dgamatch
The dgamatch lookup table is generated by the Anomali Security Analytics domain generated algorithm (DGA) detection feature. The DGA detection feature correlates domain names appearing in event logs with Anomali DGA intelligence.
Note: Correlation features including dgamatch lookups are available with eventlog queries only. See OCSF Schema Overview for more information.
| Field | Value Type | Description | Example |
|---|---|---|---|
| action | string | Action captured by the event. | allowed, blocked |
| age | number | Event time minus intel first seen. | 34 |
| answer | string | Answers for the DNS query. | ["10.10.10.10","10.10.10.11"] |
| app | string | Application detected. | Slack, Google Gmail, LinkedIn |
| app_type | string | Link type. | splunk, universal_link |
| asset_dest_criticality | string | Criticality assigned to an asset. | low, medium, high, critical |
| asset_dest_dept | string | Department of an asset. | engineering, hr, finance |
| asset_dest_hostname | string | Hostname or FQDN of an asset. | qa_jenkins.anomali.com |
| asset_dest_ip | string | IP address of an asset. | 192.168.10.77 |
| asset_dest_location | string | Location of an asset. | Redwood City headquarters |
| asset_dest_vulnerability | string | Vulnerabilities reported by the asset scanner. | CVE-2022-31214 |
| asset_src_criticality | string | Criticality assigned to an asset. | low, medium, high, critical |
| asset_src_dept | string | Department of an asset. | engineering, hr, finance |
| asset_src_hostname | string | Hostname or FQDN of an asset. | qa_jenkins.anomali.com |
| asset_src_ip | string | IP address of an asset. | 192.168.10.77 |
| asset_src_location | string | Location of an asset. | Redwood City headquarters |
| asset_src_vulnerability | string | Vulnerabilities reported by the asset scanner. | CVE-2022-31214 |
| bytes_in | number | Bytes this device or interface received. | 347 |
| bytes_out | number | Bytes this device or interface transmitted. | 665 |
| category | string | Category of alert (azure security alert). | credentialTheft, ransomware |
| command_line | string | Complete command string of the spawned process. | C:\Windows\system32\WerFault.exe -pss -s 572 -p 3208 -ip 3208 |
| count | number | Aggregate event count. | 4 |
| customer_id | string | Reserved for MSSP. | id1 |
| customer_name | string | Reserved for MSSP. | name1 |
| dcid | string | Unique ID of a registered link. | 17 |
| dest | string | Destination of network traffic. | 52.233.72.222 or www.google.com |
| dest_ip | string | IP address of the destination. | 52.233.72.222 |
| dest_port | number | Destination port of network traffic. | 80, 443, 8080 |
| dga_prob | double | DGA probability of a domain. | 0.98 |
| dga_tag | string | Additional comments and context. | registered domain |
| ds_id | string | Unique ID of a data source in a registered link. Optional. | 5 |
| ds_type | string | Type of a data source in a registered link. Optional. | qradar, sumo or az_sentinel, syslog |
| event_id | string | A Windows identification number that specifies the event type. | 4624 |
| event_name | string | Name of an event. | DnsRequest, ProcessRollup2 |
| event_time | timestamp | Time when the event was recorded on the originating device, in UNIX timestamp milliseconds. | 1706309296567 |
| file_hash | string | Cryptographic identifier assigned to the file object affected by the event. | ba7816bf8f01cfea414140de5dae2223b00361a 396177a9cb410ff61f20015ad |
| file_hash2 | string | Cryptographic identifier assigned to the file object affected by the event. | 56857cfc709d3996f057252c16ec4656f5292802 |
| file_hash3 | string | Cryptographic identifier assigned to the file object affected by the event. | e0d123e5f316bef78bfdf5a008837577 |
| file_name | string | Name of the file. | nodepad.exe |
| file_path | string | Folder containing the file. | C:\Program Files (x86)\VMware\VMware Workstation |
| host | string | Hostname or IP address where link is deployed. | 172.18.16.43 |
| http_method | string | HTTP method used in the request. | get, post, delete, patch |
| http_referrer | string | HTTP referrer used in the request. | https://example.com/ |
| image | string | Executable name of the process. | svchost.exe |
| indicator | string | Value of an indicator. | 123.160.146.123, 2cd3e0df721f0c05e3c385e55e449bf5 |
| ioc_status | string | Status assigned to the indicator. | active, inactive, falsepos |
| ioc_type | string | Indicator value type. | ip, domain, url, email or md5 |
| malware_family | string | A group of applications with similar attack techniques. | conficker |
| message_id | string | Globally-unique message identifier. | 123e4567-e89b-12d3-a456-426655440000 |
| original_file_name | string | Original name of the file that was renamed. | test.pdf |
| originator | number | Network directionality. | 0-inbound, 1-outbound |
| parent_command_line | string | Complete command string of the parent process. | C:\Windows\System32\svchost.exe -k WerSvcGroup |
| parent_image | string | Executable name of the parent process. | notepad.exe |
| parent_process_id | string | Numeric identifier of the process assigned by the operating system. | 4834 |
| platform | string | Operating system of the asset. | win, mac, linux |
| process_id | number | Numeric identifier of the process assigned by the operating system. | 3683 |
| protocol | string | Network or email protocol. | http, tcp, udp, smtp |
| query | string | Domain to be resolved. | www.google.com |
| receiver | string | Email address of the message recipient. | john.doe@amce.org |
| record_type | string | DNS resource record type. | A, CNAME, MX, NS, PTR, AAAA |
| reg_key | string | Registry key that the recorded action was applied to. | HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications |
| reg_value_data | string | Data of the registry value that the recorded action was applied to. | Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad |
| reg_value_name | string | Name of the registry value that the recorded action was applied to. | Wordpad |
| return_code | string | HTTP status code or DNS response code. | 200, 404, 504, NOERROR, NXDOMAIN |
| sender | string | Email address of the message sender. | bar@amce.org |
| sourcetype | string | Device vendor. | PAN Traffic, Cisco ASA, Zscaler |
| src | string | Source of network traffic. | 192.168.134.3 or internaltest.qa.amce.org |
| src_host | string | First non-null value of asset_src_hostname, src, and src_ip. | qa_jenkins.example.com |
| src_ip | string | IP address of the source. | 192.168.34.3 |
| src_port | number | Source port of network traffic. | 8080 |
| status | string | Status of the service. | |
| subject | string | Subject line of the email message. | Your daily Threat Model digest |
| timestamp | timestamp | Time when the event was received by Security Analytics, in UNIX timestamp milliseconds. | 1706309296568 |
| title | string | Alert title (azure security alert). | |
| ttl | number | Time-to-live of the network packet. | 3600 |
| url | string | Fully qualified URL of the requested HTTP resource. | https://www.computerhope.com/cgi-bin/search.cgi?q=example%20search |
| user | string | User that requested the traffic flow. | john.dole@amce.org |
| user_agent | string | User agent used in the request. | Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 |