Trendmicro

LogZilla App Store application: Trendmicro

UnityOne

Rule Function

Trend Micro provides cybersecurity services via the UnityOne product. This rule parses several fields and sets corresponding user tags (see below).

Vendor Documentation

Incoming Log Format

The log format used is Trend Micro Event Format (TMEF) which is a customized event format developed by Trend Micro and is used by Trend Micro products for reporting event information. This format is space-separated key-value fields.

User Tags

TaggedTag NameField NameExampleDescription
event_classevent_class7610Tipping Point event class
ProtocolappIPnetwork protocol
SrcIPsrc185.153.64.126source IP address
SrcPortsptdynamicsource IP port
SrcIPv6src_ipv62001:0db8:85a3:0000:0000:8a2e:0370:7334source IPv6 address
DstIPdst134.122.53.164destination IP address
DestPortdptmysqldestination IP port
DstIPv6dst_ipv62001:0db8:85a3:0000:0000:8a2e:0370:7334destination IPv6 address
actactBlockaction taken
dvchostdvchostbwi1-ips-01device host
catcatReputationTipping Point category
requestMethodrequestMethodPOSTHTTP request method
dhostdhosttesthost.comdestination host
sourceTranslatedAddresssourceTranslatedAddress11.22.33.44proxy address
cs1cs1Customer-TestCompany-6335market
vendorTipping Pointvendor
productUnityOneproduct
version1.0.0.17OS version
event_description246text of event description
severity0event severity
cnt0event count
requestn/arequest URI
cs5vsms.edge.domain(unknown)

In addition two additional user tags are set based on the data in the message:

  1. Event Type
  2. MITRE Category

These are determined from the ATT&CK data included in the message.

HC Tags

HC_TAGS={
    "SrcIP",
    "DstIP",
    "SrcIPv6",
    "DstIPv6",
    "sourceTranslatedAddress"
}

Field Notes

SrcPort, DstPort

These fields are translated from port numbers on the incoming log message to port service in the user tag (such as port number 443 being translated to https).

Log Examples

Block outgoing connection

vendor="TippingPoint" product="UnityOne" version="1.0.0.17"
event_class="7610" event_description="Banned" severity="1" app="IP"
cnt="1" src="11.22.33.44" sourceTranslatedAddress="99.88.77.66"
spt="43763" dst="55.66.77.88" dpt="3306" act="Block"
cs1="DB-Market-BWI" cs5="vsms.edge.domain" dvchost="bwi1-ips-01"
cat="Reputation" src_ipv6="n/a" dst_ipv6="n/a" request="n/a"
requestMethod="n/a" dhost="n/a"

Permit Windows RDP connection

vendor="TippingPoint"	product="UnityOne" version="50.179.179.104"
event_class="5873" event_description="5873: RDP: Windows Remote Desktop
Access (ATT&CK T1076)" severity="1" app="TCP" cnt="1"
src="51.231.237.140" sourceTranslatedAddress="51.231.237.140"
spt="49799" dst="120.164.31.48" dpt="3389" act="Permit"
cs1="DB-Market-BWI" cs5="vsms.edge.domain" dvchost="bwi1-ips-01"
cat="Security Policy" src_ipv6="n/a" dst_ipv6="n/a" request="n/a"
requestMethod="n/a" dhost="n/a"
Trendmicro | LogZilla Documentation