The IOC Streaming module is shipped with a set of pre-configured indicators that are derived from the Supplemental Indicators, available on the FireEye Marketplace. This set is initially installed with the module and the rules are enabled by default. These rules specifically monitor for behaviors on Windows, Mac and Linux. You can interrogate these rules and specify the ones that should be active in your environment. Since these rules are provided by Trellix, you cannot adjust their conditions, remove them or disable the ones that are not necessary. See Table of Trellix Provided Indicators for a list of theTrellix Indicators provided with the IOC Streaming module.
These rules contain
Weak-signal indicators
Intended to demonstrate how this module can be used to collect telemetry. For example:
Registry modification
Use of Crontab on Linux
Detection content that may be well-suited for specific customer environments. This content includes the following categories of indicators:
Detection of exploits
Detection of malware families and backdoors
Attacker tools such as credential stealers or commonly used legitimate utilities
Attacker methodologies
IOCs used during the MITRE 2021 evaluation.
MITRE ATT&CK technique mapping updates.
IOC for Windows Elevation of Privilege Vulnerability (CVE-2021-36934).
The breakout of these rules is
638 IOCs
456 Windows
132 Linux
50 macOS
Detection categories
10 exploits
5 malware families
7 backdoors
7 credential stealers
47 utilities often used by attackers
562 methodologies / techniques used by attackers