Views:
An OpenIOC file is an XML file which contains one or more Indicators of Compromise (IOCs). Verify that the OpenIOC file uses indicator terms supported by the type of investigation selected.
The table below lists the OpenIOC indicators supported for Detection & Response advanced endpoint assessments.
Category
Item
Required Condition
DNSENTRYITEM
HOST
IS
RECORDDATA/HOST
IS
RECORDDATA/IPV4ADDRESS
IS
FILEITEM
FILENAME
IS
FILEPATH
IS
SHA1SUM
IS
SHA2SUM
IS
SHA256SUM
IS
PORTITEM
LOCALIP
IS
REMOTEIP
IS
PROCESSITEM
ARGUMENTS
CONTAINS
NAME
IS
PATH
IS
SECTIONLIST/MEMORYSECTION/SHA1SUM
IS
SECTIONLIST/MEMORYSECTION/SHA256SUM
IS
REGISTRYITEM
KEYPATH
CONTAINS
VALUE
CONTAINS
VALUENAME
CONTAINS
USERITEM
USERNAME
IS