Sample CEF notifications are shown for various event types. The definitions for each of the <extension> field keys are provided in CEF Extension Field Key=Value Pair Definitions.
Note
The product names in CEF notifications are ‘MPS’ (for Network Security), ‘eMPS’ (for Email Security — Server Edition) ‘fMPS’ (for File Protect), ‘MAS’ (for Malware Analysis), 'HX' (for Endpoint Security) and ‘CMS’ (for Central Management).
riskware-callback (Network Security on Central Management)
CEF:0|Trellix|CMS|9.0.0.916210|RC|riskware-callback|1|rt=Jun 29 2020 07:49:43 UTC end=Jun 29 2020 07:49:43 UTC src=xx.x.x.xx dst=xxx.xx.xxx.x request=http://49939.northstar.api.socdn.com/installer/ad0d8641-dff0-11e3-8a58-80c16e6f498c/12932238/config cs1Label=sname cs1=Adware.MultiPlug act=notified dvc=xx.x.x.xx dvchost=abc.xyz.trellix.com smac=00:20:18:11:01:43 dmac=00:01:6c:a9:2f:27 spt=1072 dpt=80 cn1Label=vlan cn1=0 externalId=380 devicePayloadId=36e8bce0-1f70-44bf-ae14-90c7946422d7 msg=risk ware detected:29 proto=tcp cs4Label=link cs4=https://abc.xyz.trellix.com/detection/objects?uuid\=36e8bce0-1f70-44bf-ae14-90c7946422d7 cs6Label=channel cs6=GET /installer/ad0d8641-dff0-11e3-8a58-80c16e6f498c/12932238/config HTTP/1.1::~~Accept-Language: en-XX::~~User-Agent: DownloadMR/1.2.4+ (MSIE 8.0; Windows NT 5.1 SP3; DB\=ie; 9bf59659-7f5b-02eb-8c69-ce6a8ca6b231; m\=wXuH; u\=admin; aurora)::~~Host: 49939.northstar.api.socdn.com::~~Connection: Keep-Alive::~~::~~
riskware-infection (Network Security on Central Management)
CEF:0|Trellix|CMS|9.0.0.916210|RI|riskware-infection|1|rt=Jun 29 2020 08:07:58 UTC end=Jun 29 2020 08:07:58 UTC src=xx.xxx.xxx.xxx dst=xx.xx.xx.xx request=xxx.xx.x.x/~kjohnson/CVE-2014-8439/Exploit.html cs1Label=sname cs1=PUP.Generic.MVX act=notified dvc=xx.x.x.xx dvchost=abc.xyz.trellix.com smac=00:50:56:b4:67:9b dmac=a0:d3:c1:f1:4a:7d spt=50748 dpt=80 cn1Label=vlan cn1=0 externalId=24 devicePayloadId=8c6004a0-97ed-4e81-aa96-26ebf9baec61 msg=risk ware detected:32 cs3Label=osinfo cs3=Microsoft Windows7 32-bit 6.1 sp1 17.0112 cs4Label=link cs4=https://abc.xyz.trellix.com/detection/objects?uuid\=8c6004a0-97ed-4e81-aa96-26ebf9baec61
riskware-object (Network Security on Central Management)
CEF:0|Trellix|CMS|9.0.0.916210|RO|riskware-object|1|rt=Jun 29 2020 07:54:27 UTC start=Jun 29 2020 07:51:34 UTC end=Jun 29 2020 07:54:27 UTC src=xxx.xx.xx.x dst=xxx.xx.xx.xxx request=xxx.xx.xx.xxx/my_dir/dll_4b2155811cf0953d447df316472da01b093c55a7b3f2b9dc8d88c3e5a4484cd0 fname=dll_4b2155811cf0953d447df316472da01b093c55a7b3f2b9dc8d88c3e5a4484cd0 fileType=dll cs1Label=sname cs1=FE_Adware_Searchbar act=notified dvc=xx.x.x.xx dvchost=abc.xyz.trellix.com fileHash=30dbe64027e570ada595c1e7b89664db smac=00:50:56:c0:00:08 dmac=00:0c:29:b8:8e:a1 spt=37420 dpt=80 cn1Label=vlan cn1=0 requestMethod=GET externalId=83 devicePayloadId=2b48c503-bb98-4990-bb16-86f7a0268d6e msg=risk ware detected:31 cs3Label=osinfo cs3=Microsoft WindowsXP 32-bit 5.1 sp3 17.0112 cs4Label=link cs4=https://abc.xyz.trellix.com/detection/objects?uuid\=2b48c503-bb98-4990-bb16-86f7a0268d6e flexString1Label=sha256sum flexString1=4b2155811cf0953d447df316472da01b093c55a7b3f2b9dc8d88c3e5a4484cd0
riskware-callback (IPv4) (Network Security)
CEF:0|Trellix|MPS|9.0.2.925495|RC|riskware-callback|1|rt=Oct 22 2020 08:49:09 UTC start=Oct 22 2020 08:49:09 UTC end=Oct 22 2020 08:49:09 UTC src=xx.x.x.xx dst=xxx.xx.xxx.x request=http://stan.mxp533.com/__dmp__/ cs1Label=sname cs1=Adware.SoftPulse act=notified dvc=xx.x.x.xxx dvchost=abc.mrl.trellix.com smac=00:20:18:11:01:43 dmac=00:01:6c:a9:2f:27 spt=1076 dpt=80 cn1Label=vlan cn1=0 externalId=120 devicePayloadId=9684f196-ec61-4d08-9866-7f23db30c6db msg=risk ware detected:2 proto=tcp cs4Label=link cs4=https://abc.mrl.trellix.com/detection/objects?uuid\=9684f196-ec61-4d08- 9866-7f23db30c6db cs6Label=channel cs6=POST /__dmp__/ HTTP/1.1::~~User-Agent: dBrowser 1 CallGetResponse:1::~~Host: stan.mxp533.com::~~Content-Length: 237::~~Cache-Control: no-cache::~~::~~data\={"msg":"Connection failed","url":"","lno":0,"xtra":"","method":"function getResponseFromWrapper (url,post,callback,failcallback){window.external.getResponse (url,post,callback,failcallback)}","version":"1.5.7","av":"","fw":"","as":""} .
riskware-callback (IPv6) (Network Security)
CEF:0|Trellix|MPS|9.0.2.925495|RC|riskware-callback|1|rt=Oct 22 2020 09:15:57 UTC start=Oct 22 2020 09:15:57 UTC end=Oct 22 2020 09:15:57 UTC c6a2=2011::1:67e7:bf08 c6a2Label=Victim IP c6a3=2011::1:3c33:39f1 c6a3Label=Attacker IP request=http://savepop.co.kr/app/download/partner/2/savepop_agent.exe cs1Label=sname cs1=Adware.AppCare.Savepop act=notified dvc=xx.x.x.xxx dvchost=abc.mrl.trellix.com smac=00:20:18:11:01:43 dmac=00:01:6c:a9:2f:27 spt=1072 dpt=80 cn1Label=vlan cn1=0 externalId=771 devicePayloadId=0b623598-7795-4ca1-a1a1-9f2b02ae880b msg=risk ware detected:57 proto=tcp cs4Label=link cs4=https://abc.mrl.trellix.com/detection/objects?uuid\=0b623598-7795-4ca1-a1a1-9f2b02ae880b cs6Label=channel cs6=GET /app/download/partner/2/savepop_agent.exe HTTP/1.0::~~Host: savepop.co.kr::~~User-Agent: NSISDL/1.2 (Mozilla)::~~Accept: */*::~~::~~ .
riskware-infection (Network Security)
CEF:0|Trellix|MPS|9.0.2.924861|RI|riskware-infection|1|rt=Oct 16 2020 14:08:36 UTC start=Oct 16 2020 14:05:30 UTC end=Oct 16 2020 14:08:36 UTC src=xx.xxx.xxx.xxx dst=xx.xx.xx.xx request=xxx.xx.x.x/~kjohnson/CVE-2014-8439/Exploit.html cs1Label=sname cs1=PUP.Generic.MVX act=notified dvc=xx.x.x.xxx dvchost=abc.mrl.trellix.com smac=00:50:56:b4:67:9b dmac=a0:d3:c1:f1:4a:7d spt=50748 dpt=80 cn1Label=vlan cn1=0 externalId=4077 devicePayloadId=ed14f6a4-9796-4dec-9602-f6ce7cec871f msg=risk ware detected:5 cs3Label=osinfo cs3=Microsoft Windows7 32-bit 6.1 sp1 17.0114 cs4Label=link cs4=https://abc.mrl.trellix.com/detection/objects?uuid\=ed14f6a4-9796-4dec-9602-f6ce7cec871f .
riskware-object (IPv4) (Network Security)
CEF:0|Trellix|MPS|9.0.2.925495|RO|riskware-object|1|rt=Oct 22 2020 09:16:39 UTC start=Oct 22 2020 08:55:04 UTC end=Oct 22 2020 09:16:39 UTC src=xx.xx.xx.xx dst=xx.xx.xx.xx request=xx.xx.xx.xx/YaraAdware fname=YaraAdware fileType=exe cs1Label=sname cs1=FE_Adware_00fc8020ad243161 act=notified dvc=xx.x.x.xxx dvchost=abc.mrl.trellix.com fileHash=a5a4de61293d9dba3a46ec7e67f07c30 smac=10:60:4b:a9:b4:04 dmac=10:60:4b:a9:86:18 fsize=764296 spt=55059 dpt=80 cn1Label=vlan cn1=0 requestMethod=GET externalId=151 devicePayloadId=bdab4b33-6856-40ec-93be-1b4d7cd5968d msg=risk ware detected:66 cs4Label=link cs4=https://abc.mrl.trellix.com/detection/objects?uuid\=bdab4b33-6856-40ec-93be-1b4d7cd5968d flexString1Label=sha256sum flexString1=25b8e3cc4774975876c36de3a6e5a34bb7a48857e4f02c36416aed7631d03094 .
riskware-object (IPv6) (Network Security)
CEF:0|Trellix|MPS|9.0.2.925495|RO|riskware-object|1|rt=Oct 22 2020 09:43:47 UTC start=Oct 22 2020 09:15:57 UTC end=Oct 22 2020 09:43:47 UTC c6a2=2011::1:4d84:9b6e c6a2Label=Victim IP c6a3=2011::1:13f5:7d67 c6a3Label=Attacker IP request=xx.x.x.xx/30dbe64027e570ada595c1e7b89664db.zip fname=30dbe64027e570ada595c1e7b89664db.zip fileType=zip cs1Label=sname cs1=FE_Adware_Searchbar act=notified dvc=xx.x.x.xxx dvchost=abc.mrl.trellix.com fileHash=904478b16474f63737389b8244a66dca smac=d8:9d:67:17:19:71 dmac=d8:9d:67:17:24:75 fsize=17347 spt=50998 dpt=80 cn1Label=vlan cn1=0 requestMethod=GET externalId=224 devicePayloadId=68119bb0-bf35-4124-9af3-13c27c7ebdaa msg=risk ware detected:116 cs4Label=link cs4=https://abc.mrl.trellix.com/detection/objects?uuid\=68119bb0-bf35-4124-9af3-13c27c7ebdaa flexString1Label=sha256sum flexString1=ea74197e0337a03dd6c2565d37d37dec2e0595747b99db3f4094a686f06ef390 .
SmartVision (Network Security)
CEF:0|Trellix|MPS|9.0.0.916432|WA|smartvision-event|5|rt=Jun 26 2020 12:42:06 UTC externalId=1 act=notified cn2Lablel=signatureId cn2=91500000 cfp1Label=signatureRevision cfp1=5 devicePayloadId=20281250-7c27-4cce-a410-2f04e1002c6e cnt=5 cs1=Suspicious Remote Scheduled Task Activity cs1Label=name cat=T1053 / Remote Execution msg=Suspicious Remote Scheduled Task Activity src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 cs4=https://abc.mrl.trellix.com/notification_url?uuid\=20281250-7c27-4cce-a410-2f04e1002c6e cs4Lablel=link CEF:0|Trellix|MPS|9.0.0.916432|SE|smartvision-base-event|0 rt=Jun 26 2020 12:42:07 UTC externalId=1 cs1Label=name cs1=SMB Create Request: Delete file in Windows temp direcory proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xxx sev=1 msg=SMB Create Request: Delete file in Windows temp direcory with id:1 detected CEF:0|Trellix|MPS|9.0.0.916432|SE|smartvision-base-event|0 rt=Jun 26 2020 12:42:06 UTC externalId=2 cs1Label=name cs1=SMB Create Request: File in Windows temp direcory proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xxx sev=1 msg=SMB Create Request: File in Windows temp direcory with id:2 detected CEF:0|Trellix|MPS|9.0.0.916432|SE|smartvision-base-event|0 rt=Jun 26 2020 12:42:07 UTC externalId=3 cs1Label=name cs1=ATSVC Start Job proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xxx sev=1 msg=ATSVC Start Job with id:3 detected CEF:0|Trellix|MPS|9.0.0.916432|SE|smartvision-base-event|0 rt=Jun 26 2020 12:42:07 UTC externalId=4 cs1Label=name cs1=ATSVC Delete Job proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xxx sev=1 msg=ATSVC Delete Job with id:4 detected CEF:0|Trellix|MPS|9.0.0.916432|SE|smartvision-base-event|0 rt=Jun 26 2020 12:42:06 UTC externalId=5 cs1Label=name cs1=ATSVC Add Job: cmd.exe /C with redirect proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xxx sev=1 msg=ATSVC Add Job: cmd.exe /C with redirect with id:5 detected
SmartVision (Network Security on Central Management)
CEF:0|Trellix|CMS|9.0.0.916210|SE|smartvision-base-event|0 rt=Jun 29 2020 08:13:34 UTC externalId=12 cs1Label=name cs1=ATSVC Add Job: cmd.exe /C with redirect proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xx sev=1 msg=ATSVC Add Job: cmd.exe /C with redirect with id:12 detected . CEF:0|Trellix|CMS|9.0.0.916210|SE|smartvision-base-event|0 rt=Jun 29 2020 08:13:35 UTC externalId=14 cs1Label=name cs1=ATSVC Start Job proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xx sev=1 msg=ATSVC Start Job with id:14 detected . CEF:0|Trellix|CMS|9.0.0.916210|SE|smartvision-base-event|0 rt=Jun 29 2020 08:13:35 UTC externalId=11 cs1Label=name cs1=SMB Create Request: Delete file in Windows temp direcory proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xx sev=1 msg=SMB Create Request: Delete file in Windows temp direcory with id:11 detected . CEF:0|Trellix|CMS|9.0.0.916210|SE|smartvision-base-event|0 rt=Jun 29 2020 08:13:34 UTC externalId=13 cs1Label=name cs1=SMB Create Request: File in Windows temp direcory proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xx sev=1 msg=SMB Create Request: File in Windows temp direcory with id:13 detected . CEF:0|Trellix|CMS|9.0.0.916210|SE|smartvision-base-event|0 rt=Jun 29 2020 08:13:35 UTC externalId=15 cs1Label=name cs1=ATSVC Delete Job proto=tcp src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 dvchost=abc.mrl.trellix.com dvc=xx.x.x.xx sev=1 msg=ATSVC Delete Job with id:15 detected . CEF:0|Trellix|CMS|9.0.0.916210|WA|smartvision-event|5|rt=Jun 29 2020 08:13:34 UTC externalId=7 act=notified cn2Lablel=signatureId cn2=91500000 cfp1Label=signatureRevision cfp1=5 devicePayloadId=5985dbd8-5066-4e04-b560-3f05c93506d6 cnt=5 cs1=Suspicious Remote Scheduled Task Activity cs1Label=name cat=T1053 / Remote Execution msg=Suspicious Remote Scheduled Task Activity src=xxx.xxx.x.x dst=xxx.xxx.x.x spt=43520 dpt=445 cs4=https://abc.mrl.trellix.com/notification_url?uuid\=5985dbd8-5066-4e04-b560-3f05c93506d6 cs4Lablel=link .
riskware-object (Email Security)
CEF:0|Trellix|eMPS|9.0.2.925255|RO|riskware-object|1|rt=Oct 22 2020 10:09:29 UTC start=Oct 22 2020 10:07:11 UTC end=Oct 22 2020 10:09:29 UTC fname=BottCom_riskware1.exe fileType=exe cs1Label=sname cs1=Adware.FileTour act=blocked dvc=10.5.6.115 dvchost=abc-123.mrl.trellix.com fileHash=23780117a00b9b3526c3a0a3ea7c590f fsize=1887256 cn1Label=vlan cn1=0 externalId=29 devicePayloadId=8c145d59-3b5e-4bab-b628-f88476ba092c msg=risk ware detected:2 cs3Label=osinfo cs3=Microsoft WindowsXP 32-bit 5.1 sp3 17.0114 cs4Label=link cs4=https://abc-123.mrl.trellix.com/detection/objects?uuid\=8c145d59-3b5e-4bab-b628-f88476ba092c cs6Label=channel cs6=GET /php/track1.php HTTP/1.0::~~Host: soft.freemusicdownloads.world::~~User-Agent: InnoTools_Downloader::~~::~~ flexString1Label=sha256sum flexString1=c78be5b7b2bcb2c69ae2c1d161a2f89710638f852ddabbce0f8f675272d559e4 suser=sample@tesoro.com duser=samples@tesoro.com sourceDnsDomain=tesoro.com applicationProtocol=smtp .
Policy Changed (Endpoint Security)
CEF:0|Trellix|HX|4.8.0|Trellix Policy Changed|Trellix Policy Changed|0|rt=Jul 10 2019 15:34:19 UTC dvchost=trellix-01e410 deviceExternalId=8665C7336BD2 categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic Investigation categoryObject=/Host act=Policy update msg=Policy 1271c380-1d1f-4f14-8773-e5d5700e8e53 update by admin cs1="{"insert":{"agentLogging|log_level":"\\"NOTICE\\""},"delete":{"agentLogging|log_level":"\\"INFO\\""}}" cs1Label=Change Details outcome=Success reason=update start=Jul 10 2019 15:34:19 UTC categoryTupleDescription=A Policy change succeeded. categoryOutcome=/Success categorySignificance=/Informational categoryBehavior=/update
Malware Hit Found (Endpoint Security)
CEF:0|trellix|hx|9.9.0|Malware Hit Found|Malware Hit Found|10|rt=Feb 05 2019 17:00:36 UTC dvchost=trellix-01cb28 categoryDeviceGroup=/IDS categoryDeviceType=Malware Protection categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=HawW2jJc9O6bDMZDqxo30s dst=10.61.155.119 dmac=00-50-56-01-cb-23 dhost=WIN2feff6846b7d dntdom=WORKGROUP deviceCustomDate1Label=Agent Last Audit deviceCustomDate1=Feb 05 2019 16:55:51 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS cs6=Windows 7 Enterprise 7601 Service Pack 1 externalId=1 start=Feb 05 2019 17:00:35 UTC categoryOutcome=/Success categorySignificance=/Compromise categoryBehavior=/Found cs7Label=Resolution cs7=QUARANTINED cs8Label=Alert Types cs8=malware cs12Label=Malware Category cs12=file-event act=Detection MAL Hit msg=Host WIN2feff6846b7d Malware alert categoryTupleDescription=Malware Protection found a compromise indication. cs4Label=Process Name cs4=C:\\Python27\\python.exe cs9Label=MD5 cs9=06f391ea3f127ffc3bba3d56f374077f cs10Label=SHA1 cs10=2a85b25f583127a3903bbcd1c7187bcdb58b5c5b cs11Label=Malware Signature cs11=Generic.mg.06f391ea3f127ffc categoryTechnique=Malware cs13Label=Malware Engine cs13=MG
ExD Hit Found (Endpoint Security)
CEF:0|trellix|hx|9.9.0|ExD Hit Found|ExD Hit Found|10|rt=Feb 05 2019 17:01:56 UTC dvchost=trellix-01cb28 categoryDeviceGroup=/IDS categoryDeviceType=Exploit Detection categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=uP1q4KNadwaber6XLK6BZU dst=10.61.154.186 dmac=00-50-56-01-cb-25 dhost=WIN11b1f2d1fea1 dntdom=WORKGROUP deviceCustomDate1Label=Agent Last Audit deviceCustomDate1=Feb 05 2019 17:01:52 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS cs6=Windows 10 Enterprise 17763 externalId=2 start=Feb 05 2019 17:00:22 UTC categoryOutcome=/Success categorySignificance=/Compromise categoryBehavior=/Found cs7Label=Resolution cs7=BLOCK cs8Label=Alert Types cs8=xplt,blk act=Detection ExD Hit msg=Host WIN11b1f2d1fea1 ExD compromise alert categoryTupleDescription=ExD found a compromise indication. cs4Label=Process Name cs4=chrome.exe categoryTechnique=Exploit
Acquisition Queued (Endpoint Security)
CEF:0|trellix|hx|9.9.0|Trellix Acquisition Queued|Trellix Acquisition Queued|0|rt=Feb 05 2019 17:01:58 UTC dvchost=trellix-01cb28 categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic Investigation categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=uP1q4KNadwaber6XLK6BZU dst=10.61.154.186 dmac=00-50-56-01-cb-25 dhost=WIN11b1f2d1fea1 dntdom=WORKGROUP deviceCustomDate1Label=Agent Last Audit deviceCustomDate1=Feb 05 2019 17:01:52 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS cs6=Windows 10 Enterprise 17763 externalId=1 cs3Label=Script Name cs3=Timestamped Triage deviceCustomDate2Label=Triage Request Timestamp deviceCustomDate2=Feb 05 2019 17:00:22 UTC suser=automatic categoryOutcome=/Success categorySignificance=/Informational categoryBehavior=/Create act=Acquisition Create msg=Host WIN11b1f2d1fea1 Timestamped Triage queued by automatic categoryTupleDescription=A Host Acquisition was successfully queued.
Acquisition Started (Endpoint Security)
CEF:0|trellix|hx|9.9.0|Trellix Acquisition Started||Trellix Acquisition Started|0|rt=Feb 05 2019 17:02:11 UTC dvchost=trellix-01cb28 categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic Investigation categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=uP1q4KNadwaber6XLK6BZU dst=10.61.154.186 dmac=00-50-56-01-cb-25 dhost=WIN11b1f2d1fea1 dntdom=WORKGROUP deviceCustomDate1Label=Agent Last Audit deviceCustomDate1=Feb 05 2019 17:01:52 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS cs6=Windows 10 Enterprise 17763 externalId=1 cs3Label=Script Name cs3=Timestamped Triage deviceCustomDate2Label=Triage Request Timestamp deviceCustomDate2=Feb 05 2019 17:00:22 UTC categoryOutcome=/Success categorySignificance=/Informational categoryBehavior=/Create act=Acquisition Status msg=Host WIN11b1f2d1fea1 Timestamped Triage started categoryTupleDescription=A Host Acquisition was successfully started.
Containment Requested (Endpoint Security)
CEF:0|trellix|hx|9.9.0|Trellix Containment Requested|Trellix Containment Requested|4|rt=Feb 05 2019 17:07:28 UTC dvchost=trellix-01cb28 categoryDeviceGroup=/IDS/Application/Service categoryDeviceType=Forensic Investigation categoryObject=/Host cs1Label=Host Agent Cert Hash cs1=HawW2jJc9O6bDMZDqxo30s dst=10.61.155.119 dmac=00-50-56-01-cb-23 dhost=WIN2feff6846b7d dntdom=WORKGROUP deviceCustomDate1Label=Agent Last Audit deviceCustomDate1=Feb 05 2019 17:02:45 UTC cs2Label=Trellix Agent Version cs2=29.7.0 cs5Label=Target GMT Offset cs5=PT0H cs6Label=Target OS cs6=Windows 7 Enterprise 7601 Service Pack 1 suser=admin categoryOutcome=/Success categorySignificance=/Informational categoryBehavior=/Create act=Containment Requested msg=Host WIN2feff6846b7d containment requested by admin categoryTupleDescription=Containment was requested for a host. request=https://trellix-01cb28:3000/hx/hosts/HawW2jJc9O6bDMZDqxo30s
AT Alert (Email Security — Cloud Edition)
Note
Every AT alert generates a separate CEF notification.
CEF:0|Trellix|ETP|3.0|etp|malicious email|10|rt=Nov 07 2016 23:27:17 UTC suser=yser@abc.com duser=usera@xyz.pqr.com fname=test.zip fileHash=ca9424e92816332d8bb60a45e4ec29e9 destinationDnsDomain=xyz.pqr.com externalId=9999999 cs1Label=sname cs1=Malware.archive cs3Label=Subject cs3=Arc Sight Test CEF cs4Label=Link cs4=https://etp.trellixcloud.com/alert/9999999/ cs5Label=Client cs5=AAAA
ACE Alert (Email Security — Cloud Edition)
Note
Every ACE alert generates a separate CEF notification.
CEF:0|Trellix|ETP|3.0|etp|ace alert|10|rt=Nov 07 2016 23:27:17 UTC suser=yser@abc.com duser=usera@xyz.pqr.com fname=test.zip fileHash=5b61d32c94ca81d4f28241ca29aca9b9 destinationDnsDomain=xyz.pqr.com externalId=9999999 cs1Label=sname cs1=Malware.archive cs3Label=Subject cs3=Arc Sight Test CEF cs4Label=Link cs4=https://etp.trellixcloud.com/alert/9999999/ cs5Label=Client cs5=AAAA cs6Label=ATI Name Type Level cs6=Exploit.DTI.CVE-2008-2992\|Exploit\|Medium flexString1Label=ATI Threat Attribution flexString1=While many well-known exploit kits used to weaponize the CVE-2008-2992 exploit, the popularity of this exploit has drastically dropped overtime due to Adobe Reader’s sandbox mechanism. No APT actors have been found to actively leverage this exploit in current cyber operations. Metasploit, however, still has a module targeting CVE-2008-2992 vulnerability. As this exploit is old, the latest versions of Adobe application are already patched against this attack. It is strongly advised to update Adobe Acrobat and Reader to versions 8.1.2 and above as soon as possible.