[{"tags": ["mssp_qradar"], "id": 802124, "artifact_count": 12, "artifact_update_time": "2023-10-05T06:55:51.464036Z", "asset": 50, "close_time": null, "closing_owner": null, "closing_rule_run": null, "container_update_time": "2023-10-05T06:55:53.049161Z", "create_time": "2023-10-05T01:55:30.040240Z", "description": "Container added by QRadar", "due_time": "2023-10-25T01:55:30.040240Z", "end_time": "2023-10-05T06:53:14.013000Z", "hash": "00b75351324e3f2941e1c56c959d9a1f", "external_id": null, "ingest_app": "6cf34589-6947-409f-b776-e8fa62e01509", "kill_chain": null, "label": "mssp_offense", "name": "208222 - UBA Offense - User crossed risk threshold", "open_time": "2023-10-05T02:17:21.763890Z", "owner": 11, "role": null, "owner_name": "pwc.mss", "sensitivity": "amber", "severity": "low", "source_data_identifier": "208222", "start_time": "2023-10-05T01:47:47.012000Z", "status": "open", "version": 1, "workflow_name": "", "custom_fields": {"Detection Source": "QRadar"}, "container_type": "default", "in_case": false, "current_phase": null, "tenant": 0, "parent_container": null, "node_guid": null}, {"tags": ["approval_complete", "mssp_qradar"], "id": 802028, "artifact_count": 42, "artifact_update_time": "2023-10-05T06:55:44.379819Z", "asset": 50, "close_time": null, "closing_owner": null, "closing_rule_run": null, "container_update_time": "2023-10-05T06:54:25.286871Z", "create_time": "2023-10-04T22:45:29.124062Z", "description": "Container added by QRadar", "due_time": "2023-10-14T22:45:29.133233Z", "end_time": "2023-10-05T06:51:17.931000Z", "hash": "e1da04a5cdd9dd530f3213758a75f6fd", "external_id": null, "ingest_app": "6cf34589-6947-409f-b776-e8fa62e01509", "kill_chain": null, "label": "mssp_offense", "name": "208216 - PwC CaaS: Log4j Vulnerability Scanning\n containing Miscellaneous Webseal-Instance Event", "open_time": "2023-10-04T22:48:06.285157Z", "owner": 11, "role": null, "owner_name": "pwc.mss", "sensitivity": "amber", "severity": "high", "source_data_identifier": "208216", "start_time": "2023-10-04T22:41:01.235000Z", "status": "open", "version": 1, "workflow_name": "MSSP Offense Workbook", "custom_fields": {"Detection Source": "QRadar"}, "container_type": "case", "in_case": false, "current_phase": 51530, "tenant": 0, "parent_container": null, "node_guid": null}]

QRadar 威胁事件 - 208222 - UBA Offense - User crossed risk threshold, 208216 - PwC CaaS: Log4j Vulnerability Scanning

原文地址: https://www.cveoy.top/t/topic/o8gU 著作权归作者所有。请勿转载和采集!

免费AI点我,无需注册和登录