iocmatch Audit

Prev Next

Collects indicator of compromise (IOC) matches from host endpoints.

This audit cannot be imported into a data acquisition script. See Audits That Cannot Be Imported on page 1.

Supported Platforms

Windows, Linux and macOS

Input Parameters

The following input parameters are available for this audit.

LastSeenID

Details

Values

Description

Platform

Windows and macOS

Windows and macOS environments

Format

Numeric

Valid values are numeric.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Specify the ID of the last match that was sent. Use this parameter to avoid sending the same matches every time this audit is run. If this parameter is not included in the audit, all matches are returned.