5.6.10. Web UI `Alerts`
screen
`Alerts`
button on the navigation bar, the following screen appears.Item |
Description |
---|---|
1 |
Dashboard selector |
2 |
Display area for the list of filtered alerts |
5.6.10.1. `Alerts`
screen dashboard selector
The selector includes the following items:
Item |
Name |
Description |
---|---|---|
1 |
Number of results |
Display of the number of records found:
depends on the selection choices for the display i.e. Aggregated selector, All selector, and so on.
|
2 |
|
Aggregates the records. In this mode the information fields are different. |
3 |
Search field |
Enables entering a text to be searched in the page |
4 |
|
Filters records with all alert types: |
5 |
|
Filters out records whose alert type is
`IDS` :Equivalent to entering 'type:ids' in the search field
|
6 |
|
Filters out records whose alert type is
`MALWARE` :Equivalent to entering 'type: malware' in the search field
|
7 |
|
Filters out records whose alert type is
`SHELLCODE` :Equivalent to entering 'type: shellcode' in the search field
|
8 |
|
Filters out records whose alert type is
`POWERSHELL` :Equivalent to entering 'type: powershell' in the search field
|
9 |
|
Filters out records whose alert type is
`C&C` :Equivalent to entering 'type:c&c' in the search field
|
10 |
|
Filters out records whose alert type is
`APT` :Equivalent to entering 'type:apt' in the search field
|
11 |
|
Selection of the number of lines per page
|
12 |
GCap Selector |
Selection of GCap |
13 |
Time period selector |
Selection of the display period |
Note
Several types of alerts can be selected by pressing buttons 5 to 10.
5.6.10.2. Display area for the list of alerts in aggregate mode
The display consists of:
Item |
Name |
Description |
---|---|---|
1 |
|
Type of risks. The risk level is indicated by the color. The type of risk is indicated by the corresponding icons.
By clicking on an icon in column (1), a window displays information about the selected threat (NAME field).
There may be several records.
|
2 |
|
Type of alerts detected |
3 |
|
Date and time of last occurrence of this threat |
4 |
|
Name of the detected threat |
5 |
|
Number of cumulative records with the same detected threat |
6 |
|
Viewing the MITRE category |
7 |
|
Menu of possible actions. Depends on the recording (Go hunting, Download Shelcode, Generate CFG, Display Data..) |
Astuce
Alerts are detected by engines that:
Work
Are up to date
Have been activated
The current motor status is displayed in the Web UI `Health checks` screen.For the Malcore engine, check the white and black list that intervene on the alarm detection display.For the Codebreaker engine and the detection of shellcodes and powershells, this detection is not enabled by default and is defined in the profiles sent to GCap (see Web UI `Config - Gcaps profiles` screen).For the Machine Learning engine for DGA detection (C&C), this engine must be enabled (see `Admin-GCenter- ML Management` screen of the legacy web UI).For the CTI engine to generate alerts for Advanced Persistent Threat (APT) threats, this engine must be enabled (see `Admin-GCenter- CTI Configuration` screen of the legacy web UI).
5.6.10.3. Display area for the list of alerts in non-aggregated mode
The display consists of:
Item |
Name |
|
---|---|---|
1 |
|
Type of risks. The risk level is indicated by the colour. The type of risk is indicated by the corresponding icons.
By clicking on an icon in column (1), a window displays information about the selected threat (
`NAME` field).There may be several records.
|
2 |
|
Date and time of the recording |
3 |
|
Name of the detected threat |
4 |
|
The first IP address is the source address
The second IP address is the destination address
|
5 |
|
The first hostname is that of the source
The second hostname is that of the destination
|
6 |
|
Viewing the MITRE category |
7 |
|
Tags field if indicated (Confirmed incident, Critical, Doing, Done) |
8 |
|
Notes field if indicated |
9 |
|
Menu of possible actions. Depends on the recording (Signature definition, Alert history, Alert summary, Flow details) |
5.6.10.5. Alert information window
By clicking directly on an alert, the following window is displayed:
The window consists of 3 parts:
- Upper part (1): the summaryThis section summarizes the alert, including:
The level of risk
The name of the detected threat
Detection date and time
- Intermediate part (2): possible actionsThis part shows the buttons of possible actions on this alert: these are the same actions as the commands detailed in the previous paragraphs.
- lower part (2): detailed informationThis section displays detailed information on:
The file (ID, UUID, SHA256...)
The detected threat (type, type alert, name, description...)
Source GCap (GAP, Host)
etc