Viewing a SmartVision alert summary and downloading the context file

Prev Next

When you investigate a SmartVision alert, the Summary panel displays overview information about the alert. Click Download to download the JSON-formatted context file of related network events associated with the source IP address of the SmartVision event.

Field

Description

For all SmartVision alerts

UUID

The 128-bit universally unique identifier of the alert.

Example: 7f64ecee-463b-b5b1-a05ba7614ad7

Signature ID

The eight-digit identifier of the SmartVision rule used to detect the alert.

Example: 91500516

Context file

Click to download the text or JSON-formatted context file of related network activity associated with the source IP address of the SmartVision alert you are viewing.

Base events count

The number of base events for this alert.

Example: 2

Extracted from TLS traffic (if malicious communication between client and server was detected)

JA3 hash

TLS fingerprint (MD5 or JA3 hash) that was used to detect malicious communication between the client and server.

Example: 2d8794cb7b52b777bee2695e79c15760

Malware family reference

Category of malware detected.

Example: Ransomware

Server name indication

The host or domain that the client tried to access.

Example: www.pjtbwdp4nx5.com

Extracted from SMB traffic (if the victim and host are authenticating over NTLM)

User name(s)

The Active Directory user name associated with the attacker.

Example: user2

File share(s)

The remote shares used to initiate a transfer or to access named pipes. Usually one of the following hidden shares for Windows hosts: IPC$, ADMIN$, or C$.

Example: \\192.168.99.77\IPC$

File name(s)

The files transferred from attacker to victim machine. Can include named pipes, executables, plain-text files, and scripts.

Example: PAExec-4740-CLIENT1.exe

Domain(s)

The Active Directory domain in which the attacker resides.

Example: INSECURE

Workstation(s)

The named host initiating the request. Usually a workstation or server residing in Active Directory.

Example: CLIENT1

Prerequisites

To view the summary of a SmartVision alert:
  1. Log in to the appliance Web UI and choose Alerts > SmartVision.

  2. Click the arrow at the left side of the SmartVision alert group you want to explore.

  3. Click the arrow at the left side of the individual SmartVision alert you want to explore. The Summary panel is expanded by default.

  4. If you want to download the JSON-formatted context file of related network activity associated with the source IP address of the SmartVision event, click Download.