test with new analysis layout
This commit is contained in:
@@ -80,3 +80,171 @@ export interface InterfaceProtocolPathAnalysisResponse {
|
||||
paths: InterfaceProtocolPathEvidence[];
|
||||
notes: string[];
|
||||
}
|
||||
|
||||
export interface ConversationEvidence {
|
||||
ingress_interface?: string | null;
|
||||
egress_interface?: string | null;
|
||||
src_ip_address?: string | null;
|
||||
src_mac_address?: string | null;
|
||||
dst_ip_address?: string | null;
|
||||
dst_mac_address?: string | null;
|
||||
src_port?: number | null;
|
||||
dst_port?: number | null;
|
||||
protocol: string;
|
||||
ethernet_protocol?: string | null;
|
||||
ip_protocol?: string | null;
|
||||
hostnames: string[];
|
||||
packet_count: number;
|
||||
byte_count: number;
|
||||
first_seen: string;
|
||||
last_seen: string;
|
||||
accept_count: number;
|
||||
drop_count: number;
|
||||
reject_count: number;
|
||||
unknown_count: number;
|
||||
}
|
||||
|
||||
export interface ConversationAnalysisResponse {
|
||||
since?: string | null;
|
||||
conversations: ConversationEvidence[];
|
||||
notes: string[];
|
||||
}
|
||||
|
||||
export interface LabelCountEvidence {
|
||||
label: string;
|
||||
packet_count: number;
|
||||
}
|
||||
|
||||
export interface HostPeerEvidence {
|
||||
ip_address?: string | null;
|
||||
mac_address?: string | null;
|
||||
packet_count: number;
|
||||
byte_count: number;
|
||||
last_seen: string;
|
||||
protocols: string[];
|
||||
}
|
||||
|
||||
export interface HostServiceEvidence {
|
||||
port?: number | null;
|
||||
protocol: string;
|
||||
packet_count: number;
|
||||
byte_count: number;
|
||||
last_seen: string;
|
||||
hostnames: string[];
|
||||
}
|
||||
|
||||
export interface HostIntelligenceEvidence {
|
||||
ip_address?: string | null;
|
||||
mac_address?: string | null;
|
||||
packet_count: number;
|
||||
byte_count: number;
|
||||
first_seen: string;
|
||||
last_seen: string;
|
||||
interfaces: string[];
|
||||
source_count: number;
|
||||
destination_count: number;
|
||||
hostnames: string[];
|
||||
top_protocols: LabelCountEvidence[];
|
||||
peers: HostPeerEvidence[];
|
||||
services: HostServiceEvidence[];
|
||||
}
|
||||
|
||||
export interface HostIntelligenceAnalysisResponse {
|
||||
since?: string | null;
|
||||
hosts: HostIntelligenceEvidence[];
|
||||
notes: string[];
|
||||
}
|
||||
|
||||
export interface DiscoveryActivityEvidence {
|
||||
category: string;
|
||||
protocol: string;
|
||||
ingress_interface?: string | null;
|
||||
egress_interface?: string | null;
|
||||
src_ip_address?: string | null;
|
||||
src_mac_address?: string | null;
|
||||
dst_ip_address?: string | null;
|
||||
dst_mac_address?: string | null;
|
||||
src_port?: number | null;
|
||||
dst_port?: number | null;
|
||||
hostnames: string[];
|
||||
packet_count: number;
|
||||
byte_count: number;
|
||||
first_seen: string;
|
||||
last_seen: string;
|
||||
}
|
||||
|
||||
export interface DiscoveryAnalysisResponse {
|
||||
since?: string | null;
|
||||
activities: DiscoveryActivityEvidence[];
|
||||
notes: string[];
|
||||
}
|
||||
|
||||
export interface ScanCandidateEvidence {
|
||||
src_ip_address?: string | null;
|
||||
src_mac_address?: string | null;
|
||||
packet_count: number;
|
||||
target_host_count: number;
|
||||
target_port_count: number;
|
||||
first_seen: string;
|
||||
last_seen: string;
|
||||
}
|
||||
|
||||
export interface BeaconCandidateEvidence {
|
||||
src_ip_address?: string | null;
|
||||
src_mac_address?: string | null;
|
||||
dst_ip_address?: string | null;
|
||||
dst_mac_address?: string | null;
|
||||
dst_port?: number | null;
|
||||
protocol: string;
|
||||
packet_count: number;
|
||||
avg_interval_seconds: number;
|
||||
jitter_ratio: number;
|
||||
first_seen: string;
|
||||
last_seen: string;
|
||||
}
|
||||
|
||||
export interface RareServiceEvidence {
|
||||
dst_ip_address?: string | null;
|
||||
dst_mac_address?: string | null;
|
||||
dst_port?: number | null;
|
||||
protocol: string;
|
||||
packet_count: number;
|
||||
client_count: number;
|
||||
hostnames: string[];
|
||||
last_seen: string;
|
||||
}
|
||||
|
||||
export interface ResetHeavyPathEvidence {
|
||||
src_ip_address?: string | null;
|
||||
src_mac_address?: string | null;
|
||||
dst_ip_address?: string | null;
|
||||
dst_mac_address?: string | null;
|
||||
dst_port?: number | null;
|
||||
total_packets: number;
|
||||
reset_count: number;
|
||||
reset_ratio: number;
|
||||
last_seen: string;
|
||||
}
|
||||
|
||||
export interface DropHeavyPathEvidence {
|
||||
src_ip_address?: string | null;
|
||||
src_mac_address?: string | null;
|
||||
dst_ip_address?: string | null;
|
||||
dst_mac_address?: string | null;
|
||||
protocol: string;
|
||||
total_packets: number;
|
||||
drop_count: number;
|
||||
reject_count: number;
|
||||
failure_ratio: number;
|
||||
last_seen: string;
|
||||
}
|
||||
|
||||
export interface AnomalyAnalysisResponse {
|
||||
since?: string | null;
|
||||
scan_candidates: ScanCandidateEvidence[];
|
||||
beacon_candidates: BeaconCandidateEvidence[];
|
||||
rare_services: RareServiceEvidence[];
|
||||
reset_heavy_paths: ResetHeavyPathEvidence[];
|
||||
drop_heavy_paths: DropHeavyPathEvidence[];
|
||||
notes: string[];
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user