Overview
XOps Threat Prevention stories help admins investigate threat indications by correlating relevant security events into a story. Cato is gradually enhancing these stories so they are updated in near real time, helping admins more quickly detect and respond to relevant threat activity.
This article lists the Threat Prevention story indications that support near real-time updates.
Prerequisites
XOps license
Indications with Near Real-Time Updates
The following Threat Prevention story indications support near real-time updates:
blocked_remote_tool_activity
chaser_access_phishing
chaser_cid_cryptopool
chaser_cid_pup
chaser_cnc_certificate
chaser_json_rpc
chaser_manual_block_ip_domain
chaser_MZ_download_with_impersonated_extension
chaser_ransomware_detection_high_confidence
chaser_risky_form_submission
chaser_sid_bl_ua
chaser_submition_to_phishing
download_single_dll_file
downloaded_tool_from_unofficial_domain
file_download_attempt_low_rep
hunt_Autoit_binary_download
hunt_download_protected_archive_cloud_services
hunt_http_client_download_script
hunt_kali
hunt_mega_api
hunt_netlify_suspicious_download
hunt_psexec_execution
hunt_sam_cnc_ta0011
hunt_sam_discovery_ta0007
hunt_sam_execution_ta0002
hunt_single_PowerShell_http
hunt_system_info_exfiltration
hunt_telegram_bot
hunt_winhttp_download_binary
remote_connectivity_activity
suspicious_bot_activity
suspicious_downloading_script_github
suspicious_file_download
suspicious_response_headers
suspicious_tool_download
suspicious_trello_api_usage
suspicious_web_shell_uploaded