Skip to content

Commit

Permalink
Update iocdetection.md
Browse files Browse the repository at this point in the history
  • Loading branch information
gaelmuller authored Aug 28, 2024
1 parent c5657b0 commit edb27f6
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions docs/xdr/features/detect/iocdetection.md
Original file line number Diff line number Diff line change
Expand Up @@ -83,6 +83,9 @@ The tables below list the ECS event fields that are verified by IOC detection.

#### Observable type: IPv4 Address & IPv6 Address

!!! Note
To avoid false positives, IP addresses that are marked as "Command an Control" are only matched against `destination.ip`.

| STIX path | ECS event field |
| --- | --- |
| ipv4-addr:value<br>ipv6-addr:value | client.ip<br>destination.ip<br>host.ip<br>server.ip<br>source.ip |
Expand Down

0 comments on commit edb27f6

Please sign in to comment.