Cisco Cisco Firepower Management Center 4000 Guía Del Desarrollador

Descargar
Página de 726
Version 5.3
Sourcefire 3D System eStreamer Integration Guide
506
Understanding Legacy Data Structures
Legacy Malware Event Data Structures
Appendix B
Detection Name
Event Subtype ID
Detector ID
String Block Type (0)
String Block Type (0), cont.
String Block Length
String Block Length, cont.
Detection Name...
User
String Block Type (0)
String Block Length
User...
File Name
String Block Type (0)
String Block Length
File Name...
File Path
String Block Type (0)
String Block Length
File Path...
File SHA
Hash
String Block Type (0)
String Block Length
File SHA Hash...
File Size
File Type
File Timestamp
Parent F
ile 
Name
String Block Type (0)
String Block Length
Parent File Name...
Parent F
ile 
SHA Hash
String Block Type (0)
String Block Length
Parent File SHA Hash...
Ev
ent 
Description
String Block Type (0)
String Block Length
Event Description...
Device ID