You can enable Intelligent Sandbox to send sample data to ePO - On-prem. You must install the ATDThreatEvents_5221.zip extension on ePO to allow Intelligent Sandbox to publish threat events.
Intelligent Sandbox Custom Fields & Data
Intelligent Sandbox sends the following data to ePO - On-prem:
Intelligent Sandbox software version
Job ID
Task ID
Intelligent Sandbox IP address
Source IP address
IOC (Indicators of compromise) file Name
MD5 value
Time stamp
Size
Severity
Indicators of compromise (IOC) file Data
Note
Indicators of compromise (IOC) file Data is available from 4.12.4.x and above versions.
Download IoC (Indicators of compromise) file
You can download the Indicators of compromise file Data for a selected threat event from → . This option redirects you to the file link. You can open the file in browser by single click or downloaded by right click and Save As.
The Download IoC File will remain disabled if more than one event is selected. If an event is clean, the IoC file will not exist, in this case a message File does not exist is displayed instead of link.
Choose Columns
From → , select the following data fields to see the Intelligent Sandbox Threat Events details:
Intelligent Sandbox software version (MIS Version)
Intelligent Sandbox IP address (TIS IP)
IOC (Indicators of compromise) file Name
MD5 value
Severity
Queries and Reports
Generate the Queries and reports based on the following data fields to see the TIS Threat Events belonging to a category:
Intelligent Sandbox software version (MIS Version)
Intelligent Sandbox IP address (TIS IP)
IOC (Indicators of compromise) file Name
MD5 value
Severity
Under → → → , above columns can be selected for:
→
Columns
Filter
Note
The Queries and Reports, Choose Columns, and Download IoC custom fields are available from 4.12.4.x and above versions.
ePO Common Fields data
The following ePO Common Fields are sent by Intelligent Sandbox to ePO - On-prem:
ePO Field | Value | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Detecting Product Name | |||||||||||||
Detecting Product Version | Intelligent Sandbox software version | ||||||||||||
Threat Source IPv4 Address | Source IP address. | ||||||||||||
Threat Target Process Name | Refer IoC File, if event is not clean, else it is empty. | ||||||||||||
Threat Target File Path | Refer IoC File, if event is not clean, else it is empty. | ||||||||||||
Threat name | tis_detected_threat_<MD5 Value of sample submitted for analysis>. Md5 is appended for 4.12.4 onwards. | ||||||||||||
Threat Type | Threat Type for an event takes one of the following values based on the TIS Analysis Engine:
| ||||||||||||
Event Category | Event Category for an event takes one of the following values based on following mapping of TIS Severity to Event Category:
| ||||||||||||
Analyzer Detection Method | Analyzer Detection Method for an event takes one of the following values based on the TIS Analysis Engine:
| ||||||||||||
Threat Severity | Threat Severity for an event takes one of the following values based on the following mapping of TIS Severity to Threat Severity:
|
Note
The ePO field values are based on 4.12.4 release. These fields are enhanced from 4.12.4 release and above versions.