Class: Google::Apis::SecuritycenterV1beta1::Indicator

Inherits:
Object
  • Object
show all
Includes:
Core::Hashable, Core::JsonObjectSupport
Defined in:
lib/google/apis/securitycenter_v1beta1/classes.rb,
lib/google/apis/securitycenter_v1beta1/representations.rb,
lib/google/apis/securitycenter_v1beta1/representations.rb

Overview

Represents what's commonly known as an Indicator of compromise (IoC) in computer forensics. This is an artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion. Reference: https://en.wikipedia.org/wiki/Indicator_of_compromise

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(**args) ⇒ Indicator

Returns a new instance of Indicator.



2205
2206
2207
# File 'lib/google/apis/securitycenter_v1beta1/classes.rb', line 2205

def initialize(**args)
   update!(**args)
end

Instance Attribute Details

#domainsArray<String>

List of domains associated to the Finding. Corresponds to the JSON property domains

Returns:

  • (Array<String>)


2192
2193
2194
# File 'lib/google/apis/securitycenter_v1beta1/classes.rb', line 2192

def domains
  @domains
end

#ip_addressesArray<String>

List of ip addresses associated to the Finding. Corresponds to the JSON property ipAddresses

Returns:

  • (Array<String>)


2197
2198
2199
# File 'lib/google/apis/securitycenter_v1beta1/classes.rb', line 2197

def ip_addresses
  @ip_addresses
end

#signaturesArray<Google::Apis::SecuritycenterV1beta1::ProcessSignature>

The list of matched signatures indicating that the given process is present in the environment. Corresponds to the JSON property signatures



2203
2204
2205
# File 'lib/google/apis/securitycenter_v1beta1/classes.rb', line 2203

def signatures
  @signatures
end

Instance Method Details

#update!(**args) ⇒ Object

Update properties of this object



2210
2211
2212
2213
2214
# File 'lib/google/apis/securitycenter_v1beta1/classes.rb', line 2210

def update!(**args)
  @domains = args[:domains] if args.key?(:domains)
  @ip_addresses = args[:ip_addresses] if args.key?(:ip_addresses)
  @signatures = args[:signatures] if args.key?(:signatures)
end