AhnLab EPP

Download 224
Last updated Mar 5, 2024

ahnlab-epp-unknown-behaviors

Fetch behavior logs of specified unknown threat from AhnLab EPP.

ahnlab-epp-unknown-behaviors watchobj=WATCHOBJ node=NODE
watchobj=WATCHOBJ
watch_obj_id of ahnlab-epp-unknowns output
node=NODE
node_id of ahnlab-epp-unknowns output

Output Fields

FieldTypeNameDescription
_timeDateClient time
profileStringConnect profile
behaviorStringBehaviore.g. 4000005
behavior_typeStringBehavior typee.g. PROCESS
levelIntegerLevele.g. 1, 2
log_typeIntegerLog typee.g. 7
rule_typeIntegerRule typee.g. 128
rule_idStringRule IDe.g. 40010005
rule_seqIntegerRule sequencee.g. 0
severityIntegerSeveritye.g. 20
scoreIntegerScoree.g. 8
current_pidLongCurrent PID
current_file_nameStringCurrent file namee.g. svchost.exe
current_file_signerStringCurrent file signere.g. Microsoft Windows Publisher
current_file_issuerStringCurrent file issuere.g. Microsoft Windows Production PCA 2011
is_firstBoolFirst or not
is_targetBoolTarget or not
is_trunkBoolTrunk or not
target_pidLongTarget PID
target_file_nameStringTarget file namee.g. rundll32.exe
target_file_signerStringTarget file signere.g. unsigned
target_file_issuerStringTarget file issuere.g. unsigned
src_portStringSource port
dst_ipIP addressDestination IP
dst_portIntegerDestination port
current_file_sizeLongCurrent file size
target_file_sizeLongTarget file size
current_pathStringCurrent pathe.g. C:\WINDOWS\system32\svchost.exe
target_pathStringTarget pathe.g. C:\WINDOWS\system32\rundll32.exe
target_cmd_lineStringTarget command line
edr_obj_idStringEDR object IDe.g. 60c7aa6f7356d62baf598534
current_hashStringCurrent hash
target_hashStringTarget hash
hash_algorithmStringHash algorithme.g. MD5
pathStringPathe.g. 60c7aa6f7356d62baf598532 > 60c7aa6f7356d62baf598534
scan_info_flagStringScan info flage.g. 2
detect_msg_seqIntegerDetect message sequencee.g. 4041
current_file_sign_infoListCurrent file sign infosigner, issuer properties
target_file_sign_infoListTarget file sign infosigner, issuer properties
mitre_infoStringMITRE infoEncoded data