You can view the details of a specific attack for a clearer picture of the key information related to the attack. The information can then be used to augment your policy settings and/or to initiate a response action, such as a TCP reset or endpoint quarantine rule.
To view the details of a specific attack, do the following:
Task
- Navigate to Analysis → <Admin Domain Name> → Attack Log.
-
Double-click on the alert for which you want to view the details.
The <Attack Name> panel opens on the right hand side.The details of the alert are displayed as follows:
Option Definition Summary - Event — Displays the general alert details like the time, direction, device, etc.
- Attacker/Target — Displays the IP address, hostname and other details of the attacker and the target. In case of mobile related alerts, the relevant fields related to mobile traffic are displayed.
- Attacked HIP Endpoint — You can view the details of attacked endpoint and perform forensics by navigating to the ePO console.
Details - Matched Signature — Displays information about the configured signature conditions that matches with the attack.
- Malware File — Displays the malware attack information such as the file name, file hash (MD5, SHA1, and SHA256), malware name, malware confidence, engine, size, description, and CVE ID.
Note
Malware File option is displayed only for malware attacks.
- Layer 7 — Displays the layer 7 information for protocols like HTTP, SMTP, etc.
Description Displays further details about the alert like the BTP score, RfSB, protection category, etc. - Reference — Displays the different IDs created for the alert and attack.
- Component Attacks — Displays the component attacks in case of reconnaissance attacks only.
- Signatures — Displays the signature associated with the attack.
- Comments — You can add any comments for the alert if any.
Alert Details panel .png)