Sample CSV notifications per event type

Prev Next

Sample CSV notifications are shown for various event types. The definitions for each of the <extension> field keys are provided in CSV extension field key=value pair definitions.

Note

The product names in CSV notifications are ‘MPS’ (for Network Security), ‘eMPS’ (for Email Security — Server Edition) ‘fMPS’ (for File Protect), ‘MAS’ (for Malware Analysis), 'HX' (for Endpoint Security) and ‘CMS’ (for Central Management).

domain-match (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:DM:domain-match,osinfo=,sev=minr,malware_
type=,alertid=85,app=,spt=1070,locations=,smac=6a:c0:02:9a:9b:7d,header=,cnchost=fgetcareer.
com,alertType=domain-match,shost=,dst=,original_name=,application=,sid=80461038,malwarenote=,
sha256=,objurl=,mwurl=,profile=,dmac=00:50:56:e5:3f:c5,product=Web
MPS,sname=Trojan.Ramnit.SNK.DNS,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:36:16Z,release=9.0.2.924861,dpt=,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id=85,cncport=53,src=xxx.xxx.xxx.xxx,sha1=,sha512=,dvc=10.5.6.126,channel=,anomaly=,action=notified,os=,stype=b
lacklist, .

domain-match (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:DM:domain-match,osinfo=,sev=minr,malware_
type=,alertid=70200,app=,spt=1062,locations=,smac=d6:96:0a:84:24:15,header=,cnchost=fgetcareer.
com,alertType=domain-match,shost=,dst=,original_name=,application=,sid=80461038,malwarenote=,
objurl=,mwurl=,profile=,dmac=00:50:56:e5:3f:c5,product=MPS,sname=Trojan.Ramnit.SNK.DNS,fileHash=,dvchost=
xxxx,occurred=2020-06-28T09:47:43Z,release=wMPS (wMPS) 9.0.0.916432,link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_
id=70200,cncport=53,src=xxx.xxx.xxx.xxx,dpt=,anomaly=,dvc=xx.x.x.xxx,channel=,action=notified,os=,stype=blackli
st,

infection-match (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:IM:infection-match,osinfo=,sev=minr,malware_
type=,alertid=84,app=,spt=1058,locations=,smac=6a:c0:02:9a:9b:7d,header=,cnchost=xxx.xxx.xxx.xxx,alertType=infe
ction-match,shost=,dst=xxx.xxx.xxx.xxx,original_name=,application=,sid=84400123,malwarenote=,
sha256=,objurl=,mwurl=,profile=,dmac=00:50:56:e5:3f:c5,product=Web
MPS,sname=Worm.Ramnit,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:36:12Z,release=9.0.2.924861,dpt=80,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id=84,cncport=80,src=xxx.xxx.xxx.xxx,sha1=,sha512=,dvc=xx.x.x.xxx,channel=GET http://yy8311.com/?/goods_
list/14_25_0 HTTP/1.1::~~Host: yy8311.com::~~../..7^{xd_.4=.k....]..}xFs...`k..z{.\y.[..O..d.G....p7y.{g
xa%k._.....M?~..}.ox..cx\{|Z._h~x8?t|m_O.d0\.GA.._{O=...Q}G/UG.+;..po\G/v^..p..u..p..np;]=|....={~/yN..V|x|.[_
\S/]c^.]/|ic}[........6 7Z_`c8.]{r=;_....u7.=.~.o.5W62>4w_s>X)c..Q>z.k^%O?EO].)..-a4.q8C.[WO{gwx*;?~?{{?][p^{gg
{~_y.....|...}...o.ka..k./iz.....<gk?.?q...W::....UnI....D.1..L3.1fxL~~y4 m.o..::....[W.}{_}+w...._
yk9~].....<.N?.8..8^...}]:96h.~.."4..._~U.y/?.v<6X{..l...?c......QW?+<zzyn?>.x,O=...>7?.'>xy_y{t.?>.}W>%KY-
<.G|.....iiU...... 94pnPZgs[y..N!=.b9.=47%u^.g+G(k..RGe>e?CNGc\B2O2mmgO};..e.[^s
(.jbM.OZV,anomaly=,action=notified,os=,stype=bot-command, .

infection-match (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:IM:infection-match,osinfo=,sev=minr,malware_
type=,alertid=70184,app=,spt=1165,locations=US/TN/Johnson
City,smac=92:73:75:00:00:35,header=,cnchost=xxx.xxx.xxx.xx,alertType=infection-match,shost=xxx-xxx-xxxxxx.
rev.home.ne.jp,dst=xxx.xxx.xxx.xx,original_name=,application=,sid=600144,malwarenote=,
objurl=,mwurl=,profile=,dmac=00:19:d1:fd:a2:52,product=MPS,sname=Local.Infection,fileHash=,dvchost=xxxx,o
ccurred=2020-06-28T09:02:20Z,release=wMPS (wMPS) 9.0.0.916432,link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_id=70184,cncport=80,src=xxx.xxx.xxx.xxx,dpt=80,anomaly=,dvc=xx.x.x.xxx,channel=GET
/014.exe HTTP/1.1::~~Accept: */*::~~Accept-Encoding: gzip, deflate::~~User-Agent: Mozilla/4.0 (compatible; MSIE
6.0; Windows NT 5.1; SV1)::~~Host: exe.xinniankl.com::~~Connection: Keep-
Alive::~~::~~,action=notified,os=,stype=bot-command,

malware-callback (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:MC:malware-callback,osinfo=,sev=crit,malware_
type=,alertid=88,app=,spt=49193,locations=HK/Kwun
Tong,smac=00:0c:29:75:37:4a,header=,cnchost=xx.xxx.xxx.xxx,alertType=malwarecallback,
shost=,dst=xx.xxx.xxx.xxx,original_name=,application=,sid=86112670,malwarenote=,
sha256=,objurl=,mwurl=,profile=,dmac=00:50:56:fe:a1:97,product=Web
MPS,sname=Trojan.Gootkit,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:36:29Z,release=9.0.2.924861,dpt=443,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ev_
id=88,cncport=443,src=xx.xxx.xxx.xxx,sha1=,sha512=,dvc=xx.x.x.xxx,channel=...,anomaly=,action=notified,os=,styp
e=bot-command, .

malware-callback (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:MC:malware-callback,osinfo=,sev=crit,malware_
type=,alertid=70252,app=,spt=55689,locations=,smac=00:0c:29:ec:df:a4,header=,cnchost=xxx.xx.x.xx,alertType=malw
are-callback,shost=,dst=xxx.xx.x.xx,original_name=,application=,sid=33351211,malwarenote=,
objurl=,mwurl=,profile=,dmac=00:50:56:be:42:a6,product=MPS,sname=Trojan.APT.PingBed,fileHash=,dvchost=xxx
x,occurred=2020-06-29T07:00:34Z,release=wMPS (wMPS) 9.0.0.916248,link=https://abc.mrl.trellix.com/event_
stream/events_for_bot?ev_id=70252,cncport=8080,src=xxx.xx.x.xx,dpt=8080,anomaly=,dvc=xx.x.x.xxx,channel=GET
http://colville.com/Gallery/Winterfest/2.jpg HTTP/1.1::~~User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows
NT 5.1; Trident/4.0; #1atEW5tuNDl0kt579c9.BMWUS)::~~Host: Colville.com::~~Pragma: nocache::~~::~~,
action=notified,os=,stype=bot-command

malware-object (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:MO:malware-object,osinfo=Microsoft Windows7 64-bit x.x sp1 17.0114;Microsoft
WindowsXP 32-bit 5.1 sp3 17.0114,sev=majr,malware_
type=exe,alertid=32,app=,spt=3926,locations=,smac=00:50:8b:08:b8:f6,header=GET /images/miscexes/
0d043e3acbc3af58970d3365b6f91d29.exe HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Referer: http://xxx.xxx.x.xxx/images/misc-exes/ Accept-Language: en-us Accept-Encoding: gzip, deflate User-
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; (R1 1.3); InfoPath.2) Host: xxx.xxx.x.xxx
Connection: Keep-Alive HTTP/1.1 200 OK Date: Thu, 27 Nov 2008 07:35:32 GMT Server: Apache/2.2.3 (Fedora) Last-
Modified: Fri, 09 May 2008 10:21:38 GMT ETag: "4f83f6-15cc2-902f5080" Accept-Ranges: bytes Content-Length:
89282 Connection: close Content-Type: application/octet-stream,cnchost=wa3d.no-ip.biz,alertType=malwareobject,
shost=,dst=xxx.xxx.x.xxx,original_name=0d043e3acbc3af58970d3365b6f91d29.exe,application=Windows
Explorer,sid=,malwarenote=,
sha256=9a8724dfb4ae1f044a28be30ff3885b7558d1ae00664308ecb11f7164a7a3ddf,objurl=,mwurl=192.168.2.171/image
s/misc-exes/0d043e3acbc3af58970d3365b6f91d29.exe,profile=winxp-sp3,dmac=00:02:b3:a1:87:14,product=Web
MPS,sname=Win.Trojan.Bifrose-194;fe_ml_heuristic;Malware.Binary.exe,fileHash=0d043e3acbc3af58970d

malware-object (Network Security on Central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:MO:malware-object,osinfo=,sev=majr,malware_
type=exe,alertid=23049,app=,spt=1165,locations=,smac=92:73:75:00:00:35,header=GET /014.exe HTTP/1.1 Accept: */*
Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) Host:
exe.xinniankl.com Connection: Keep-Alive HTTP/1.0 200 OK Content-Length: 23717 Content-Type: application/octet-
stream Last-Modified: Mon, 25 Feb 2008 15:47:02 GMT Accept-Ranges: bytes ETag: "e0e6f3a9c577c81:470" Server:
Microsoft-IIS/6.0 Date: Sun, 23 Mar 2008 03:27:10 GMT Age: 44649 X-Cache: HIT from gateway.palmchip.com XCache-
Lookup: HIT from gateway.palmchip.com:3128 Via: 1.0 gateway.palmchip.com:3128 (squid/2.6.STABLE16)
Connection: keep-alive,cnchost=,alertType=malware-object,shost=119-168-188-
108.rev.home.ne.jp,dst=xxx.xxx.xxx.xx,original_name=014.exe,application=,sid=,malwarenote=,
objurl=,mwurl=exe.xinniankl.com/014.exe,profile=,dmac=00:19:d1:fd:a2:52,product=MPS,sname=Heuristic.Backd
oor.20,fileHash=bfaf373042d10517fdc0fe713bbeb093,dvchost=xxxx,occurred=2020-06-28T08:54:56Z,release=wMPS (wMPS)
9.0.0.916432,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?ma_
id=23049,cncport=,src=xxx.xxx.xxx.xxx,dpt=80,anomaly=,dvc=xx.x.x.xxx,channel=,action=notified,os=,stype=knownmd5sum,

malware-object (File Protect)

CSV:0:Trellix:File MPS:9.0.0.916210:MO:malware-object,osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0112;Microsoft Windows7 64-bit 6.1 sp1 17.0112,sev=majr,malware_
type=exe,alertid=92,locations=,header=,cnchost=xx.xx.xx.xx,alertType=malware-object,repository=liveurl,
original_name=/data/ma/notify/Malware_Sample135,application=Windows Explorer,run_end=2020-06-
26T17:06:53Z,sid=86107514;86115447;89080514;86117644,malware-note=,anomaly=98304,mwurl=/data/ma/notify/Malware_
Sample135,profile=win7x64-sp1,parent_maid=,product=File MPS,sname=fe_ml_
heuristic;Trojan.Sality,fileHash=434da9ab51c3f9e70b7611bd70cc9e52,dvchost=xx-xxxxx.
eng.trellix.com,occurred=2020-06-26T17:02:43Z,link=https://xx.xxx.xx.xxx/fmps/fanalysis?ma_id=92&lms_
iden=0CC47AA8FFA6,cncport=7455,url_domain=,download_end=2020-06-
26T17:06:52Z,dvc=xx.xxx.xx.xxx,username=,channel=,release=9.0.0.916210,malware_scan_id=1,stype=malwareguard;
vm-bot-command

malware-object (Malware Analysis)

CSV:0:Trellix:MAS:9.0.0.916210:MO:malware-object,osinfo=Microsoft Windows10 64-bit 10.0 base
17.0112,sev=majr,malware_type=doc,al ertid=15741,locations=,header=,cnchost=,alertType=malware-object,original_
name=/data/ma/share/source_mas/4fdd859854b5d4b54a2effe6608aeb7e,application=MS Word 2013 SP1,run_end=2020-06-
23T07:38:00Z,si d=111,malware-note=,anomaly=512,mwurl=/data/ma/share/source_
mas/4fdd859854b5d4b54a2effe6608aeb7e,profile=win10x64,parent_maid=,product=MAS,sname=Doc.Trojan.Xaler-1;FE_
Macro_keimeno_Doc,fileHash=4fdd 859854b5d4b54a2effe6608aeb7e,dvchost=xx-xxx-xx.eng.trellix.com,occurred=2020-
06-22T17:07:27Z,link=https://xx-xxx-xx.eng.trellix.com/malware_analysis/analyses?maid=15741,cncport=,url_
domain=,download _end=2020-06-
23T07:37:59Z,dvc=xxx.xx.xxx.xx,username=unattended,channel=,release=9.0.0.916210,stype=av-match;yara,

malware-object (Email Security)

CSV:0:Trellix:Email MPS:9.0.2.925255:MO:malware-object,osinfo=Microsoft Windows7 64-bit 6.1 sp1
17.0114,sev=majr,malware_
type=exe,alertid=20,locations=,header=,cnchost=xezlifewvupazah.ws,protocol=,subject=mal sample ::
original,alertType=malware-object,date=Thu, 22 Oct 2020 12:30:16 +0500,smtp-to=samples@tesoro.com,original_
name=......... ............... ............... ............ .........,application=Windows Explorer,run_
end=2020-10-22T07:33:36Z,last-malware=Trojan.Expiro,sid=33351836;86105968,malwarenote=,
sha256=83920de959a29be45ff40a3f513f7ec94ad21433e009a3f9e36dea44a8d42b45,sha512=601a9acb9417210612be55d282
e6eb672a5a6d66890f7decb432184e655248a5236d96a89f34e23ede57cd5864e040e2b2a0d88cff62375ccc95ea5822440047,mwurl
=......... ............... ............... ............ .........,profile=win7x64-sp1m,product=Email
MPS,sname=fe_ml_heuristic;Trojan.Expiro,fileHash=ebe52c916b26694796abef44b154e58e,dvchost=abc-
123.mrl.trellix.com,occurred=2020-10-22T07:30:24Z,smtp-mail-from=sample@tesoro.com,smtp-cc=,link=https://abc-
123.mrl.trellix.com/emps/eanalysis?e_id=12&type=attch,cncport=80,url_
domain=,sha1=be89a185d43bd7e003b33d46e59d1671c323427c,anomaly=99329,download_end=2020-10-
22T07:33:35Z,dvc=10.5.6.115,username=,channel=POST xezlifewvupazah.ws HTTP/1.1::~~User-Agent: Mozilla/4.0
(compatible; msie 40; NT6.1.7601-7C783FD6.ENU.00371-222-1977552-33559_1B41C8; .NET CLR
00000000/00000000)::~~::~~, E.......@...

web-infection (Network Security)

CSV:0:Trellix:Web MPS:9.0.2.924861:WI:web-infection,osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0114,sev=majr,malware_type=,alertid=4079,app=InternetExplorer
8.0,spt=1058,locations=,smac=6a:c0:02:9a:9b:7d,header=,cnchost=fget-career.com,alertType=webinfection,
shost=,dst=xxx.xxx.xxx.xxx,original_name=,application=,sid=86115851,malwarenote=,
sha256=,objurl=yy8311.com/?/goods_list/14_25_0,mwurl=,profile=winxp-sp3,dmac=,product=Web
MPS,sname=HTML.Infector.Ramnit;Trojan.Ramnit,fileHash=,dvchost=abc.mrl.trellix.com,occurred=2020-10-
16T14:41:43Z,release=9.0.2.924861,dpt=80,link=https://abc.mrl.trellix.com/event_stream/events_for_bot?inc_
id=4079,cncport=443,src=xxx.xxx.xxx.xxx,sha1=,sha512=,dvc=xx.x.x.xxx,channel=\000\377\001\000\000\000,anomaly=9
8305,action=notified,os=Microsoft WindowsXP 32-bit 5.1 sp3 17.0114,stype=trellix-content;vm-bot-command, .

web-infection (Network Security on central Management)

CSV:0:Trellix:xxxx:9.0.0.916210:WI:web-infection,osinfo=Microsoft WindowsXP 32-bit 5.1 sp3
17.0113,sev=majr,malware_type=,alertid=151,app=InternetExplorer
8.0,spt=1057,locations=,smac=d6:96:0a:84:24:15,header=,cnchost=xisock.com,alertType=web-infection,shost=xx-xxxxx-
xx.dyn.actaccess.net,dst=xx.xx.xxx.xxx,original_name=,application=,sid=86115851;86114877;86114876,malwarenote=,
objurl=yipinlawyer.com/,mwurl=,profile=winxp-
sp3m,dmac=,product=MPS,sname=Exploit.Browser;Trojan.Virut.DNS;Trojan.Ramnit,fileHash=,dvchost=xxxx,occurred=202
0-06-29T05:47:41Z,release=wMPS (wMPS) 9.0.0.916248,link=https://abc.mrl.trellix.com/event_stream/events_for_
bot?inc_
id=151,cncport=443,src=xx.xxx.xx.xx,dpt=80,anomaly=,dvc=xx.x.x.xxx,channel=,action=notified,os=Microsoft
WindowsXP 32-bit 5.1 sp3 17.0113,stype=vm-bot-command,

ips-event (Network Security)

CSV:0:Trellix:Web MPS:9.0.0.916432:IE:ips-event,id=12,occurred=2020-06-
26T13:30:17Z,src=xxx.xx.x.xx,spt=80,smac=00:17:a4:aa:f4:93,dst=xxx.xx.x.xxx,dpt=1043,dmac=00:0c:29:b2:fb:4f,sev
=crit,sigId=85302399,sigrevision=12,matchcount=1,signame=Microsoft Internet Explorer XML Processing Memory
Corruption,cve_id=,action_taken=notified,attack_mode=client,url=https://abc.mrl.trellix.com/notification_
url/ips_events?ev_id=12,mvx_status=N/A

ips-event (Network Security on Central Management)

CSV:0:Trellix:CMS:9.0.0.916210:IE:ips-event,id=15,occurred=2020-06-
29T08:36:01Z,src=xxx.xx.x.x,spt=80,smac=00:1b:78:75:79:68,dst=172.16.8.44,dpt=33501,dmac=00:0c:29:5e:e3:6c,sev=
crit,sigId=85311119,sigrevision=8,matchcount=1,signame=Potential Heap Spray Memory Allocation,cve_id=,action_
taken=notified,attack_mode=client,url=https://abc.mrl.trellix.com/notification_url/ips_events?ev_id=15,mvx_
status=N/A

SmartVision (Network Security)

CSV:0:Trellix:Web MPS:9.0.0.916432:WA:smartvisionevent,
id=1,sigId=91500000,sigrevision=5,eventCount=5,occured=2020-06-26
12:43:45,sev=5,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,vlan=0,name=Suspicious Remote Scheduled Task
Activity,type=T1053 / Remote Execution,description=Suspicious Remote Scheduled Task
Activity,url=https://abc.mrl.trellix.com/notification_url?uuid\=20281250-7c27-4cce-a410-2f04e1002c6e,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=1,alertId=1,sigId=0,occured=2020-06-
26T12:42:07Z,name=SMB Create Request: Delete file in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"user": "DomainAdmin",
"domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=2,alertId=1,sigId=0,occured=2020-06-
26T12:42:06Z,name=SMB Create Request: File in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=3,alertId=1,sigId=0,occured=2020-06-
26T12:42:07Z,name=ATSVC Start Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=4,alertId=1,sigId=0,occured=2020-06-
26T12:42:07Z,name=ATSVC Delete Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:Web MPS:9.0.0.916432:SE:smartvision-base-event,id=5,alertId=1,sigId=0,occured=2020-06-
26T12:42:06Z,name=ATSVC Add Job: cmd.exe /C with
redirect,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,

SmartVision (Network Security on Central Management)

CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=11,alertId=7,sigId=0,occured=2020-06-
29T08:13:35Z,name=SMB Create Request: Delete file in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"user": "DomainAdmin",
"domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=13,alertId=7,sigId=0,occured=2020-06-
29T08:13:34Z,name=SMB Create Request: File in Windows temp
direcory,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=12,alertId=7,sigId=0,occured=2020-06-
29T08:13:34Z,name=ATSVC Add Job: cmd.exe /C with
redirect,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails={"payload":
"AAAARf9TTUJyAAAAAAAACAAAAAAAAAAAAAAAAP//AAAAAAAAACIAAk5UIExNIDAuMTIAAlNNQiAyLjAwMgACU01CIDIuPz8/AAAAAGr+U01CQA
ABAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJAADAAEAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=15,alertId=7,sigId=0,occured=2020-06-
29T08:13:35Z,name=ATSVC Delete Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:CMS:9.0.0.916210:SE:smartvision-base-event,id=14,alertId=7,sigId=0,occured=2020-06-
29T08:13:35Z,name=ATSVC Start Job,proto=tcp,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,eventDetails=
{"user": "DomainAdmin", "domain": "internal", "payload":
"AAAAvP5TTUJAAAEAAAAAAAsAfwAAAAAAAAAAAAsAAAAAAAAAAAAAAAEAAAAFAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAA5AAAAF8ARAA0AAAAAAA
AAAQAAAP////94AAAARAAAAAAAAAAAAAAAAAAAAP//AAABAAAAAAAAAAUAAAMQAAAARAAAAAQAA,
CSV:0:Trellix:CMS:9.0.0.916210:WA:smartvisionevent,
id=7,sigId=91500000,sigrevision=5,eventCount=5,occured=2020-06-29
13:14:34,sev=5,src=xxx.xxx.x.x,dst=xxx.xxx.x.x,spt=43520,dpt=445,vlan=0,name=Suspicious Remote Scheduled Task
Activity,type=T1053 / Remote Execution,description=Suspicious Remote Scheduled Task
Activity,url=https://abc.mrl.trellix.com/notification_url?uuid\=5985dbd8-5066-4e04-b560-3f05c93506d6, .