The ToolAlert class carries additional information related to the use of attack tools or malevolent programs such as Trojan horses and can be used by the analyzer when it is able to identify these tools. It is intended to group one or more previously-sent alerts together, to say "these alerts were all the result of someone using this tool".
digraph ToolAlert { graph [bb="0,0,176,92", rankdir=LR ]; node [label="\N"]; ToolAlert [height=1.2778, label=<<table BORDER="0" CELLBORDER="1" CELLSPACING="0"> <tr > <td BGCOLOR="#737373" HREF="/idmef_parser/IDMEF/ToolAlert.html" TITLE="The ToolAlert class carries additional information related to the use of attack tools or malevolent programs such as Trojan horses and can be used by the analyzer when it is able to identify these tools. It is intended to group one or more previously-sent alerts together, to say "these alerts were all the result of someone using this tool". ">ToolAlert</td> </tr>" %<tr><td BGCOLOR="#BFBFBF" HREF="/idmef_parser/IDMEF/ToolAlert.html" TITLE="The reason for grouping the alerts together, for example, the name of a particular tool.">[STRING] name (1) </td></tr>%<tr><td BGCOLOR="#BFBFBF" HREF="/idmef_parser/IDMEF/ToolAlert.html" TITLE="The command or operation that the tool was asked to perform, for example, a BackOrifice ping.">[STRING] command (0..1) </td></tr>%<tr><td BGCOLOR="#BFBFBF" HREF="/idmef_parser/IDMEF/ToolAlert.html" TITLE="The list of alert identifiers that are related to this alert. Because alert identifiers are only unique across the alerts sent by a single analyzer, the optional "analyzerid" attribute of "alertident" should be used to identify the analyzer that a particular alert came from. If the "analyzerid" is not provided, the alert is assumed to have come from the same analyzer that is sending the ToolAlert.">[STRING] alertident (1..*) </td></tr>%</table>>, pos="88,46", shape=plaintext, width=2.4444]; }
The reason for grouping the alerts together, for example, the name of a particular tool.
The command or operation that the tool was asked to perform, for example, a BackOrifice ping.
The list of alert identifiers that are related to this alert. Because alert identifiers are only unique across the alerts sent by a single analyzer, the optional "analyzerid" attribute of "alertident" should be used to identify the analyzer that a particular alert came from. If the "analyzerid" is not provided, the alert is assumed to have come from the same analyzer that is sending the ToolAlert.