Push Security 로그
Push Security 로그를 Panther Console에 연결
마지막 업데이트
도움이 되었나요?
도움이 되었나요?
스키마: Custom.PushSecurity.Activity
설명: Push Security 최종 사용자 활동
참조 URL: https://pushsecurity.redoc.ly/webhooks-v1#tag/Activity
fieldDiscoveryEnabled: true
필드:
- 이름: id
필수: true
유형: string
- 이름: new
필수: true
유형: object
필드:
- name: accountId
유형: string
- 이름: 앱 ID
유형: string
- 이름: email
유형: string
지표:
- email
- 이름: employeeId
유형: string
- name: identityProvider
유형: string
- 이름: leakedPassword
유형: boolean
- 이름: loginTimestamp
유형: timestamp
시간 형식:
- unix
- 이름: loginType
유형: string
- 이름: loginUrl
유형: string
지표:
- url
- 이름: passwordId
유형: string
- 이름: passwordManuallyTyped
유형: boolean
- 이름: weakPassword
유형: boolean
- 이름: weakPasswordReasons
유형: array
요소:
유형: string
- 이름: workApp
유형: boolean
- 이름: appBanner
유형: object
필드:
- 이름: action
유형: string
- 이름: buttonText
유형: string
- 이름: mode
유형: string
- 이름: subtext
유형: string
- 이름: title
유형: string
- 이름: employee
유형: object
필드:
- 이름: chatopsEnabled
유형: boolean
- 이름: creationTimestamp
유형: timestamp
시간 형식:
- unix
- 이름: department
유형: string
- 이름: email
유형: string
지표:
- email
- 이름: firstName
유형: string
- 이름: id
유형: string
- 이름: lastName
유형: string
- 이름: licensed
유형: boolean
- 이름: location
유형: string
- 이름: 앱 유형
유형: string
- 이름: browser
유형: string
- 이름: os
유형: string
- 이름: sourceIpAddress
유형: string
지표:
- ip
- name: userAgent
유형: string
- 이름: object
검증:
허용: [ "LOGIN",
"APP_BANNER"]
필수: true
유형: string
- 이름: timestamp
필수: true
유형: timestamp
이벤트 시간 여부: true
시간 형식:
- unix
- 이름: version
필수: true
유형: bigint스키마: PushSecurity.Controls
설명: Push Security가 탐지한 공격
참조 URL: https://pushsecurity.redoc.ly/webhooks-v1#tag/Controls
필드:
- 이름: id
필수: true
유형: string
- 이름: new
필수: true
유형: object
필드:
- 이름: action
유형: string
- 이름: 앱 유형
유형: string
- 이름: browser
유형: string
- 이름: email
유형: string
지표:
- email
- 이름: employee
유형: object
필드:
- 이름: chatopsEnabled
유형: boolean
- 이름: creationTimestamp
유형: timestamp
시간 형식:
- unix
- 이름: department
유형: string
- 이름: email
유형: string
지표:
- email
- 이름: firstName
유형: string
- 이름: id
유형: string
- 이름: lastName
유형: string
- 이름: licensed
유형: boolean
- 이름: location
유형: string
- 이름: mode
유형: string
- 이름: os
유형: string
- 이름: referrerUrl
유형: string
지표:
- url
- 이름: sourceIpAddress
유형: string
지표:
- ip
- 이름: url
유형: string
지표:
- url
- name: userAgent
유형: string
- 이름: object
필수: true
유형: string
- 이름: category
필수: true
유형: string
검증:
allow:
- CONTROL
- 이름: timestamp
필수: true
유형: timestamp
시간 형식:
- unix
이벤트 시간 여부: true
- 이름: version
필수: true
유형: bigint스키마: Custom.PushSecurity.Entities
설명: Push Security 앱, 직원, 계정 및 발견 사항
참조 URL: https://pushsecurity.redoc.ly/webhooks-v1#tag/Entities
fieldDiscoveryEnabled: true
필드:
- 이름: id
필수: true
유형: string
- 이름: new
필수: true
유형: object
필드:
- 이름: chatopsEnabled
유형: boolean
- 이름: department
유형: string
- 이름: firstName
유형: string
- 이름: lastName
유형: string
- 이름: licensed
유형: boolean
- 이름: location
유형: string
- 이름: mfaMethods
유형: array
요소:
유형: string
- 이름: mfaRegistered
유형: boolean
- 이름: state
유형: string
- 이름: 앱 ID
유형: string
- 이름: 앱 유형
유형: string
- 이름: passwordId
유형: string
- 이름: approvalStatus
유형: string
- 이름: notes
유형: string
- 이름: ownerId
유형: string
- 이름: sensitivityLevel
유형: string
- 이름: type
유형: string
- 이름: otherAppId
유형: string
- 이름: lastUsedTimestamp
유형: timestamp
시간 형식:
- unix
- 이름: loginMethods
유형: object
필드:
- 이름: oktaSwaLogin
유형: boolean
- 이름: vendorSsoLogin
유형: string
- 이름: oidcLogin
유형: string
- 이름: passwordLogin
유형: boolean
- 이름: samlLogin
유형: string
- 이름: email
유형: string
지표:
- email
- 이름: employeeId
유형: string
- name: domain
유형: string
- 이름: hidden
유형: boolean
- 이름: name
유형: string
- 이름: oauthAppId
유형: bigint
- 이름: requestSupportStatus
유형: string
- 이름: creationTimestamp
유형: timestamp
시간 형식:
- unix
- 이름: id
유형: string
- 이름: object
필수: true
검증:
허용: [ "EMPLOYEE",
"ACCOUNT",
"FINDING",
"APP",
"ACCOUNT_OTHER",
"APP_OTHER"]
유형: string
- 이름: old
required: false
유형: object
필드:
- 이름: chatopsEnabled
유형: boolean
- 이름: department
유형: string
- 이름: firstName
유형: string
- 이름: lastName
유형: string
- 이름: licensed
유형: boolean
- 이름: location
유형: string
- 이름: lastUsedTimestamp
유형: timestamp
시간 형식:
- unix
- 이름: mfaMethods
유형: array
요소:
유형: string
- 이름: mfaRegistered
유형: boolean
- 이름: state
유형: string
- 이름: 앱 ID
유형: string
- 이름: 앱 유형
유형: string
- 이름: passwordId
유형: string
- 이름: approvalStatus
유형: string
- 이름: notes
유형: string
- 이름: ownerId
유형: string
- 이름: sensitivityLevel
유형: string
- 이름: type
유형: string
- 이름: otherAppId
유형: string
- 이름: loginMethods
유형: object
필드:
- 이름: oidcLogin
유형: string
- 이름: oktaSwaLogin
유형: boolean
- 이름: samlLogin
유형: string
- 이름: vendorSsoLogin
유형: string
- 이름: passwordLogin
유형: boolean
- 이름: email
유형: string
지표:
- email
- 이름: employeeId
유형: string
- name: domain
유형: string
- 이름: hidden
유형: boolean
- 이름: name
유형: string
- 이름: oauthAppId
유형: bigint
- 이름: requestSupportStatus
유형: string
- 이름: creationTimestamp
유형: timestamp
시간 형식:
- unix
- 이름: id
유형: string
- 이름: timestamp
필수: true
유형: timestamp
이벤트 시간 여부: true
시간 형식:
- unix
- 이름: type
필수: true
유형: string
- 이름: version
필수: true
유형: bigint