OpenIOC 檔案是包含一或多個入侵指標 (IOC) 的 XML 檔案。請確認 OpenIOC 檔案使用的指標項受所選調查類型支援。
下表列出了 Detection & Response 進階端點評估支援的 OpenIOC 指標。
類別
|
項目
|
要求的條件
|
DNSENTRYITEM
|
HOST
|
IS
|
RECORDDATA/HOST
|
IS
|
|
RECORDDATA/IPV4ADDRESS
|
IS
|
|
FILEITEM
|
FILENAME
|
IS
|
FILEPATH
|
IS
|
|
SHA1SUM
|
IS
|
|
SHA2SUM
|
IS
|
|
SHA256SUM
|
IS
|
|
PORTITEM
|
LOCALIP
|
IS
|
REMOTEIP
|
IS
|
|
PROCESSITEM
|
ARGUMENTS
|
CONTAINS
|
NAME
|
IS
|
|
PATH
|
IS
|
|
SECTIONLIST/MEMORYSECTION/SHA1SUM
|
IS
|
|
SECTIONLIST/MEMORYSECTION/SHA256SUM
|
IS
|
|
REGISTRYITEM
|
KEYPATH
|
CONTAINS
|
VALUE
|
CONTAINS
|
|
VALUENAME
|
CONTAINS
|
|
USERITEM
|
USERNAME
|
IS
|