show alerts type <malware_type> id <id> [detail <detail_level>]

Prev Next

This command displays information about a specified alert type.

Syntax

show alerts type <malware_type> id <aler_ID> detail <detail_level>

Parameters

malware_type

Shows alerts of the specified alert type Not all malware types are available on all appliances.

  • all—All alert types

  • malware-callback—Malware-callback alerts

  • domain-match—Domain-match alerts

  • infection-match—Infection-match alerts

  • web-infection—Web-infection alerts

  • malware-object—Malware-object alerts

alert_ID

The alert ID.

detail_level

Shows alerts for the specified alert type with the specified level of detail:

  • concise—A concise summary of every alert

  • normal—The normal details of every alert

  • extended—The extended details of every alert

Example

The following command displays information for the specified malware-object alert:

hostname # show alerts type malware-object id 55224 detail concise
  msg: concise
  product: Email MPS
  version: 8.3.0.850861
  appliance: IE-EX3400.eng.fireeye.com
  appliance-id: 002590879432
  alert (id:55224, name:malware-object):
    severity: majr
    ack: no
    sc-version: 837.118
    uuid: 3bb086b2-5974-46bb-99ce-5ea2d9efcbaa
    explanation:
      analysis: none
      malware-detected:
        malware (name:Trojan.Dridex):
          type: zip
          sha1: e3f96bb3e413fcbb3b74262d20d3d9b2052121d0
          md5sum: 14918f93d14bcf35c1383a8aefd57cbe
          submitted-at: 2019-03-15T09:00:32Z
          sha256: ffd038673d836833a8443259a3fe3efcd3e0417bbcc58ba2dead9c656f3df8c7
          sha512: 4404c7487ab2286008df7ac19b5ccaa28c4fb6c09d241364a64349e635d557177b66191dada4c14fbf00ce4d71583990f0f2134ebbad8f0c16ebac6462c8bf78
          executed-at: 2019-03-15T09:02:04Z
    src:
      domain: a.com
      smtp-mail-from: a@a.com
      url: /8779d8d3-fa83-490a-99d7-9cb902d803de
    dst:
      smtp-to: b@test.com
    occurred: 2019-03-15T09:02:04Z
    alert-url: https://IE-EX3400.eng.fireeye.com/emps/eanalysis?e_id=28204
    action: notified

Output fields

The following table describes each field in the output. Not all fields may be shown for a given alert.

Field

Description

msg

The level of detail of the alert.

product

Trellix product name.

version

Trellix software release on the appliance that detected the malware and sent the alert.

appliance

Domain name.

appliance-id

Appliance identifier.

ack

Whether the alert has been acknowledged.

sc-version

Security content version.

severity

Alert severity.

uuid

Alert ID number (assigned internally).

type

Malware type.

sha1

SHA-1 checksum.

md5sum

MD5 checksum.

submitted-at

When the malware was discovered.

sha256

SHA-256 checksum.

sha512

SHA-512 checksum.

executed-at

When the action was taken.

src

Source of malware.

dst

Destination of malware.

occurred

Date and time the event occurred.

alert-url

URL for the alert.

action

Action that was taken in response to the alert.

User role

Admin, Monitor, Operator

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Malware Analysis: Before release 6.4.

  • Central Management System: Before release 6.4.

  • Email Security — Server: Before release 6.4

  • File Protect: Before release 6.4.

  • Network Security: Before release 6.4.