Use the show events type command to view detailed information about the events: the event's type, occurrence time, interface, action, analysis type, and so on.
Use the show alerts type command to view information about alerts, such as log records of malicious events. Alerts are viewed by time frame, host, or infection type.
Enable the CLI enable mode.
hostname > enable
Verify detailed information about a particular type of event.
hostname > show events type <event>
where
<event>is the following type:The following example displays partial output about the binary checksum match:
hostname # show events type checksum-match Event 15: Occurrence Time : 2015-09-30 23:49:35 PDT Interface : any Action : notified (default policy): 0 Event Type : checksum-match Analysis Type : Binary Analysis Trace ID : 2 Malware ID : 2 Source IP : 34.232.235.10 Destination IP : 44.142.250.4 Source MAC : 8A:2B:65:33:BD:E9 Destination MAC : 00:50:56:F0:7E:18 VLAN ID : 0 Attacked Port : 80 IP Protocol : tcp Original Malware ID : 0 Match Type : av-match Name : Mal/Generic-L EDP Page URL : https://mil.fireeye.com/edp.php?sname=Mal/Generic-L PCAP URL : https://172.16.146.84/event_stream/send_ pcap_file?ev_id=15 PCAP URL (TEXT) : https://172.16.146.84/event_stream/send_ pcap_ascii?ev_id=15 Event Page URL : https://172.16.146.84/event_ stream/events?event_id=15 Event 3: Occurrence Time : 2015-09-30 23:45:15 PDT Interface : any Action : notified (default policy): 0 Event Type : checksum-match Analysis Type : Binary Analysis Trace ID : 1 Malware ID : 1 Source IP : 115.52.174.36 Destination IP : 124.151.168.211 Source MAC : 00:0C:29:28:84:3F Destination MAC : 00:03:47:4E:69:AA VLAN ID : 0 Attacked Port : 80 IP Protocol : tcp Original Malware ID : 0 Match Type : av-match Name : Mal/Whybo-A EDP Page URL : https://mil.fireeye.com/edp.php?sname=Mal/Whybo-A PCAP URL : https://172.16.146.84/event_stream/send_pcap_ file?ev_id=3 PCAP URL (TEXT) : https://172.16.146.84/event_stream/send_pcap_ ascii?ev_id=3 Event Page URL : https://172.16.146.84/event_stream/events?event_ id=3
Enable the CLI enable mode.
hostname > show alerts type <alert>
where
<alert>is the following type:Verify detailed information about a particular type of alert.
The following example displays partial output about a malware callback alert:
crit MC 3 128.79.164.86 2015-12-22 20:24:53+00 DTI.Callback crit MC 18 128.98.118.169 2015-12-22 20:44:46+00 DTI.Callback crit MC 142 128.137.250.207 2015-12-22 21:06:33+00 Trojan.ZeroAccess crit MC 206 128.226.97.235 2015-12-22 21:08:10+00 Exploit.JS.Pdfka.bde crit MC 217 128.92.95.151 2015-12-22 21:08:16+00 Trojan.Downloader.Tipikit.C crit MC 226 128.179.144.48 2015-12-22 21:08:40+00 Virus.Sality.AT crit MC 216 128.92.95.151 2015-12-22 21:08:15+00 Trojan.Expiro crit MC 301 128.241.214.221 2015-12-22 21:11:08+00 Trojan.Expiro crit MC 362 128.28.43.100 2015-12-22 21:12:52+00 Virus.Virut crit MC 370 128.24.68.198 2015-12-22 21:13:10+00 Trojan.Expiro crit MC 390 128.128.82.116 2015-12-22 21:13:42+00 Trojan.Generic crit MC 429 5.116.179.24 2015-12-22 21:14:39+00 Trojan.CeeInject.gen.KK crit MC 459 128.91.176.80 2015-12-22 21:15:34+00 Trojan.Cutwail