Skip to content

Latest commit

 

History

History
31 lines (24 loc) · 1 KB

MATCH-S00638.md

File metadata and controls

31 lines (24 loc) · 1 KB

Rules: McAfee Web Gateway - Suspicious or Malicious Categories

Description

This rule triggers any time there is a Suspicious or Malicious McAfee Web Gateway category which could indicate there is a problem with the host making the connection.

Additional Details

Detail Value
Type Templated Match
Category Command and Control
Apply Risk to Entities srcDevice_ip
Signal Name McAfee Web Gateway - Suspicious or Malicious Categories
Summary Expression Web traffic with category {{http_category}} was found for URL: {{http_url}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1071, _mitreAttackTechnique:T1071.001

Vendors and Products

Fields Used

Origin Field
Normalized Schema http_category
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip