Note
Every ACE alert generates a separate CEF notification.
CEF:0|Trellix|ETP|3.0|etp|ace alert|10|rt=Nov 07 2016 23:27:17 UTC suser=yser@abc.com duser=usera@xyz.pqr.com fname=test.zip fileHash=5b61d32c94ca81d4f28241ca29aca9b9 destinationDnsDomain=xyz.pqr.com externalId=9999999 cs1Label=sname cs1=Malware.archive cs3Label=Subject cs3=Arc Sight Test CEF cs4Label=Link cs4=https://etp.trellixcloud.com/alert/9999999/ cs5Label=Client cs5=AAAA cs6Label=ATI Name Type Level cs6=Exploit.DTI.CVE-2008-2992\|Exploit\|Medium flexString1Label=ATI Threat Attribution flexString1=While many well-known exploit kits used to weaponize the CVE-2008-2992 exploit, the popularity of this exploit has drastically dropped overtime due to Adobe Reader’s sandbox mechanism. No APT actors have been found to actively leverage this exploit in current cyber operations. Metasploit, however, still has a module targeting CVE-2008-2992 vulnerability. As this exploit is old, the latest versions of Adobe application are already patched against this attack. It is strongly advised to update Adobe Acrobat and Reader to versions 8.1.2 and above as soon as possible.