Class: Google::Apis::SecuritycenterV1beta2::Indicator

Inherits:
Object
  • Object
show all
Includes:
Core::Hashable, Core::JsonObjectSupport
Defined in:
lib/google/apis/securitycenter_v1beta2/classes.rb,
lib/google/apis/securitycenter_v1beta2/representations.rb,
lib/google/apis/securitycenter_v1beta2/representations.rb

Overview

Represents what's commonly known as an Indicator of compromise (IoC) in computer forensics. This is an artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion. Reference: https://en.wikipedia.org/wiki/Indicator_of_compromise

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(**args) ⇒ Indicator

Returns a new instance of Indicator.



1626
1627
1628
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 1626

def initialize(**args)
   update!(**args)
end

Instance Attribute Details

#domainsArray<String>

List of domains associated to the Finding. Corresponds to the JSON property domains

Returns:

  • (Array<String>)


1613
1614
1615
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 1613

def domains
  @domains
end

#ip_addressesArray<String>

List of ip addresses associated to the Finding. Corresponds to the JSON property ipAddresses

Returns:

  • (Array<String>)


1618
1619
1620
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 1618

def ip_addresses
  @ip_addresses
end

#signaturesArray<Google::Apis::SecuritycenterV1beta2::ProcessSignature>

The list of matched signatures indicating that the given process is present in the environment. Corresponds to the JSON property signatures



1624
1625
1626
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 1624

def signatures
  @signatures
end

Instance Method Details

#update!(**args) ⇒ Object

Update properties of this object



1631
1632
1633
1634
1635
# File 'lib/google/apis/securitycenter_v1beta2/classes.rb', line 1631

def update!(**args)
  @domains = args[:domains] if args.key?(:domains)
  @ip_addresses = args[:ip_addresses] if args.key?(:ip_addresses)
  @signatures = args[:signatures] if args.key?(:signatures)
end