Documentation Index

Fetch the complete documentation index at: https://knowledge.catonetworks.com/llms.txt

Use this file to discover all available pages before exploring further.

Threat Prevention Stories with Near Real-Time Updates

Prev Next

Overview

XOps Threat Prevention stories help admins investigate threat indications by correlating relevant security events into a story. Cato is gradually enhancing these stories so they are updated in near real time, helping admins more quickly detect and respond to relevant threat activity.

This article lists the Threat Prevention story indications that support near real-time updates.

Prerequisites

  • XOps license

Indications with Near Real-Time Updates

The following Threat Prevention story indications support near real-time updates:

  • blocked_remote_tool_activity

  • chaser_access_phishing

  • chaser_cid_cryptopool

  • chaser_cid_pup

  • chaser_cnc_certificate

  • chaser_json_rpc

  • chaser_manual_block_ip_domain

  • chaser_MZ_download_with_impersonated_extension

  • chaser_ransomware_detection_high_confidence

  • chaser_risky_form_submission

  • chaser_sid_bl_ua

  • chaser_submition_to_phishing

  • download_single_dll_file

  • downloaded_tool_from_unofficial_domain

  • file_download_attempt_low_rep

  • hunt_Autoit_binary_download

  • hunt_download_protected_archive_cloud_services

  • hunt_http_client_download_script

  • hunt_kali

  • hunt_mega_api

  • hunt_netlify_suspicious_download

  • hunt_psexec_execution

  • hunt_sam_cnc_ta0011

  • hunt_sam_discovery_ta0007

  • hunt_sam_execution_ta0002

  • hunt_single_PowerShell_http

  • hunt_system_info_exfiltration

  • hunt_telegram_bot

  • hunt_winhttp_download_binary

  • remote_connectivity_activity

  • suspicious_bot_activity

  • suspicious_downloading_script_github

  • suspicious_file_download

  • suspicious_response_headers

  • suspicious_tool_download

  • suspicious_trello_api_usage

  • suspicious_web_shell_uploaded