{{#if INCIDENT_SUMMARY}}
{{INCIDENT_SUMMARY}}
{{else if REASON}}{{REASON}}
{{/if}}Device | {{DEVICE_NAME}} |
Device username | {{DEVICE_EMAIL}} |
Policy | {{DEVICE_GROUP_NAME}} |
Policy ID | {{POLICY_ID}} |
Target value | {{TARGET_VALUE}} |
Severity | {{THREAT_SCORE}} |
Alert ID | {{INCIDENT_ID}} |
Alert created | {{LAST_UPDATE_TIME}} |
ATT&CK tactic | {{ATTACK_TACTIC}} |
ATT&CK technique | {{ATTACK_TECHNIQUE}} |
MDR workflow | {{ANALYST_TRIAGE_INFO_PRESENTATION}} |
MDR determination | {{ANALYST_STATE_PRESENTATION}} |
Process | {{APPLICATION_NAME}} |
Process username | {{PROCESS_USER_NAME}} |
Process SHA-256 | {{SHA256_HASH}} |
Parent process | {{PARENT_PROCESS_NAME}} |
Parent process username | {{PARENT_PROCESS_USER_NAME}} |
Parent process SHA-256 | {{PARENT_PROCESS_SHA256_HASH}} |
{{linksLabel}} |
{{ this.label }} |
Application | {{#equal type "WATCHLIST"}} IOCs {{else}} TTPs {{/equal}} |
---|---|
{{this.[0].applicationName}} |
{{#each this}}
{{ this.indicatorName }}
{{#if @first}}
{{#if ../../IOC_HIT}}
({{#if ../../IOC_FIELD}}{{../../IOC_FIELD}}: {{/if}}{{../../IOC_HIT}})
{{/if}}
{{/if}}
{{/each}} |
This alert is based on notification settings specified in '{{RULE_NAME}}'. Update settings