networkThreatDetails:arpSpoofDetails Fields
Man-in-the-Middle ARP spoof events are returned as
THREAT
events with
type=NETWORK
and a
networkThreatDetails:arpSpoofDetails
block with the following information:
"details": {
...,
"assessments": [...],
"networkThreatDetails": {
"arpSpoofDetails" {
"type": "ARP_SPOOF"
}
}
}
Field | Type | Description |
---|---|---|
|
String | Always
ARP_SPOOF |