Attribute
|
Operator
|
Action
|
---|---|---|
Host Name
|
Contains/Does not
contain
|
Type a value
|
IP address
|
Contains/Does not
contain
In range/Not in range
|
Type a value
Type a range
|
MAC address
|
In/Not in
|
Type a value
|
Network Group
|
In/Not in
|
Select one or more of the following:
|
Registered Services
|
In/Not in
|
Select one or more of the following:
|
Protocol
|
In/Not in
|
Select one or more of the following:
|
Transport Layer Security (TLS)
|
Over SSL/TLS/Not over
SSL/TLS
|
|
Direction
|
Equals
|
Select one of the following:
|
Status
|
Equals
|
Select one of the following:
|
Threat/Detection/Reference
|
Contains/Does not
contain/Equals
|
Type a value
|
Detection Rule ID
|
In/Not in
|
Type a value
|
Correlation Rule ID (ICID)
|
In/Not in
|
Type a value
|
Detection Type
|
In/Not in
|
Select one or more of the following:
|
Attack Phase
|
In/Not in
|
Select one or more of the following:
|
C&C List Source
|
In/Not in
|
Select one or more of the following:
|
C&C Callback Address
|
Contains/Does not
contain/Equals
|
Type a value
|
C&C Risk Level
|
In/Not in
|
Select one or more of the following:
|
Virtual Analyzer Result
|
Has analysis results/No analysis
results
|
|
PCAP File
|
Has PCAP file/No PCAP
file
|
|
Is Targeted Attack Related
|
Yes/No
|
|
File Detection Type
|
In
|
Select one or more of the following:
|
File Name
|
Has file name/No file
name
|
|
Contains/Does not
contain
|
Type a value
|
|
File SHA-1
|
Has file SHA-1/No file
SHA-1
|
|
Contains/Does not
contain
|
Type a value
|
|
File SHA-256
|
Has file SHA-256/No file
SHA-256
|
|
Contains/Does not
contain
|
Type a value
|
|
IP Address/Domain/URL
|
Has network object/No network
object
|
|
Contains/Does not
contain/Equals
|
Type a value
|
|
Suspicious Object/Deny List Entity
|
Contains/Does not
contain/Equals
|
Type a value
|
Email Address
|
Has email address/No email
address
|
|
Contains/Does not
contain
|
Type a value
|
|
Message ID (Email)
|
Has message ID/No message
ID
|
|
Contains/Does not
contain
|
Type a value
|
|
Subject (Email)
|
Has subject/No subject
|
|
Contains/Does not
contain
|
Type a value
|