Experimental

Download 56
Last updated Dec 22, 2024

sonar-indicators

Enumerate indicators of compromise in Logpresso Sonar.

sonar-indicators [type=TYPE]
type=TYPE
Filter indicators by types. Use comma-separated values. e.g. IP, DOMAIN, URL, MD5, EMAIL

Output Fields

FieldTypeNameDescription
typeStringTypeType of indicator. e.g. URL, MD5, IP, DOMAIN, EMAIL
valueStringValueValue of the indicator.
riskStringRiskRisk level. e.g. BENIGN, LOW, MEDIUM, HIGH
reputationStringReputationReputation. e.g. WAIT, UNKNOWN, BENIGN, SUSPICIOUS, MALICIOUS
statusStringStatusStatus. e.g. WAIT, ERROR, RETRY, DONE
first_seenDateFirst seenFirst detection time.
last_seenDateLast seenLast detection time.
createdDateCreatedCreation time.
updatedDateUpdatedLast update time.