THREAT_INTEL alerts

Prev Next

The NDR Alerts page also displays Mandiant Threat Intelligence alerts. THREAT_INTEL alerts are generated when the NDR appliance identifies a match between NDR indexed metadata and a downloaded Mandiant Threat Intelligence IOC.

View a summary of all THREAT_INTEL alerts at the top of the NDR dashboard. Use the Details and Intel tabs to analyze each alert and obtain additional information from the Mandiant Threat Intelligence portal. The Details tab allows you to log directly into the Mandiant Threat Intelligence portal to view information about the alert and attacker. The Intel tab allows you to download a full intelligence report.

To view INTEL_ALERT details in the Web UI:

Note

THREAT_INTEL alerts are generated for each direction of the flow.

  1. Click Main_menu.png and from INVESTIGATION, select Alerts.

  2. Select a THREAT_INTEL alert in the alerts table.

  3. Click on the Details tab to view additional information about the particular alert including alert severity.

  4. Click on the Alert url to go directly to the Mandiant Threat Intelligence portal and find additional context.

  5. Click on the Intel tab to download a full intelligence report.