Anomali System Lookup Tables
The table below summarizes the lookup tables that Anomali provides out of the box.
| Source | Lookup Table | Description |
|---|---|---|
| Your event logs | eventlog |
Represents the schema that Security Analytics uses to map to different event log fields from varied event log sources. As an example, here are some categories of essential fields captured by the Eventlog Schema, among several others: Network: Web Proxy: DNS: Email Gateway: EDR: |
| Security Analytics | iocmatch |
Generated by the Anomali Security Analytics IOC correlation engine. This engine correlates event telemetry — firewalls, proxy servers, email gateways, or endpoints, and more — with ThreatStream IOCs. The following fields are used for correlating events: IP addresses: Domain: URL: Email: File Hash: |
| Security Analytics | dgamatch | Generated by the Anomali Security Analytics domain generated algorithm detection feature. This feature correlates domain names found in your event telemetry data with Anomali DGA intelligence. |
| Security Analytics | ignite | Generated by the Anomali Ignite detection feature that correlates file hashes present in event logs with endpoint file hashes that identify high-fidelity intelligence. |
| Security Analytics | tmmatch | Generated by threat model correlation that summarizes threat model matches present in your event logs. |
| ThreatStream | observables | Contains observable details generated from several sources such as intelligence feeds, telemetry data (SIEM, EDR data, and so on), threat bulletins, STIX/TAXII servers, and more. This lookup table features a centralized repo of threat observables from ThreatStream that supports correlation, enrichment, analysis, and integrations. |
| ThreatStream | threat_models | Contains details about Threat Models in ThreatStream. This lookup table enables correlation and threat hunting, curates threat profiles, aiding in response prioritization, reporting, and defense planning. |
| Security Analytics | audit | Generates different user actions such as creating alerts, launching a forensic search, or creating a dashboard, among other actions. This lookup table helps you gain crucial insight into the history of different user actions, ensuring transparency, traceability, compliance, reporting, and accountability for every action initiated by API clients, users, or other automated processes. |
| ThreatStream | consolidated_actor_descriptions_ng | Adds AI-generated descriptions to the AI Actor Profile dashboard for each unique threat actor and its aliases in ThreatStream. |
| ThreatStream | consolidated_actor_observables_ng | Links threat actor associations from the consolidated_actor_profiles_ng lookup table with corresponding observable information based on Actor IDs.
This table contributes data to the AI Actor Profile dashboard. |
| ThreatStream | consolidated_actor_profiles_ng | Populates the AI Actor Profile dashboard with consolidated information about threat actors, including aliases, associations, motivations, and other contextual details available in ThreatStream. |
| ThreatStream | actor_associations | Generates information about threat actor associations available in your ThreatStream instance. |
| Security Analytics | asset | Maintains a continuously updated reference that stores metadata of imported assets such as hostnames, IPs, ownership, criticality, or location, and is automatically refreshed whenever new asset data is ingested. This asset data enriches search results with asset context for more accurate monitoring and reporting. |
| ThreatStream | investigation | Stores metadata for security investigations created in ThreatStream, including assignment, priority, status, Traffic Light Protocol, and timestamps. This table supports querying and reporting on investigation workflows across your organization. |
| Security Analytics | investigation_elements | Provides a centralized reference for all investigation-related elements used within Security Analytics. Enriches investigations with full entity data from the underlying threat model or observable. This table standardizes and organizes investigation data to support consistent querying, reporting, and analysis. |