Skip to content

[Infoblox] New CDFs#174

Open
mcdequiroz wants to merge 1 commit intomainfrom
markchesterdq-infoblox
Open

[Infoblox] New CDFs#174
mcdequiroz wants to merge 1 commit intomainfrom
markchesterdq-infoblox

Conversation

@mcdequiroz
Copy link
Copy Markdown
Collaborator

Add 10 new CDF under tm-v1-sigma-rules/third_party_logs/Infoblox to detect Infoblox threat-intel hits. Each rule matches vendorParsed content (InfobloxThreatProperty values or severity fields) to surface events such as MalwareDownload, Malicious_TDS, Phishing_Generic, Proxy_Generic, Suspicious_Nameserver/EmergentDomain/TDS, and high/medium risk severities. Rules target THIRD_PARTY_LOG product Infoblox, use level: info and taxonomy: tm-v1 to capture vendor-flagged detections.

Add 10 new CDF under tm-v1-sigma-rules/third_party_logs/Infoblox to detect Infoblox threat-intel hits. Each rule matches vendorParsed content (InfobloxThreatProperty values or severity fields) to surface events such as MalwareDownload, Malicious_TDS, Phishing_Generic, Proxy_Generic, Suspicious_Nameserver/EmergentDomain/TDS, and high/medium risk severities. Rules target THIRD_PARTY_LOG product Infoblox, use level: info and taxonomy: tm-v1 to capture vendor-flagged detections.
@mcdequiroz mcdequiroz changed the title Add Infoblox Sigma rules for third-party logs [Infoblox] New CDFs Mar 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant