Viewing base event details for a SmartVision alert

Prev Next

The Base Event Details panel lists the indicators that triggered the selected SmartVision alert.

SmartVision_events_BaseEventDetails_expanded.png

The Base Event Details panel lists all indicators that triggered the alert and shows the following information for each indicator:

Field

Description

Displayed for all alert base events

Name

The name of the base event.

Example: MSRPC SCMR Service StartService SMBv1 TCP Port 445

Source IP (port)

The IP address of the network host that originated the event and the port number from which the traffic was sent.

Example: 192.168.0.3 (52836)

Destination IP (port)

The IP address of the network host that was targeted by the event and the port number to which the traffic was sent.

Example: 192.168.0.254 (445)

Occurred

Date and time when the event occurred.

Example: 07/04/20 13:02:19.901258

Protocol

The protocol used to transport data.

Example: tcp

Payload

By default, the payload is displayed encoded.

Example: a2VyYmVyb3M6Omxpc3QK

Click Show decoded to view the payload decoded.

Example: kerberos::list

Extracted from SMB traffic (if the victim and host are authenticating over NTLM)

File name

The files transferred from attacker to the victim machine. Can include named pipes, executables, plain-text files, and scripts.

Example: \svcctl

File share

The remote shares used to initiate a transfer or to access named pipes. Usually one of the following hidden shares for Windows hosts: IPC$, ADMIN$, or C$.

Example: \\192.168.0.254\IPC$

File UUID

The universally unique identifier associated with the files transferred from attacker to the victim machine.

Example: aa010b59-365b-4827-b40e-b7cbc4b803fc

Host

The name of the attacker machine.

Example: MIKE-PC

User name

The username on the attacker machine.

Example: DomainAdmin

Workgroup

The workgroup of the host.

Example: INTERNAL

Prerequisites

To view the base event details for a SmartVision event:
  1. Log in to the appliance Web UI and choose Alerts > SmartVision.

  2. Click the arrow at the left side of the SmartVision alert group you want to explore.

  3. Click the arrow at the left side of the individual SmartVision alert you want to explore. The Summary panel is expanded by default.

  4. Click Base Event Details. The panel lists the events seen in the network that caused the alert to be generated.

  5. Expand a numbered event to view base event details.

    SmartVision_events_BaseEventDetails.png