Configure ePO - On-prem integration to publish threat events

Prev Next

You can enable Intelligent Sandbox to send sample data to ePO - On-prem. You must install the ATDThreatEvents_5221.zip extension on ePO to allow Intelligent Sandbox to publish threat events.

Intelligent Sandbox Custom Fields & Data

Intelligent Sandbox sends the following data to ePO - On-prem:

  • Intelligent Sandbox software version

  • Job ID

  • Task ID

  • Intelligent Sandbox IP address

  • Source IP address

  • IOC (Indicators of compromise) file Name

  • MD5 value

  • Time stamp

  • Size

  • Severity

  • Indicators of compromise (IOC) file Data

    Note

    Indicators of compromise (IOC) file Data is available from 4.12.4.x and above versions.

Download IoC (Indicators of compromise) file

You can download the Indicators of compromise file Data for a selected threat event from ActionsDownload IoC File. This option redirects you to the file link. You can open the file in browser by single click or downloaded by right click and Save As.

The Download IoC File will remain disabled if more than one event is selected. If an event is clean, the IoC file will not exist, in this case a message File does not exist is displayed instead of link.

Choose Columns

From ActionsChoose Columns, select the following data fields to see the Intelligent Sandbox Threat Events details:

  • Intelligent Sandbox software version (MIS Version)

  • Intelligent Sandbox IP address (TIS IP)

  • IOC (Indicators of compromise) file Name

  • MD5 value

  • Severity

Queries and Reports

Generate the Queries and reports based on the following data fields to see the TIS Threat Events belonging to a category:

  • Intelligent Sandbox software version (MIS Version)

  • Intelligent Sandbox IP address (TIS IP)

  • IOC (Indicators of compromise) file Name

  • MD5 value

  • Severity

Under Queries & reportsNew Query(Feature Group) Events(Result Type) Trellix Intelligent Sandbox Events, above columns can be selected for:

  • ChartBar labels

  • Columns

  • Filter

Note

The Queries and Reports, Choose Columns, and Download IoC custom fields are available from 4.12.4.x and above versions.

ePO Common Fields data

The following ePO Common Fields are sent by Intelligent Sandbox to ePO - On-prem:

ePO Field

Value

Detecting Product Name

Detecting Product Version

Intelligent Sandbox software version

Threat Source IPv4 Address

Source IP address.

Threat Target Process Name

Refer IoC File, if event is not clean, else it is empty.

Threat Target File Path

Refer IoC File, if event is not clean, else it is empty.

Threat name

tis_detected_threat_<MD5 Value of sample submitted for analysis>.

Md5 is appended for 4.12.4 onwards.

Threat Type

Threat Type for an event takes one of the following values based on the TIS Analysis Engine:

  • [TIS] Static

  • [TIS] Dynamic

  • [TIS] BlockedList (Blacklist)

  • [TIS] ApprovedList (Whitelist)

  • [TIS] Unverified

Event Category

Event Category for an event takes one of the following values based on following mapping of TIS Severity to Event Category:

TIS Severity

ePO Threat Severity

NA | Clean | Information | Empty

Informational Event

Low | Very Low | Medium | High | Very High

Malware detected

Analyzer Detection Method

Analyzer Detection Method for an event takes one of the following values based on the TIS Analysis Engine:

  • [TIS] Static

  • [TIS] Dynamic

  • [TIS] BlockedList (Blacklist)

  • [TIS] ApprovedList (Whitelist)

  • [TIS] Unverified

Threat Severity

Threat Severity for an event takes one of the following values based on the following mapping of TIS Severity to Threat Severity:

TIS Severity

ePO Threat Severity

NA | Clean | Information | Empty

Informational (6)

Low | Very Low

Notice (5)

Medium

Warning (4)

High

Critical (2)

Very High

Alert (1)

Note

The ePO field values are based on 4.12.4 release. These fields are enhanced from 4.12.4 release and above versions.