iocmatch

The iocmatch lookup table is generated by the Anomali Security Analytics IOC correlation engine. The IOC correlation engine correlates your event logs with your ThreatStream IOCs.

Note: Correlation features including iocmatch lookups are available with eventlog queries only. See OCSF Schema Overview for more information.

Name Value Type Description Example
action string Action captured by the event. allowed, blocked
actor_ids list Associated actor IDs in ThreatStream. [2342, 2313]
age number Event time minus intel first seen. 34
answer string Answers for the DNS query. ["10.10.10.10","10.10.10.11"]
app string Application detected. Slack, Google Gmail, LinkedIn
app_type string Link type. splunk, universal_link
asn string Autonomous System (AS) number. 48780
asset_dest_criticality string Criticality assigned to an asset. low, medium, high, critical
asset_dest_dept string Department of an asset. engineering, hr, finance
asset_dest_hostname string Hostname or FQDN of an asset. qa_jenkins.example.com
asset_dest_ip string IP address of an asset. 192.168.10.77
asset_dest_location string Location of an asset. Redwood city headquarters
asset_dest_vulnerability string Vulnerabilities reported by the asset scanner. CVE-2022-31214
asset_src_criticality string Criticality assigned to an asset. low, medium, high, critical
asset_src_dept string Department of an asset. engineering, hr, finance
asset_src_hostname string Hostname or FQDN of an asset. qa_jenkins.example.com
asset_src_ip string IP address of an asset. 192.168.10.77
asset_src_location string Location of an asset. Redwood City headquarters
asset_src_vulnerability string Vulnerabilities reported by the asset scanner. CVE-2022-31214
attackpattern_ids list Associated attack pattern IDs in ThreatStream. [2342, 2313]
bytes_in number Bytes this device or interface received. 347
bytes_out number Bytes this device or interface transmitted. 665
campaign_ids list Associated campaign IDs in ThreatStream. [2342, 2313]
category string Category of alert (azure security alert). credentialTheft, ransomware
classification string Classification of an intel. public or private
command_line string Complete command string of the spawned process. C:\Windows\system32\WerFault.exe -pss -s 572 -p 3208 -ip 3208
confidence number Confidence score assigned to the indicator. 85
count number Aggregate event count. 23
country string Country associated with the indicator. US
created_ts timestamp First seen on ThreatStream. 1705557025030
customer_id string Reserved for MSSP. id1
customer_name string Reserved for MSSP. name1
dcid string Unique ID of a registered link. 17
dest string Destination of network traffic. 52.233.72.222 or www.google.com
dest_ip string IP address of the destination. 52.233.72.222
dest_port number Destination port of network traffic. 80, 443, 8080
ds_id string Unique ID of a data source in a registered link. Optional. 5
ds_type string Type of a data source in a registered link. Optional. qradar, sumo or az_sentinel, syslog
event_id string A Windows identification number that specifies the event type. 4624
event_name string Name of an event. DnsRequest, ProcessRollup2
event_time timestamp Time when the event was recorded on the originating device, in UNIX timestamp milliseconds. 1705557025030
feed_id number Source feed ID in ThreatStream of the indicator. 345
feed_name string Source of the indicator. crowdstrike, recorded future
file_hash string Cryptographic identifier assigned to the file object affected by the event. e0d123e5f316bef78bfdf5a008837577
file_hash2 string Cryptographic identifier assigned to the file object affected by the event. 56857cfc709d3996f057252c16ec4656f5292802
file_hash3 string Cryptographic identifier assigned to the file object affected by the event. ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
file_name string Name of the file. nodepad.exe
file_path string Folder containing the file. C:\Program Files (x86)\VMware\VMware Workstation
host string Hostname or IP address where link is deployed. 192.0.2.1
http_method string HTTP method used in the request. get, post, delete, patch
http_referrer string HTTP referrer used in the request. https://example.com/
id number ID of an indicator. 34566
image string Executable name of the process. svchost.exe
import_session_id number ID of import session in which the indicator was imported. 234
indicator string Value of an indicator. 123.160.146.123, 2cd3e0df721f0c05e3c385e55e449bf5
ioc_match_id string Unique ID, having format {orgid}_{event_id}_0_{ioc_id}. 1773_79618005142_0_59324653376
ioc_status string Status assigned to the indicator. active, inactive, falsepos
ioc_type string Indicator value type. ip, domain, url, email or md5
itype string Indicator type. apt_ip
latitude double Latitude associated with the Geo location of the IP address. 37.579
longitude double Longitude associated with the Geo location of the IP address. 126.975
message_id string Globally-unique message identifier. 123e4567-e89b-12d3-a456-426655440000
modified_ts timestamp Last updated on ThreatStream. 1705557025030
org string Registered owner (organization) of the IP address associated with the indicator. Acme Corp
original_file_name string Original name of the file that was renamed. test.pdf
originator number Network directionality. 0-inbound, 1-outbound
parent_command_line string Complete command string of the parent process. C:\Windows\System32\svchost.exe -k WerSvcGroup
parent_image string Executable name of the parent process. notepad.exe
parent_process_id string Numeric identifier of the process assigned by the operating system. 4834
platform string Operating system of the asset. win, mac, linux
process_id number Numeric identifier of the process assigned by the operating system. 3683
protocol string Network or email protocol. http, tcp, udp, smtp
query string Domain to be resolved. www.google.com
receiver string Email address of the message recipient. john.doe@amce.org
record_type string DNS resource record type. A, CNAME, MX, NS, PTR, AAAA
reg_key string Registry key that the recorded action was applied to. HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
reg_value_data string Data of the registry value that the recorded action was applied to. Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad
reg_value_name string Name of the registry value that the recorded action was applied to. Wordpad
resource_uri string URI for the indicator  
return_code string HTTP status code or DNS response code. 200, 404, 504, NOERROR, NXDOMAIN
sender string Email address of the message sender. bar@amce.org
severity string Severity assigned to the indicator. low, medium, high, very-high
sourcetype string Device vendor. PAN Traffic, Cisco ASA, Zscaler
src string Source of network traffic. 192.168.134.3 or internaltest.qa.amce.org
src_host string First non-null value of asset_src_hostname, src, and src_ip. qa_jenkins.example.com
src_ip string IP address of the source. 192.168.34.3
src_port number Source port of network traffic. 8080
status string Status of the service.  
subject string Subject line of the email message. Document shared with you
tags string Additional comments and context. popularity=low, malware
timestamp timestamp Time when the event was received by Security Analytics, in UNIX timestamp milliseconds. 1705557025030
tipreport_ids list Associated threat bulletin IDs in ThreatStream. [2342, 2313]
title string Alert title (azure security alert).  
trusted_circle_ids list List of trusted circle ids assigned in ThreatStream to the indicator. [ 1, 45 ]
trusted_circle_names list List of trusted circle names. [ "circle1", "circle45" ]
ttl number Time-to-live of the network packet. 3600
ttp_ids list Associated TTP IDs in ThreatStream. [ 5473, 34724 ]
url string Fully qualified URL of the requested HTTP resource. https://www.computerhope.com/cgi-bin/search.cgi?q=example%20search
user string User that requested the traffic flow. john.dole@amce.org
user_agent string User agent used in the request. Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101
vulnerability_ids list Associated vulnerability IDs in ThreatStream. [ 5473, 34724 ]