LibPrelude IDMEF path¶
Here will be listed all the fields available in LibPrelude with their respective paths.
Alert¶
- alert.messageid STRING
- alert.tool_alert.alertident.alertident STRING
- alert.tool_alert.alertident.analyzerid STRING
- alert.correlation_alert.name STRING
- alert.correlation_alert.alertident.alertident STRING
- alert.correlation_alert.alertident.analyzerid STRING
Time¶
- alert.analyzer_time TIME
- alert.create_time TIME
- alert.detect_time TIME
Analyzer¶
- alert.analyzer().analyzerid STRING
- alert.analyzer().name STRING
- alert.analyzer().manufacturer STRING
- alert.analyzer().model STRING
- alert.analyzer().version STRING
- alert.analyzer().class STRING
- alert.analyzer().ostype STRING
- alert.analyzer().osversion STRING
Node/Address¶
- alert.analyzer().node.address().ident STRING
- alert.analyzer().node.address().category ENUM
- alert.analyzer().node.address().vlan_name STRING
- alert.analyzer().node.address().vlan_num INT
- alert.analyzer().node.address().address STRING
- alert.analyzer().node.address().netmask STRING
Process¶
- alert.analyzer().process.ident STRING
- alert.analyzer().process.name STRING
- alert.analyzer().process.pid INT
- alert.analyzer().process.path STRING
- alert.analyzer().process.arg STRING
- alert.analyzer().process.env STRING
Source¶
Node/Address¶
- alert.source().node.ident STRING
- alert.source().node.category ENUM
- alert.source().node.location STRING
- alert.source().node.name STRING
- alert.source().node.address().ident STRING
- alert.source().node.address().category ENUM
- alert.source().node.address().vlan_name STRING
- alert.source().node.address().vlan_num INT
- alert.source().node.address().address STRING
- alert.source().node.address().netmask STRING
Process¶
- alert.source().process.ident STRING
- alert.source().process.name STRING
- alert.source().process.pid INT
- alert.source().process.path STRING
- alert.source().process.arg STRING
- alert.source().process.env STRING
User/UserId¶
- alert.source().user.ident STRING
- alert.source().user.category ENUM
- alert.source().user.user_id().ident STRING
- alert.source().user.user_id().type ENUM
- alert.source().user.user_id().tty STRING
- alert.source().user.user_id().name STRING
- alert.source().user.user_id().number INT
Service¶
- alert.source().service.ident STRING
- alert.source().service.ip_version INT
- alert.source().service.iana_protocol_number INT
- alert.source().service.iana_protocol_name STRING
- alert.source().service.name STRING
- alert.source().service.port INT
- alert.source().service.portlist STRING
- alert.source().service.protocol STRING
- alert.source().service.web_service.url STRING
- alert.source().service.web_service.cgi STRING
- alert.source().service.web_service.http_method STRING
- alert.source().service.web_service.arg STRING
- alert.source().service.snmp_service.oid STRING
- alert.source().service.snmp_service.message_processing_model INT
- alert.source().service.snmp_service.security_model STRING
- alert.source().service.snmp_service.security_name STRING
- alert.source().service.snmp_service.security_level INT
- alert.source().service.snmp_service.context_name STRING
- alert.source().service.snmp_service.context_engine_id STRING
- alert.source().service.snmp_service.command STRING
- alert.source().service.snmp_service.community STRING
Target¶
Node/Address¶
- alert.target().node.ident STRING
- alert.target().node.category ENUM)
- alert.target().node.location STRING
- alert.target().node.name STRING
- alert.target().node.address().ident STRING
- alert.target().node.address().category ENUM
- alert.target().node.address().vlan_name STRING
- alert.target().node.address().vlan_num INT
- alert.target().node.address().address STRING
- alert.target().node.address().netmask STRING
Process¶
- alert.target().process.ident STRING
- alert.target().process.name STRING
- alert.target().process.pid INT
- alert.target().process.path STRING
- alert.target().process.arg STRING
- alert.target().process.env STRING
User/UserId¶
- alert.target().user.user_id().ident STRING
- alert.target().user.user_id().type ENUM
- alert.target().user.user_id().tty STRING
- alert.target().user.user_id().name STRING
- alert.target().user.user_id().number INT
Service¶
- alert.target().service.ident STRING
- alert.target().service.ip_version INT
- alert.target().service.iana_protocol_number STRING
- alert.target().service.iana_protocol_name INT
- alert.target().service.name STRING
- alert.target().service.port INT
- alert.target().service.portlist STRING
- alert.target().service.protocol STRING
- alert.target().service.web_service.url STRING
- alert.target().service.web_service.cgi STRING
- alert.target().service.web_service.http_method STRING
- alert.target().service.web_service.arg STRING
- alert.target().service.snmp_service.oid STRING
- alert.target().service.snmp_service.message_processing_model INT
- alert.target().service.snmp_service.security_model STRING
- alert.target().service.snmp_service.security_name STRING
- alert.target().service.snmp_service.security_level INT
- alert.target().service.snmp_service.context_name STRING
- alert.target().service.snmp_service.context_engine_id STRING
- alert.target().service.snmp_service.command STRING
- alert.target().service.snmp_service.community STRING
File¶
- alert.target().file().ident STRING
- alert.target().file().name STRING
- alert.target().file().path STRING
- alert.target().file().create_time TIME
- alert.target().file().modify_time TIME
- alert.target().file().access_time TIME
- alert.target().file().data_size INT
- alert.target().file().disk_size INT
- alert.target().file().file_access().permissionENUM
- alert.target().file().file_access().user_id().ident STRING
- alert.target().file().file_access().user_id().type ENUM
- alert.target().file().file_access().user_id().tty STRING
- alert.target().file().file_access().user_id().name STRING
- alert.target().file().file_access().user_id().number INT
- alert.target().file().linkage().category ENUM
- alert.target().file().linkage().name STRING
- alert.target().file().linkage().path STRING
- alert.target().file().linkage().file... _FILE_
- alert.target().file().inode.change_time _TIME_
- alert.target().file().inode.number INT
- alert.target().file().inode.major_device INT
- alert.target().file().inode.minor_device INT
- alert.target().file().inode.c_major_device INT
- alert.target().file().inode.c_minor_device INT
- alert.target().file().checksum.value STRING
- alert.target().file().checksum.key STRING
- alert.target().file().checksum.algorithm ENUM
- alert.target().file().category ENUM
- alert.target().file().fstype ENUM
- alert.target().file().file_type STRING
Assessment¶
- alert.assessment.impact.severity ENUM
- alert.assessment.impact.completion ENUM
- alert.assessment.impact.type ENUM
- alert.assessment.impact.description STRING
Classification¶
- alert.classification.reference().origin ENUM
- alert.classification.reference().name STRING
- alert.classification.reference().url STRING
- alert.classification.reference().meaning STRING