When you investigate a SmartVision alert, the Summary panel displays overview information about the alert. Click Download to download the JSON-formatted context file of related network events associated with the source IP address of the SmartVision event.
Field | Description |
|---|---|
For all SmartVision alerts | |
UUID | The 128-bit universally unique identifier of the alert. Example: |
Signature ID | The eight-digit identifier of the SmartVision rule used to detect the alert. Example: |
Context file | Click to download the text or JSON-formatted context file of related network activity associated with the source IP address of the SmartVision alert you are viewing. |
Base events count | The number of base events for this alert. Example: |
Extracted from TLS traffic (if malicious communication between client and server was detected) | |
JA3 hash | TLS fingerprint (MD5 or JA3 hash) that was used to detect malicious communication between the client and server. Example: |
Malware family reference | Category of malware detected. Example: |
Server name indication | The host or domain that the client tried to access. Example: |
Extracted from SMB traffic (if the victim and host are authenticating over NTLM) | |
User name(s) | The Active Directory user name associated with the attacker. Example: |
File share(s) | The remote shares used to initiate a transfer or to access named pipes. Usually one of the following hidden shares for Windows hosts: Example: |
File name(s) | The files transferred from attacker to victim machine. Can include named pipes, executables, plain-text files, and scripts. Example: |
Domain(s) | The Active Directory domain in which the attacker resides. Example: |
Workstation(s) | The named host initiating the request. Usually a workstation or server residing in Active Directory. Example: |
Prerequisites
Log in to the appliance Web UI and choose Alerts > SmartVision.
Click the arrow at the left side of the SmartVision alert group you want to explore.
Click the arrow at the left side of the individual SmartVision alert you want to explore. The Summary panel is expanded by default.
If you want to download the JSON-formatted context file of related network activity associated with the source IP address of the SmartVision event, click Download.