The Alert Details page serves as a centralized hub for in-depth investigation and management of specific security alerts within the NDR platform. It provides comprehensive information about a single, specific alert and allows security analysts to investigate, understand, and manage a detected threat.
The Alert Details page is crucial for security operations for the following reasons:
Understand the alert's context: Get immediate details on severity, involved IPs, and when it happened.
Drill-down into specifics: Find out the alert category, detection mechanism, and if it maps to any known CVEs or MITRE ATT&CK TTPs.
Investigate network flows: See the underlying network conversations and events that triggered the alert, even if the visual map is not populated.
Identify affected assets: Identify the exact source and destination assets, including ports, and potentially geolocation.
Gather raw data: Use the JSON view for in-depth analysis or integration with other tools.
Leverage threat intelligence: Quickly navigate to external intelligence sources like "Trellix Wise" for more context on "THREAT_INTEL."
You can access the Alert Details page in several ways, including:
Selecting an individual alert from the Top Alerts widget.
Navigating through the main menu: Alerts > Alert List and selecting the alert for which you want to view the details.
Clicking
> Open Alert Details for the alert you want to view the details.
Additionally, you can select multiple alerts by using the checkboxes beside each entry and perform its related actions.