Investigate Assets

Prev Next

Investigating assets is crucial for investigating a potential threat originating from or targeting a specific asset (endpoint/device). It evaluates an alert context, reviews the events timeline, and gathers necessary evidence to reconstruct an attack or troubleshoot an issue.

The Asset Details page provides comprehensive information about the devices connected to NDR that are being monitored, tracked, and analyzed. It offers a detailed view of the asset's activity and any associated potential risks, which includes insights into the asset's information, activity timeline, options to manage the asset, its conversation map, and associated event details. You can also download this asset data to a CSV file.

Note

The feature is available only to users with an Enterprise or Core license.

The Asset Details page is structured into key areas with several widgets to display different categories of information. Each widget is designed to present correlated information for efficient analysis.

Timeline

Displays asset’s activity, showcasing the total data traffic that occurred per day providing a quick-reference history of activity to establish a chain of events leading up to or following a security incident. It enables investigation on a specific time range to identify anomalous activity.

Alerts

The Alerts widget display specific security warnings that indicate one or more related events may compromise the asset's security. The main objective of the widget is to flag verified or potential threats and provide immediate context to the security team.

Field

Description

Alert Name

The name of the specific threat or condition detected.

Severity

A classification of the potential or actual magnitude of harm that can result from the security event.

Occurrence Count

The total number of times this specific alert condition has been observed.

Latest Occurrence

The most recent timestamp when the alert fired.

First Occurrence

The initial timestamp when this alert condition was first observed.

ALERT MITRE TTP

Provides the associated MITRE ATT&CK Tactic, Technique, and Procedure used in the threat. The MITRE ATT&CK link navigates you to the MITRE organization official page and provides complete information about specific technique or sub-technique.

Conversation Map

Provides asset’s life cycle and behaviour patterns providing visibility on the asset On-boarding and Off-boarding. It illustrates communication flows (example, FLOW, DNS) between the local asset (example, 10.11.65.111) and other hosts (example, 224.0.0.22, 10.11.65.110).

Events

Displays the details of the events created on this asset. You can perform a reconstruction session on the events by clicking the Browse.JPG and selecting Reconstruct Session.

Field

Description

Date

The specific date and time of the individual event occurrence

User

The user associated with the event (NA = Not Applicable/Available).

Source IP

The IP address from which the activity originated.

Destination IP

The IP address targeted by the activity.

Action

Placeholder for available actions, such as pivoting to an investigation or performing a response like containment.

Searching asset data

A wildcard or prefix/partial word matching search box on an Assets page enhances the user productivity. This enables intuitive and efficient retrieval of asset information based on initial input. It leverages advanced search capabilities to filter and display relevant asset data dynamically as users interact with the search interface.

Viewing additional details of the asset

The Additional Details tab provides information about integrated appliances, offering a comprehensive view of how the asset interacts with or is managed by other systems within your environment. This typically displays details from external security tools that are integrated with NDR, giving you a centralized location to see relevant information from across your systems.

Investigating a potential threats

  1. Click Main_menu.png and from DASHBOARD>Detection, click an asset of interest from Top Risky Assets widget.

    The Asset Details page is displayed.

  2. Click Browse_icon.JPG to mark the asset as priority, acknowledge asset, and contain asset.

  3. Click an asset name on the Affected Assets tab on an alert details page.