Malware detection log fields

Prev Next

The Endpoint Security (HX) logs messages when malware is found on a destination host. In addition to the common CEF fields, malware detection logging includes the following fields and field settings:

Malware hit detection

Name: Malware Hit Found
ID: Malware Hit Found
cs4Label: Process Name
cs4: The process or IOC for which the malware was detected
cs5Label: Target GMT Offset
cs5: The GMT offset of the host generating the event in ISO 8601 duration format
cs6Label: Target OS
cs6: The operating system of the host generating the event
cs7Label: Resolution
cs7: The resolution name (for example, ALERT or QUARANTINED)
cs8Label: Alert Types
cs8: malware, spyware, adware, dialer, pup, zipbomb
cs9Label: MD5
cs9: MD5 hash of the malware object
cs10Label: SHA1
cs10: SHA1 hash of the malware object
cs11Label: Malware Signature
cs11: The malware signature
cs12Label: Malware Category
cs12: location of the hit -- boot-sector, registry, or process.
cs13Label: Malware Engine
cs13=AV or MG
act: Detection MAL Hit
externalId: The HX unique identifier associated with this hit
start: Timestamp when the malware was detected on the destination host
categoryOutcome: /Success
categoryBehavior: /Found
categoryDeviceGroup: /IDS
categoryDeviceType: Malware Protection
categoryTechnique: Malware
categoryObject: /Host
categorySignificance: /Compromise
categoryTupleDescription: Malware Protection found a compromise indication
msg: Host <hostname> Malware alert