The Endpoint Security (HX) logs messages when malware is found on a destination host. In addition to the common CEF fields, malware detection logging includes the following fields and field settings:
Malware hit detection
Name: Malware Hit Found ID: Malware Hit Found cs4Label: Process Name cs4: The process or IOC for which the malware was detected cs5Label: Target GMT Offset cs5: The GMT offset of the host generating the event in ISO 8601 duration format cs6Label: Target OS cs6: The operating system of the host generating the event cs7Label: Resolution cs7: The resolution name (for example, ALERT or QUARANTINED) cs8Label: Alert Types cs8: malware, spyware, adware, dialer, pup, zipbomb cs9Label: MD5 cs9: MD5 hash of the malware object cs10Label: SHA1 cs10: SHA1 hash of the malware object cs11Label: Malware Signature cs11: The malware signature cs12Label: Malware Category cs12: location of the hit -- boot-sector, registry, or process. cs13Label: Malware Engine cs13=AV or MG act: Detection MAL Hit externalId: The HX unique identifier associated with this hit start: Timestamp when the malware was detected on the destination host categoryOutcome: /Success categoryBehavior: /Found categoryDeviceGroup: /IDS categoryDeviceType: Malware Protection categoryTechnique: Malware categoryObject: /Host categorySignificance: /Compromise categoryTupleDescription: Malware Protection found a compromise indication msg: Host <hostname> Malware alert