Trace an attacker's path

Prev Next

You can reconstruct the sequence of events during an attack by following the attacker's movements through your network.

  1. Start your investigation with a known Indicator Of Compromise (IOC), such as a malicious IP address or a compromised user account. Enter this value into the Search hostname / ipaddr or Search username field.

  2. In the results grid, identify a related host or account you want to investigate further.

  3. Pivot your search by clicking on the value in the Src/Tgt Host or Src/Tgt Acct column. This action automatically starts a new search for all activity related to that entity.

  4. Repeat this pivoting process to follow the trail from one system to the next, which builds a timeline of the attacker's activity.