zulip/zerver/webhooks/thinkst/fixtures/canary_file_access.json

33 lines
944 B
JSON

{
"ReverseDNS": "",
"CanaryName": "bar-foo",
"Description": "Shared File (Re)Opened",
"CanaryPort": 445,
"Timestamp": "2020-07-20 16:27:20 (UTC)",
"CanaryIP": "1.1.1.1",
"AlertType": "CanaryIncident",
"Intro": "Shared File (Re)Opened has been detected against one of your Canaries (bar-foo) at 1.1.1.1.",
"IncidentHash": "a7bb317ba2072415462233cef3bc615a",
"CanaryLocation": "dining room",
"SourceIP": "1.1.1.1",
"AdditionalDetails": [
[
"User",
"guest"
],
[
"Filename",
"secret/bar.doc"
],
[
"Additional Information",
"This file 'secret/bar.doc' was previously opened by the host 'zulip-dev' on 2020-07-20 16:18:56.\n\nIt was also opened 2 times before by the same host, on 2020-06-10 14:33:50, 2020-06-18 19:02:33."
],
[
"Background Context",
"You have had 20 incidents from 1.1.1.1 previously."
]
],
"CanaryID": "00000000aa8a310e"
}