Threat Intelligence Alert Destination IP Threat Indicated

Threat Intelligence Alert - Destination IP Threat Indicated

Configuration

query

dst_ip_threat_indicated:true

config

Key | Value — | — type | aggregation-v1 query | dst_ip_threat_indicated:true streams | [5f74fe0891d2ba1b645adb8d] conditions | {expression:null} search_within_ms | 3600000 execute_every_ms | 3600000

Threat Intelligence Alert Destination IP Threat Indicated

Event destination IP address is listed on one of more blocklists as having an IOC - Indication of compromise.

notes

Last modified December 31, 1969