Sophos EP - update sample data
This commit is contained in:
Родитель
ea63b0e459
Коммит
ca48c5b19d
|
@ -1,21 +1,15 @@
|
|||
[
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "low",
|
||||
"created_at": "6/15/2021, 7:29:45.191 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "AMSI/Mimikatz-A",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "AMSI",
|
||||
"when": "6/15/2021, 7:29:41.837 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
|
||||
"amsi_threat_data_processId_s": "10588",
|
||||
"amsi_threat_data_processName_s": "Windows PowerShell",
|
||||
|
@ -34,22 +28,16 @@
|
|||
"EventProduct": "Endpoint Protection"
|
||||
},
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "medium",
|
||||
"created_at": "6/15/2021, 7:29:59.307 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "EICAR-AV-Test",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "",
|
||||
"when": "6/15/2021, 7:29:57.000 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "",
|
||||
"amsi_threat_data_processId_s": "",
|
||||
"amsi_threat_data_processName_s": "",
|
||||
|
@ -68,22 +56,16 @@
|
|||
"EventProduct": "Endpoint Protection"
|
||||
},
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "low",
|
||||
"created_at": "6/15/2021, 7:29:59.320 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "EICAR-AV-Test",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "",
|
||||
"when": "6/15/2021, 7:29:57.000 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "",
|
||||
"amsi_threat_data_processId_s": "",
|
||||
"amsi_threat_data_processName_s": "",
|
||||
|
@ -102,22 +84,16 @@
|
|||
"EventProduct": "Endpoint Protection"
|
||||
},
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 10:25:00.818 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "low",
|
||||
"created_at": "6/15/2021, 7:31:12.095 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "",
|
||||
"when": "6/15/2021, 7:31:12.083 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "",
|
||||
"amsi_threat_data_processId_s": "",
|
||||
"amsi_threat_data_processName_s": "",
|
||||
|
@ -136,22 +112,16 @@
|
|||
"EventProduct": "Endpoint Protection"
|
||||
},
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "low",
|
||||
"created_at": "6/15/2021, 7:29:45.191 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "AMSI/Mimikatz-A",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "AMSI",
|
||||
"when": "6/15/2021, 7:29:41.837 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
|
||||
"amsi_threat_data_processId_s": "10588",
|
||||
"amsi_threat_data_processName_s": "Windows PowerShell",
|
||||
|
@ -170,22 +140,16 @@
|
|||
"EventProduct": "Endpoint Protection"
|
||||
},
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "medium",
|
||||
"created_at": "6/15/2021, 7:29:59.307 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "EICAR-AV-Test",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "",
|
||||
"when": "6/15/2021, 7:29:57.000 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "",
|
||||
"amsi_threat_data_processId_s": "",
|
||||
"amsi_threat_data_processName_s": "",
|
||||
|
@ -204,22 +168,16 @@
|
|||
"EventProduct": "Endpoint Protection"
|
||||
},
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "low",
|
||||
"created_at": "6/15/2021, 7:29:59.320 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "EICAR-AV-Test",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "",
|
||||
"when": "6/15/2021, 7:29:57.000 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "",
|
||||
"amsi_threat_data_processId_s": "",
|
||||
"amsi_threat_data_processName_s": "",
|
||||
|
@ -238,22 +196,16 @@
|
|||
"EventProduct": "Endpoint Protection"
|
||||
},
|
||||
{
|
||||
"SourceSystem": "RestAPI",
|
||||
"MG": "",
|
||||
"ManagementGroupName": "",
|
||||
"TimeGenerated": "6/15/2021, 8:02:19.705 AM",
|
||||
"Computer": "",
|
||||
"RawData": "",
|
||||
"user_id": "60b88e8dfd5fd40e3b6eaad2",
|
||||
"customer_id": "84b93e3c-7299-45ef-81ff-a548fb5754a9",
|
||||
"severity": "low",
|
||||
"created_at": "6/15/2021, 7:31:12.095 AM",
|
||||
"created_at": "2021-06-16T02:27:00.00000Z",
|
||||
"source_info_ip": "10.211.55.3",
|
||||
"threat": "",
|
||||
"endpoint_id": "82912e0e-660c-4b84-8e1f-b46c2cd8b041",
|
||||
"endpoint_type": "computer",
|
||||
"origin": "",
|
||||
"when": "6/15/2021, 7:31:12.083 AM",
|
||||
"when": "2021-06-16T02:27:00.00000Z",
|
||||
"amsi_threat_data_processPath_s": "",
|
||||
"amsi_threat_data_processId_s": "",
|
||||
"amsi_threat_data_processName_s": "",
|
||||
|
|
Загрузка…
Ссылка в новой задаче