Feedback:

Anomali System Lookup Tables

The table below summarizes the lookup tables that Anomali provides out of the box.

Source Lookup Table Description
Your event logs eventlog

Represents the schema that Security Analytics uses to map to different event log fields from varied event log sources.

As an example, here are some categories of essential fields captured by the Eventlog Schema, among several others:

Network: event_time, action, src_ip, dest_ip, src_port, dest_port, protocol, bytes_in, bytes_out

Web Proxy: event_time, action, src_ip, dest, url, user, user_agent, http_referrer, status, http_method

DNS: event_time, action, src_ip, query, answer, record_type

Email Gateway: event_time, message_id, subject, sender, receiver, src_ip, dest_ip

EDR: event_time, event_id, event_name, evt_type, host, user, platform, process_id, file_path, file_name, image, command_line, file_hash, file_hash2, file_hash3, src

Security Analytics iocmatch

Generated by the Anomali Security Analytics IOC correlation engine. This engine correlates event telemetry — firewalls, proxy servers, email gateways, or endpoints, and more — with ThreatStream IOCs.

The following fields are used for correlating events:

IP addresses: src_ip, dest_ip, src, dest

Domain: src, dest, query, url

URL: url, http_referrer

Email: sender, receiver

File Hash: file_hash, file_hash2, file_hash3

Security Analytics dgamatch Generated by the Anomali Security Analytics domain generated algorithm detection feature. This feature correlates domain names found in your event telemetry data with Anomali DGA intelligence.
Security Analytics ignite Generated by the Anomali Ignite detection feature that correlates file hashes present in event logs with endpoint file hashes that identify high-fidelity intelligence.
Security Analytics tmmatch Generated by threat model correlation that summarizes threat model matches present in your event logs.
ThreatStream observables Contains observable details generated from several sources such as intelligence feeds, telemetry data (SIEM, EDR data, and so on), threat bulletins, STIX/TAXII servers, and more. This lookup table features a centralized repo of threat observables from ThreatStream that supports correlation, enrichment, analysis, and integrations.
ThreatStream threat_models Contains details about Threat Models in ThreatStream. This lookup table enables correlation and threat hunting, curates threat profiles, aiding in response prioritization, reporting, and defense planning.
Security Analytics audit Generates different user actions such as creating alerts, launching a forensic search, or creating a dashboard, among other actions. This lookup table helps you gain crucial insight into the history of different user actions, ensuring transparency, traceability, compliance, reporting, and accountability for every action initiated by API clients, users, or other automated processes.
ThreatStream consolidated_actor_descriptions_ng Adds AI-generated descriptions to the AI Actor Profile dashboard for each unique threat actor and its aliases in ThreatStream.
ThreatStream consolidated_actor_observables_ng Links threat actor associations from the consolidated_actor_profiles_ng lookup table with corresponding observable information based on Actor IDs. This table contributes data to the AI Actor Profile dashboard.
ThreatStream consolidated_actor_profiles_ng Populates the AI Actor Profile dashboard with consolidated information about threat actors, including aliases, associations, motivations, and other contextual details available in ThreatStream.
ThreatStream actor_associations Generates information about threat actor associations available in your ThreatStream instance.
Security Analytics asset Maintains a continuously updated reference that stores metadata of imported assets such as hostnames, IPs, ownership, criticality, or location, and is automatically refreshed whenever new asset data is ingested. This asset data enriches search results with asset context for more accurate monitoring and reporting.
ThreatStream investigation Stores metadata for security investigations created in ThreatStream, including assignment, priority, status, Traffic Light Protocol, and timestamps. This table supports querying and reporting on investigation workflows across your organization.
Security Analytics investigation_elements Provides a centralized reference for all investigation-related elements used within Security Analytics. Enriches investigations with full entity data from the underlying threat model or observable. This table standardizes and organizes investigation data to support consistent querying, reporting, and analysis.