| Attribute | Operator | Action | 
|---|---|---|
| Host Name | Contains/Does not
                                 contain | Type a value | 
| IP address | Contains/Does not
                                 contain In range/Not in range | Type a value Type a range | 
| MAC address | In/Not in | Type a value | 
| Network Group | In/Not in | Select one or more of the following: 
 | 
| Registered Services | In/Not in | Select one or more of the following: 
 | 
| Protocol | In/Not in | Select one or more of the following: 
 | 
| Transport Layer Security (TLS) | Over SSL/TLS/Not over
                                 SSL/TLS | |
| Direction | Equals | Select one of the following: 
 | 
| Status | Equals | Select one of the following: 
 | 
| Threat/Detection/Reference | Contains/Does not
                                 contain/Equals | Type a value | 
| Detection Rule ID | In/Not in | Type a value | 
| Correlation Rule ID (ICID) | In/Not in | Type a value | 
| Detection Type | In/Not in | Select one or more of the following: 
 | 
| Attack Phase | In/Not in | Select one or more of the following: 
 | 
| C&C List Source | In/Not in | Select one or more of the following: 
 | 
| C&C Callback Address | Contains/Does not
                                 contain/Equals | Type a value | 
| C&C Risk Level | In/Not in | Select one or more of the following: 
 | 
| Virtual Analyzer Result | Has analysis results/No analysis
                                 results | |
| PCAP File | Has PCAP file/No PCAP
                                 file | |
| Is Targeted Attack Related | Yes/No | |
| File Detection Type | In | Select one or more of the following: 
 | 
| File Name | Has file name/No file
                                 name | |
| Contains/Does not
                                 contain | Type a value | |
| File SHA-1 | Has file SHA-1/No file
                                 SHA-1 | |
| Contains/Does not
                                 contain | Type a value | |
| File SHA-256 | Has file SHA-256/No file
                                 SHA-256 | |
| Contains/Does not
                                 contain | Type a value | |
| IP Address/Domain/URL | Has network object/No network
                                 object | |
| Contains/Does not
                                 contain/Equals | Type a value | |
| Suspicious Object/Deny List Entity | Contains/Does not
                                 contain/Equals | Type a value | 
| Email Address | Has email address/No email
                                 address | |
| Contains/Does not
                                 contain | Type a value | |
| Message ID (Email) | Has message ID/No message
                                 ID | |
| Contains/Does not
                                 contain | Type a value | |
| Subject (Email) | Has subject/No subject | |
| Contains/Does not
                                 contain | Type a value |