Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Refresh intakes documentation #1975

Merged
merged 1 commit into from
Sep 9, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -197,6 +197,60 @@ In this section, you will find examples of raw logs as generated natively by the



=== "collaborationProtectionEmailScan"


```json
{
"id": "cf81f722-6d92-3965-8cd7-89da1dc3c91d_0",
"serverTimestamp": 1589373818926,
"persistenceTimestamp": 1589373818926,
"account": {
"uuid": "51cebe8d-f671-4d50-b4fd-7f701cea1dc3",
"name": "Test Company",
"orgPath": "00000000-0000-0000-0000-000000000000/51cebe8d-f671-4d50-b4fd-7f701cea1dc3/51cebe8d-f671-4d50-b4fd-7f701cea1dc3/"
},
"severity": "warning",
"engine": "collaborationProtectionEmailScan",
"source": "",
"action": "noneBecauseMissing",
"txId": "0000-a7b175cb49074a86-0000-24347384954574830",
"details": {
"eventId": "82d7000d-c6ce-42db-823e-a14bf0d9f5af",
"userPrincipalName": "[email protected]",
"serviceType": "o365-exchange",
"serviceId": "11111111-1111-1111-1111-111111111111",
"severity": "medium",
"category": "harmfulContent",
"created": "1683888672000",
"itemSender": "[email protected]",
"sendingServerIP": "fe80::459d:de80:c84:df2e",
"itemParentFolderName": "Inbox",
"itemSize": "36647",
"itemSubject": "Test111",
"internetMessageId": "<AM5PR03MB30590FDF840881C2FC831988AC759@AM5PR03MB3059.eurprd03.prod.outlook.com>",
"itemType": "EmailMessage",
"unsafeUrlCount": "1",
"unsafeAttachmentCount": "2",
"itemDateTimeReceived": "1683888661000",
"attachments": "[{\"sha1\":\"f698eb70e11a36e0ffa6525d386cc127815247fd\",\"prevalence\":\"common\",\"filename\":\"bad_boy.scan\",\"size\":\"251\",\"prevalenceScore\":\"60\",\"verdict\":\"Unsafe\",\"reputation\":\"unknown\",\"reputationScore\":\"150\",\"detonation\":\"false\"},{\"sha1\":\"0912b6e31ec6f676af5bab5f1e95b3ab8cb13660\",\"prevalence\":\"unique\",\"filename\":\"good_boy-unique-1.ok\",\"size\":\"1048836\",\"prevalenceScore\":\"1\",\"verdict\":\"Safe\",\"reputation\":\"unknown\",\"reputationScore\":\"150\",\"detonation\":\"false\"}]",
"urls": "[{\"sha1\":\"ebe616225523aa82c5398a543a56761dd74bd3ff\",\"verdict\":\"HarmfulUrl\",\"reputation\":\"unsafe_url\",\"reputationScore\":\"-80\",\"url\":\"unsafe.fstestdomain.com\"}]"
},
"reporting": {
"timestamp": 1589373818926
},
"target": {
"id": "[email protected]",
"name": "[email protected]"
},
"fingerprint": {
"similarity": "g10F9A4ycYu9z9FP"
}
}
```



=== "deepguard_blocked_executable_file"


Expand Down Expand Up @@ -322,6 +376,52 @@ In this section, you will find examples of raw logs as generated natively by the



=== "emailscan_event"


```json
{
"severity": "critical",
"acknowledged": false,
"engine": "emailScan",
"serverTimestamp": "2024-07-18T07:47:29.438Z",
"organization": {
"name": "MyCompany FR",
"id": "984a72d0-473f-440b-bfa8-1a9cd453ae67"
},
"action": "subjectModifiedAndUrlsUnlinked",
"details": {
"serviceType": "o365-exchange",
"severity": "high",
"unsafeAttachmentCount": "0",
"eventId": "c01c51ab-e816-4855-720b-e4cead0c7ed0",
"itemType": "EmailMessage",
"itemDateTimeReceived": "1721288846000",
"created": "1721288849000",
"itemSender": "[email protected]",
"itemSubject": "RE: Discussion contrat important MyCompany",
"sendingServerIP": "168.40.38.82",
"internetMessageId": "<[email protected]>",
"urls": "[{\"sha1\":\"3b923d078ea3bd39489ed6d334c423e4478a8ee3\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"80\",\"url\":\"https://aka.ms/LearnAboutSenderIdentification\"},{\"sha1\":\"429365d0bd3efc753c6cc7b50900005037a3b341\",\"verdict\":\"HarmfulUrl\",\"reputation\":\"unsafe_url\",\"reputationScore\":\"-100\",\"url\":\"https://attacker.com/mk/op/sh/zejfz4647646/zef545zef\"},{\"sha1\":\"72c4aa6d5261823eae1cdf42ff4831501fc1833b\",\"verdict\":\"HarmfulUrl\",\"reputation\":\"unsafe_url\",\"reputationScore\":\"-100\",\"url\":\"https://attacker.com/mk/cl/f/sh/sg6r4gr6g4r6gegg/r4g4g6g\"},{\"sha1\":\"eecba1edb19a70641dd4147569d7034bd0eba8dd\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"0\",\"url\":\"https://attacker.com/im/sh/zef46zf4e.png?u=zef4efezf\"},{\"sha1\":\"b0f1884585d0f926ad3f7514f687fa9dd9d43440\",\"verdict\":\"HarmfulUrl\",\"reputation\":\"unsafe_url\",\"reputationScore\":\"-100\",\"url\":\"https://attacker.com/mk/cl/f/sh/ze4fz4fz4fzfe/45zef5-I\"},{\"sha1\":\"2ff0b754247642ecc8a7108094c4762c43a8be76\",\"verdict\":\"HarmfulUrl\",\"reputation\":\"unsafe_url\",\"reputationScore\":\"-100\",\"url\":\"https://attacker.com/mk/cl/f/sh/zefezfezfz4fe/zefezf\"},{\"sha1\":\"2db67f3b041683ac7f09a97a7f467f2ea741c676\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"80\",\"url\":\"https://cloud.sucpiciousserver.com/collect/bc/zefzfz?p=zefz4z4fz6f-wh878kG0mKc-zef5fez5fez-x7\"},{\"sha1\":\"627e5d03ba9c069feba1631f075a3ac9430b2213\",\"verdict\":\"HarmfulUrl\",\"reputation\":\"unsafe_url\",\"reputationScore\":\"-100\",\"url\":\"https://attacker.com/mk/un/sh/zefzf654fzfz/TDv7NJlnZGSy\"},{\"sha1\":\"7b12be67065fbf8a90f060715b519d85377583dc\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"80\",\"url\":\"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd\"},{\"sha1\":\"52eba95aa675c57a73054346fb8e85898c1d3a55\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"0\",\"url\":\"https://attacker.com/im/sh/zf5f4ezf.png?u=q5f4ezfzf\"},{\"sha1\":\"852dd2f9350123f2aa549c38388566eaf1eebdf6\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"80\",\"url\":\"cloud.letsignit.com\"},{\"sha1\":\"3d7a60d037e4ddf46283b1f256392bfcda4870a0\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"0\",\"url\":\"https://attacker.com/im/sh/fe4f5-.png?u=2BpAyz2gMiWncgNhSdtyKCSpskKSlwJEaT\"},{\"sha1\":\"3620e33317a00f5f5541846a6528671583460d69\",\"verdict\":\"Safe\",\"reputation\":\"safe_url\",\"reputationScore\":\"0\",\"url\":\"https://attacker.com/im/sh/zefzf6ezf.png?u=zf7ez4fezf1ezf\"}]",
"itemParentFolderName": "Junk Email",
"itemSize": "57452",
"category": "harmfulContent",
"serviceId": "89b60773-40d4-4354-8431-f846e38487a1",
"unsafeUrlCount": "5",
"userPrincipalName": "[email protected]"
},
"id": "f3ae087f-058d-3963-bdf7-2b2f18789369_0",
"persistenceTimestamp": "2024-07-18T07:47:33.590Z",
"eventTransactionId": "0000-48892313f0334054-0000-2truoi8ofr840vm",
"target": {
"name": "[email protected]",
"id": "[email protected]"
}
}
```



=== "firewall_blocked_connection"


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -399,6 +399,126 @@ This section demonstrates how the raw logs will be transformed by our parsers. I
```


=== "test_connection_acknowledged.json"

```json

{
"message": "{\"time\":\"2024-08-30T07:00:12.5431823Z\",\"tenantId\":\"e9dc510f-a9d1-4041-ba9c-3308ff2cafba\",\"operationName\":\"Publish\",\"category\":\"AdvancedHunting-DeviceNetworkEvents\",\"_TimeReceivedBySvc\":\"2024-08-30T06:57:48.6877713Z\",\"properties\":{\"DeviceName\":\"dks001.example.org\",\"DeviceId\":\"fe0395f347034d61a2c2c718d14df664\",\"ReportId\":33227,\"RemoteIP\":\"5.6.7.8\",\"RemotePort\":443,\"LocalIP\":\"1.2.3.4\",\"LocalPort\":56468,\"Protocol\":\"TcpV4\",\"RemoteUrl\":null,\"InitiatingProcessCreationTime\":null,\"InitiatingProcessId\":0,\"InitiatingProcessCommandLine\":null,\"InitiatingProcessParentCreationTime\":null,\"InitiatingProcessParentId\":0,\"InitiatingProcessParentFileName\":null,\"InitiatingProcessSHA1\":null,\"InitiatingProcessMD5\":null,\"InitiatingProcessFolderPath\":null,\"InitiatingProcessAccountName\":null,\"InitiatingProcessAccountDomain\":null,\"InitiatingProcessAccountSid\":null,\"InitiatingProcessFileName\":null,\"InitiatingProcessIntegrityLevel\":null,\"InitiatingProcessTokenElevation\":\"None\",\"AppGuardContainerId\":\"\",\"LocalIPType\":null,\"RemoteIPType\":null,\"ActionType\":\"InboundConnectionAcknowledged\",\"InitiatingProcessSHA256\":null,\"InitiatingProcessAccountUpn\":null,\"InitiatingProcessAccountObjectId\":null,\"AdditionalFields\":\"{\\\"Source Mac\\\":\\\"84:fa:b1:70:bf:8e\\\",\\\"Destination Mac\\\":\\\"80:95:bb:71:95:aa\\\",\\\"Tcp Flags\\\":18,\\\"Packet Size\\\":66}\",\"InitiatingProcessFileSize\":null,\"InitiatingProcessVersionInfoCompanyName\":null,\"InitiatingProcessVersionInfoProductName\":null,\"InitiatingProcessVersionInfoProductVersion\":null,\"InitiatingProcessVersionInfoInternalFileName\":null,\"InitiatingProcessVersionInfoOriginalFileName\":null,\"InitiatingProcessVersionInfoFileDescription\":null,\"InitiatingProcessSessionId\":null,\"IsInitiatingProcessRemoteSession\":false,\"InitiatingProcessRemoteSessionDeviceName\":null,\"InitiatingProcessRemoteSessionIP\":null,\"Timestamp\":\"2024-08-30T07:04:25.6763023Z\",\"MachineGroup\":null},\"Tenant\":\"DefaultTenant\"}\n",
"event": {
"category": [
"network"
],
"dataset": "device_network_events",
"type": [
"info"
]
},
"@timestamp": "2024-08-30T07:04:25.676302Z",
"action": {
"type": "InboundConnectionAcknowledged"
},
"destination": {
"address": "1.2.3.4",
"ip": "1.2.3.4",
"port": 56468
},
"host": {
"id": "fe0395f347034d61a2c2c718d14df664",
"name": "dks001.example.org"
},
"microsoft": {
"defender": {
"report": {
"id": "33227"
}
}
},
"network": {
"protocol": "TcpV4"
},
"process": {
"parent": {
"pid": 0
},
"pid": 0
},
"related": {
"ip": [
"1.2.3.4",
"5.6.7.8"
]
},
"source": {
"address": "5.6.7.8",
"ip": "5.6.7.8",
"port": 443
}
}

```


=== "test_connection_attempt.json"

```json

{
"message": "{\"time\": \"2024-08-07T14:40:43.3217277Z\", \"tenantId\": \"32fd1322-613a-4307-8da8-d9f2ba7dcfee\", \"operationName\": \"Publish\", \"category\": \"AdvancedHunting-DeviceNetworkEvents\", \"_TimeReceivedBySvc\": \"2024-08-07T14:39:52.9339374Z\", \"properties\": {\"DeviceName\": \"desktop01.example.com\", \"DeviceId\": \"a94a8fe5ccb19ba61c4c0873d391e987982fbbd3\", \"ReportId\": 355896, \"RemoteIP\": \"1.2.3.4\", \"RemotePort\": 7680, \"LocalIP\": \"5.6.7.8\", \"LocalPort\": 56499, \"Protocol\": \"TcpV4\", \"RemoteUrl\": null, \"InitiatingProcessCreationTime\": null, \"InitiatingProcessId\": 0, \"InitiatingProcessCommandLine\": null, \"InitiatingProcessParentCreationTime\": null, \"InitiatingProcessParentId\": 0, \"InitiatingProcessParentFileName\": null, \"InitiatingProcessSHA1\": null, \"InitiatingProcessMD5\": null, \"InitiatingProcessFolderPath\": null, \"InitiatingProcessAccountName\": null, \"InitiatingProcessAccountDomain\": null, \"InitiatingProcessAccountSid\": null, \"InitiatingProcessFileName\": null, \"InitiatingProcessIntegrityLevel\": null, \"InitiatingProcessTokenElevation\": \"None\", \"AppGuardContainerId\": \"\", \"LocalIPType\": null, \"RemoteIPType\": null, \"ActionType\": \"ConnectionAttempt\", \"InitiatingProcessSHA256\": null, \"InitiatingProcessAccountUpn\": null, \"InitiatingProcessAccountObjectId\": null, \"AdditionalFields\": \"{\\\"Source Mac\\\":\\\"10:9f:4b:3c:50:d7\\\",\\\"Destination Mac\\\":\\\"b0:df:72:9d:29:9b\\\",\\\"Tcp Flags\\\":2,\\\"Packet Size\\\":66}\", \"InitiatingProcessFileSize\": null, \"InitiatingProcessVersionInfoCompanyName\": null, \"InitiatingProcessVersionInfoProductName\": null, \"InitiatingProcessVersionInfoProductVersion\": null, \"InitiatingProcessVersionInfoInternalFileName\": null, \"InitiatingProcessVersionInfoOriginalFileName\": null, \"InitiatingProcessVersionInfoFileDescription\": null, \"InitiatingProcessSessionId\": null, \"IsInitiatingProcessRemoteSession\": false, \"InitiatingProcessRemoteSessionDeviceName\": null, \"InitiatingProcessRemoteSessionIP\": null, \"Timestamp\": \"2024-08-07T14:39:37.2995901Z\", \"MachineGroup\": \"All_Win10_11\"}, \"Tenant\": \"DefaultTenant\"}",
"event": {
"category": [
"network"
],
"dataset": "device_network_events",
"type": [
"info"
]
},
"@timestamp": "2024-08-07T14:39:37.299590Z",
"action": {
"type": "ConnectionAttempt"
},
"destination": {
"address": "1.2.3.4",
"ip": "1.2.3.4",
"port": 7680
},
"host": {
"id": "a94a8fe5ccb19ba61c4c0873d391e987982fbbd3",
"name": "desktop01.example.com"
},
"microsoft": {
"defender": {
"report": {
"id": "355896"
}
}
},
"network": {
"protocol": "TcpV4"
},
"process": {
"parent": {
"pid": 0
},
"pid": 0
},
"related": {
"ip": [
"1.2.3.4",
"5.6.7.8"
]
},
"source": {
"address": "5.6.7.8",
"ip": "5.6.7.8",
"port": 56499
}
}

```


=== "test_detection_source.json"

```json
Expand Down Expand Up @@ -1993,6 +2113,66 @@ This section demonstrates how the raw logs will be transformed by our parsers. I
```


=== "test_inbound_connection_attempt.json"

```json

{
"message": "{\"time\": \"2024-08-08T06:10:51.1543444Z\", \"tenantId\": \"a8904d16-ae79-4f8f-90bd-f64c48898705\", \"operationName\": \"Publish\", \"category\": \"AdvancedHunting-DeviceNetworkEvents\", \"_TimeReceivedBySvc\": \"2024-08-08T06:09:04.2831271Z\", \"properties\": {\"DeviceName\": \"device-01\", \"DeviceId\": \"42b7f57bd4dfbb5e693ce27196e4811ba5ca84d1\", \"ReportId\": 7053, \"RemoteIP\": \"1.2.3.4\", \"RemotePort\": 46112, \"LocalIP\": \"5.6.7.8\", \"LocalPort\": 443, \"Protocol\": \"TcpV4\", \"RemoteUrl\": null, \"InitiatingProcessCreationTime\": null, \"InitiatingProcessId\": 0, \"InitiatingProcessCommandLine\": null, \"InitiatingProcessParentCreationTime\": null, \"InitiatingProcessParentId\": 0, \"InitiatingProcessParentFileName\": null, \"InitiatingProcessSHA1\": null, \"InitiatingProcessMD5\": null, \"InitiatingProcessFolderPath\": null, \"InitiatingProcessAccountName\": null, \"InitiatingProcessAccountDomain\": null, \"InitiatingProcessAccountSid\": null, \"InitiatingProcessFileName\": null, \"InitiatingProcessIntegrityLevel\": null, \"InitiatingProcessTokenElevation\": \"None\", \"AppGuardContainerId\": \"\", \"LocalIPType\": null, \"RemoteIPType\": null, \"ActionType\": \"InboundConnectionAttempt\", \"InitiatingProcessSHA256\": null, \"InitiatingProcessAccountUpn\": null, \"InitiatingProcessAccountObjectId\": null, \"AdditionalFields\": \"{\\\"Source Mac\\\":\\\"0a:ac:f5:b4:e6:37\\\",\\\"Destination Mac\\\":\\\"18:e8:f8:74:c9:0d\\\",\\\"Tcp Flags\\\":2,\\\"Packet Size\\\":60}\", \"InitiatingProcessFileSize\": null, \"InitiatingProcessVersionInfoCompanyName\": null, \"InitiatingProcessVersionInfoProductName\": null, \"InitiatingProcessVersionInfoProductVersion\": null, \"InitiatingProcessVersionInfoInternalFileName\": null, \"InitiatingProcessVersionInfoOriginalFileName\": null, \"InitiatingProcessVersionInfoFileDescription\": null, \"InitiatingProcessSessionId\": null, \"IsInitiatingProcessRemoteSession\": false, \"InitiatingProcessRemoteSessionDeviceName\": null, \"InitiatingProcessRemoteSessionIP\": null, \"Timestamp\": \"2024-08-08T06:07:08.3444146Z\", \"MachineGroup\": \"UnassignedGroup\"}, \"Tenant\": \"DefaultTenant\"}",
"event": {
"category": [
"network"
],
"dataset": "device_network_events",
"type": [
"info"
]
},
"@timestamp": "2024-08-08T06:07:08.344414Z",
"action": {
"type": "InboundConnectionAttempt"
},
"destination": {
"address": "5.6.7.8",
"ip": "5.6.7.8",
"port": 443
},
"host": {
"id": "42b7f57bd4dfbb5e693ce27196e4811ba5ca84d1",
"name": "device-01"
},
"microsoft": {
"defender": {
"report": {
"id": "7053"
}
}
},
"network": {
"protocol": "TcpV4"
},
"process": {
"parent": {
"pid": 0
},
"pid": 0
},
"related": {
"ip": [
"1.2.3.4",
"5.6.7.8"
]
},
"source": {
"address": "1.2.3.4",
"ip": "1.2.3.4",
"port": 46112
}
}

```


=== "test_local_ip.json"

```json
Expand Down
Loading
Loading