SonicOS 8 Rules and Policies for Classic Mode

Table of Contents

Indicator of Compromise (IoC) Support – Hashes

Indicators of compromise (IOCs) are forensic evidence of discrepancies, or unusual activities in the organization's network, that help identify security threats, data breaches, insider threats, and more before any harm occurs. IOCs act not just as a warning sign for impending attacks, but they also help in analyzing what has happened. By learning about possible security threats, organizations can deploy their counter security measures to limit or prevent damage to their network.

The Indicator of Compromise (IoC) – Hashes feature in SonicOS enables administrators to block file transfers based on known malicious or unwanted file hashes. By leveraging a custom-defined list of file hashes, SonicOS can detect and prevent the transfer of identified threats across the network perimeter.

When enabled, SonicOS inspects files traversing supported protocols and compares their computed hash values against the configured IoC hash lists. If a match is detected, the file transfer is blocked and an event is generated.

Key Features

Supports custom hash list creation and management

  • Blocks files based on exact hash match
  • Supports up to 500K hash entries
  • Automatically prevents duplicate hash entries
  • Generates detailed log entries for matched events
  • Integrates with Network Security Manager (NSM) for monitoring and reporting

Supported Hash Types

SonicOS supports the following hash algorithms:

  • MD5
  • SHA-1
  • SHA-256

SHA-256 is recommended for improved accuracy and security.