Endpoint Security Supplementary IOCs

 These real-time IOCs are designed to supplement FireEye Endpoint Security’s production indicators, for environment-specific detection and testing, like tests based on MITRE’s ATT&CK framework. Most of these IOCs will require substantial tuning to use in a production environment, as they will alert on legitimate activity. Some IOCs may work well, depending on the practices of the organization, for instance the sdelete and psexec IOCs. These IOCs should be used as examples, starting points for tuning, or for testing. They should not be bulk uploaded to a production controller, as is.

These IOCs should be viewed and edited using the OpenIOC 1.1 Editor (v3.1.4 and above).

These IOCs can be uploaded to the FireEye Endpoint Security controller using an API tool such as the Endpoint Security IOC Uploader. They can also be used with Enterprise Search, using HXTool, or the IOC Enterprise Search Script (v1.1.0 or above).

These IOCs should be used as examples, starting points for tuning, or for testing. They should not be bulk uploaded to a production controller, as is.

Authentication RequiredDownloading this app requires a FireEye subscription to use and is only accessible for FireEye users with an active FireEye Support account. If you already have an account, please . Otherwise, please Request Support Access or Contact Sales to learn more about becoming a FireEye customer.

Support

Developer:FireEye
Supported By:FireEye
Contact:Email

App Info

Version:2.3.0
Size:1.34 MB
MD5:3EB2AA45EEE255D09EC5CD325E451469
SHA1:362B422D63326089B0B847CE4E8EABD5240431EF
SHA256:D7CF2105A4D566050BFBB2A685D5B0566EE87333319F5D3649741D9096B6A798

Similar Apps