By leveraging GTI’s threat intelligence, NDR determines the potential risk caused by files entering or operating within the network. The integration with GTI allows NDR to generate alerts when files with a malicious reputation are detected in Packet Capture, Network Security, and IPS FileInfo events.
You can filter the GTI alerts from the Top Alerts widget available on the NDR dashboard. The Alerts page shows summary information about the GTI alerts in your appliance, as well as a table of GTI alerts.
You can also click the main menu icon and then select Alerts to access the Alerts page. GTI alerts are then filtered from the Alert Summary filters.

The top of the page contains summary information, including statistics about the number of alerts over the last 30 days. A chart provides a visual display, by date and risk level, that helps you determine patterns.
The table in the lower half of the page contains a list of the GTI alerts created in NDR.