show incident <incident_ID>

Prev Next

Displays information for a specific Web analysis incident job that is confirmed as malicious on the appliance. This command does not show incident information that was not deemed malicious. For details about displaying a list of all malicious and nonmalicious events, see .

Syntax

show incident <incident_ID>

Parameters

None

Output fields

The following table describes the output fields for the show incident command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

Web Analysis Incident

Specific Web analysis incident job number.

Target OS

Guest image profile that was the target of the malware.

Target Application

Application that was the target of the malware.

Page URL

Page URL submitted to the virtual machine (VM) as a confirmed incident.

Source IP

IP address of the source.

Noticed At

Date and time that the confirmed incident was seen.

Updated At

Date and time that the confirmed incident was updated.

Events found

Number of events involved in the confirmed incident.

URLs

Number of URLs involved in the confirmed incident.

ContentType

Type of retrieved object, such as application or text.

Example

The following example displays the information about job number 6680:

hostname # show incident 6680
Web Analysis Incident: 6680
   Target OS              : Microsoft WindowsXP 32-bit 5.1 sp3 15.0826
   Target Application     : InternetExplorer 8.0
   Page URL               : www.rxktpnjr.cjb.net/63bhputj/?2
   Source IP              : 6.169.35.252
   Noticed At             : 2015-09-25 06:19:41 PDT
   Updated At             : 2015-09-25 06:21:58 PDT
   Events found           : (2) 1581(NA) 1580(OS)
   URLs                   : (4)
   ContentType            URL
   --------------------------
   appl/octet-stream      www.rxktpnjr.cjb.net/63bhputj/?2dc6ba8fd447903e571c060d5
   text/html              www.rxktpnjr.cjb.net/63bhputj/?2dc6ba8fd447903e571c060d5
   text/html              www.rxktpnjr.cjb.net/63bhputj/?2
   appl/octet-stream      www.rxktpnjr.cjb.net/63bhputj/?362f56117ea4eb38415e5b5d0

User role

Admin, Operator, Monitor, or Analyst

Command mode

Enable

Supported appliances

This command is supported on the following appliance running the specified release or later:

  • Network Security: Before Release 7.5