Exploit Guard log fields

Prev Next

The Endpoint Security (HX) logs messages when exploits are found on a destination host. In addition to the common CEF fields, exploit hit detection logging includes the following fields and field settings:

Exploit hit detection

Name: ExD Hit Found
ID: ExD Hit Found
cs4Label: Process Name
cs4: The process for which the exploit was detected
cs5Label: Target GMT Offset
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event
act: Detection ExD Hit
externalId: The HX unique identifier associated with this hit
start: Timestamp when the exploit was detected on the destination host
categoryOutcome: /Success
categoryBehavior: /Found
categoryDeviceGroup: /IDS
categoryDeviceType: Exploit Detection
categoryObject: /Host
categorySignificance: /Compromise
categoryTechnique: Exploit
categoryTupleDescription: ExD found a compromise indication
msg: Host <hostname> ExD compromise