The following hit data is captured and mapped to the Helix Taxonomy.
Common Fields
Attribute | Helix Destination Field | Notes |
|---|---|---|
agent_id | agentid | The ID of the agent |
agent_ipv4 / agent_ipv6 | agentip / agentipv6 | The IP address of the agent |
condition_id | eventid | The ID of the condition that was matched |
device_id | deviceid | The ID of the HX that the agent is associated to |
domain | agentdomain | The domain that the agent is a member of |
event_type | eventtype | The type of event that matched the condition |
hostname | hostname | The host name of the agent |
indicator_id | indicator_id | The ID of the indicator associated to the condition that was matched. For FireEye preconfigured indicators, his will be an OpenID |
indicator_meta.confidence | confidence1,2 | The confidence associated to the indicator |
indicator_meta.desciption | description | The description associated to the indicator |
indicator_meta.name | iocnames | The name associated to the indicator |
indicator_meta.threat_ | threat_model_associations1 | The threat modeled by the indicator. For MITRE modeling this will include the technique identifiers |
intel_version | intel_version | The version of the rules that contained the condition that was matched |
mac_address | agentmac | Mac address of the agent |
match_timestamp | detectedtime | The timestamp for when the condition was matched |
message_type | category | ioc-meta : denotes that this event originated from the IOC Streaming module |
metadata-version | metdata-version | 1.1 |
timestamp | eventtime | The timestamp for when the event occurred on the agent |
1Available only for Trellix preconfigured indicators. 2Optional. May not be present for all indicators.