Viewing the table of IOC files

The table of IOC files contains information about IOC files used for scanning on computers with the Endpoint Sensors component installed; you can find the table in the IOC/IOA Analysis section, IOC Scanner subsection of the program web interface window.

The table of IOC files contains the following information:

  1. Apt_icon_Importance_new—Importance level that will be assigned to an alert generated using this IOC file.

    The importance level can have one of the following values:

    • Apt_icon_importance_low—Low importance.
    • Apt_icon_importance_medium—Medium importance.
    • Apt_icon_importance_high—High importance.
  2. Type—Type of uploaded IOC file depending on the application operating mode and the server on which the IOC file was uploaded. IOC files can be one of the following types:
    • Global—Uploaded to the PCN server. These IOC files are used to scan events on this PCN server and on all SCN servers connected to this PCN server. Scanned events belong to the organization which the user is managing in the program web interface (in the distributed solution and multitenancy mode).
    • Local—Uploaded to a SCN server. These IOC files are used to scan events on this SCN server. Scanned events belong to the organization which the user is managing in the program web interface (in the distributed solution and multitenancy mode).
  3. Name—Name of the IOC file.
  4. Servers—Name of the server with the Central Node component on which events were scanned based on this IOC file.
  5. Autoscan—Use of an IOC file during an automatic scan of events.

    Event scanning using this IOC file can have one of the following statuses:

    • Enabled
    • Disabled

See also

IOC scan of events

Viewing information about an IOC file

Uploading an IOC file

Downloading an IOC file to a computer

Enabling and disabling the automatic use of an IOC file when scanning events

Deleting an IOC file

Searching IOC scan results

Filtering and searching IOC files

Clearing an IOC file filter

Configuring an IOC scan schedule

Supported OpenIOC Indicators of Compromise

Page top