Class Indicator (1.23.0)

Indicator(mapping=None, *, ignore_unknown_fields=False, **kwargs)

Represents what's commonly known as an indicator of compromise (IoC) in computer forensics. This is an artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion. For more information, see Indicator of compromise <>__.


ip_addresses MutableSequence[str]
The list of IP addresses that are associated with the finding.
domains MutableSequence[str]
List of domains associated to the Finding.
signatures MutableSequence[]
The list of matched signatures indicating that the given process is present in the environment.
uris MutableSequence[str]
The list of URIs associated to the Findings.



ProcessSignature(mapping=None, *, ignore_unknown_fields=False, **kwargs)

Indicates what signature matched this process.

This message has oneof_ fields (mutually exclusive fields). For each oneof, at most one member field can be set at the same time. Setting any member of the oneof automatically clears all other members.

.. _oneof: