An OpenIOC file is an XML file which contains one or more Indicators of
Compromise (IOCs). Verify that the OpenIOC file uses indicator terms supported by
the type of
investigation selected.
The table below lists the OpenIOC indicators supported for Detection & Response advanced
endpoint assessments.
Category
|
Item
|
Required Condition
|
DNSENTRYITEM
|
HOST
|
IS
|
RECORDDATA/HOST
|
IS
|
|
RECORDDATA/IPV4ADDRESS
|
IS
|
|
FILEITEM
|
FILENAME
|
IS
|
FILEPATH
|
IS
|
|
SHA1SUM
|
IS
|
|
SHA2SUM
|
IS
|
|
SHA256SUM
|
IS
|
|
PORTITEM
|
LOCALIP
|
IS
|
REMOTEIP
|
IS
|
|
PROCESSITEM
|
ARGUMENTS
|
CONTAINS
|
NAME
|
IS
|
|
PATH
|
IS
|
|
SECTIONLIST/MEMORYSECTION/SHA1SUM
|
IS
|
|
SECTIONLIST/MEMORYSECTION/SHA256SUM
|
IS
|
|
REGISTRYITEM
|
KEYPATH
|
CONTAINS
|
VALUE
|
CONTAINS
|
|
VALUENAME
|
CONTAINS
|
|
USERITEM
|
USERNAME
|
IS
|