iocmatch
The iocmatch lookup table is generated by the Anomali Security Analytics IOC correlation engine. The IOC correlation engine correlates your event logs with your ThreatStream IOCs.
Note: Correlation features including iocmatch lookups are available with eventlog queries only. See OCSF Schema Overview for more information.
| Name | Value Type | Description | Example |
|---|---|---|---|
| action | string | Action captured by the event. | allowed, blocked |
| actor_ids | list | Associated actor IDs in ThreatStream. | [2342, 2313] |
| age | number | Event time minus intel first seen. | 34 |
| answer | string | Answers for the DNS query. | ["10.10.10.10","10.10.10.11"] |
| app | string | Application detected. | Slack, Google Gmail, LinkedIn |
| app_type | string | Link type. | splunk, universal_link |
| asn | string | Autonomous System (AS) number. | 48780 |
| asset_dest_criticality | string | Criticality assigned to an asset. | low, medium, high, critical |
| asset_dest_dept | string | Department of an asset. | engineering, hr, finance |
| asset_dest_hostname | string | Hostname or FQDN of an asset. | qa_jenkins.example.com |
| asset_dest_ip | string | IP address of an asset. | 192.168.10.77 |
| asset_dest_location | string | Location of an asset. | Redwood city headquarters |
| asset_dest_vulnerability | string | Vulnerabilities reported by the asset scanner. | CVE-2022-31214 |
| asset_src_criticality | string | Criticality assigned to an asset. | low, medium, high, critical |
| asset_src_dept | string | Department of an asset. | engineering, hr, finance |
| asset_src_hostname | string | Hostname or FQDN of an asset. | qa_jenkins.example.com |
| asset_src_ip | string | IP address of an asset. | 192.168.10.77 |
| asset_src_location | string | Location of an asset. | Redwood City headquarters |
| asset_src_vulnerability | string | Vulnerabilities reported by the asset scanner. | CVE-2022-31214 |
| attackpattern_ids | list | Associated attack pattern IDs in ThreatStream. | [2342, 2313] |
| bytes_in | number | Bytes this device or interface received. | 347 |
| bytes_out | number | Bytes this device or interface transmitted. | 665 |
| campaign_ids | list | Associated campaign IDs in ThreatStream. | [2342, 2313] |
| category | string | Category of alert (azure security alert). | credentialTheft, ransomware |
| classification | string | Classification of an intel. | public or private |
| command_line | string | Complete command string of the spawned process. | C:\Windows\system32\WerFault.exe -pss -s 572 -p 3208 -ip 3208 |
| confidence | number | Confidence score assigned to the indicator. | 85 |
| count | number | Aggregate event count. | 23 |
| country | string | Country associated with the indicator. | US |
| created_ts | timestamp | First seen on ThreatStream. | 1705557025030 |
| customer_id | string | Reserved for MSSP. | id1 |
| customer_name | string | Reserved for MSSP. | name1 |
| dcid | string | Unique ID of a registered link. | 17 |
| dest | string | Destination of network traffic. | 52.233.72.222 or www.google.com |
| dest_ip | string | IP address of the destination. | 52.233.72.222 |
| dest_port | number | Destination port of network traffic. | 80, 443, 8080 |
| ds_id | string | Unique ID of a data source in a registered link. Optional. | 5 |
| ds_type | string | Type of a data source in a registered link. Optional. | qradar, sumo or az_sentinel, syslog |
| event_id | string | A Windows identification number that specifies the event type. | 4624 |
| event_name | string | Name of an event. | DnsRequest, ProcessRollup2 |
| event_time | timestamp | Time when the event was recorded on the originating device, in UNIX timestamp milliseconds. | 1705557025030 |
| feed_id | number | Source feed ID in ThreatStream of the indicator. | 345 |
| feed_name | string | Source of the indicator. | crowdstrike, recorded future |
| file_hash | string | Cryptographic identifier assigned to the file object affected by the event. | e0d123e5f316bef78bfdf5a008837577 |
| file_hash2 | string | Cryptographic identifier assigned to the file object affected by the event. | 56857cfc709d3996f057252c16ec4656f5292802 |
| file_hash3 | string | Cryptographic identifier assigned to the file object affected by the event. | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad |
| file_name | string | Name of the file. | nodepad.exe |
| file_path | string | Folder containing the file. | C:\Program Files (x86)\VMware\VMware Workstation |
| host | string | Hostname or IP address where link is deployed. | 192.0.2.1 |
| http_method | string | HTTP method used in the request. | get, post, delete, patch |
| http_referrer | string | HTTP referrer used in the request. | https://example.com/ |
| id | number | ID of an indicator. | 34566 |
| image | string | Executable name of the process. | svchost.exe |
| import_session_id | number | ID of import session in which the indicator was imported. | 234 |
| indicator | string | Value of an indicator. | 123.160.146.123, 2cd3e0df721f0c05e3c385e55e449bf5 |
| ioc_match_id | string | Unique ID, having format {orgid}_{event_id}_0_{ioc_id}. | 1773_79618005142_0_59324653376 |
| ioc_status | string | Status assigned to the indicator. | active, inactive, falsepos |
| ioc_type | string | Indicator value type. | ip, domain, url, email or md5 |
| itype | string | Indicator type. | apt_ip |
| latitude | double | Latitude associated with the Geo location of the IP address. | 37.579 |
| longitude | double | Longitude associated with the Geo location of the IP address. | 126.975 |
| message_id | string | Globally-unique message identifier. | 123e4567-e89b-12d3-a456-426655440000 |
| modified_ts | timestamp | Last updated on ThreatStream. | 1705557025030 |
| org | string | Registered owner (organization) of the IP address associated with the indicator. | Acme Corp |
| original_file_name | string | Original name of the file that was renamed. | test.pdf |
| originator | number | Network directionality. | 0-inbound, 1-outbound |
| parent_command_line | string | Complete command string of the parent process. | C:\Windows\System32\svchost.exe -k WerSvcGroup |
| parent_image | string | Executable name of the parent process. | notepad.exe |
| parent_process_id | string | Numeric identifier of the process assigned by the operating system. | 4834 |
| platform | string | Operating system of the asset. | win, mac, linux |
| process_id | number | Numeric identifier of the process assigned by the operating system. | 3683 |
| protocol | string | Network or email protocol. | http, tcp, udp, smtp |
| query | string | Domain to be resolved. | www.google.com |
| receiver | string | Email address of the message recipient. | john.doe@amce.org |
| record_type | string | DNS resource record type. | A, CNAME, MX, NS, PTR, AAAA |
| reg_key | string | Registry key that the recorded action was applied to. | HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications |
| reg_value_data | string | Data of the registry value that the recorded action was applied to. | Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad |
| reg_value_name | string | Name of the registry value that the recorded action was applied to. | Wordpad |
| resource_uri | string | URI for the indicator | |
| return_code | string | HTTP status code or DNS response code. | 200, 404, 504, NOERROR, NXDOMAIN |
| sender | string | Email address of the message sender. | bar@amce.org |
| severity | string | Severity assigned to the indicator. | low, medium, high, very-high |
| sourcetype | string | Device vendor. | PAN Traffic, Cisco ASA, Zscaler |
| src | string | Source of network traffic. | 192.168.134.3 or internaltest.qa.amce.org |
| src_host | string | First non-null value of asset_src_hostname, src, and src_ip. | qa_jenkins.example.com |
| src_ip | string | IP address of the source. | 192.168.34.3 |
| src_port | number | Source port of network traffic. | 8080 |
| status | string | Status of the service. | |
| subject | string | Subject line of the email message. | Document shared with you |
| tags | string | Additional comments and context. | popularity=low, malware |
| timestamp | timestamp | Time when the event was received by Security Analytics, in UNIX timestamp milliseconds. | 1705557025030 |
| tipreport_ids | list | Associated threat bulletin IDs in ThreatStream. | [2342, 2313] |
| title | string | Alert title (azure security alert). | |
| trusted_circle_ids | list | List of trusted circle ids assigned in ThreatStream to the indicator. | [ 1, 45 ] |
| trusted_circle_names | list | List of trusted circle names. | [ "circle1", "circle45" ] |
| ttl | number | Time-to-live of the network packet. | 3600 |
| ttp_ids | list | Associated TTP IDs in ThreatStream. | [ 5473, 34724 ] |
| url | string | Fully qualified URL of the requested HTTP resource. | https://www.computerhope.com/cgi-bin/search.cgi?q=example%20search |
| user | string | User that requested the traffic flow. | john.dole@amce.org |
| user_agent | string | User agent used in the request. | Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 |
| vulnerability_ids | list | Associated vulnerability IDs in ThreatStream. | [ 5473, 34724 ] |