Sophos EP - update sample data

This commit is contained in:
Vitalii Uslystyi 2021-07-01 16:47:51 +03:00
Родитель ea63b0e459
Коммит ca48c5b19d
1 изменённых файлов: 16 добавлений и 64 удалений

Просмотреть файл

@ -1,21 +1,15 @@
[
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "low",
"created_at": "6/15/2021, 7:29:45.191 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "AMSI/Mimikatz-A",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "AMSI",
"when": "6/15/2021, 7:29:41.837 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
"amsi_threat_data_processId_s": "10588",
"amsi_threat_data_processName_s": "Windows PowerShell",
@ -34,22 +28,16 @@
"EventProduct": "Endpoint Protection"
},
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "medium",
"created_at": "6/15/2021, 7:29:59.307 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "EICAR-AV-Test",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "",
"when": "6/15/2021, 7:29:57.000 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "",
"amsi_threat_data_processId_s": "",
"amsi_threat_data_processName_s": "",
@ -68,22 +56,16 @@
"EventProduct": "Endpoint Protection"
},
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "low",
"created_at": "6/15/2021, 7:29:59.320 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "EICAR-AV-Test",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "",
"when": "6/15/2021, 7:29:57.000 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "",
"amsi_threat_data_processId_s": "",
"amsi_threat_data_processName_s": "",
@ -102,22 +84,16 @@
"EventProduct": "Endpoint Protection"
},
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "low",
"created_at": "6/15/2021, 7:31:12.095 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "",
"when": "6/15/2021, 7:31:12.083 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "",
"amsi_threat_data_processId_s": "",
"amsi_threat_data_processName_s": "",
@ -136,22 +112,16 @@
"EventProduct": "Endpoint Protection"
},
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "low",
"created_at": "6/15/2021, 7:29:45.191 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "AMSI/Mimikatz-A",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "AMSI",
"when": "6/15/2021, 7:29:41.837 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
"amsi_threat_data_processId_s": "10588",
"amsi_threat_data_processName_s": "Windows PowerShell",
@ -170,22 +140,16 @@
"EventProduct": "Endpoint Protection"
},
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "medium",
"created_at": "6/15/2021, 7:29:59.307 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "EICAR-AV-Test",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "",
"when": "6/15/2021, 7:29:57.000 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "",
"amsi_threat_data_processId_s": "",
"amsi_threat_data_processName_s": "",
@ -204,22 +168,16 @@
"EventProduct": "Endpoint Protection"
},
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "low",
"created_at": "6/15/2021, 7:29:59.320 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "EICAR-AV-Test",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "",
"when": "6/15/2021, 7:29:57.000 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "",
"amsi_threat_data_processId_s": "",
"amsi_threat_data_processName_s": "",
@ -238,22 +196,16 @@
"EventProduct": "Endpoint Protection"
},
{
"SourceSystem": "RestAPI",
"MG": "",
"ManagementGroupName": "",
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
"Computer": "",
"RawData": "",
"user_id": "60b88e8dfd5fd40e3b6eaad2",
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
"severity": "low",
"created_at": "6/15/2021, 7:31:12.095 AM",
"created_at": "2021-06-16T02:27:00.00000Z",
"source_info_ip": "10.211.55.3",
"threat": "",
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
"endpoint_type": "computer",
"origin": "",
"when": "6/15/2021, 7:31:12.083 AM",
"when": "2021-06-16T02:27:00.00000Z",
"amsi_threat_data_processPath_s": "",
"amsi_threat_data_processId_s": "",
"amsi_threat_data_processName_s": "",