Class Indicator (1.15.0)

Stay organized with collections Save and categorize content based on your preferences.
Indicator(mapping=None, *, ignore_unknown_fields=False, **kwargs)

Represents what's commonly known as an Indicator of compromise (IoC) in computer forensics. This is an artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion. Reference:


ip_addresses Sequence[str]
List of ip addresses associated to the Finding.
domains Sequence[str]
List of domains associated to the Finding.
signatures Sequence[]
The list of matched signatures indicating that the given process is present in the environment.
uris Sequence[str]
The list of URIs associated to the Findings.


builtins.object > proto.message.Message > Indicator



ProcessSignature(mapping=None, *, ignore_unknown_fields=False, **kwargs)

Indicates what signature matched this process.

This message has oneof_ fields (mutually exclusive fields). For each oneof, at most one member field can be set at the same time. Setting any member of the oneof automatically clears all other members.

.. _oneof: