Views:

An OpenIOC file is an XML file which contains one or more Indicators of Compromise (IOCs). Verify that the OpenIOC file uses indicator terms supported by the type of investigation selected.

The table below lists the IOC indicators supported in investigations.

Table 1. Supported IOC Indicators for Real-Time Investigations

Category

Item

Required Condition

FILEITEM

FULLPATH

IS, CONTAINS, STARTS-WITH, ENDS-WITH

FILEPATH

IS

FILENAME

IS, CONTAINS, STARTS-WITH, ENDS-WITH

MD5SUM

IS

SHA1SUM

IS

SHA256SUM

IS

SIZEINBYTES

IS

CREATED

IS, GREATER-THAN, LESS-THAN

MODIFIED

GREATER-THAN, LESS-THAN

ACCESSED

GREATER-THAN, LESS-THAN

Note:

After selection, Endpoint Sensor displays a preview of the OpenIOC file. Review the preview to verify if the OpenIOC file contains supported indicators and conditions. Unsupported combinations are formatted with a strike-through and are ignored during the investigation.