LEEF extension field key=value pair definitions

Prev Next

Trellix uses the following parameters in its LEEF extension field key=value pairs. The header fields are separated using the pipe ('|') character, and the body fields are separated using the caret ('^') character.

LEEF:0|<vendor>|<product name>|<IP_Address>|<eventID>|<extension>

The following table provides definitions for each extension field key in a CEF message.

Note

The Z character at the end of a time stamp indicates that the time displayed is in the UTC time zone. Starting in the 7.0.0 release, the time is displayed in UTC by default. To change the displayed time to your local time, use the following CLI command: fenotify default timezone localtime

Ext.

Field Key

Description

Products

Event Type

Data Type

Release

sev=

Severity

The least important event is 1; the most important event is 10.

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

IE

RC

RI

RO

Integer

Valid numbers 1-10

7.5 and later

src=

Source Address

src represents the IP address of the infected host.

For example:

src=192.168.85.141

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

IPv4 or IPV6 Address

16 bytes

7.x

8.x

sname=

sname

sname represents the Trellix-assigned signature name.

For example:

sname=Bot.Mariposa.DNS

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

dstmac=

dstMac

dstmac represents the MAC address of the destination when any communication to an external host is observed within the MVX.

For example:

dstmac=00:50:56:e8:ba:21

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

MAC Address

Six colon-

separated

hexadecimal

numbers

7.x

8.x

proto=

Transport Protocol

proto represents the transport protocol detected by a Trellix appliance MVX

0 indicates no protocol detected

For example:

proto=udp

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

31 characters

7.x

8.x

dvchost=

device hostname

dvchost represents the hostname or the fully qualified domain name of the Trellix appliance performing the detection and sending the notification

For example:

dvchost=dave

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

100 characters

7.x

8.x

vlan=

vlan

vlan represents the vlan ID of the infected host.

For example:

vlan=0

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

String

100 characters

7.x

8.x

action=

action

When action=blocked, the alert has been blocked. When action=notified, the alert is not blocked.

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

IE

RC

RO

String

63 characters

7.5 and later

srcPort=

source port

srcPort represents the infected host’s source port as detected by a Trellix appliance MVX.

For example:

srcPort=1047

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

Integer

Valid Port Numbers 0~65535

7.x

8.x

dvc

device Address

dvc represents the device address of the detecting Trellix appliance MVX.

For example:

dvc=xxx.xxx.xxx.xxx

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

IPv4 address

16 bytes

7.x

8.x

cncHost=

Malicious C&C hostname

cnchost represents the hostname of the CnC server; however, if the appliance is unable to resolve the CnC server's hostname, this field will contain the IP address of the CnC server.

For example:

cncHost=hayboxiw.cn

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

externalId=

externalId

externalId represents the Trellix internal alert ID (which is external for ArcSight)

For example:

externalId=218799

externalId=96

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

Integer

7.x

8.x

devTime=

devTime

devTime represents the time the Trellix appliance MVX application emitted the malware event.

For example:

devTime=Oct 17 2012 23:13:20 Z

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

Time Stamp mmmddyyyy HH:mm:ss

or millisecs

since epoch

7.x

8.x

sid=

sid

sid represents the Trellix internal signature ID.

For example:

sigID=80442765

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

Integer

7.x

8.x

cncPort=

cncPort

cncPort represents the CnC listening server port

For example:

cncPort=53

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

Numeric

Integer Long

7.x

8.x

link=

link

link represents the local path or URL of the malware object (local to the detecting appliance:).

For example:

link=/analysis/17FFD13A0289-0-Email

-50_3174990d783f4a

1bd5e99db60176b920

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

String

1023 characters

7.x

8.x

srcMAC=

srcMAC

srcMAC represents the source MAC address of the infected host.

For example:

srcMAC=00:0c:29:76:bb:28

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

MAC Address

7.x

8.x

dst=

dstIPAddress

dst represents the IP address of the destination when any communication to an external host is observed within the MVX.

For example:

dst=128.12.38.6

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

IPv4 Address or IPv6 address

16 bytes

7.x

8.x

dstPort=

destinationPort

dstPort represents the port of the destination when any communication to an external host is observed within the MVX.

For example:

dstPort=20

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

Integer

7.x

8.x

cnc

Channel=

cncChannel

cncChannel= represents the CnC channel

For example:

cncChannel=GET

/message.php?subid\=148&version

\=_nn2&id\=XG0FZ7W00ZHZZHKZ

B0WY HTTP/1.1::~~Host: smartcontrol

.info::~~User-Agent: firefox.exe;Windows

NT 5.1::~~::~~

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

fileHash=

fileHash

fileHash represents the checksum of the malware object from a Trellix appliance MVX.

For example:

filehash=3174990d783f4a

1bd5e99db60176b920

EX

CM

MO

RC

RO

String

1023 characters

7.x

8.x

filePath=

filePath

filePath represents the local path and URL of the malware object (local to the detecting appliance).

For example:

filePath=/analysis/198.126.166

.186_80-196.107.232.238_1158

-455169465_14_T.pcoff

EX

CM

MO

RC

RO

String

1023 characters

7.x

8.x

osinfo=

deviceCustom string3 Label

osinfo indicates the OS against which the malware was detected.

For example:

osinfo=Microsoft WindowsXP Professional 5.1 base

NX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

targetApp=

targetApp

targetApp represents the name of the target application running on the MVX during malware detection

For example:

targetApp=Firefox 4.0.0

NX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

request=

request URL

request represents the URL of the detected malware as detected by a Trellix appliance MVX

For example:

request=http://jrecsimpdegsa

.ontheweb.nu/b/9/065a0b5a3

b65c1c6d5f5f8c883a9037237

a6a6a28803d4e7a6876a26e

2d00343request=ad.haoliulia

ng.com/dm/diao.htm

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

anomaly=

anomaly

anomaly represents attributes of OS changes made by the malware, data theft, or miscellaneous anomaly

For example:

anomaly=misc-anomaly, datatheft-anomaly

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RO

String

1023 characters

7.x

8.x

suser=

SMTPSender

suser represents the user name of the sender of the malicious email detected by a Trellix appliance

For example:

suser=perfEmail

@automation.local

EX

CM

MO

RO

String

1023 characters

7.x

8.x

duser=

SMTPrecipient

duser represents the recipient of the malicious email detected by a Trellix appliance

For example:

duser=qa_test_1@y.com

EX

CM

MO

RO

String

1023 characters

7.x

8.x

msg=

SMTPID

msg represents the SMTP email message ID of the infected email

For example:

msg=201210172324

25.6706.77689

.Email-48@trellix.com

EX

CM

MO

RO

String

1023 characters

7.x

8.x

devTimeFormat=

devTime Format

devTimeFormat represents the format that devTime uses.

For example:

devTimeFormat=MMM dd yyyy HH:mm:ssz

NX

AX

FX

EX

CM

WI

MC

IM

DM

MO

RC

RI

RO

String

7.x

8.x

url=

Riskware URL

url represents the URL associated with the riskware.

For example:

url=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3-8a58-80c16e6f498c/12932238/config

NX

CM

RC

RI

RO

String

7.x

8.x

proto-header=

Protocol header

proto-header represents the details of the riskware communication.

For example:

proto-header=GET /ba4ca624c2e5d01cfcf537891ec5c HTTP/1.0::~~User-Agent: Wget/1.12 (linux-gnu)::~~Accept: */*::~~Host: 16.16.16.11::~~Connection: Keep-Alive::~~HTTP/1.1 200 OK::~~Date: Wed, 30 Sep 2015 16:02:39 GMT::~~Server: Apache/2.2.15 (CentOS)::~~Last-Modified: Tue, 29 Sep 2015 22:56:32 GMT::~~ETag: "1940779-ba988-520eab99e6191"::~~Accept-Ranges: bytes::~~Content-Length: 764296::~~Connection: close::~~Content-Type: text/plain; charset\=UTF-8::~~^

NX

CM

RC

RO

String

7.x

8.x

cat=

cat represents the device event category.

The originating device assigns the category.

For example:

cat=retro-detection

EX

MO

String

1023 characters

7.x

8.x

start=

Date when the event was originally analyzed by the appliance.

For example:

start=Nov 17 2016 10:30:38 UTC

EX

MO

RO

Date in the following format: MMM dd yyyy HH:mm:ss UTC

7.x

8.x

subject=

subject represents the SMTP email message subject line on the infected email.

For example:

subject=ISO-2022-JP:_????????

EX

CM

MC

WI

IM

DM

MO

IE

RC

RO

String

1023 characters

7.x

8.x

sha256sum=

sha256sum represents the sha256 value.

For example:

sha256sum=bb4f5c84c93528473539f9d8b8da4abaf08dbcaf64411a37c2f77594cc2f7ec1

AX

CM

EX

FX

NX

MC

WI

IM

DM

MO

IE

RC

RO

String

256 characters

7.9

8.x

uuid=

uuid represent unique identifier.

For example:

uuid=8f9abc99-4a53-43dd-82fb-eb487a54f6a5

AX

CM

EX

FX

NX

MC

WI

IM

DM

MO

IE

RC

RO

String

36 characters

7.9

8.x