Skip to content

Is there a list of Threat Object Types #37

Answered by tskinnerarlo
tskinnerarlo asked this question in Q&A
Discussion options

You must be logged in to vote

I have not found a list in dev.splunk or docs, so i'm thinking most appropriate list that may help, because the purpose of this is to connect to Threat Intel in ES is to look at the list of ThreatIntel types supported in ES which are (from https://docs.splunk.com/Documentation/ES/latest/Admin/Supportedthreatinteltypes):

X509 Certificates
Email
file_hash
file_name
url
ip address
domain
Processes
Registry entries
Services
Users

Might even be able to use any of the supported fields in the intel lookups as types, if the purpose is to match against threat intel lookups. There isn't a lot about the mechanics of it in the docs.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by tskinnerarlo
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants