Skip to content

Latest commit

 

History

History
37 lines (29 loc) · 1.15 KB

MATCH-S00042.md

File metadata and controls

37 lines (29 loc) · 1.15 KB

Rules: McAfee Web Gateway - Poor Reputation

Description

Observes for sites categorized as having a poor reputation by McAfee Web Gateway

Additional Details

Detail Value
Type Templated Match
Category Initial Access
Apply Risk to Entities srcDevice_ip, user_username, device_hostname, device_ip
Signal Name McAfee Web Gateway - Poor Reputation - {{fields['urlCategories']}}
Summary Expression HTTP connection to the following site with a poor reputation of "{{description}}":

{{fields['urlCategories']}}| |Score/Severity|Static: 1| |Enabled by Default|True| |Prototype|False| |Tags|_mitreAttackTactic:TA0001, _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1071, _mitreAttackTechnique:T1071.001|

Vendors and Products

Fields Used

Origin Field
Normalized Schema description
Normalized Schema device_hostname
Normalized Schema device_ip
Direct from Record fields['urlCategories']
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip
Normalized Schema user_username