IOC scan results

Depending on the type of processed object, the indicator of compromise search result window can display the following information:

The IOC section displays the structure of the IOC file. If the processed object matches a condition of the IOC rule, that condition is highlighted. If the processed object matches multiple conditions, the text of the whole branch is highlighted.

See also

Viewing alerts

Viewing alert details

General information about an alert of any type

Information in the Object information section

Information in the Alert information section

Information in the Scan results section

Information in the IDS rule section

Information in the Network event section

Scan results in Sandbox

Information in the Hosts section

Information in the Change log section

Sending alert data

Page top