public class AlertExtraInfo extends AbstractModel
header, skipSign
Constructor and Description |
---|
AlertExtraInfo() |
AlertExtraInfo(AlertExtraInfo source)
NOTE: Any ambiguous key set via .set("AnyKey", "value") will be a shallow copy,
and any explicit key, i.e Foo, set via .setFoo("value") will be a deep copy.
|
Modifier and Type | Method and Description |
---|---|
String |
getAffectedFileName()
Get 受影响文件名
|
String |
getAttackContent()
Get 攻击内容
|
String |
getAttackDomain()
Get 被攻击域名
|
String |
getAttackEventDesc()
Get 攻击事件描述
|
String |
getAttackIPProfile()
Get 攻击IP画像
|
String |
getAttackIPTags()
Get 攻击IP标签
|
String |
getBehavioralCharacteristics()
Get 行为特征
|
String |
getCallbackAddressPortrait()
Get 回连地址画像
|
String |
getCallbackAddressTag()
Get 回连地址标签
|
String |
getClassFileMD5()
Get 类文件MD5
|
String |
getClassFileSize()
Get 类文件大小
|
String |
getClassLoader()
Get 所属类加载器
|
String |
getClassName()
Get 类名
|
String |
getCommandContent()
Get 命令内容
|
String |
getCommandList()
Get 命令列表
|
String |
getComment()
Get 注释
|
String |
getCVE()
Get 公共漏洞和暴露
|
String |
getDecoyPath()
Get 诱饵路径
|
String |
getDescription()
Get 事件描述
|
String |
getDifferent()
Get 变更内容
|
String |
getEventType()
Get 事件类型
|
String |
getExecutedCommand()
Get 执行命令
|
String |
getFileLastAccessTime()
Get 文件最近访问时间
|
String |
getFileMD5()
Get 文件MD5
|
String |
getFileModifyTime()
Get 文件修改时间
|
String |
getFileName()
Get 文件名
|
String |
getFilePath()
Get 文件路径
|
String |
getFilePermission()
Get 文件权限
|
String |
getFileSize()
Get 文件大小
|
String |
getFileType()
Get 文件类型(容器文件篡改)
|
KeyValue[] |
getFromLogAnalysisData()
Get 来源于日志分析的信息字段
|
String |
getHitHoneyPot()
Get 命中蜜罐
|
String |
getHitProbe()
Get 命中探针
|
String |
getHitStrategy()
Get 主机防护命中策略,是策略ID和策略名称的组合
|
String |
getHttpLog()
Get HTTP日志
|
String |
getInheritedInterface()
Get 继承接口
|
String |
getLeakAPI()
Get 泄漏API
|
String |
getLeakContent()
Get 泄漏内容
|
String |
getLogID()
Get 日志ID
|
String |
getLoginUserName()
Get 登录用户名
|
String |
getMaliciousProcessFileMD5()
Get 恶意进程文件MD5
|
String |
getMaliciousProcessFileSize()
Get 恶意进程文件大小
|
String |
getMaliciousProcessNamePID()
Get 恶意进程名(PID)
|
String |
getMaliciousProcessPath()
Get 恶意进程路径
|
String |
getMaliciousProcessStartTime()
Get 恶意进程启动时间
|
String |
getMaliciousRequestDomain()
Get 恶意请求域名(容器恶意外联)
|
String |
getNewPermissions()
Get 新增权限
|
String |
getParentClassName()
Get 父类名
|
String |
getParentProcess()
Get 父进程
|
String |
getPayloadContent()
Get 载荷内容
|
String |
getPID()
Get PID
|
String |
getPodID()
Get 容器PodID
|
String |
getPodName()
Get 容器Pod名
|
String |
getProcessCommandLine()
Get 进程命令行
|
String |
getProcessInfo()
Get 进程信息
|
String |
getProcessMD5()
Get 进程MD5
|
String |
getProcessName()
Get 进程名
|
String |
getProcessNamePID()
Get 进程名(PID)
|
String |
getProcessPath()
Get 进程路径
|
String |
getProcessPermissions()
Get 进程权限
|
String |
getProtocolPort()
Get 协议端口
|
String |
getRecentAccessTime()
Get 最近访问时间
|
String |
getRecentModifyTime()
Get 最近修改时间
|
RelatedEvent |
getRelateEvent()
Get 相关攻击事件
|
String |
getRequestHeaders()
Get 请求头
|
String |
getRequestMethod()
Get 请求方式
|
String |
getRequestObject()
Get 请求对象(容器K8sAPI异常请求)
|
String |
getRequestURI()
Get 请求资源(容器K8sAPI异常请求)
|
String |
getRequestUser()
Get 发起请求用户(容器K8sAPI异常请求)
|
String |
getResponse()
Get Http响应
|
String |
getResponseObject()
Get 响应对象(容器K8sAPI异常请求)
|
String |
getRule()
Get 命中规则
|
String |
getRuleDesc()
Get 规则描述
|
String |
getRuleType()
Get 规则类型(容器K8sAPI异常请求)
|
String |
getSecretID()
Get secretID
|
String |
getServiceProcess()
Get 服务进程
|
String |
getSourceIP()
Get 来源IP(容器K8sAPI异常请求)
|
String |
getStartupUser()
Get 启动用户
|
String |
getStrategyID()
Get 主机防护策略ID
|
String |
getStrategyName()
Get 主机防护策略名称
|
String |
getSystemCall()
Get 系统调用
|
String |
getTargetAddress()
Get 目标地址(容器反弹shell)
|
String |
getTIType()
Get 标签特征(容器恶意外联)
|
String |
getUserAgent()
Get user_agent
|
String |
getUserGroup()
Get 用户所属组
|
String |
getUserNameAndPwd()
Get 使用用户名&密码
|
String |
getVerb()
Get 操作类型verb
|
String |
getVirusFileTags()
Get 病毒文件标签
|
String |
getVirusName()
Get 病毒名
|
String |
getVulnerabilityName()
Get 漏洞名称
|
void |
setAffectedFileName(String AffectedFileName)
Set 受影响文件名
|
void |
setAttackContent(String AttackContent)
Set 攻击内容
|
void |
setAttackDomain(String AttackDomain)
Set 被攻击域名
|
void |
setAttackEventDesc(String AttackEventDesc)
Set 攻击事件描述
|
void |
setAttackIPProfile(String AttackIPProfile)
Set 攻击IP画像
|
void |
setAttackIPTags(String AttackIPTags)
Set 攻击IP标签
|
void |
setBehavioralCharacteristics(String BehavioralCharacteristics)
Set 行为特征
|
void |
setCallbackAddressPortrait(String CallbackAddressPortrait)
Set 回连地址画像
|
void |
setCallbackAddressTag(String CallbackAddressTag)
Set 回连地址标签
|
void |
setClassFileMD5(String ClassFileMD5)
Set 类文件MD5
|
void |
setClassFileSize(String ClassFileSize)
Set 类文件大小
|
void |
setClassLoader(String ClassLoader)
Set 所属类加载器
|
void |
setClassName(String ClassName)
Set 类名
|
void |
setCommandContent(String CommandContent)
Set 命令内容
|
void |
setCommandList(String CommandList)
Set 命令列表
|
void |
setComment(String Comment)
Set 注释
|
void |
setCVE(String CVE)
Set 公共漏洞和暴露
|
void |
setDecoyPath(String DecoyPath)
Set 诱饵路径
|
void |
setDescription(String Description)
Set 事件描述
|
void |
setDifferent(String Different)
Set 变更内容
|
void |
setEventType(String EventType)
Set 事件类型
|
void |
setExecutedCommand(String ExecutedCommand)
Set 执行命令
|
void |
setFileLastAccessTime(String FileLastAccessTime)
Set 文件最近访问时间
|
void |
setFileMD5(String FileMD5)
Set 文件MD5
|
void |
setFileModifyTime(String FileModifyTime)
Set 文件修改时间
|
void |
setFileName(String FileName)
Set 文件名
|
void |
setFilePath(String FilePath)
Set 文件路径
|
void |
setFilePermission(String FilePermission)
Set 文件权限
|
void |
setFileSize(String FileSize)
Set 文件大小
|
void |
setFileType(String FileType)
Set 文件类型(容器文件篡改)
|
void |
setFromLogAnalysisData(KeyValue[] FromLogAnalysisData)
Set 来源于日志分析的信息字段
|
void |
setHitHoneyPot(String HitHoneyPot)
Set 命中蜜罐
|
void |
setHitProbe(String HitProbe)
Set 命中探针
|
void |
setHitStrategy(String HitStrategy)
Set 主机防护命中策略,是策略ID和策略名称的组合
|
void |
setHttpLog(String HttpLog)
Set HTTP日志
|
void |
setInheritedInterface(String InheritedInterface)
Set 继承接口
|
void |
setLeakAPI(String LeakAPI)
Set 泄漏API
|
void |
setLeakContent(String LeakContent)
Set 泄漏内容
|
void |
setLogID(String LogID)
Set 日志ID
|
void |
setLoginUserName(String LoginUserName)
Set 登录用户名
|
void |
setMaliciousProcessFileMD5(String MaliciousProcessFileMD5)
Set 恶意进程文件MD5
|
void |
setMaliciousProcessFileSize(String MaliciousProcessFileSize)
Set 恶意进程文件大小
|
void |
setMaliciousProcessNamePID(String MaliciousProcessNamePID)
Set 恶意进程名(PID)
|
void |
setMaliciousProcessPath(String MaliciousProcessPath)
Set 恶意进程路径
|
void |
setMaliciousProcessStartTime(String MaliciousProcessStartTime)
Set 恶意进程启动时间
|
void |
setMaliciousRequestDomain(String MaliciousRequestDomain)
Set 恶意请求域名(容器恶意外联)
|
void |
setNewPermissions(String NewPermissions)
Set 新增权限
|
void |
setParentClassName(String ParentClassName)
Set 父类名
|
void |
setParentProcess(String ParentProcess)
Set 父进程
|
void |
setPayloadContent(String PayloadContent)
Set 载荷内容
|
void |
setPID(String PID)
Set PID
|
void |
setPodID(String PodID)
Set 容器PodID
|
void |
setPodName(String PodName)
Set 容器Pod名
|
void |
setProcessCommandLine(String ProcessCommandLine)
Set 进程命令行
|
void |
setProcessInfo(String ProcessInfo)
Set 进程信息
|
void |
setProcessMD5(String ProcessMD5)
Set 进程MD5
|
void |
setProcessName(String ProcessName)
Set 进程名
|
void |
setProcessNamePID(String ProcessNamePID)
Set 进程名(PID)
|
void |
setProcessPath(String ProcessPath)
Set 进程路径
|
void |
setProcessPermissions(String ProcessPermissions)
Set 进程权限
|
void |
setProtocolPort(String ProtocolPort)
Set 协议端口
|
void |
setRecentAccessTime(String RecentAccessTime)
Set 最近访问时间
|
void |
setRecentModifyTime(String RecentModifyTime)
Set 最近修改时间
|
void |
setRelateEvent(RelatedEvent RelateEvent)
Set 相关攻击事件
|
void |
setRequestHeaders(String RequestHeaders)
Set 请求头
|
void |
setRequestMethod(String RequestMethod)
Set 请求方式
|
void |
setRequestObject(String RequestObject)
Set 请求对象(容器K8sAPI异常请求)
|
void |
setRequestURI(String RequestURI)
Set 请求资源(容器K8sAPI异常请求)
|
void |
setRequestUser(String RequestUser)
Set 发起请求用户(容器K8sAPI异常请求)
|
void |
setResponse(String Response)
Set Http响应
|
void |
setResponseObject(String ResponseObject)
Set 响应对象(容器K8sAPI异常请求)
|
void |
setRule(String Rule)
Set 命中规则
|
void |
setRuleDesc(String RuleDesc)
Set 规则描述
|
void |
setRuleType(String RuleType)
Set 规则类型(容器K8sAPI异常请求)
|
void |
setSecretID(String SecretID)
Set secretID
|
void |
setServiceProcess(String ServiceProcess)
Set 服务进程
|
void |
setSourceIP(String SourceIP)
Set 来源IP(容器K8sAPI异常请求)
|
void |
setStartupUser(String StartupUser)
Set 启动用户
|
void |
setStrategyID(String StrategyID)
Set 主机防护策略ID
|
void |
setStrategyName(String StrategyName)
Set 主机防护策略名称
|
void |
setSystemCall(String SystemCall)
Set 系统调用
|
void |
setTargetAddress(String TargetAddress)
Set 目标地址(容器反弹shell)
|
void |
setTIType(String TIType)
Set 标签特征(容器恶意外联)
|
void |
setUserAgent(String UserAgent)
Set user_agent
|
void |
setUserGroup(String UserGroup)
Set 用户所属组
|
void |
setUserNameAndPwd(String UserNameAndPwd)
Set 使用用户名&密码
|
void |
setVerb(String Verb)
Set 操作类型verb
|
void |
setVirusFileTags(String VirusFileTags)
Set 病毒文件标签
|
void |
setVirusName(String VirusName)
Set 病毒名
|
void |
setVulnerabilityName(String VulnerabilityName)
Set 漏洞名称
|
void |
toMap(HashMap<String,String> map,
String prefix)
Internal implementation, normal users should not use it.
|
any, fromJsonString, getBinaryParams, GetHeader, getMultipartRequestParams, getSkipSign, isStream, set, SetHeader, setParamArrayObj, setParamArraySimple, setParamObj, setParamSimple, setSkipSign, toJsonString
public AlertExtraInfo()
public AlertExtraInfo(AlertExtraInfo source)
public RelatedEvent getRelateEvent()
public void setRelateEvent(RelatedEvent RelateEvent)
RelateEvent
- 相关攻击事件public String getLeakContent()
public void setLeakContent(String LeakContent)
LeakContent
- 泄漏内容public String getLeakAPI()
public void setLeakAPI(String LeakAPI)
LeakAPI
- 泄漏APIpublic String getSecretID()
public void setSecretID(String SecretID)
SecretID
- secretIDpublic String getRule()
public void setRule(String Rule)
Rule
- 命中规则public String getRuleDesc()
public void setRuleDesc(String RuleDesc)
RuleDesc
- 规则描述public String getProtocolPort()
public void setProtocolPort(String ProtocolPort)
ProtocolPort
- 协议端口public String getAttackContent()
public void setAttackContent(String AttackContent)
AttackContent
- 攻击内容public String getAttackIPProfile()
public void setAttackIPProfile(String AttackIPProfile)
AttackIPProfile
- 攻击IP画像public String getAttackIPTags()
public void setAttackIPTags(String AttackIPTags)
AttackIPTags
- 攻击IP标签public String getRequestMethod()
public void setRequestMethod(String RequestMethod)
RequestMethod
- 请求方式public String getHttpLog()
public void setHttpLog(String HttpLog)
HttpLog
- HTTP日志public String getAttackDomain()
public void setAttackDomain(String AttackDomain)
AttackDomain
- 被攻击域名public String getFilePath()
public void setFilePath(String FilePath)
FilePath
- 文件路径public String getUserAgent()
public void setUserAgent(String UserAgent)
UserAgent
- user_agentpublic String getRequestHeaders()
public void setRequestHeaders(String RequestHeaders)
RequestHeaders
- 请求头public String getLoginUserName()
public void setLoginUserName(String LoginUserName)
LoginUserName
- 登录用户名public String getVulnerabilityName()
public void setVulnerabilityName(String VulnerabilityName)
VulnerabilityName
- 漏洞名称public String getCVE()
public void setCVE(String CVE)
CVE
- 公共漏洞和暴露public String getServiceProcess()
public void setServiceProcess(String ServiceProcess)
ServiceProcess
- 服务进程public String getFileName()
public void setFileName(String FileName)
FileName
- 文件名public String getFileSize()
public void setFileSize(String FileSize)
FileSize
- 文件大小public String getFileMD5()
public void setFileMD5(String FileMD5)
FileMD5
- 文件MD5public String getFileLastAccessTime()
public void setFileLastAccessTime(String FileLastAccessTime)
FileLastAccessTime
- 文件最近访问时间public String getFileModifyTime()
public void setFileModifyTime(String FileModifyTime)
FileModifyTime
- 文件修改时间public String getRecentAccessTime()
public void setRecentAccessTime(String RecentAccessTime)
RecentAccessTime
- 最近访问时间public String getRecentModifyTime()
public void setRecentModifyTime(String RecentModifyTime)
RecentModifyTime
- 最近修改时间public String getVirusName()
public void setVirusName(String VirusName)
VirusName
- 病毒名public String getVirusFileTags()
public void setVirusFileTags(String VirusFileTags)
VirusFileTags
- 病毒文件标签public String getBehavioralCharacteristics()
public void setBehavioralCharacteristics(String BehavioralCharacteristics)
BehavioralCharacteristics
- 行为特征public String getProcessNamePID()
public void setProcessNamePID(String ProcessNamePID)
ProcessNamePID
- 进程名(PID)public String getProcessPath()
public void setProcessPath(String ProcessPath)
ProcessPath
- 进程路径public String getProcessCommandLine()
public void setProcessCommandLine(String ProcessCommandLine)
ProcessCommandLine
- 进程命令行public String getProcessPermissions()
public void setProcessPermissions(String ProcessPermissions)
ProcessPermissions
- 进程权限public String getExecutedCommand()
public void setExecutedCommand(String ExecutedCommand)
ExecutedCommand
- 执行命令public String getAffectedFileName()
public void setAffectedFileName(String AffectedFileName)
AffectedFileName
- 受影响文件名public String getDecoyPath()
public void setDecoyPath(String DecoyPath)
DecoyPath
- 诱饵路径public String getMaliciousProcessFileSize()
public void setMaliciousProcessFileSize(String MaliciousProcessFileSize)
MaliciousProcessFileSize
- 恶意进程文件大小public String getMaliciousProcessFileMD5()
public void setMaliciousProcessFileMD5(String MaliciousProcessFileMD5)
MaliciousProcessFileMD5
- 恶意进程文件MD5public String getMaliciousProcessNamePID()
public void setMaliciousProcessNamePID(String MaliciousProcessNamePID)
MaliciousProcessNamePID
- 恶意进程名(PID)public String getMaliciousProcessPath()
public void setMaliciousProcessPath(String MaliciousProcessPath)
MaliciousProcessPath
- 恶意进程路径public String getMaliciousProcessStartTime()
public void setMaliciousProcessStartTime(String MaliciousProcessStartTime)
MaliciousProcessStartTime
- 恶意进程启动时间public String getCommandContent()
public void setCommandContent(String CommandContent)
CommandContent
- 命令内容public String getStartupUser()
public void setStartupUser(String StartupUser)
StartupUser
- 启动用户public String getUserGroup()
public void setUserGroup(String UserGroup)
UserGroup
- 用户所属组public String getNewPermissions()
public void setNewPermissions(String NewPermissions)
NewPermissions
- 新增权限public String getParentProcess()
public void setParentProcess(String ParentProcess)
ParentProcess
- 父进程public String getClassName()
public void setClassName(String ClassName)
ClassName
- 类名public String getClassLoader()
public void setClassLoader(String ClassLoader)
ClassLoader
- 所属类加载器public String getClassFileSize()
public void setClassFileSize(String ClassFileSize)
ClassFileSize
- 类文件大小public String getClassFileMD5()
public void setClassFileMD5(String ClassFileMD5)
ClassFileMD5
- 类文件MD5public String getParentClassName()
public void setParentClassName(String ParentClassName)
ParentClassName
- 父类名public String getInheritedInterface()
public void setInheritedInterface(String InheritedInterface)
InheritedInterface
- 继承接口public String getComment()
public void setComment(String Comment)
Comment
- 注释public String getPayloadContent()
public void setPayloadContent(String PayloadContent)
PayloadContent
- 载荷内容public String getCallbackAddressPortrait()
public void setCallbackAddressPortrait(String CallbackAddressPortrait)
CallbackAddressPortrait
- 回连地址画像public String getCallbackAddressTag()
public void setCallbackAddressTag(String CallbackAddressTag)
CallbackAddressTag
- 回连地址标签public String getProcessMD5()
public void setProcessMD5(String ProcessMD5)
ProcessMD5
- 进程MD5public String getFilePermission()
public void setFilePermission(String FilePermission)
FilePermission
- 文件权限public KeyValue[] getFromLogAnalysisData()
public void setFromLogAnalysisData(KeyValue[] FromLogAnalysisData)
FromLogAnalysisData
- 来源于日志分析的信息字段public String getHitProbe()
public void setHitProbe(String HitProbe)
HitProbe
- 命中探针public String getHitHoneyPot()
public void setHitHoneyPot(String HitHoneyPot)
HitHoneyPot
- 命中蜜罐public String getCommandList()
public void setCommandList(String CommandList)
CommandList
- 命令列表public String getAttackEventDesc()
public void setAttackEventDesc(String AttackEventDesc)
AttackEventDesc
- 攻击事件描述public String getProcessInfo()
public void setProcessInfo(String ProcessInfo)
ProcessInfo
- 进程信息public String getUserNameAndPwd()
public void setUserNameAndPwd(String UserNameAndPwd)
UserNameAndPwd
- 使用用户名&密码public String getStrategyID()
public void setStrategyID(String StrategyID)
StrategyID
- 主机防护策略IDpublic String getStrategyName()
public void setStrategyName(String StrategyName)
StrategyName
- 主机防护策略名称public String getHitStrategy()
public void setHitStrategy(String HitStrategy)
HitStrategy
- 主机防护命中策略,是策略ID和策略名称的组合public String getProcessName()
public void setProcessName(String ProcessName)
ProcessName
- 进程名public String getPID()
public void setPID(String PID)
PID
- PIDpublic String getPodName()
public void setPodName(String PodName)
PodName
- 容器Pod名public String getPodID()
public void setPodID(String PodID)
PodID
- 容器PodIDpublic String getResponse()
public void setResponse(String Response)
Response
- Http响应public String getSystemCall()
public void setSystemCall(String SystemCall)
SystemCall
- 系统调用public String getVerb()
public void setVerb(String Verb)
Verb
- 操作类型verbpublic String getLogID()
public void setLogID(String LogID)
LogID
- 日志IDpublic String getDifferent()
public void setDifferent(String Different)
Different
- 变更内容public String getEventType()
public void setEventType(String EventType)
EventType
- 事件类型public String getDescription()
public void setDescription(String Description)
Description
- 事件描述public String getTargetAddress()
public void setTargetAddress(String TargetAddress)
TargetAddress
- 目标地址(容器反弹shell)public String getMaliciousRequestDomain()
public void setMaliciousRequestDomain(String MaliciousRequestDomain)
MaliciousRequestDomain
- 恶意请求域名(容器恶意外联)public String getRuleType()
public void setRuleType(String RuleType)
RuleType
- 规则类型(容器K8sAPI异常请求)public String getRequestURI()
public void setRequestURI(String RequestURI)
RequestURI
- 请求资源(容器K8sAPI异常请求)public String getRequestUser()
public void setRequestUser(String RequestUser)
RequestUser
- 发起请求用户(容器K8sAPI异常请求)public String getRequestObject()
public void setRequestObject(String RequestObject)
RequestObject
- 请求对象(容器K8sAPI异常请求)public String getResponseObject()
public void setResponseObject(String ResponseObject)
ResponseObject
- 响应对象(容器K8sAPI异常请求)public String getFileType()
public void setFileType(String FileType)
FileType
- 文件类型(容器文件篡改)public String getTIType()
public void setTIType(String TIType)
TIType
- 标签特征(容器恶意外联)public String getSourceIP()
public void setSourceIP(String SourceIP)
SourceIP
- 来源IP(容器K8sAPI异常请求)Copyright © 2024. All rights reserved.