You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

20 KiB

1data_sourcedata_source_categorydata_source_categoriesdsideventtypeIds2m2_data_sources2m2
2EmailEmail Access/OpenEmail > Email Access/OpenDS001MAILDS001MAIL-ET01Accessfull email logsMIL2
3EmailIncoming MessagesEmail > Incoming MessagesDS001MAILDS001MAIL-ET02Receivefull email logsMIL2
4EmailOutgoing MessagesEmail > Outgoing MessagesDS001MAILDS001MAIL-ET03Sendfull email logsMIL2
5DNSPaired DNS Queries and ResponsesDNS > Paired DNS Queries and ResponsesDS002DNSDS002DNS-ET01QueryDNS (external)MIL2
6DNSDNS QueriesDNS > DNS QueriesDS002DNSDS002DNS-ET01QueryRequestDNS (external)MIL2
7DNSDNS ResponsesDNS > DNS ResponsesDS002DNSDS002DNS-ET01QueryResponseDNS (external)MIL2
8AuthenticationSuccessful AuthenticationAuthentication > Successful AuthenticationDS003AuthenticationDS003Authentication-ET01SuccessDirectory Servcies (MS-AD, Azure AD, SSO, etc.)MIL1
9AuthenticationSuccessful Default AuthenticationAuthentication > Successful Default AuthenticationDS003AuthenticationDS003Authentication-ET01SuccessDefaultDirectory Servcies (MS-AD, Azure AD, SSO, etc.)MIL1
10AuthenticationSuccessful Insecure AuthenticationAuthentication > Successful Insecure AuthenticationDS003AuthenticationDS003Authentication-ET01SuccessInsecureDirectory Servcies (MS-AD, Azure AD, SSO, etc.)MIL1
11AuthenticationFailed AuthenticationAuthentication > Failed AuthenticationDS003AuthenticationDS003Authentication-ET02FailureDirectory Servcies (MS-AD, Azure AD, SSO, etc.)MIL1
12AuthenticationAuthentication with Failed Two FactorAuthentication > Authentication with Failed Two FactorDS003AuthenticationDS003Authentication-ET02FailureBadFactorDirectory Servcies (MS-AD, Azure AD, SSO, etc.)MIL1
13AuthenticationAuthentication with an Unknown FailureAuthentication > Authentication with an Unknown FailureDS003AuthenticationDS003Authentication-ET02FailureErrorDirectory Servcies (MS-AD, Azure AD, SSO, etc.)MIL1
14AuthenticationAuthentication Against Unknown AccountsAuthentication > Authentication Against Unknown AccountsDS003AuthenticationDS003Authentication-ET02FailureUnknownAccountDirectory Servcies (MS-AD, Azure AD, SSO, etc.)MIL1
15Anti-Virus or Anti-MalwareMalware DetectedAnti-Virus or Anti-Malware > Malware DetectedDS004EndPointAntiMalwareDS004EndPointAntiMalware-ET01SigDetectedAnti-VirusMIL1
16Anti-Virus or Anti-MalwareMalware Definition UpdatesAnti-Virus or Anti-Malware > Malware Definition UpdatesDS004EndPointAntiMalwareDS004EndPointAntiMalware-ET02UpdatedSigAnti-VirusMIL1
17Anti-Virus or Anti-MalwareDetection Engine UpdatedAnti-Virus or Anti-Malware > Detection Engine UpdatedDS004EndPointAntiMalwareDS004EndPointAntiMalware-ET03UpdatedEngAnti-VirusMIL1
18Web ProxyProxy RequestsWeb Proxy > Proxy RequestsDS005WebProxyRequestDS005WebProxyRequest-ET01RequestedFirewall (f)MIL2
19Web ProxyApplication AwarenessWeb Proxy > Application AwarenessDS005WebProxyRequestDS005WebProxyRequest-ET01RequestedWebAppAwareFirewall (f)MIL2
20User Activity AuditList ActivityUser Activity Audit > List ActivityDS006UserActivityDS006UserActivity-ET01ListDirectory Services (+ enrichment)MIL2
21User Activity AuditRead ActivityUser Activity Audit > Read ActivityDS006UserActivityDS006UserActivity-ET02ReadDirectory Services (+ enrichment)MIL2
22User Activity AuditCreate ActivityUser Activity Audit > Create ActivityDS006UserActivityDS006UserActivity-ET03CreateDirectory Services (+ enrichment)MIL2
23User Activity AuditUpdate ActivityUser Activity Audit > Update ActivityDS006UserActivityDS006UserActivity-ET04UpdateDirectory Services (+ enrichment)MIL2
24User Activity AuditDelete ActivityUser Activity Audit > Delete ActivityDS006UserActivityDS006UserActivity-ET05DeleteDirectory Services (+ enrichment)MIL2
25User Activity AuditSearch eventsUser Activity Audit > Search eventsDS006UserActivityDS006UserActivity-ET06SearchDirectory Services (+ enrichment)MIL2
26User Activity AuditExecute As EventsUser Activity Audit > Execute As EventsDS006UserActivityDS006UserActivity-ET07ExecuteAsDirectory Services (+ enrichment)MIL2
27Generic Audit LogClearing Audit LogGeneric Audit Log > Clearing Audit LogDS007AuditTrailDS007AuditTrail-ET01ClearAudit TrailsMIL2
28Generic Audit LogAltering Audit LogGeneric Audit Log > Altering Audit LogDS007AuditTrailDS007AuditTrail-ET02AlterAudit TrailsMIL2
29Generic Audit LogTime Sync EventsGeneric Audit Log > Time Sync EventsDS007AuditTrailDS007AuditTrail-ET03TimeSyncAudit TrailsMIL2
30HR SystemJoined UsersHR System > Joined UsersDS008HRMasterDataDS008HRMasterData-ET01JoinedIdentity Data HR Data (Service/NHA/Admin/etc)MIL3
31HR SystemSeparation Notice GivenHR System > Separation Notice GivenDS008HRMasterDataDS008HRMasterData-ET02SeparationNoticeIdentity Data HR Data (Service/NHA/Admin/etc)MIL3
32HR SystemImmediate Separate EventsHR System > Immediate Separate EventsDS008HRMasterDataDS008HRMasterData-ET03SeperationImmediateIdentity Data HR Data (Service/NHA/Admin/etc)MIL3
33HR SystemIdentity RecordHR System > Identity RecordDS008HRMasterDataDS008HRMasterData-ET01IdentityIdentity Data HR Data (Service/NHA/Admin/etc)MIL3
34HR SystemIdentity RecordHR System > Identity RecordDS008HRMasterDataDS008HRMasterData-ET01AssetIdentity Data HR Data (Service/NHA/Admin/etc)MIL3
35HR SystemEvents from Expired IdentityHR System > Events from Expired IdentityDS008HRMasterDataDS008HRMasterData-ET01ExpiredIdentityIdentity Data HR Data (Service/NHA/Admin/etc)MIL3
36Endpoint Detection and ResponseObject ChangeEndpoint Detection and Response > Object ChangeDS009EndPointIntelDS009EndPointIntel-ET01ObjectChangeClient EDR (alerts only)MIL1
37Endpoint Detection and ResponseProcess LaunchEndpoint Detection and Response > Process LaunchDS009EndPointIntelDS009EndPointIntel-ET01ProcessLaunchClient EDR (alerts only)MIL1
38Endpoint Detection and ResponseProcess Launch with CLIEndpoint Detection and Response > Process Launch with CLIDS009EndPointIntelDS009EndPointIntel-ET03ProcessLaunchwithCLIServer EDR (Full logs)MIL3
39Endpoint Detection and ResponseProcess Launch with Executable HashEndpoint Detection and Response > Process Launch with Executable HashDS009EndPointIntelDS009EndPointIntel-ET04ProcessLaunchWithHashServer EDR (Full logs)MIL3
40Endpoint Detection and ResponseObject Change on Removable StorageEndpoint Detection and Response > Object Change on Removable StorageDS009EndPointIntelDS009EndPointIntel-ET05ObjectChangeRemovableStorageServer EDR (Full logs)MIL3
41Endpoint Detection and ResponseListening Port(s)Endpoint Detection and Response > Listening Port(s)DS009EndPointIntelDS009EndPointIntel-ET06ListeningPortsServer EDR (Full logs)MIL3
42Endpoint Detection and ResponseService LaunchEndpoint Detection and Response > Service LaunchDS009EndPointIntelDS009EndPointIntel-ET07ServiceServer EDR (Full logs)MIL3
43Network CommunicationBasic Traffic LogsNetwork Communication > Basic Traffic LogsDS010NetworkCommunicationDS010NetworkCommunication-ET01TrafficFirewall (Basic logs, cloud firewall)MIL1
44Network CommunicationAllowed - Basic Traffic LogsNetwork Communication > Allowed - Basic Traffic LogsDS010NetworkCommunicationDS010NetworkCommunication-ET01TrafficAllowedFirewall (Basic logs, cloud firewall)MIL1
45Network CommunicationBlocked - Basic Traffic LogsNetwork Communication > Blocked - Basic Traffic LogsDS010NetworkCommunicationDS010NetworkCommunication-ET01TrafficBlockedFirewall (Basic logs, cloud firewall)MIL1
46Network CommunicationApplication-aware Traffic LogsNetwork Communication > Application-aware Traffic LogsDS010NetworkCommunicationDS010NetworkCommunication-ET01TrafficAppAwareFirewall (f)MIL2
47Network CommunicationState LogsNetwork Communication > State LogsDS010NetworkCommunicationDS010NetworkCommunication-ET02StateFirewall (f)MIL2
48Network CommunicationUser-aware Traffic LogsNetwork Communication > User-aware Traffic LogsDS010NetworkCommunicationDS010NetworkCommunication-ET03UserAwareFirewall (f)MIL2
49Malware AnalysisMalware Analysis ResultsMalware Analysis > Malware Analysis ResultsDS011MalwareDetonationDS011MalwareDetonation-ET01DetectionSandboxMIL3
50IDS or IPSIDS or IPS AlertsIDS or IPS > IDS or IPS AlertsDS012NetworkIntrusionDetectionDS012NetworkIntrusionDetection-ET01SigDetectionFirewall (f)MIL2
51Ticket ManagementTicket StatusTicket Management > Ticket StatusDS013TicketManagementDS013TicketManagement-ET01Case managementMIL2
52Ticket ManagementLow Level Correlated EventsTicket Management > Low Level Correlated EventsDS013TicketManagementDS013TicketManagement-ET02LowLevelEventsCase managementMIL2
53Web ServerWeb server access logsWeb Server > Web server access logsDS014WebServerDS014WebServer-ET01AccessWeb Server LogsMIL4
54Web ServerInternal Knowledge SystemsWeb Server > Internal Knowledge SystemsDS014WebServerDS014WebServer-ET02InternalKnowledgeManagementWeb Server LogsMIL4
55Web ServerSource Code SystemsWeb Server > Source Code SystemsDS014WebServerDS014WebServer-ET03SourceCodeWeb Server LogsMIL4
56Configuration ManagementGeneral Config Management LogsConfiguration Management > General Config Management LogsDS015ConfigurationManagementDS015ConfigurationManagement-ET01GeneralAudit TrailsMIL2
57DLPDLP ViolationsDLP > DLP ViolationsDS016DataLossPreventionDS016DataLossPrevention-ET01ViolationDLPMIL4
58Physical SecurityAccess logsPhysical Security > Access logsDS017PhysicalSecurityDS017PhysicalSecurity-ET01AccessPhysical Security (Badge Reader, Security Cameras)MIL4
59Vulnerability DetectionVuln DetectedVulnerability Detection > Vuln DetectedDS018VulnerabilityDetectionDS018VulnerabilityDetection-ET01SigDetectedVulnerability Scanner (normalized)MIL2
60Patch ManagementPatch AppliedPatch Management > Patch AppliedDS019PatchManagementDS019PatchManagement-AppliedVulnerability ScannerMIL1
61Patch ManagementSystem eligible for patchPatch Management > System eligible for patchDS019PatchManagementDS019PatchManagement-EligibleVulnerability ScannerMIL1
62Patch ManagementPatch FailedPatch Management > Patch FailedDS019PatchManagementDS019PatchManagement-FailedVulnerability ScannerMIL1
63Host-based IDSHIDS Event DetectedHost-based IDS > HIDS Event DetectedDS020HostIntrustionDetectionDS020HostIntrustionDetection-ET01SigDetectedClient EDR (alerts only)MIL1
64TelephonyCDR LogTelephony > CDR LogDS021TelephonyDS021Telephony-ET01CDRPhysical Security (Badge Reader, Security Cameras)MIL4
65Host PerformanceHost PerformanceHost Performance > Host PerformanceDS022HostPerformanceDS022HostPerformance-ET01GeneralApplication LogsMIL2
66Crash ReportingCrash ReportCrash Reporting > Crash ReportDS023CrashReportingDS023CrashReporting-ET01GeneralApplication LogsMIL2
67App ServerApp Server LogsApp Server > App Server LogsDS024ApplicationServerDS024ApplicationServer-ET01GeneralApplication LogsMIL2
68IP Address AssignmentIP Address AssignmentIP Address Assignment > IP Address AssignmentDS025IPAddressAssignmentDS025IPAddressAssignment-ET01GeneralDHCPMIL2
69Web Application FirewallWeb Application Firewall Alert LogsWeb Application Firewall > Web Application Firewall Alert LogsDS026WebApplicationFWDS026WebApplicationFW-ET01Generalwaf logsMIL4
70BackupBackup LogsBackup > Backup LogsDS027EndpointBackupDS027EndpointBackup-ET01GeneralAudit TrailsMIL2
71Nework Device AssociationNework Device AssociationNework Device Association > Nework Device AssociationDS028NetworkDeviceAssociationDS028NetworkDeviceAssociation-ET01GeneralNACMIL4
72Database System Logs and MetricsDatabase System Logs and MetricsDatabase System Logs and Metrics > Database System Logs and MetricsDS029DatabaseServerDS029DatabaseServer-ET01GeneralDatabase MonitoringMIL3
73Application Load BalancerApplication Load BalancerApplication Load Balancer > Application Load BalancerDS031ApplicationLoadBalancerDS031ApplicationLoadBalancer-ET01GeneralDNS (external)MIL2
74DNS Global Load BalancerDNS Global Load BalancerDNS Global Load Balancer > DNS Global Load BalancerDS032DNSGlobalLoadBalancerDS032DNSGlobalLoadBalancer-ET01GeneralDNS (external)MIL2
75System LogsSystem LogsSystem Logs > System LogsDS033SystemLogsDS033SystemLogs-ET01GeneralServer logs (Sysmon, CLI, Powershell)MIL3
76Application DataApplication LogsApplication Data > Application LogsDS034ApplicationLogsDS034ApplicationLogs-ET01GeneralApplication LogsMIL2
77Network Flow DataNetwork Flow DataNetwork Flow Data > Network Flow DataDS035NetworkFlowDS035NetworkFlow-ET01Generaltransaction logsMIL4
78Cloud Infrastructure DataCloud Infrastructure Compute Audit LogsCloud Infrastructure Data > Cloud Infrastructure Compute Audit LogsDS036CloudInfrastructureDS036CloudInfrastructure-ET01ComputeCloud Server logsMIL2
79Cloud Infrastructure DataCloud Infrastructure Storage Audit LogsCloud Infrastructure Data > Cloud Infrastructure Storage Audit LogsDS036CloudInfrastructureDS036CloudInfrastructure-ET02StorageCloud Server logsMIL2
80Cloud Infrastructure DataCloud Infrastructure Traffic LogsCloud Infrastructure Data > Cloud Infrastructure Traffic LogsDS036CloudInfrastructureDS036CloudInfrastructure-ET03TrafficCloud Server logsMIL2
81Cloud Infrastructure DataCloud Infrastructure Authentication LogsCloud Infrastructure Data > Cloud Infrastructure Authentication LogsDS036CloudInfrastructureDS036CloudInfrastructure-ET04AuthenticationCloud Server logsMIL2
82Change Events DataChange LogsChange Events Data > Change LogsDS037ChangeDS037Change-ET01ChangeDatabase MonitoringMIL3
83Change Events DataAccount Change LogsChange Events Data > Account Change LogsDS037ChangeDS037Change-ET02ChangeAccountDatabase MonitoringMIL3
84Change Events DataAuditing Change LogsChange Events Data > Auditing Change LogsDS037ChangeDS037Change-ET02ChangeAuditingDatabase MonitoringMIL3
85Change Events DataNetwork Change LogsChange Events Data > Network Change LogsDS037ChangeDS037Change-ET02ChangeNetworkDatabase MonitoringMIL3
86Threat Activity DataThreat Activity EventsThreat Activity Data > Threat Activity EventsDS038ThreatIntelDS038ThreatIntel-ET01IOCDetectedThreat List (curated/paid for)MIL3
87Inventory DataCompute InventoryInventory Data > Compute InventoryDS039ComputeInventoryDS039ComputeInventory-ET01InventoryAsset and Identity Data Basic (UID, categories, priorities + CMDB)MIL2
88Inventory DataCompute Inventory Default AccountInventory Data > Compute Inventory Default AccountDS039ComputeInventoryDS039ComputeInventory-ET01InventoryDefaultUserAsset and Identity Data Basic (UID, categories, priorities + CMDB)MIL2
89Inventory DataCompute Inventory Clear Text PasswordInventory Data > Compute Inventory Clear Text PasswordDS039ComputeInventoryDS039ComputeInventory-ET01InventoryCleartext_PasswordsAsset and Identity Data Basic (UID, categories, priorities + CMDB)MIL2
90Risk ModifiersRisk ModifiersRisk Modifiers > Risk ModifiersDS040RiskModifiersDS040RiskModifiers-ET01RiskSecurity Alerts from ES, EDRMIL1
91Vendor-Specific DataSalesforce Event Log FileVendor-Specific Data > Salesforce Event Log FileVendorSpecificVendorSpecific-sfdc-elfApplication LogsMIL2
92Vendor-Specific DataWindows Security LogsVendor-Specific Data > Windows Security LogsVendorSpecificVendorSpecific-winsecServer (Critical assets)MIL1
93Vendor-Specific DataDomain Controller's Windows Security LogsVendor-Specific Data > Domain Controller's Windows Security LogsVendorSpecificVendorSpecific-winsec-domaincontrollerServer (Critical assets)MIL1
94Vendor-Specific DataMicrosoft Powershell LogsVendor-Specific Data > Microsoft Powershell LogsVendorSpecificVendorSpecific-winsec-powershellServer logs (Sysmon, CLI, Powershell)MIL3
95Vendor-Specific DataMicrosoft Sysmon LogsVendor-Specific Data > Microsoft Sysmon LogsVendorSpecificVendorSpecific-winsec-sysmonServer logs (Sysmon, CLI, Powershell)MIL3
96Vendor-Specific DataMicrosoft IIS LogsVendor-Specific Data > Microsoft IIS LogsVendorSpecificVendorSpecific-ms-iisWeb Server LogsMIL4
97Vendor-Specific DataMicrosoft System EventLogVendor-Specific Data > Microsoft System EventLogVendorSpecificVendorSpecific-win-systemServer (Critical assets)MIL4
98Vendor-Specific DataMicrosoft Windows Print ServiceVendor-Specific Data > Microsoft Windows Print ServiceVendorSpecificVendorSpecific-win-printservicePrinterMIL4
99Vendor-Specific DataMicrosoft Windows Task SchedulerVendor-Specific Data > Microsoft Windows Task SchedulerVendorSpecificVendorSpecific-win-taskschedulerServer (Critical assets)MIL4
100Vendor-Specific DataOSQueryVendor-Specific Data > OSQueryVendorSpecificVendorSpecific-osqueryServer logs (Sysmon, CLI, Powershell)MIL3
101Vendor-Specific DataAWS CloudtrailVendor-Specific Data > AWS CloudtrailVendorSpecificVendorSpecific-aws-cloudtrailCloud Server logsMIL2
102Vendor-Specific DataAWS CloudWatch Kubernetes AuditVendor-Specific Data > AWS CloudWatch Kubernetes AuditVendorSpecificVendorSpecific-aws-cloudwatch-eksCloud Server logsMIL2
103Vendor-Specific DataAWS ConfigVendor-Specific Data > AWS ConfigVendorSpecificVendorSpecific-aws-configCloud Server logsMIL2
104Vendor-Specific DataAWS DescriptionVendor-Specific Data > AWS DescriptionVendorSpecificVendorSpecific-aws-descriptionCloud Server logsMIL2
105Vendor-Specific DataAWS S3 Access LogsVendor-Specific Data > AWS S3 Access LogsVendorSpecificVendorSpecific-aws-s3-accessCloud Server logsMIL2
106Vendor-Specific DataAmazon Security HubVendor-Specific Data > Amazon Security HubVendorSpecificVendorSpecific-aws-securityhubCloud Server logsMIL2
107Vendor-Specific DataAmazon VPC FlowVendor-Specific Data > Amazon VPC FlowVendorSpecificVendorSpecific-aws-vpcflowFirewall (Basic logs, cloud firewall)MIL1
108Vendor-Specific DataGCP AuditVendor-Specific Data > GCP AuditVendorSpecificVendorSpecific-gcp-auditCloud Server logsMIL2
109Vendor-Specific DataGCP Kubernetes AuditVendor-Specific Data > GCP Kubernetes AuditVendorSpecificVendorSpecific-gcp-gke-auditCloud Server logsMIL2
110Vendor-Specific DataGCP LogsVendor-Specific Data > GCP LogsVendorSpecificVendorSpecific-gcpCloud Server logsMIL2
111Vendor-Specific DataGoogle GmailVendor-Specific Data > Google GmailVendorSpecificVendorSpecific-google-gmailfull email logsMIL4
112Vendor-Specific DataGoogle GdriveVendor-Specific Data > Google GdriveVendorSpecificVendorSpecific-google-drivefile auditing logsMIL3
113Vendor-Specific DataGoogle CalendarVendor-Specific Data > Google CalendarVendorSpecificVendorSpecific-google-calendarCloud Server logsMIL2
114Vendor-Specific DataAzure AuditVendor-Specific Data > Azure AuditVendorSpecificVendorSpecific-azure-auditCloud Server logsMIL2
115Vendor-Specific DataAzure AD AuditVendor-Specific Data > Azure AD AuditVendorSpecificVendorSpecific-azure-ad-auditCloud Server logsMIL2
116Vendor-Specific DataAzure Kubernetes AuditVendor-Specific Data > Azure Kubernetes AuditVendorSpecificVendorSpecific-azure-aks-auditCloud Server logsMIL2
117Vendor-Specific DataKubernetesVendor-Specific Data > KubernetesVendorSpecificVendorSpecific-kubernetesCloud Server logsMIL2
118Vendor-Specific DataZoomVendor-Specific Data > ZoomVendorSpecificVendorSpecific-zoomchat logsMIL4
119Vendor-Specific DataZeekVendor-Specific Data > ZeekVendorSpecificVendorSpecific-zeektransaction logsMIL4
120Vendor-Specific DataCircleCIVendor-Specific Data > CircleCIVendorSpecificVendorSpecific-circleciCustom Application LogsMIL4
121Vendor-Specific DataF5 Big-IpVendor-Specific Data > F5 Big-IpVendorSpecificVendorSpecific-f5bigipFirewall (f)MIL2
122Vendor-Specific DataCisco IOSVendor-Specific Data > Cisco IOSVendorSpecificVendorSpecific-cisco-iosFirewall (f)MIL2
123Vendor-Specific DataCerner EMRVendor-Specific Data > Cerner EMRVendorSpecificVendorSpecific-CernerDatabase Query RecordsMIL4
124Vendor-Specific DataAny Logs in SplunkVendor-Specific Data > Any Logs in SplunkVendorSpecificVendorSpecific-AnySplunkServer (Critical assets)MIL1
125Vendor-Specific DataSplunk's Internal LogsVendor-Specific Data > Splunk's Internal LogsVendorSpecificVendorSpecific-SplunkInternalServer (Critical assets)MIL1
126Vendor-Specific DataBox Audit LogsVendor-Specific Data > Box Audit LogsVendorSpecificVendorSpecific-Boxfile auditing logsMIL3
127Vendor-Specific DataOktaVendor-Specific Data > OktaVendorSpecificVendorSpecific-OktaSAMLMIL4
128Vendor-Specific DataCrowdstrike LogsVendor-Specific Data > Crowdstrike LogsVendorSpecificVendorSpecific-CrowdstrikeClient EDR (full logs)MIL3