ignite
The ignite lookup table is generated by the Anomali Security Analytics Ignite detection feature. The Ignite detection feature correlates file hashes appearing in event logs with high fidelity intelligence identifying endpoint filehash IOCs.
| Field | Value Type | Description | Example |
|---|---|---|---|
| action | string | Action captured by the event. | allowed, blocked |
| age | number | Event time minus intel first seen. | 34 |
| answer | string | Answers for the DNS query. | ["10.10.10.10","10.10.10.11"] |
| app | string | Application detected. | Slack, Google Gmail, LinkedIn |
| app_type | string | Link type. | splunk, universal_link |
| asset_dest_criticality | string | Criticality assigned to an asset. | low, medium, high, critical |
| asset_dest_dept | string | Department of an asset. | engineering, hr, finance |
| asset_dest_hostname | string | Hostname or FQDN of an asset. | qa_jenkins.example.com |
| asset_dest_ip | string | IP address of an asset. | 192.168.10.77 |
| asset_dest_location | string | Location of an asset. | Redwood city headquarters |
| asset_dest_vulnerability | string | Vulnerabilities reported by the asset scanner. | CVE-2022-31214 |
| asset_src_criticality | string | Criticality assigned to an asset. | low, medium, high, critical |
| asset_src_dept | string | Department of an asset. | engineering, hr, finance |
| asset_src_hostname | string | Hostname or FQDN of an asset. | qa_jenkins.example.com |
| asset_src_ip | string | IP address of an asset. | 192.168.10.77 |
| asset_src_location | string | Location of an asset. | Redwood City headquarters |
| asset_src_vulnerability | string | Vulnerabilities reported by the asset scanner. | CVE-2022-31214 |
| bytes_in | number | Bytes this device or interface received. | 347 |
| bytes_out | number | Bytes this device or interface transmitted. | 665 |
| category | string | Category of alert (azure security alert). | credentialTheft, ransomware |
| command_line | string | Complete command string of the spawned process. | C:\Windows\system32\WerFault.exe -pss -s 572 -p 3208 -ip 3208 |
| confidence | number | Confidence score assigned to the indicator. | 85 |
| count | number | Aggregate event count. | 23 |
| customer_id | string | Reserved for MSSP. | id1 |
| customer_name | string | Reserved for MSSP. | name1 |
| dcid | string | Unique ID of a registered link. | 17 |
| dest | string | Destination of network traffic. | 52.233.72.222 or www.google.com |
| dest_ip | string | IP address of the destination. | 52.233.72.222 |
| dest_port | number | Destination port of network traffic. | 80, 443, 8080 |
| ds_id | string | Unique ID of a data source in a registered link. Optional. | 5 |
| ds_type | string | Type of a data source in a registered link. Optional. | qradar, sumo or az_sentinel, syslog |
| event_id | string | A Windows identification number that specifies the event type. | 4624 |
| event_name | string | Name of an event. | DnsRequest, ProcessRollup2 |
| event_time | timestamp | Time when the event was recorded on the originating device, in UNIX timestamp milliseconds. | 1705557025030 |
| feed_id | number | Source feed ID in ThreatStream of the indicator. | 345 |
| feed_name | string | Source of the indicator. | crowdstrike, recorded future |
| file_hash | string | Cryptographic identifier assigned to the file object affected by the event. | e0d123e5f316bef78bfdf5a008837577 |
| file_hash2 | string | Cryptographic identifier assigned to the file object affected by the event. | 56857cfc709d3996f057252c16ec4656f5292802 |
| file_hash3 | string | Cryptographic identifier assigned to the file object affected by the event. | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad |
| file_name | string | Name of the file. | nodepad.exe |
| file_path | string | Folder containing the file. | C:\Program Files (x86)\VMware\VMware Workstation |
| host | string | Hostname or IP address where link is deployed. | 192.0.2.1 |
| http_method | string | HTTP method used in the request. | get, post, delete, patch |
| http_referrer | string | HTTP referrer used in the request. | https://example.com/ |
| id | number | ID of an indicator. | 34566 |
| ignite_match_id | string | Unique ID. | |
| image | string | Executable name of the process. | svchost.exe |
| indicator | string | Value of an indicator. | 123.160.146.123, 2cd3e0df721f0c05e3c385e55e449bf5 |
| ioc_status | string | Status assigned to the indicator. | active, inactive, falsepos |
| ioc_type | string | Indicator value type. | ip, domain, url, email or md5 |
| itype | string | Indicator type. | apt_ip |
| message_id | string | Globally-unique message identifier. | 123e4567-e89b-12d3-a456-426655440000 |
| original_file_name | string | Original name of the file that was renamed. | test.pdf |
| parent_command_line | string | Complete command string of the parent process. | C:\Windows\System32\svchost.exe -k WerSvcGroup |
| parent_image | string | Executable name of the parent process. | notepad.exe |
| parent_process_id | string | Numeric identifier of the process assigned by the operating system. | 4834 |
| platform | string | Operating system of the asset. | win, mac, linux |
| process_id | number | Numeric identifier of the process assigned by the operating system. | 3683 |
| protocol | string | Network or email protocol. | http, tcp, udp, smtp |
| query | string | Domain to be resolved. | www.google.com |
| receiver | string | Email address of the message recipient. | john.doe@amce.org |
| record_type | string | DNS resource record type. | A, CNAME, MX, NS, PTR, AAAA |
| reg_key | string | Registry key that the recorded action was applied to. | HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications |
| reg_value_data | string | Data of the registry value that the recorded action was applied to. | Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad |
| reg_value_name | string | Name of the registry value that the recorded action was applied to. | Wordpad |
| return_code | string | HTTP status code or DNS response code. | 200, 404, 504, NOERROR, NXDOMAIN |
| sender | string | Email address of the message sender. | bar@amce.org |
| severity | string | Severity assigned to the indicator. | low, medium, high, very-high |
| sourcetype | string | Device vendor. | PAN Traffic, Cisco ASA, Zscaler |
| src | string | Source of network traffic. | 192.168.134.3 or internaltest.qa.amce.org |
| src_host | string | First non-null value of asset_src_hostname, src, and src_ip. | qa_jenkins.example.com |
| src_ip | string | IP address of the source. | 192.168.34.3 |
| src_port | number | Source port of network traffic. | 8080 |
| status | string | Status of the service. | |
| subject | string | Subject line of the email message. | Document shared with you |
| tags | string | Additional comments and context. | popularity=low, malware |
| timestamp | timestamp | Time when the event was received by Security Analytics, in UNIX timestamp milliseconds. | 1705557025030 |
| title | string | Alert title (azure security alert). | |
| ttl | number | Time-to-live of the network packet. | 3600 |
| url | string | Fully qualified URL of the requested HTTP resource. | https://www.computerhope.com/cgi-bin/search.cgi?q=example%20search |
| user | string | User that requested the traffic flow. | john.dole@amce.org |
| user_agent | string | User agent used in the request. | Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 |