mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1 line
26 KiB
JSON
1 line
26 KiB
JSON
{"lookups": [{"filename": "3cx_ioc_domains.csv", "default_match": "false", "match_type": "WILDCARD(domain)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "3cx_ioc_domains", "description": "A list of domains from the 3CX supply chain attack."}, {"filename": "__mlspl_detect_dns_data_exfiltration_using_pretrained_model_in_dsdl.mlmodel", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "__mlspl_detect_dns_data_exfiltration_using_pretrained_model_in_dsdl", "description": "Detect DNS Data Exfiltration using pretrained Model in DSDL"}, {"filename": "__mlspl_detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl.mlmodel", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "__mlspl_detect_suspicious_dns_txt_records_using_pretrained_model_in_dsdl", "description": "Detect suspicious DNS txt records using Pretrained Model in DSDL"}, {"filename": "__mlspl_detect_suspicious_processnames_using_pretrained_model_in_dsdl.mlmodel", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "__mlspl_detect_suspicious_processnames_using_pretrained_model_in_dsdl", "description": "Detect a suspicious processname using Pretrained Model in DSDL"}, {"filename": "__mlspl_pretrained_dga_model_dsdl.mlmodel", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "__mlspl_pretrained_dga_model_dsdl", "description": "Detect DGA domains using Pretrained Model in DSDL"}, {"filename": "__mlspl_risky_spl_pre_trained_model.mlmodel", "default_match": "false", "match_type": null, "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "__mlspl_risky_spl_pre_trained_model", "description": "Detect Risky SPL using Pretrained ML Model"}, {"filename": "__mlspl_unusual_commandline_detection.mlmodel", "default_match": "false", "match_type": null, "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "__mlspl_unusual_commandline_detection", "description": "An MLTK model for detecting malicious commandlines"}, {"filename": "advanced_audit_policy_guids.csv", "default_match": "false", "match_type": "WILDCARD(GUID)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "advanced_audit_policy_guids", "description": "List of GUIDs associated with Windows advanced audit policies"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "api_call_by_user_baseline", "fields_list": "arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls", "name": "api_call_by_user_baseline", "description": "A collection that will contain the baseline information for number of AWS API calls per user"}, {"filename": "applockereventcodes.csv", "default_match": "false", "match_type": "WILDCARD(AppLocker_Event_Code)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "applockereventcodes", "description": "A csv of the ID and rule name for AppLocker event codes."}, {"filename": "asr_rules.csv", "default_match": "false", "match_type": "WILDCARD(ASR_Rule)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "asr_rules", "description": "A csv of the ID and rule name for ASR, Microsoft Attack Surface Reduction rules."}, {"filename": "attacker_tools.csv", "default_match": "false", "match_type": "WILDCARD(attacker_tool_names)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "attacker_tools", "description": "A list of tools used by attackers"}, {"filename": "aws_service_accounts.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "aws_service_accounts", "description": "A lookup file that will contain AWS Service accounts"}, {"filename": "baseline_blocked_outbound_connections.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "baseline_blocked_outbound_connections", "description": "A lookup file that will contain the baseline information for number of blocked outbound connections"}, {"filename": "brand_monitoring.csv", "default_match": "false", "match_type": "WILDCARD(domain)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "brandMonitoring_lookup", "description": "A file that contains look-a-like domains for brands that you want to monitor"}, {"filename": "browser_app_list.csv", "default_match": "false", "match_type": "WILDCARD(browser_process_name), WILDCARD(browser_object_path)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "browser_app_list", "description": "A list of known browser application being targeted for credential extraction."}, {"filename": "char_conversion_matrix.csv", "default_match": "false", "match_type": "WILDCARD(data)", "min_matches": 1, "case_sensitive_match": "true", "collection": null, "fields_list": null, "name": "char_conversion_matrix", "description": "A simple conversion matrix for converting to and from UTF8/16 base64/hex/decimal encoding. Created mosty from https://community.splunk.com/t5/Splunk-Search/base64-decoding-in-search/m-p/27572#M177741, with small modifications for UTF16LE parsing for powershell encoding."}, {"filename": null, "default_match": "false", "match_type": "WILDCARD(filter)", "min_matches": null, "case_sensitive_match": "false", "collection": "cloud_instances_enough_data", "fields_list": "_key, filter, enough_data", "name": "cloud_instances_enough_data", "description": "A lookup to determine if you have a sufficient amount of time has passed to collect cloud instance data for behavioral searches"}, {"filename": "discovered_dns_records.csv", "default_match": "false", "match_type": null, "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "discovered_dns_records", "description": "A placeholder for a list of discovered DNS records generated by the baseline discover_dns_records"}, {"filename": "domain_admins.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "domain_admins", "description": "List of domain admins"}, {"filename": "domains.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "domains", "description": "A list of domains that can be ignored"}, {"filename": "dynamic_dns_providers_default.csv", "default_match": "false", "match_type": "WILDCARD(dynamic_dns_domains)", "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "dynamic_dns_providers_default", "description": "A list of dynammic dns providers that should not be modified"}, {"filename": "dynamic_dns_providers_local.csv", "default_match": "false", "match_type": "WILDCARD(dynamic_dns_domains)", "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "dynamic_dns_providers_local", "description": "A list of dynammic dns providers that can be modified"}, {"filename": "hijacklibs.csv", "default_match": "false", "match_type": "WILDCARD(library)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "hijacklibs", "description": "A list of potentially abused libraries in Windows"}, {"filename": "hijacklibs_loaded.csv", "default_match": "false", "match_type": "WILDCARD(library),WILDCARD(excludes)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "hijacklibs_loaded", "description": "A list of potentially abused libraries in Windows"}, {"filename": "images_to_repository.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "images_to_repository", "description": "Mapping images to repositories"}, {"filename": "is_net_windows_file20231221.csv", "default_match": "false", "match_type": null, "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "is_net_windows_file", "description": "A full baseline of executable files in \\Windows\\, including sub-directories from Server 2016 and Windows 11. Certain .net binaries may not have been captured due to different Windows SDK's or developer utilities not installed during baseline."}, {"filename": "is_nirsoft_software20231221.csv", "default_match": "false", "match_type": null, "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "is_nirsoft_software", "description": "A subset of utilities provided by NirSoft that may be used by adversaries."}, {"filename": "is_suspicious_file_extension_lookup.csv", "default_match": "false", "match_type": "WILDCARD(file_name)", "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "is_suspicious_file_extension_lookup", "description": "A list of suspicious extensions for email attachments"}, {"filename": "is_windows_system_file20231221.csv", "default_match": "false", "match_type": null, "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "is_windows_system_file", "description": "A full baseline of executable files in Windows\\System32 and Windows\\Syswow64, including sub-directories from Server 2016 and Windows 10."}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "k8s_container_network_io_baseline", "fields_list": "key, avg_outbound_network_io, avg_inbound_network_io, stdev_outbound_network_io, stdev_inbound_network_io, count, last_seen", "name": "k8s_container_network_io_baseline", "description": "A place holder for a list of used Kuberntes Container Network IO"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "k8s_container_network_io_ratio_baseline", "fields_list": "key, avg_outbound_network_io, avg_inbound_network_io, stdev_outbound_network_io, stdev_inbound_network_io, count, last_seen", "name": "k8s_container_network_io_ratio_baseline", "description": "A place holder for a list of used Kuberntes Container Network IO Ratio"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "k8s_process_resource_baseline", "fields_list": "host.name, k8s.cluster.name, k8s.node.name, process.executable.name, avg_process.cpu.time, avg_process.cpu.utilization, avg_process.disk.io, avg_process.disk.operations, avg_process.memory.usage, avg_process.memory.utilization, avg_process.memory.virtual, avg_process.threads, stdev_process.cpu.time, stdev_process.cpu.utilization, stdev_process.disk.io, stdev_process.disk.operations, stdev_process.memory.usage, stdev_process.memory.utilization, stdev_process.memory.virtual, stdev_process.threads, key", "name": "k8s_process_resource_baseline", "description": "A place holder for a list of used Kuberntes Process Resource"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "k8s_process_resource_ratio_baseline", "fields_list": "key, avg_cpu:mem, stdev_cpu:mem, avg_cpu:disk, stdev_cpu:disk, avg_mem:disk, stdev_mem:disk, avg_cpu:threads, stdev_cpu:threads, avg_disk:threads, avg_disk:threads, count, last_seen", "name": "k8s_process_resource_ratio_baseline", "description": "A place holder for a list of used Kuberntes Process Ratios"}, {"filename": "legit_domains.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "legit_domains", "description": "A list of legit domains to be used as an ignore list for possible phishing sites"}, {"filename": "linux_tool_discovery_process.csv", "default_match": "false", "match_type": "WILDCARD(process)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "linux_tool_discovery_process", "description": "A list of suspicious bash commonly used by attackers via scripts"}, {"filename": "local_file_inclusion_paths.csv", "default_match": "false", "match_type": "WILDCARD(local_file_inclusion_paths)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "local_file_inclusion_paths", "description": "A list of interesting files in a local file inclusion attack"}, {"filename": "lolbas_file_path.csv", "default_match": "false", "match_type": "WILDCARD(lolbas_file_name)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "lolbas_file_path", "description": "A list of LOLBAS and their file path used in determining if a script or binary is valid on windows"}, {"filename": "loldrivers.csv", "default_match": "false", "match_type": "WILDCARD(driver_name)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "loldrivers", "description": "A list of known vulnerable drivers"}, {"filename": "rare_process_allow_list_default.csv", "default_match": "false", "match_type": "WILDCARD(process)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "lookup_rare_process_allow_list_default", "description": "A list of rare processes that are legitimate that is provided by Splunk"}, {"filename": "rare_process_allow_list_local.csv", "default_match": "false", "match_type": "WILDCARD(process)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "lookup_rare_process_allow_list_local", "description": "A list of rare processes that are legitimate provided by the end user"}, {"filename": "uncommon_processes_default.csv", "default_match": "false", "match_type": "WILDCARD(process)", "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "lookup_uncommon_processes_default", "description": "A list of processes that are not common"}, {"filename": "uncommon_processes_local.csv", "default_match": "false", "match_type": "WILDCARD(process)", "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "lookup_uncommon_processes_local", "description": "A list of processes that are not common"}, {"filename": "mandatory_job_for_workflow.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "mandatory_job_for_workflow", "description": "A lookup file that will be used to define the mandatory job for workflow"}, {"filename": "mandatory_step_for_job.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "mandatory_step_for_job", "description": "A lookup file that will be used to define the mandatory step for job"}, {"filename": "network_acl_activity_baseline.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "network_acl_activity_baseline", "description": "A lookup file that will contain the baseline information for number of AWS Network ACL Activity"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_api_calls_from_user_roles", "fields_list": "_key,earliest,latest,userName,eventName", "name": "previously_seen_api_calls_from_user_roles", "description": "A placeholder for a list of IPs that have access S3"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_aws_cross_account_activity", "fields_list": "_key,firstTime,lastTime,requestingAccountId,requestedAccountId", "name": "previously_seen_aws_cross_account_activity", "description": "A placeholder for a list of AWS accounts and assumed roles"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_aws_regions", "fields_list": "_key,earliest,latest,awsRegion", "name": "previously_seen_aws_regions", "description": "A place holder for a list of used AWS regions"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_cloud_api_calls_per_user_role", "fields_list": "_key, user, command, firstTimeSeen, lastTimeSeen, enough_data", "name": "previously_seen_cloud_api_calls_per_user_role", "description": "A table of users, commands, and the first and last time that they have been seen"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_cloud_compute_creations_by_user", "fields_list": "_key, firstTimeSeen, lastTimeSeen, user, enough_data", "name": "previously_seen_cloud_compute_creations_by_user", "description": "A table of previously seen users creating cloud instances"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_cloud_compute_images", "fields_list": "_key, firstTimeSeen, lastTimeSeen, image_id, enough_data", "name": "previously_seen_cloud_compute_images", "description": "A table of previously seen Cloud image IDs"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_cloud_compute_instance_types", "fields_list": "_key, firstTimeSeen, lastTimeSeen, instance_type, enough_data", "name": "previously_seen_cloud_compute_instance_types", "description": "A place holder for a list of used cloud compute instance types"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_cloud_instance_modifications_by_user", "fields_list": "_key, firstTimeSeen, lastTimeSeen, user, enough_data", "name": "previously_seen_cloud_instance_modifications_by_user", "description": "A table of users seen making instance modifications, and the first and last time that the activity was observed"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_cloud_provisioning_activity_sources", "fields_list": "_key, src, City, Country, Region, firstTimeSeen, lastTimeSeen, enough_data", "name": "previously_seen_cloud_provisioning_activity_sources", "description": "A table of source IPs, geographic locations, and the first and last time that they have that done cloud provisioning activities"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_cloud_regions", "fields_list": "_key, firstTimeSeen, lastTimeSeen, vendor_region, enough_data", "name": "previously_seen_cloud_regions", "description": "A table of vendor_region values and the first and last time that they have been observed in cloud provisioning activities"}, {"filename": "previously_seen_cmd_line_arguments.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "previously_seen_cmd_line_arguments", "description": "A placeholder for a list of cmd line arugments that been seen before"}, {"filename": "previously_seen_ec2_modifications_by_user.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "previously_seen_ec2_modifications_by_user", "description": "A place holder for a list of AWS EC2 modifications done by each user"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_gcp_storage_access_from_remote_ip", "fields_list": "_key, firstTime, lastTime, bucket_name, remote_ip, operation, request_uri", "name": "previously_seen_gcp_storage_access_from_remote_ip", "description": "A place holder for a list of GCP storage access from remote IPs"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_running_windows_services", "fields_list": "_key, service, firstTimeSeen, lastTimeSeen", "name": "previously_seen_running_windows_services", "description": "A placeholder for the list of Windows Services running"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_S3_access_from_remote_ip", "fields_list": "_key, bucket_name,remote_ip,earliest,latest", "name": "previously_seen_S3_access_from_remote_ip", "description": "A placeholder for a list of IPs that have access S3"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "previously_seen_users_console_logins", "fields_list": "_key, firstTime, lastTime, user, src, City, Region, Country", "name": "previously_seen_users_console_logins", "description": "A table of users seen doing console logins, and the first and last time that the activity was observed"}, {"filename": "privileged_azure_ad_roles.csv", "default_match": "false", "match_type": "WILDCARD(azureadrole)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "privileged_azure_ad_roles", "description": "A list of privileged Azure Active Directory roles."}, {"filename": "prohibited_apps_launching_cmd20231221.csv", "default_match": "false", "match_type": "WILDCARD(prohibited_applications)", "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "prohibited_apps_launching_cmd", "description": "A list of processes that should not be launching cmd.exe"}, {"filename": "prohibited_processes.csv", "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "prohibited_processes", "description": "A list of processes that have been marked as prohibited"}, {"filename": "ransomware_extensions_20231219.csv", "default_match": "false", "match_type": "WILDCARD(Extensions)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "ransomware_extensions_lookup", "description": "A list of file extensions that are associated with ransomware"}, {"filename": "ransomware_notes_20231219.csv", "default_match": "false", "match_type": "WILDCARD(ransomware_notes)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "ransomware_notes_lookup", "description": "A list of file names that are ransomware note files"}, {"filename": "remote_access_software.csv", "default_match": "false", "match_type": "WILDCARD(remote_utility),WILDCARD(remote_domain),WILDCARD(remote_utility_fileinfo)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "remote_access_software", "description": "A list of Remote Access Software"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "s3_deletion_baseline", "fields_list": "_key, arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls", "name": "s3_deletion_baseline", "description": "A placeholder for the baseline information for AWS S3 deletions"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "security_group_activity_baseline", "fields_list": "_key, arn,latestCount,numDataPoints,avgApiCalls,stdevApiCalls", "name": "security_group_activity_baseline", "description": "A placeholder for the baseline information for AWS security groups"}, {"filename": "security_services.csv", "default_match": "false", "match_type": "WILDCARD(service)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "security_services_lookup", "description": "A list of services that deal with security"}, {"filename": "splunk_risky_command_20240601.csv", "default_match": "false", "match_type": "WILDCARD(splunk_risky_command)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "splunk_risky_command", "description": "A list of Risky Splunk Command that are candidates for abuse"}, {"filename": "suspicious_files.csv", "default_match": "false", "match_type": "WILDCARD(file)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "suspicious_writes_lookup", "description": "A list of suspicious file names"}, {"filename": "windows_protocol_handlers.csv", "default_match": "false", "match_type": "WILDCARD(handler)", "min_matches": 1, "case_sensitive_match": "false", "collection": null, "fields_list": null, "name": "windows_protocol_handlers", "description": "A list of Windows Protocol Handlers"}, {"filename": null, "default_match": "false", "match_type": null, "min_matches": null, "case_sensitive_match": "false", "collection": "zoom_first_time_child_process", "fields_list": "_key, dest, process_name, firstTimeSeen, lastTimeSeen", "name": "zoom_first_time_child_process", "description": "A list of suspicious file names"}]} |