Investigating assets is crucial for investigating a potential threat originating from or targeting a specific asset (endpoint/device). It evaluates an alert context, reviews the events timeline, and gathers necessary evidence to reconstruct an attack or troubleshoot an issue.
The Asset Details page provides comprehensive information about the devices connected to NDR that are being monitored, tracked, and analyzed. It offers a detailed view of the asset's activity and any associated potential risks, which includes insights into the asset's information, activity timeline, options to manage the asset, its conversation map, and associated event details. You can also download this asset data to a CSV file.
Note
The feature is available only to users with an Enterprise or Core license.
The Asset Details page is structured into key areas with several widgets to display different categories of information. Each widget is designed to present correlated information for efficient analysis.
Timeline
Displays asset’s activity, showcasing the total data traffic that occurred per day providing a quick-reference history of activity to establish a chain of events leading up to or following a security incident. It enables investigation on a specific time range to identify anomalous activity.
Alerts
The Alerts widget display specific security warnings that indicate one or more related events may compromise the asset's security. The main objective of the widget is to flag verified or potential threats and provide immediate context to the security team.
Field | Description |
|---|---|
Alert Name | The name of the specific threat or condition detected. |
Severity | A classification of the potential or actual magnitude of harm that can result from the security event. |
Occurrence Count | The total number of times this specific alert condition has been observed. |
Latest Occurrence | The most recent timestamp when the alert fired. |
First Occurrence | The initial timestamp when this alert condition was first observed. |
ALERT MITRE TTP | Provides the associated MITRE ATT&CK Tactic, Technique, and Procedure used in the threat. The MITRE ATT&CK link navigates you to the MITRE organization official page and provides complete information about specific technique or sub-technique. |
Conversation Map
Provides asset’s life cycle and behaviour patterns providing visibility on the asset On-boarding and Off-boarding. It illustrates communication flows (example, FLOW, DNS) between the local asset (example, 10.11.65.111) and other hosts (example, 224.0.0.22, 10.11.65.110).
Events
Displays the details of the events created on this asset. You can perform a reconstruction session on the events by clicking the and selecting Reconstruct Session.
Field | Description |
|---|---|
Date | The specific date and time of the individual event occurrence |
User | The user associated with the event (NA = Not Applicable/Available). |
Source IP | The IP address from which the activity originated. |
Destination IP | The IP address targeted by the activity. |
Action | Placeholder for available actions, such as pivoting to an investigation or performing a response like containment. |
Searching asset data
A wildcard or prefix/partial word matching search box on an Assets page enhances the user productivity. This enables intuitive and efficient retrieval of asset information based on initial input. It leverages advanced search capabilities to filter and display relevant asset data dynamically as users interact with the search interface.
Viewing additional details of the asset
The Additional Details tab provides information about integrated appliances, offering a comprehensive view of how the asset interacts with or is managed by other systems within your environment. This typically displays details from external security tools that are integrated with NDR, giving you a centralized location to see relevant information from across your systems.
Investigating a potential threats
Click
and from DASHBOARD>Detection, click an asset of interest from Top Risky Assets widget.The Asset Details page is displayed.
Click
to mark the asset as priority, acknowledge asset, and contain asset.
Click an asset name on the Affected Assets tab on an alert details page.