Cisco Cisco Firepower Management Center 2000 Guida Dello Sviluppatore

Pagina di 536
 
B-33
FireSIGHT eStreamer Integration Guide
 
Appendix B      Understanding Legacy Data Structures
  Legacy Malware Event Data Structures
Detection Name
Host IP Address, 
cont.
Detector ID
String Block Type (0)
String Block Type (0), cont.
String Block Length
String Block Length, cont.
Detection Name...
User
String Block Type (0)
String Block Length
User...
File Name
String Block Type (0)
String Block Length
File Name...
File Path
String Block Type (0)
String Block Length
File Path...
File SHA
Hash
String Block Type (0)
String Block Length
File SHA Hash...
File Size
File Type
File Timestamp
Parent File 
Name
File Timestamp, cont.
String Block Type (0)
String Block Type (0), 
cont.
String Block Length
String Block Length, 
cont.
Parent File Name...
Parent File 
SHA Hash
String Block Type (0)
String Block Length
Parent File SHA Hash...
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31