This topic covers the following information:
About the alerts Tab
Fields in the alerts Tab
Details for a rule-specific alert grouping
About the Alerts tab
An IPS platform offers three views of malware events. Two views list malware alerts (both MVX-verified malware events and MVX-correlated IPS events), and the third view lists callback activity associated with malware. When you choose Alerts > Alerts, the Hosts tab is selected by default.
To view the alerts grouped by attack rule name, click the Alerts link in the control bar.
The Alerts tab lists all malware alerts and IPS alerts, grouped by attack rule name only. Multiple alerts associated with the same signature rule are combined in a single entry in the list.
Fields in the Alerts tab
The Alerts tab lists MVX-verified events that occurred within the selected time frame, consolidated by attack rule name only, and sorted in reverse chronological order. On an IPS platform, the list includes IPS events and can optionally include acknowledged IPS alerts.
The following table describes the fields in this view of alerts grouped by attack
Column | Description |
|---|---|
| If the entry represents multiple alerts, click the purple triangle to show the individual alerts in the grouping rather than the alert grouping. |
| Click the gold triangle to expand the row to display additional results. |
Type | Attack detection type: • Domain Match—Domain matching on DNS requests. • Infection Match—Pattern matching from a full or partial URL. • Malware Callback—Communication with a botnet server. • Malware Object—Local MVX engine rule matches a URL, an MD5 checksum, or both. • Web Infection—Local MVX engine rule matches a URL. |
ID | System-internal identification number for the alert. To display detailed information about this alert, click the linked text. |
FT | Type of file analyzed from the traffic stream. File types include the following: • DLL (Dynamic Link Library) • Archived files (ZIP, RAR, TNEF, and 7-ZIP) • XFF (X-Forwarding) • XOR (eXclusive-OR encoded) obfuscated Web objects • TCP Reset and Out-of-Band Blocking For more information, see the Network Security User Guide. |
Malware | Name of malware or attack. |
Severity | The icon represents the event severity level. Event severity estimates the likelihood that the targeted host was compromised by the event. The following types of icons are used:
A row of 7 ‑ 10 red dots indicates acriticalseverity level (threat score 7 ‑ 10).
A row of 4 ‑ 6 orange dots indicates amajorseverity level (threat score 4 ‑ 6).
A row of 1 ‑ 3 gold dots indicates aminorseverity level (threat score 1 ‑ 3). |
Time | Date and time of the most recent occurrence of the attack. |
Source IP | IP address of the victim that received the attack. This address corresponds to the Attacked Port and Src IP fields in the drill-down view. |
Target IP | IP address of the attacker. |
URL/MD5sum | URL or MD5 checksum that triggered the Malware Object or Web Infection alert. |
Location | Location in which the server is located, if known. This column is displayed only if geo-location data is loaded. |
SC Version | Version number of the security content that was in use when the event occurred. |
Badges | On an IPS platform, this column displays badges that indicate analysis of alerts represented by the entry:
The entry represents one or more IPS alerts. For more information, see the following topics: • Malware Events and IPS Events • IPS Event and Alert Management
The entry represents one or more non-IPS alerts in which data theft occurred. In the Alerts tab, Data Theft badges are not hyperlinked. For more information, see the Network Security User Guide. |
On any Network Security appliance enabled for Advanced Threat Analysis (ATI), Threat Info badges can appear in this column. The color of the badge indicates the level of risk that the threat poses to your network:
A red badge indicates an ATI alert for a threat that poses a high risk.
An orange badge indicates an ATI alert for a threat that poses a medium level of risk.
An amber badge indicates an ATI alert for a threat that poses a low risk to your network. For managed Network Security appliances, ATI badges and ATI information are visible from the Central Management System Web UI only. For more information about ATI, see the Network Security User Guide. For an ATI alert, the threat level measures the level of risk posed by the attack against the targeted organization. This score is based on the malware's behavioral capabilities and intent, threat actor profiles, and other FireEye intelligence as available. The ATI threat level determination for an ATI alert is different from the threat severity for an alert. The severity estimates the likelihood that the targeted host has been compromised by an event. For example, established command and control (CnC) channels result in highest severity, while host connection to a compromised site is low severity because it does not indicate whether the host was breached. |
Times are displayed in UTC format by default. To set the time zone, choose Settings > Date and Time.
You can filter the list on a single column. Click Show / Hide Filters to show or hide filter options for each column.
To filter the list on one or more types of badges, open the Select Badge(s) list, select the types of badges you want to include, then click Apply.
For all other columns, type the text you want to match and then press Enter.
Details for a rule-specific alert grouping
For any entry in the Alerts tab, click the arrow to expand the view and display the following types of attack information, based on event type. For more information, see the Network Security User Guide.
Analysis Details
Attempted Infection Communication
Bot Communication Details
Callback Communication from Infected Host
Callback Communication Observed from the MVX Engine
Malware Detected
Malware Binaries
OS Change Details









