dgamatch

The dgamatch lookup table is generated by the Anomali Security Analytics domain generated algorithm (DGA) detection feature. The DGA detection feature correlates domain names appearing in event logs with Anomali DGA intelligence.

Note: Correlation features including dgamatch lookups are available with eventlog queries only. See OCSF Schema Overview for more information.

Field Value Type Description Example
action string Action captured by the event. allowed, blocked
age number Event time minus intel first seen. 34
answer string Answers for the DNS query. ["10.10.10.10","10.10.10.11"]
app string Application detected. Slack, Google Gmail, LinkedIn
app_type string Link type. splunk, universal_link
asset_dest_criticality string Criticality assigned to an asset. low, medium, high, critical
asset_dest_dept string Department of an asset. engineering, hr, finance
asset_dest_hostname string Hostname or FQDN of an asset. qa_jenkins.anomali.com
asset_dest_ip string IP address of an asset. 192.168.10.77
asset_dest_location string Location of an asset. Redwood City headquarters
asset_dest_vulnerability string Vulnerabilities reported by the asset scanner. CVE-2022-31214
asset_src_criticality string Criticality assigned to an asset. low, medium, high, critical
asset_src_dept string Department of an asset. engineering, hr, finance
asset_src_hostname string Hostname or FQDN of an asset. qa_jenkins.anomali.com
asset_src_ip string IP address of an asset. 192.168.10.77
asset_src_location string Location of an asset. Redwood City headquarters
asset_src_vulnerability string Vulnerabilities reported by the asset scanner. CVE-2022-31214
bytes_in number Bytes this device or interface received. 347
bytes_out number Bytes this device or interface transmitted. 665
category string Category of alert (azure security alert). credentialTheft, ransomware
command_line string Complete command string of the spawned process. C:\Windows\system32\WerFault.exe -pss -s 572 -p 3208 -ip 3208
count number Aggregate event count. 4
customer_id string Reserved for MSSP. id1
customer_name string Reserved for MSSP. name1
dcid string Unique ID of a registered link. 17
dest string Destination of network traffic. 52.233.72.222 or www.google.com
dest_ip string IP address of the destination. 52.233.72.222
dest_port number Destination port of network traffic. 80, 443, 8080
dga_prob double DGA probability of a domain. 0.98
dga_tag string Additional comments and context. registered domain
ds_id string Unique ID of a data source in a registered link. Optional. 5
ds_type string Type of a data source in a registered link. Optional. qradar, sumo or az_sentinel, syslog
event_id string A Windows identification number that specifies the event type. 4624
event_name string Name of an event. DnsRequest, ProcessRollup2
event_time timestamp Time when the event was recorded on the originating device, in UNIX timestamp milliseconds. 1706309296567
file_hash string Cryptographic identifier assigned to the file object affected by the event. ba7816bf8f01cfea414140de5dae2223b00361a
396177a9cb410ff61f20015ad
file_hash2 string Cryptographic identifier assigned to the file object affected by the event. 56857cfc709d3996f057252c16ec4656f5292802
file_hash3 string Cryptographic identifier assigned to the file object affected by the event. e0d123e5f316bef78bfdf5a008837577
file_name string Name of the file. nodepad.exe
file_path string Folder containing the file. C:\Program Files (x86)\VMware\VMware Workstation
host string Hostname or IP address where link is deployed. 172.18.16.43
http_method string HTTP method used in the request. get, post, delete, patch
http_referrer string HTTP referrer used in the request. https://example.com/
image string Executable name of the process. svchost.exe
indicator string Value of an indicator. 123.160.146.123, 2cd3e0df721f0c05e3c385e55e449bf5
ioc_status string Status assigned to the indicator. active, inactive, falsepos
ioc_type string Indicator value type. ip, domain, url, email or md5
malware_family string A group of applications with similar attack techniques. conficker
message_id string Globally-unique message identifier. 123e4567-e89b-12d3-a456-426655440000
original_file_name string Original name of the file that was renamed. test.pdf
originator number Network directionality. 0-inbound, 1-outbound
parent_command_line string Complete command string of the parent process. C:\Windows\System32\svchost.exe -k WerSvcGroup
parent_image string Executable name of the parent process. notepad.exe
parent_process_id string Numeric identifier of the process assigned by the operating system. 4834
platform string Operating system of the asset. win, mac, linux
process_id number Numeric identifier of the process assigned by the operating system. 3683
protocol string Network or email protocol. http, tcp, udp, smtp
query string Domain to be resolved. www.google.com
receiver string Email address of the message recipient. john.doe@amce.org
record_type string DNS resource record type. A, CNAME, MX, NS, PTR, AAAA
reg_key string Registry key that the recorded action was applied to. HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
reg_value_data string Data of the registry value that the recorded action was applied to. Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
reg_value_name string Name of the registry value that the recorded action was applied to. Wordpad
return_code string HTTP status code or DNS response code. 200, 404, 504, NOERROR, NXDOMAIN
sender string Email address of the message sender. bar@amce.org
sourcetype string Device vendor. PAN Traffic, Cisco ASA, Zscaler
src string Source of network traffic. 192.168.134.3 or internaltest.qa.amce.org
src_host string First non-null value of asset_src_hostname, src, and src_ip. qa_jenkins.example.com
src_ip string IP address of the source. 192.168.34.3
src_port number Source port of network traffic. 8080
status string Status of the service.  
subject string Subject line of the email message. Your daily Threat Model digest
timestamp timestamp Time when the event was received by Security Analytics, in UNIX timestamp milliseconds. 1706309296568
title string Alert title (azure security alert).  
ttl number Time-to-live of the network packet. 3600
url string Fully qualified URL of the requested HTTP resource. https://www.computerhope.com/cgi-bin/search.cgi?q=example%20search
user string User that requested the traffic flow. john.dole@amce.org
user_agent string User agent used in the request. Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101