network: more typefixes

This commit is contained in:
ljstella
2024-11-15 10:37:10 -06:00
parent 4b5f5a98c3
commit f15bde0e1b
29 changed files with 30 additions and 30 deletions
@@ -47,7 +47,7 @@ rba:
$src$, kindly review.
risk_objects:
- field: src
type: hostname
type: system
score: 63
threat_objects:
- field: domain
@@ -51,7 +51,7 @@ rba:
message: A DNS data exfiltration request was sent by this host $src$ , kindly review.
risk_objects:
- field: src
type: hostname
type: system
score: 45
threat_objects:
- field: query
@@ -56,7 +56,7 @@ rba:
host $host$
risk_objects:
- field: host
type: hostname
type: system
score: 56
threat_objects: []
tags:
@@ -42,7 +42,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -56,7 +56,7 @@ rba:
message: A domain for a known remote access software $query$ was contacted by $src$.
risk_objects:
- field: src
type: hostname
type: system
score: 4
threat_objects:
- field: query
@@ -57,7 +57,7 @@ rba:
detected from $src$.
risk_objects:
- field: src
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -31,7 +31,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -35,7 +35,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -50,7 +50,7 @@ rba:
message: A suspicious DNS TXT response was detected on host $src$ , kindly review.
risk_objects:
- field: src
type: hostname
type: system
score: 45
threat_objects:
- field: answer
@@ -34,7 +34,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -33,7 +33,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -46,7 +46,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -45,7 +45,7 @@ rba:
query in host $host$
risk_objects:
- field: host
type: hostname
type: system
score: 56
threat_objects: []
tags:
@@ -33,7 +33,7 @@ rba:
message: Excessive DNS failures detected on $src$
risk_objects:
- field: src
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -50,7 +50,7 @@ rba:
occurred.
risk_objects:
- field: dest
type: hostname
type: system
score: 70
threat_objects: []
tags:
@@ -42,7 +42,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -50,7 +50,7 @@ rba:
IPs
risk_objects:
- field: src_ip
type: hostname
type: system
score: 64
threat_objects: []
tags:
@@ -51,7 +51,7 @@ rba:
IPs
risk_objects:
- field: src_ip
type: hostname
type: system
score: 72
threat_objects: []
tags:
@@ -50,7 +50,7 @@ rba:
message: $src_ip$ has scanned $totalDestPortCount$ ports on $dest_ip$
risk_objects:
- field: src_ip
type: hostname
type: system
score: 64
threat_objects: []
tags:
@@ -36,7 +36,7 @@ rba:
message: Large volume of IDS signatures triggered by $src$
risk_objects:
- field: src
type: hostname
type: system
score: 64
threat_objects: []
tags:
@@ -27,7 +27,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -43,7 +43,7 @@ rba:
message: An endpoint, $src$, is beaconing out to the reverse proxy service of Ngrok.
risk_objects:
- field: src
type: hostname
type: system
score: 50
threat_objects: []
tags:
@@ -32,7 +32,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -37,7 +37,7 @@ rba:
type: user
score: 25
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -30,10 +30,10 @@ rba:
message: $dest$ may be the target of an RDP Bruteforce
risk_objects:
- field: dest
type: hostname
type: system
score: 25
- field: src
type: hostname
type: system
score: 25
threat_objects: []
tags:
+1 -1
View File
@@ -31,7 +31,7 @@ rba:
message: Anomalous splike of SMB traffic sent from $src$
risk_objects:
- field: src
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -46,7 +46,7 @@ rba:
message: tbd
risk_objects:
- field: dest
type: hostname
type: system
score: 25
threat_objects: []
tags:
@@ -36,7 +36,7 @@ rba:
email domain on $dest$.
risk_objects:
- field: dest
type: hostname
type: system
score: 15
threat_objects: []
tags:
@@ -36,7 +36,7 @@ rba:
alternative name on $dest$.
risk_objects:
- field: dest
type: hostname
type: system
score: 15
threat_objects: []
tags: