeline.yml @@ -1,4 +1,4 @@ -description: Pipeline for parsing checkpoint firewall logs +description: Pipeline for parsing Cisco AMP logs processors: - remove: @@ -54,7 +54,7 @@ processors: if: ctx?.cisco?.amp?.severity == 'High' - set: field: event.severity - value: 3 + value: 4 if: ctx?.cisco?.amp?.severity == 'Critical' - set: field: event.severity @@ -94,11 +94,11 @@ processors: ignore_missing: true - set: field: network.direction - value: outbound + value: egress if: "ctx?.cisco?.amp?.network_info?.nfm?.direction == 'Outgoing connection from'" - set: field: network.direction - value: outbound + value: ingress if: "ctx?.cisco?.amp?.network_info?.nfm?.direction != null && ctx?.cisco?.amp?.network_info?.nfm?.direction != 'Outgoing connection from'" ##################### @@ -114,32 +114,24 @@ processors: ######################## - rename: field: cisco.amp.network_info.local_ip - target_field: source.address + target_field: source.ip ignore_missing: true - rename: field: cisco.amp.network_info.local_port target_field: source.port ignore_missing: true -- set: - field: source.ip - value: "{{ source.address }}" - if: ctx?.source?.address != null ############################# ## ECS Destination Mapping ## ############################# - rename: field: cisco.amp.network_info.remote_ip - target_field: destination.address + target_field: destination.ip ignore_missing: true - rename: field: cisco.amp.network_info.remote_port target_field: destination.port ignore_missing: true -- set: - field: destination.ip - value: "{{ destination.address }}" - if: ctx?.destination?.address != null ###################### ## ECS File Mapping ## @@ -263,6 +255,10 @@ processors: value: "{{ cisco.amp.network_info.parent.identity.sha1 }}" if: ctx?.cisco?.amp?.network_info?.parent?.identity?.sha1 != null allow_duplicates: false +- append: + field: related.hosts + value: "{{ host.name }}" + if: ctx?.host?.name != null - append: field: related.ip value: "{{ source.ip }}" @@ -271,6 +267,10 @@ processors: field: related.ip value: "{{ destination.ip }}" if: ctx?.destination?.ip != null +- append: + field: related.ip + value: "{{ cisco.amp.computer.external_ip }}" + if: ctx?.cisco?.amp?.computer?.external_ip != null - foreach: field: cisco.amp.computer.network_addresses processor: @@ -293,9 +293,95 @@ processors: value: "{{ _ingest._value.cve }}" if: ctx?.cisco?.amp?.vulnerabilities != null +############# +## GeoIP ## +############# +- geoip: + field: source.ip + target_field: source.geo + ignore_missing: true + if: "ctx.source?.geo == null" +- geoip: + field: destination.ip + target_field: destination.geo + ignore_missing: true + if: "ctx.destination?.geo == null" +- geoip: + database_file: GeoLite2-ASN.mmdb + field: source.ip + target_field: source.as + properties: + - asn + - organization_name + ignore_missing: true +- geoip: + database_file: GeoLite2-ASN.mmdb + field: destination.ip + target_field: destination.as + properties: + - asn + - organization_name + ignore_missing: true +- rename: + field: source.as.asn + target_field: source.as.number + ignore_missing: true +- rename: + field: source.as.organization_name + target_field: source.as.organization.name + ignore_missing: true +- rename: + field: destination.as.asn + target_field: destination.as.number + ignore_missing: true +- rename: + field: destination.as.organization_name + target_field: destination.as.organization.name + ignore_missing: true + ############# ## Cleanup ## ############# +- date: + field: cisco.amp.threat_hunting.incident_start_time + target_field: cisco.amp.threat_hunting.incident_start_time + formats: + - UNIX + ignore_failure: true + if: ctx?.cisco?.amp?.threat_hunting?.incident_start_time != null +- date: + field: cisco.amp.threat_hunting.incident_end_time + target_field: cisco.amp.threat_hunting.incident_end_time + formats: + - UNIX + ignore_failure: true + if: ctx?.cisco?.amp?.threat_hunting?.incident_end_time != null + +- script: + lang: painless + if: ctx?.json != null + source: | + void handleMap(Map map) { + for (def x : map.values()) { + if (x instanceof Map) { + handleMap(x); + } else if (x instanceof List) { + handleList(x); + } + } + map.values().removeIf(v -> v == null); + } + void handleList(List list) { + for (def x : list) { + if (x instanceof Map) { + handleMap(x); + } else if (x instanceof List) { + handleList(x); + } + } + } + handleMap(ctx); + - remove: field: - cisco.amp.timestamp diff --git a/x-pack/filebeat/module/cisco/amp/manifest.yml b/x-pack/filebeat/module/cisco/amp/manifest.yml index b2ba71513b6..9458f80a17d 100644 --- a/x-pack/filebeat/module/cisco/amp/manifest.yml +++ b/x-pack/filebeat/module/cisco/amp/manifest.yml @@ -10,6 +10,8 @@ var: - name: ssl - name: request_timeout default: 60s + - name: limit + default: 100 - name: client_id - name: api_key - name: first_interval diff --git a/x-pack/filebeat/module/cisco/amp/test/cisco_amp.ndjson.log-expected.json b/x-pack/filebeat/module/cisco/amp/test/cisco_amp.ndjson.log-expected.json index e002b6d454e..841c86a5dec 100644 --- a/x-pack/filebeat/module/cisco/amp/test/cisco_amp.ndjson.log-expected.json +++ b/x-pack/filebeat/module/cisco/amp/test/cisco_amp.ndjson.log-expected.json @@ -63,7 +63,11 @@ "9a8557b98ed1469272fa0ace91d63477", "d0c4192b65e36553fvfd2b83f3113f6ae8390baa" ], + "related.hosts": [ + "testhost" + ], "related.ip": [ + "8.8.8.8", "192.168.196.22", "192.168.120.1", "192.168.160.1" diff --git a/x-pack/filebeat/module/cisco/amp/test/cisco_amp2.ndjson.log-expected.json b/x-pack/filebeat/module/cisco/amp/test/cisco_amp2.ndjson.log-expected.json index e4aaf6c87b5..fc253e7ccf6 100644 --- a/x-pack/filebeat/module/cisco/amp/test/cisco_amp2.ndjson.log-expected.json +++ b/x-pack/filebeat/module/cisco/amp/test/cisco_amp2.ndjson.log-expected.json @@ -46,7 +46,6 @@ "name": "Scheduled Task/Job", "permissions": "Administrator, SYSTEM, User", "platforms": "Windows, Linux, macOS", - "system_requirements": null, "tactics_names": "Execution, Persistence, Privilege Escalation" }, { @@ -58,16 +57,15 @@ "name": "Scripting", "permissions": "User", "platforms": "Linux, macOS, Windows", - "system_requirements": null, "tactics_names": "Defense Evasion, Execution" } ], - "cisco.amp.threat_hunting.incident_end_time": 1592478770, + "cisco.amp.threat_hunting.incident_end_time": "2020-06-18T11:12:50.000Z", "cisco.amp.threat_hunting.incident_hunt_guid": "4bdbaf20-020f-4bb5-9da9-585da0e07817", "cisco.amp.threat_hunting.incident_id": 416, "cisco.amp.threat_hunting.incident_remediation": "We recommend the following:\r\n\r\n- Isolation of the affected hosts from the network\r\n- Perform forensic investigation\r\n - Review all activity performed by the user\r\n - Upload any suspicious files to ThreatGrid for analysis\r\n - Search the registry for data \"var config = ( COMMAND_C2\" and remove the key\r\n - Review scheduled tasks and cancel any involving the execution of WSCRIPT.EXE //E:jscript C:\\Users\\Public\\PowerManagerSpm.jar:LocalZone lqjsxokgowhbxjaetyrifnbigtcxmuj eimljujnv\r\n - Remove the Alternate Data Stream file located C:\\Users\\Public\\PowerManagerSpm.jar:LocalZone.\r\n- If possible, reimage the affected system to prevent potential unknown persistence methods.", "cisco.amp.threat_hunting.incident_report_guid": "6e5292d5-248c-49dc-839d-201bcba64562", - "cisco.amp.threat_hunting.incident_start_time": 1610707688, + "cisco.amp.threat_hunting.incident_start_time": "2021-01-15T10:48:08.000Z", "cisco.amp.threat_hunting.incident_summary": "The host Demo_Threat_Hunting is compromised by a Valak malware variant. Valak is a multi-stage malware attack that uses screen capture, reconnaissance, geolocation, and fileless execution techniques to infiltrate and exfiltrate sensitive information. Based on the event details listed and the techniques used, we recommend the host in question be investigated further.", "cisco.amp.threat_hunting.incident_title": "Valak Variant", "cisco.amp.threat_hunting.severity": "critical", @@ -102,7 +100,6 @@ "name": "Scheduled Task/Job", "permissions": "Administrator, SYSTEM, User", "platforms": "Windows, Linux, macOS", - "system_requirements": null, "tactics_names": "Execution, Persistence, Privilege Escalation" }, { @@ -114,7 +111,6 @@ "name": "Scripting", "permissions": "User", "platforms": "Linux, macOS, Windows", - "system_requirements": null, "tactics_names": "Defense Evasion, Execution" } ], @@ -123,13 +119,17 @@ "event.dataset": "cisco.amp", "event.kind": "alert", "event.module": "cisco", - "event.severity": 3, + "event.severity": 4, "fileset.name": "amp", "host.hostname": "Demo_Threat_Hunting", "host.name": "Demo_Threat_Hunting", "input.type": "log", "log.offset": 0, + "related.hosts": [ + "Demo_Threat_Hunting" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -192,7 +192,11 @@ "e2f5dcd966e26d54329e8d79c7201652", "70aef829bec17195e6c8ec0e6cba0ed39f97ba48" ], + "related.hosts": [ + "Demo_Upatre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -258,7 +262,11 @@ "e2f5dcd966e26d54329e8d79c7201652", "70aef829bec17195e6c8ec0e6cba0ed39f97ba48" ], + "related.hosts": [ + "Demo_Upatre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -314,7 +322,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -347,7 +359,13 @@ "e1:e5:94:ea:a5:44" ], "cisco.amp.timestamp_nanoseconds": 978000000, - "destination.address": "8.8.4.4", + "destination.as.number": 15169, + "destination.as.organization.name": "Google LLC", + "destination.geo.continent_name": "North America", + "destination.geo.country_iso_code": "US", + "destination.geo.country_name": "United States", + "destination.geo.location.lat": 37.751, + "destination.geo.location.lon": -97.822, "destination.ip": "8.8.4.4", "destination.port": 443, "event.action": "DFC Threat Detected", @@ -362,7 +380,7 @@ "host.user.name": "user@testdomain.com", "input.type": "log", "log.offset": 17081, - "network.direction": "outbound", + "network.direction": "egress", "network.transport": "TCP", "process.parent.hash.md5": "b3581f426dc500a51091cdd5bacf0454", "process.parent.hash.sha1": "8de30174cebc8732f1ba961e7d93fe5549495a80", @@ -374,16 +392,19 @@ "b3581f426dc500a51091cdd5bacf0454", "8de30174cebc8732f1ba961e7d93fe5549495a80" ], + "related.hosts": [ + "Demo_Upatre" + ], "related.ip": [ "10.10.0.0", "8.8.4.4", + "8.8.8.8", "10.10.10.10" ], "related.user": [ "user@testdomain.com" ], "service.type": "cisco", - "source.address": "10.10.0.0", "source.ip": "10.10.0.0", "source.port": 55810, "tags": [ @@ -435,7 +456,11 @@ "69d6fff3e0a0c4d77a62b4d71e1e3a8d10d93c46782a1b05f0ec4b8919c384b9", "935c1861df1f4018d698e8b65abfa02d7e9037d8f68ca3c2065b6ca165d44ad2" ], + "related.hosts": [ + "Demo_Command_Line_Arguments_Meterpreter" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -489,7 +514,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -546,7 +575,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -603,7 +636,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -660,7 +697,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -717,7 +758,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -774,7 +819,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -827,7 +876,11 @@ "9e1ec8b43a88e68767fd8fed2f38e7984357b3f4186d0f907e62f8b6c9ff56ad", "3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -881,7 +934,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -936,7 +993,11 @@ "5ad3c37e6f2b9db3ee8b5aeedc474645de90c66e3d95f8620c48102f1eba4124", "b1380fd95bc5c0729738dcda2696aa0a7c6ee97a93d992931ce717a0df523967" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -990,7 +1051,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1047,7 +1112,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1104,7 +1173,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1169,7 +1242,11 @@ "0a8ce026714e03e72c619307bd598add5f9b639cfd91437cb8d9c847bf9f6894", "4312cdb2ead8fd8d2dd6d8d716f3b6e9717b3d7167a2a0495e4391312102170f" ], + "related.hosts": [ + "Demo_AMP_Exploit_Prevention" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1223,7 +1300,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1280,7 +1361,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1337,7 +1422,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1394,7 +1483,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1450,7 +1543,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1503,7 +1600,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1556,7 +1657,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1619,7 +1724,11 @@ "b2e15a06b0cca8a926c94f8a8eae3d88", "f9b02ad8d25157eebdb284631ff646316dc606d5" ], + "related.hosts": [ + "Demo_Upatre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1676,7 +1785,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -1732,7 +1845,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1782,7 +1899,11 @@ "9e1ec8b43a88e68767fd8fed2f38e7984357b3f4186d0f907e62f8b6c9ff56ad", "3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1835,7 +1956,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1888,7 +2013,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1941,7 +2070,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -1994,7 +2127,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2047,7 +2184,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2100,7 +2241,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2153,7 +2298,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2216,7 +2365,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -2272,7 +2425,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2325,7 +2482,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2379,7 +2540,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -2435,7 +2600,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2488,7 +2657,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2551,7 +2724,11 @@ "209a288c68207d57e0ce6e60ebf60729", "e654d39cd13414b5151e8cf0d8f5b166dddd45cb" ], + "related.hosts": [ + "Demo_TeslaCrypt" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -2607,7 +2784,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2660,7 +2841,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2714,7 +2899,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -2771,7 +2960,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -2827,7 +3020,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2880,7 +3077,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2933,7 +3134,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -2986,7 +3191,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3039,7 +3248,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3093,7 +3306,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -3150,7 +3367,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -3206,7 +3427,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3259,7 +3484,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3312,7 +3541,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3365,7 +3598,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3418,7 +3655,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3472,7 +3713,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -3528,7 +3773,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3582,7 +3831,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -3638,7 +3891,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3691,7 +3948,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3744,7 +4005,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3798,7 +4063,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -3855,7 +4124,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -3911,7 +4184,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -3951,7 +4228,11 @@ "host.name": "Demo_AMP_Exploit_Prevention", "input.type": "log", "log.offset": 264441, + "related.hosts": [ + "Demo_AMP_Exploit_Prevention" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4004,7 +4285,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4057,7 +4342,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4110,7 +4399,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4163,7 +4456,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4217,7 +4514,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -4273,7 +4574,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4326,7 +4631,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4379,7 +4688,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4432,7 +4745,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4495,7 +4812,11 @@ "bfcc0861c7fb965c1f7473d3dc42cff6", "420da91c3199993c9f245b21ea060b69d7ecfd49" ], + "related.hosts": [ + "Demo_TDSS" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -4556,7 +4877,11 @@ "4a052246c5551e83d2d55f80e72f03eb", "bc29f1e8460915596e1dcafd0c92d6309457d149" ], + "related.hosts": [ + "Demo_TDSS" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -4612,7 +4937,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4662,7 +4991,11 @@ "1e675cb7df214172f7eb0497f7275556038a0d09c6e5a3e6862c5e26885ef455", "b75fd580c29736abd11327eef949e449f6d466a05fb6fd343d3957684c8036e5" ], + "related.hosts": [ + "Demo_TDSS" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4715,7 +5048,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4769,7 +5106,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -4825,7 +5166,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -4879,7 +5224,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -4945,7 +5294,11 @@ "e74f1b3fffc4ae61e077bbdec3230e95", "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5" ], + "related.hosts": [ + "Demo_Zbot" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5011,7 +5364,11 @@ "e74f1b3fffc4ae61e077bbdec3230e95", "e0feb4af86ef2f7a82e01b8704900e1e86c9e7a5" ], + "related.hosts": [ + "Demo_Zbot" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5067,7 +5424,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -5121,7 +5482,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5178,7 +5543,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5244,7 +5613,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5300,7 +5673,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -5353,7 +5730,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -5407,7 +5788,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5473,7 +5858,11 @@ "b99e0a8c56f963246b6464b9fffbf7a2", "b024546a49bad1bd60fccef0a5d11b55f9a442c4" ], + "related.hosts": [ + "Demo_AMP_Threat_Audit" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5529,7 +5918,11 @@ "e9d8c15e7d18678dd41771f72ed6693c", "ec80314ae4a2817be806b7ae27dbdb31a88226a0" ], + "related.hosts": [ + "Demo_Dyre" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "service.type": "cisco", @@ -5592,7 +5985,11 @@ "4a052246c5551e83d2d55f80e72f03eb", "bc29f1e8460915596e1dcafd0c92d6309457d149" ], + "related.hosts": [ + "Demo_TDSS" + ], "related.ip": [ + "8.8.8.8", "10.10.10.10" ], "related.user": [ @@ -5628,7 +6025,13 @@ "5a:ff:4a:a3:8a:2f" ], "cisco.amp.timestamp_nanoseconds": 706000000, - "destination.address": "8.8.4.4", + "destination.as.number": 15169, + "destination.as.organization.name": "Google LLC", + "destination.geo.continent_name": "North America", + "destination.geo.country_iso_code": "US", + "destination.geo.country_name": "United States", + "destination.geo.location.lat": 37.751, + "destination.geo.location.lon": -97.822, "destination.ip": "8.8.4.4", "destination.port": 80, "event.action": "DFC Threat Detected", @@ -5643,7 +6046,7 @@ "host.user.name": "user@testdomain.com", "input.type": "log", "log.offset": 324228, - "network.direction": "outbound", + "network.direction": "egress", "network.transport": "TCP", "process.parent.hash.md5": "12896823fb95bfb3dc9b46bcaedc9923", "process.parent.hash.sha1": "9d2bf84874abc5b6e9a2744b7865c193c08d362f", @@ -5655,16 +6058,19 @@ "12896823fb95bfb3dc9b46bcaedc9923", "9d2bf84874abc5b6e9a2744b7865c193c08d362f" ], + "related.hosts": [ + "Demo_Tinba" + ], "related.ip": [ "10.10.0.0", "8.8.4.4", + "8.8.8.8", "10.10.10.10" ], "related.user": [ "user@testdomain.com" ], "service.type": "cisco", - "source.address": "10.10.0.0", "source.ip": "10.10.0.0", "source.port": 1083, "tags": [ diff --git a/x-pack/filebeat/module/cisco/fields.go b/x-pack/filebeat/module/cisco/fields.go index 33d34866094..4d465edfa97 100644 --- a/x-pack/filebeat/module/cisco/fields.go +++ b/x-pack/filebeat/module/cisco/fields.go @@ -19,5 +19,5 @@ func init() { // AssetCisco returns asset data. // This is the base64 encoded gzipped contents of module/cisco. func AssetCisco() string { - return "" + return "" }