Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "id": 1,
- "jsonrpc": "1.0",
- "method": "add",
- "params": [
- {
- "data": {
- "address-filter": null,
- "creation-time": 1645793716,
- "description": "COMPANY-Botnet-Communication-Detection-By-Threat",
- "device": [
- {
- "id": 1,
- "name": "All_Devices",
- "type": 2,
- "vdom": null
- }
- ],
- "device-specify": 0,
- "email-html-format": 0,
- "email-subject": "COMPANY-Botnet-Communication-Detection-By-Threat",
- "email-svr": "smtp.office365.com",
- "enable": 1,
- "enable-time": 0,
- "fabric-connector": null,
- "filter": [
- {
- "aggregate-expr": "",
- "dev-type": 0,
- "enable": 1,
- "eventstatus": "open",
- "eventtype": "",
- "extrainfo": "Traffic to Botnet C&C ${virus}, Reference: ${ref}, Traffic path: PolicyID ${policyid}\\${dstintf}\\${dstip}:${dstport}",
- "extrainfo-type": 1,
- "filter-expr": "logid==0202009249",
- "groupby1": "virus",
- "groupby2": "endpoint",
- "groupby3": "",
- "id": 2,
- "indicator": null,
- "logtype": "virus",
- "rule": null,
- "rule-relation": 0,
- "severity": 0,
- "subject": "Traffic to Botnet C&C from $groupby2 detected",
- "tag": "Botnet,IP,C&C",
- "thres-count": 1,
- "thres-duration": 1440,
- "utmevent": ""
- },
- {
- "aggregate-expr": "",
- "dev-type": 0,
- "enable": 1,
- "eventstatus": "open",
- "eventtype": "",
- "extrainfo": "Traffic to Botnet C&C ${attack}, Reference: ${ref}, Traffic path: PolicyID ${policyid}\\${dstintf}\\${dstip}:${dstport}",
- "extrainfo-type": 1,
- "filter-expr": "attack ~ Botnet and direction=incoming and (action=='detected' or action=='pass session')",
- "groupby1": "attack",
- "groupby2": "endpoint",
- "groupby3": "",
- "id": 4,
- "indicator": null,
- "logtype": "ips",
- "rule": null,
- "rule-relation": 0,
- "severity": 0,
- "subject": "Traffic to Botnet C&C from $groupby2 detected",
- "tag": "Botnet,Signature,C&C",
- "thres-count": 1,
- "thres-duration": 1440,
- "utmevent": ""
- },
- {
- "aggregate-expr": "",
- "dev-type": 0,
- "enable": 1,
- "eventstatus": "open",
- "eventtype": "",
- "extrainfo": "Traffic from Botnet C&C ${attack}, Reference: ${ref}, Traffic path: PolicyID ${policyid}\\${srcintf}\\${srcip}:${srcport}",
- "extrainfo-type": 1,
- "filter-expr": "attack ~ Botnet and direction=outgoing and (action=='detected' or action=='pass session')",
- "groupby1": "attack",
- "groupby2": "dstendpoint",
- "groupby3": "",
- "id": 6,
- "indicator": null,
- "logtype": "ips",
- "rule": null,
- "rule-relation": 0,
- "severity": 0,
- "subject": "Traffic from Botnet C&C to $groupby2 detected",
- "tag": "Botnet,Signature,C&C",
- "thres-count": 1,
- "thres-duration": 1440,
- "utmevent": ""
- },
- {
- "aggregate-expr": "",
- "dev-type": 0,
- "enable": 1,
- "eventstatus": "open",
- "eventtype": "",
- "extrainfo": "Traffic to C&C:${dstip}, Reference: ${ref}, Traffic path: PolicyID:${policyid}\\${dstintf}",
- "extrainfo-type": 1,
- "filter-expr": "logid==0422016400",
- "groupby1": "attack",
- "groupby2": "endpoint",
- "groupby3": "",
- "id": 8,
- "indicator": null,
- "logtype": "ips",
- "rule": null,
- "rule-relation": 1,
- "severity": 1,
- "subject": "Traffic to Botnet $groupby1 from $groupby2 blocked",
- "tag": "Botnet,IP,C&C",
- "thres-count": 1,
- "thres-duration": 1440,
- "utmevent": ""
- },
- {
- "aggregate-expr": "",
- "dev-type": 0,
- "enable": 1,
- "eventstatus": "open",
- "eventtype": "",
- "extrainfo": "Traffic to C&C:${dstip}, Reference: ${ref}, Traffic path: PolicyID:${policyid}\\${dstintf}",
- "extrainfo-type": 1,
- "filter-expr": "logid==0422016401",
- "groupby1": "attack",
- "groupby2": "endpoint",
- "groupby3": "",
- "id": 9,
- "indicator": null,
- "logtype": "ips",
- "rule": null,
- "rule-relation": 0,
- "severity": 0,
- "subject": "Traffic to Botnet $groupby1 from $groupby2 detected",
- "tag": "Botnet,IP,C&C",
- "thres-count": 1,
- "thres-duration": 1440,
- "utmevent": ""
- }
- ],
- "filter-relation": 1,
- "handlertype": 0,
- "id": 10,
- "name": "COMPANY-Botnet-Communication-Detection-By-Threat",
- "pre-filter": null,
- "pre-filter-option": 0,
- "protected": 0,
- "target-enable": 1,
- "template-url": "",
- "update-time": 1645793768,
- "uuid": "",
- "version": 2
- },
- "url": "config/adom/root/log-alert/trigger"
- }
- ],
- "session": "",
- "verbose": 1
- }
Advertisement
Add Comment
Please, Sign In to add comment