01-08-2020 09:22 PM - edited 02-21-2020 09:49 AM
Hi All,
I have observed a internal to internal machine traffic and observed the event IOC_STATE_RECORD on my SIEM console.
This event flagged by the cisco firepower center (FMC), checked the traffic logs between the these two internal machines. Observed only IOC_STATE_RECORD related events and no firewall logs were found. Please let me know what is IOC_STATE_RECORD ? Is it something, do I need to pay attention for these kind of events. ?
01-09-2020 03:24 AM
Hello,
IOC States for Indication of Compromise.
Here is the Event Information:
To better have a translation of what an IOC_ID stands for you can grab them all at:
Go to FMC CLI and in expert mode raise your self to root and type the following command:
OmniQuery.pl -db mdb -e "select ioc_id,category,event_type,description from ioc\G;"
So you need to have the IOC_ID and find out what Compromise that is being detected, and if it is a false positive or not.
You can definitely after this program your SIEM to translate these events from IOC_ID to an actual text.
In some SIEMs the IOC_ID may be called another property of the event. example: iocState.value=11
Best Regards,
Luiz Silva
Best Regards,
Luiz
01-12-2020 05:02 AM
01-13-2020 12:19 AM
07-21-2021 09:57 AM
Can you provide us with official documentation for this issue?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide