CSV extension field key=value pair definitions

Prev Next

Trellix uses the following parameters in its CSV extension field key=value pairs:

Trellix:<product name>:<event-type>:<event-name>:<severity>:<extension>

The following table provides definitions for each extension field key in a CSV message.

Note

The Z character at the end of a time stamp indicates that the time displayed is in the UTC time zone. Starting in the 7.0.0 release, the time is displayed in UTC by default. To change the displayed time to your local time, use the following CLI command: fenotify default timezone localtime

Ext.

Field Key

Description

Products

Event Type

Data Type

Release

fileHash=

fileHash

fileHash represents the checksum of the malware object from a Trellix appliance MVX

For example:

filehash=3174990d783f4a1bd5e99db60176b920

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

255 characters

7.x

8.x

src=

Source Address

src represents the IP address of the infected host

For example:

src=xxx.xxx.xxx.xxx

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

IPv4 Address

16 bytes

7.x

8.x

shost=

source hostname

shost represents the hostname of the infected machine as detected by a Trellix appliance MVX

For example:

shost=IM-testing.fe-notify-examples.com

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

proto=

Transport Protocol

proto represents the transport protocol detected by a Trellix appliance MVX.

0 indicates no protocol detected.

For example:

proto=udp

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

31 characters

7.x

8.x

dvchost=

device hostname

dvchost represents the hostname or the fully qualified domain name of the Trellix appliance performing the detection and sending the notification.

For example:

dvchost=dave

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

100 characters

7.x

8.x

spt=

source port

spt represents the infected host’s source port as detected by a Trellix appliance MVX.

For example:

spt=1116

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

Integer

Valid Port Numbers 0~65535

7.x

8.x

dvc=

device Address

dvc represents the device address of the detecting Trellix appliance MVX.

For example:

dvc=xxx.xxx.xxx.xxx

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

IPv4 address

16 bytes

7.x

8.x

smtp-mail-from=

smtp-mail-from

smtp-mail-from represents the user name of the sender of the malicious email detected by a Trellix appliance MVX.

For example:

smtp-mail-from=perfEmail@automation.local

EX

CM

MO

String

1023 characters

7.x

8.x

message-id=

message

message-id represents the email message ID of the infected email

For example:

message-id=20121017232425.6706.77689.Email-48@trellix.com

EX

CM

MO

String

1023 characters

7.x

8.x

smac=

sourceMacAddress

smac represents the source MAC address of the infected host

For example:

smac=00:0c:29:76:bb:28

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

MAC Address

7.x

8.x

dmac=

destinationMacAddress

dmac represents the MAC address of the destination when any communication to an external host is observed within the MVX.

For example:

dmac=00:50:56:e8:ba:21

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

MAC Address

7.x

8.x

alertid=

alertid

alertid represents the Trellix internal alert ID (which is external for ArcSight)

For example:

alertid=218799

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

Integer

7.x

8.x

smtp-to=

smtp-to

smtp-to represents the recipient of the malicious email detected by a Trellix appliance

For example:

smtp-to=x@y.com

EX

CM

MO

String

1023 characters

7.x

8.x

app=

app

app represents the name of the target application running on the MVX during malware detection

For example:

app=Firefox 4.0.0

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

dst=

destinationName

dst represents the IP address of the destination when any communication to an external host is observed within the MVX.

For example:

dst=xxx.xxx.xxx.xxx

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

IPv4 Address

16 bytes

7.x

8.x

dpt=

destinationPort

dpt represents port of the destination when any communication to an external host is observed within the MVX.

For example:

dst=20

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

Integer

7.x

8.x

eventURL=

link

eventURL represents the alert URL

For example:

eventURL=https://xxx.xxx.xxx.xxx/event_stream/events_for_bot?ma_id\=51056&lms_iden\=00:25:90:54:7E:6E cs1Label=sname cs1=Trojan.Generic

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

repository=

repository is the file system SharePoint or mount point.

For example:

repository=sharepoint1

AX

FX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

locations=

locations represents geolocations.

For example:

locations=Tokyo

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

application=

application represents the name of the target application running on the MVX during malware detection.

For example:

application=Firefox 4.0.0

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

vlan=

vlan represents the VLAN ID.

For example:

vlan=0

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

Integer

7.x

8.x

cnchost=

cnchost represents the CnC hostname.

For example:

cnchost=xxx.xxx.xxx.xxx

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

IP address or String

1023 characters

7.x

8.x

cncport=

cncport represents the CnC listening server port.

For example:

cncport=53

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

Integer

7.x

8.x

smtp-cc=

smtp-cc represents the CC'd recipient of the malicious email detected by a Trellix appliance MVX.

For example:

smtp-cc=x@y.com

EX

CM

MO

String

1023 characters

7.x

8.x

channel=

channel represents the CnC channel.

For example:

channel=GET /images/news.php?p=15353&id=34992661&e=0 HTTP/1.1::~~User-Agent: szNotifyIdent::~~Host: efrering-basilea.com::~~::~~

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

header=

header represents the protocol header.

For example:

header=udp

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

action=

action represents the action taken by the Trellix appliance MVX.

For example:

action=blocked

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

osinfo=

osinfo represents the Trellix appliance OS name and version.

For example:

osinfo=Microsoft WindowsXP Professional 5.1 base

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

profile=

profile represents the Trellix appliance MVX profile OS name and version.

For example:

profile=Microsoft Windows7 Professional 6.1 base

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

sType=

sType represents the Trellix-assigned signature type.

Available values:

'unknown',

'generated-content',

'trellix-content',

'bot-command',

'fqc',

'known-md5sum',

duplicate-md5sum',

'av-match',

'MVX-bot-command',

blacklist',

'yara',

'avs',

'archive',

'encoding',

'timestamp'

For example:

sType=Blacklist

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

occurred=

occurred represents the malware event time as detected by a Trellix appliance MVX.

For example:

occurred=Oct 17 2012 23:13:20 Z

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

Time Stamp mmmddyyyy HH:mm:ss

or millisecs

since epoch

7.x

8.x

os=

os represents the name of the target OS.

For example:

os=Microsoft WindowsXP Professional 5.1 sp2

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

anomaly=

anomaly represents attributes of OS changes made by the malware, data theft, or miscellaneous anomaly.

For example:

anomaly=misc-anomaly, datatheft-anomaly

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

sName=

sName represents the Trellix-assigned signature name

For example:

sName=Trojan.Generic

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

String

1023 characters

7.x

8.x

sID=

sId represents the Trellix internal signature ID.

For example:

sID=234643322

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

Integer

7.x

8.x

sev=

Severity

For example:

sev=minr

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

IE

RC

RO

String representing minor, major, or critical severity.

7.5 and later

malware_type=

Type of malware

For example:

malware_type=jar

NX

AX

FX

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

alertType=

Type of alert

For example:

alertType=infection-match

NX

AX

FX

EX

CM

MC

WI

IM

MO

IE

RC

RO

String

The valid values are domain-match, ips-event, infection-match, malware-callback, malware object, riskware-callback, riskware-object, and web-infection.

7.x

8.x

malware-note=

Notes about the malware

NX

AX

FX

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

objurl=

The objurl element provides details about the detected malware URL.

NX

AX

FX

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

1023 characters

7.x

8.x

mwurl=

URL that triggered the malware event.

For example:

mwurl=enkinie.in/02/jaghay.jar

NX

AX

FX

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

1023 characters

7.x

8.x

product=

Product name

For example:

product=Web MPS

NX

AX

FX

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

release=

Product release

For example:

release=8.2.0.476393

NX

AX

FX

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

link=

Link link represents the local path or URL of the malware object (local to the detecting appliance).

For example:

link=https://tikka.mrl.trellix.com/event_stream/events_for_bot?ev_id=1999

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

original_name=

Original file name of the malware

For example:

original_name=jaghay.jar

NX

AX

FX

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

protocol=

protocol represents the transport protocol detected by the Trellix appliance MVX.

For example:

protocol=8

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

Integer

Valid values are 8 (URL), 9 (attachment), and 10 (header).

7.x

8.x

subject=

subject represents the SMTP email message subject line on the infected email.

For example:

Subject: noti-test User-Agent: Heirloom mailx 12.4 7/29/08 MIME-Version: 1.0 Content-Type: text/plain;

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

1023 characters

7.x

8.x

date=

Date when the alert was found.

For example:

date=Wed, 27 Jul 2016 12:28:33 -0700

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

Time stamp in the following format:

yyyy-mm-ddTHH:mm

7.x

8.x

run_end=

End of process.

For example:

run_end=2016-07-27T18:56:27Z

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

1023 characters

Standard XML daytime format

6.x

7.x

8.x

last-malware=

last-malware represents the name associated with last malicious email infection.

For example:

last-malware=TestFire.exe

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

1023 characters

7.x

8.x

smtp-header=

smtp-header provides the SMTP email message header (including any configured X-header) of the infected email.

For example:

smtp-header=Received: from ghost.localdomain (unknown [xxx.xx.xx.x]) #011by superman.eng.trellix.com (Postfix) with ESMTP id 3s04m14LGsz7LSW3 #011for &lt;trellix@spiderman.com&gt;; Wed, 27 Jul 2016 19:28:33 +0000 (UTC) Received: by ghost.localdomain (Postfix, from userid 0) #011id 876A213C0320; Wed, 27 Jul 2016 12:28:33 -0700 (PDT) Date: Wed, 27 Jul 2016 12:28:33 -0700 To: trellix@spiderman.com Subject: noti-test User-Agent: Heirloom mailx 12.4 7/29/08 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Message-Id: &lt;20160727192833.876A213C0320@ghost.localdomain&gt; From: root@ghost.localdomain (root)

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

1023 characters

7.x

8.x

download_end=

End of download

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

Time stamp

7.x

8.x

sigId=

Trellix internal signature ID.

For example:

sigId=85304723

NX

CM

MC

WI

IM

DM

MO

IE

RC

RO

Integer

7.x

8.x

sigrevision=

Revision of the Trellix internal signature ID.

For example:

sigrevision=1

NX

CM

MC

WI

IM

DM

MO

IE

RC

RO

Integer

7.x

8.x

matchcount=

Number of matches

For example

matchcount=1

NX

CM

MC

WI

IM

DM

MO

IE

RC

RO

Integer

7.x

8.x

signame=

Name of the Trellix internal signature ID.

For example:

signame=Apple QuickTime TeXML textBox Element Memory Corruption

NX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

cve_id=

CVE ID

For example:

cve_id=CVE-2013-1015

NX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

action_taken=

Type of action taken

For example:

action_taken=notified

NX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

Valid values are notified and blocked.

7.x

8.x

attack_mode=

Attack mode

For example:

attack_mode=client

NX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

7.x

8.x

mvx_status=

MVX status

For example:

mvx_status=N/A

NX

CM

IE

String

7.x

8.x