Trellix uses the following parameters in its LEEF extension field key=value pairs. The header fields are separated using the pipe ('|') character, and the body fields are separated using the caret ('^') character.
LEEF:0|<vendor>|<product name>|<IP_Address>|<eventID>|<extension>
The following table provides definitions for each extension field key in a CEF message.
Note
The Z character at the end of a time stamp indicates that the time displayed is in the UTC time zone. Starting in the 7.0.0 release, the time is displayed in UTC by default. To change the displayed time to your local time, use the following CLI command: fenotify default timezone localtime
Ext. Field Key | Description | Products | Event Type | Data Type | Release |
|---|---|---|---|---|---|
sev= | Severity The least important event is 1; the most important event is 10. | NX AX FX EX CM | WI MC IM DM MO IE RC RI RO | Integer Valid numbers 1-10 | 7.5 and later |
src= | Source Address src represents the IP address of the infected host. For example: src=192.168.85.141 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | IPv4 or IPV6 Address 16 bytes | 7.x 8.x |
sname= | sname sname represents the Trellix-assigned signature name. For example: sname=Bot.Mariposa.DNS | NX AX FX EX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
dstmac= | dstMac dstmac represents the MAC address of the destination when any communication to an external host is observed within the MVX. For example: dstmac=00:50:56:e8:ba:21 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | MAC Address Six colon- separated hexadecimal numbers | 7.x 8.x |
proto= | Transport Protocol proto represents the transport protocol detected by a Trellix appliance MVX 0 indicates no protocol detected For example: proto=udp | NX AX FX EX CM | WI MC IM DM MO RC RO | String 31 characters | 7.x 8.x |
dvchost= | device hostname dvchost represents the hostname or the fully qualified domain name of the Trellix appliance performing the detection and sending the notification For example: dvchost=dave | NX AX FX EX CM | WI MC IM DM MO RC RO | String 100 characters | 7.x 8.x |
vlan= | vlan vlan represents the vlan ID of the infected host. For example: vlan=0 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | String 100 characters | 7.x 8.x |
action= | action When action=blocked, the alert has been blocked. When action=notified, the alert is not blocked. | NX AX FX EX CM | WI MC IM DM MO IE RC RO | String 63 characters | 7.5 and later |
srcPort= | source port srcPort represents the infected host’s source port as detected by a Trellix appliance MVX. For example: srcPort=1047 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | Integer Valid Port Numbers 0~65535 | 7.x 8.x |
dvc | device Address dvc represents the device address of the detecting Trellix appliance MVX. For example: dvc=xxx.xxx.xxx.xxx | NX AX FX EX CM | WI MC IM DM MO RC RO | IPv4 address 16 bytes | 7.x 8.x |
cncHost= | Malicious C&C hostname cnchost represents the hostname of the CnC server; however, if the appliance is unable to resolve the CnC server's hostname, this field will contain the IP address of the CnC server. For example: cncHost=hayboxiw.cn | NX AX FX EX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
externalId= | externalId externalId represents the Trellix internal alert ID (which is external for ArcSight) For example: externalId=218799 externalId=96 | NX AX FX EX CM | WI MC IM DM MO RC RO | Integer | 7.x 8.x |
devTime= | devTime devTime represents the time the Trellix appliance MVX application emitted the malware event. For example: devTime=Oct 17 2012 23:13:20 Z | NX AX FX EX CM | WI MC IM DM MO RC RI RO | Time Stamp mmmddyyyy HH:mm:ss or millisecs since epoch | 7.x 8.x |
sid= | sid sid represents the Trellix internal signature ID. For example: sigID=80442765 | NX AX FX EX CM | WI MC IM DM MO RC RO | Integer | 7.x 8.x |
cncPort= | cncPort cncPort represents the CnC listening server port For example: cncPort=53 | NX AX FX EX CM | WI MC IM DM MO RC RO | Numeric Integer Long | 7.x 8.x |
link= | link link represents the local path or URL of the malware object (local to the detecting appliance:). For example: link=/analysis/17FFD13A0289-0-Email -50_3174990d783f4a 1bd5e99db60176b920 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | String 1023 characters | 7.x 8.x |
srcMAC= | srcMAC srcMAC represents the source MAC address of the infected host. For example: srcMAC=00:0c:29:76:bb:28 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | MAC Address | 7.x 8.x |
dst= | dstIPAddress dst represents the IP address of the destination when any communication to an external host is observed within the MVX. For example: dst=128.12.38.6 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | IPv4 Address or IPv6 address 16 bytes | 7.x 8.x |
dstPort= | destinationPort dstPort represents the port of the destination when any communication to an external host is observed within the MVX. For example: dstPort=20 | NX AX FX EX CM | WI MC IM DM MO RC RI RO | Integer | 7.x 8.x |
cnc Channel= | cncChannel cncChannel= represents the CnC channel For example: cncChannel=GET /message.php?subid\=148&version \=_nn2&id\=XG0FZ7W00ZHZZHKZ B0WY HTTP/1.1::~~Host: smartcontrol .info::~~User-Agent: firefox.exe;Windows NT 5.1::~~::~~ | NX AX FX EX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
fileHash= | fileHash fileHash represents the checksum of the malware object from a Trellix appliance MVX. For example: filehash=3174990d783f4a 1bd5e99db60176b920 | EX CM | MO RC RO | String 1023 characters | 7.x 8.x |
filePath= | filePath filePath represents the local path and URL of the malware object (local to the detecting appliance). For example: filePath=/analysis/198.126.166 .186_80-196.107.232.238_1158 -455169465_14_T.pcoff | EX CM | MO RC RO | String 1023 characters | 7.x 8.x |
osinfo= | deviceCustom string3 Label osinfo indicates the OS against which the malware was detected. For example: osinfo=Microsoft WindowsXP Professional 5.1 base | NX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
targetApp= | targetApp targetApp represents the name of the target application running on the MVX during malware detection For example: targetApp=Firefox 4.0.0 | NX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
request= | request URL request represents the URL of the detected malware as detected by a Trellix appliance MVX For example: request=http://jrecsimpdegsa .ontheweb.nu/b/9/065a0b5a3 b65c1c6d5f5f8c883a9037237 a6a6a28803d4e7a6876a26e 2d00343request=ad.haoliulia ng.com/dm/diao.htm | NX AX FX EX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
anomaly= | anomaly anomaly represents attributes of OS changes made by the malware, data theft, or miscellaneous anomaly For example: anomaly=misc-anomaly, datatheft-anomaly | NX AX FX EX CM | WI MC IM DM MO RC RO | String 1023 characters | 7.x 8.x |
suser= | SMTPSender suser represents the user name of the sender of the malicious email detected by a Trellix appliance For example: suser=perfEmail @automation.local | EX CM | MO RO | String 1023 characters | 7.x 8.x |
duser= | SMTPrecipient duser represents the recipient of the malicious email detected by a Trellix appliance For example: duser=qa_test_1@y.com | EX CM | MO RO | String 1023 characters | 7.x 8.x |
msg= | SMTPID msg represents the SMTP email message ID of the infected email For example: msg=201210172324 25.6706.77689 .Email-48@trellix.com | EX CM | MO RO | String 1023 characters | 7.x 8.x |
devTimeFormat= | devTime Format devTimeFormat represents the format that devTime uses. For example: devTimeFormat=MMM dd yyyy HH:mm:ssz | NX AX FX EX CM | WI MC IM DM MO RC RI RO | String | 7.x 8.x |
url= | Riskware URL url represents the URL associated with the riskware. For example: url=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3-8a58-80c16e6f498c/12932238/config | NX CM | RC RI RO | String | 7.x 8.x |
proto-header= | Protocol header proto-header represents the details of the riskware communication. For example: proto-header=GET /ba4ca624c2e5d01cfcf537891ec5c HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host: 16.16.16.11::~~Connection: Keep-Alive::~~HTTP/1.1 200 OK::~~Date: Wed, 30 Sep 2015 16:02:39 GMT::~~Server: Apache/2.2.15 (CentOS)::~~Last-Modified: Tue, 29 Sep 2015 22:56:32 GMT::~~ETag: "1940779-ba988-520eab99e6191"::~~Accept-Ranges: bytes::~~Content-Length: 764296::~~Connection: close::~~Content-Type: text/plain; charset\=UTF-8::~~^ | NX CM | RC RO | String | 7.x 8.x |
cat= | cat represents the device event category. The originating device assigns the category. For example: cat=retro-detection | EX | MO | String 1023 characters | 7.x 8.x |
start= | Date when the event was originally analyzed by the appliance. For example: start=Nov 17 2016 10:30:38 UTC | EX | MO RO | Date in the following format: MMM dd yyyy HH:mm:ss UTC | 7.x 8.x |
subject= | subject represents the SMTP email message subject line on the infected email. For example: subject=ISO-2022-JP:_???????? | EX CM | MC WI IM DM MO IE RC RO | String 1023 characters | 7.x 8.x |
sha256sum= | sha256sum represents the sha256 value. For example: sha256sum=bb4f5c84c93528473539f9d8b8da4abaf08dbcaf64411a37c2f77594cc2f7ec1 | AX CM EX FX NX | MC WI IM DM MO IE RC RO | String 256 characters | 7.9 8.x |
uuid= | uuid represent unique identifier. For example: uuid=8f9abc99-4a53-43dd-82fb-eb487a54f6a5 | AX CM EX FX NX | MC WI IM DM MO IE RC RO | String 36 characters | 7.9 8.x |