ignite

The ignite lookup table is generated by the Anomali Security Analytics Ignite detection feature. The Ignite detection feature correlates file hashes appearing in event logs with high fidelity intelligence identifying endpoint filehash IOCs.

Field Value Type Description Example
action string Action captured by the event. allowed, blocked
age number Event time minus intel first seen. 34
answer string Answers for the DNS query. ["10.10.10.10","10.10.10.11"]
app string Application detected. Slack, Google Gmail, LinkedIn
app_type string Link type. splunk, universal_link
asset_dest_criticality string Criticality assigned to an asset. low, medium, high, critical
asset_dest_dept string Department of an asset. engineering, hr, finance
asset_dest_hostname string Hostname or FQDN of an asset. qa_jenkins.example.com
asset_dest_ip string IP address of an asset. 192.168.10.77
asset_dest_location string Location of an asset. Redwood city headquarters
asset_dest_vulnerability string Vulnerabilities reported by the asset scanner. CVE-2022-31214
asset_src_criticality string Criticality assigned to an asset. low, medium, high, critical
asset_src_dept string Department of an asset. engineering, hr, finance
asset_src_hostname string Hostname or FQDN of an asset. qa_jenkins.example.com
asset_src_ip string IP address of an asset. 192.168.10.77
asset_src_location string Location of an asset. Redwood City headquarters
asset_src_vulnerability string Vulnerabilities reported by the asset scanner. CVE-2022-31214
bytes_in number Bytes this device or interface received. 347
bytes_out number Bytes this device or interface transmitted. 665
category string Category of alert (azure security alert). credentialTheft, ransomware
command_line string Complete command string of the spawned process. C:\Windows\system32\WerFault.exe -pss -s 572 -p 3208 -ip 3208
confidence number Confidence score assigned to the indicator. 85
count number Aggregate event count. 23
customer_id string Reserved for MSSP. id1
customer_name string Reserved for MSSP. name1
dcid string Unique ID of a registered link. 17
dest string Destination of network traffic. 52.233.72.222 or www.google.com
dest_ip string IP address of the destination. 52.233.72.222
dest_port number Destination port of network traffic. 80, 443, 8080
ds_id string Unique ID of a data source in a registered link. Optional. 5
ds_type string Type of a data source in a registered link. Optional. qradar, sumo or az_sentinel, syslog
event_id string A Windows identification number that specifies the event type. 4624
event_name string Name of an event. DnsRequest, ProcessRollup2
event_time timestamp Time when the event was recorded on the originating device, in UNIX timestamp milliseconds. 1705557025030
feed_id number Source feed ID in ThreatStream of the indicator. 345
feed_name string Source of the indicator. crowdstrike, recorded future
file_hash string Cryptographic identifier assigned to the file object affected by the event. e0d123e5f316bef78bfdf5a008837577
file_hash2 string Cryptographic identifier assigned to the file object affected by the event. 56857cfc709d3996f057252c16ec4656f5292802
file_hash3 string Cryptographic identifier assigned to the file object affected by the event. ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
file_name string Name of the file. nodepad.exe
file_path string Folder containing the file. C:\Program Files (x86)\VMware\VMware Workstation
host string Hostname or IP address where link is deployed. 192.0.2.1
http_method string HTTP method used in the request. get, post, delete, patch
http_referrer string HTTP referrer used in the request. https://example.com/
id number ID of an indicator. 34566
ignite_match_id string Unique ID.  
image string Executable name of the process. svchost.exe
indicator string Value of an indicator. 123.160.146.123, 2cd3e0df721f0c05e3c385e55e449bf5
ioc_status string Status assigned to the indicator. active, inactive, falsepos
ioc_type string Indicator value type. ip, domain, url, email or md5
itype string Indicator type. apt_ip
message_id string Globally-unique message identifier. 123e4567-e89b-12d3-a456-426655440000
original_file_name string Original name of the file that was renamed. test.pdf
parent_command_line string Complete command string of the parent process. C:\Windows\System32\svchost.exe -k WerSvcGroup
parent_image string Executable name of the parent process. notepad.exe
parent_process_id string Numeric identifier of the process assigned by the operating system. 4834
platform string Operating system of the asset. win, mac, linux
process_id number Numeric identifier of the process assigned by the operating system. 3683
protocol string Network or email protocol. http, tcp, udp, smtp
query string Domain to be resolved. www.google.com
receiver string Email address of the message recipient. john.doe@amce.org
record_type string DNS resource record type. A, CNAME, MX, NS, PTR, AAAA
reg_key string Registry key that the recorded action was applied to. HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
reg_value_data string Data of the registry value that the recorded action was applied to. Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
reg_value_name string Name of the registry value that the recorded action was applied to. Wordpad
return_code string HTTP status code or DNS response code. 200, 404, 504, NOERROR, NXDOMAIN
sender string Email address of the message sender. bar@amce.org
severity string Severity assigned to the indicator. low, medium, high, very-high
sourcetype string Device vendor. PAN Traffic, Cisco ASA, Zscaler
src string Source of network traffic. 192.168.134.3 or internaltest.qa.amce.org
src_host string First non-null value of asset_src_hostname, src, and src_ip. qa_jenkins.example.com
src_ip string IP address of the source. 192.168.34.3
src_port number Source port of network traffic. 8080
status string Status of the service.  
subject string Subject line of the email message. Document shared with you
tags string Additional comments and context. popularity=low, malware
timestamp timestamp Time when the event was received by Security Analytics, in UNIX timestamp milliseconds. 1705557025030
title string Alert title (azure security alert).  
ttl number Time-to-live of the network packet. 3600
url string Fully qualified URL of the requested HTTP resource. https://www.computerhope.com/cgi-bin/search.cgi?q=example%20search
user string User that requested the traffic flow. john.dole@amce.org
user_agent string User agent used in the request. Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101