Viewing the details of the alert

Prev Next

The Alert Details page serves as a centralized hub for in-depth investigation and management of specific security alerts within the NDR platform. It provides comprehensive information about a single, specific alert and allows security analysts to investigate, understand, and manage a detected threat.

The Alert Details page is crucial for security operations for the following reasons:

  • Understand the alert's context: Get immediate details on severity, involved IPs, and when it happened.

  • Drill-down into specifics: Find out the alert category, detection mechanism, and if it maps to any known CVEs or MITRE ATT&CK TTPs.

  • Investigate network flows: See the underlying network conversations and events that triggered the alert, even if the visual map is not populated.

  • Identify affected assets: Identify the exact source and destination assets, including ports, and potentially geolocation.

  • Gather raw data: Use the JSON view for in-depth analysis or integration with other tools.

  • Leverage threat intelligence: Quickly navigate to external intelligence sources like "Trellix Wise" for more context on "THREAT_INTEL."

You can access the Alert Details page in several ways, including:

  • Selecting an individual alert from the Top Alerts widget.

  • Navigating through the main menu: Alerts > Alert List and selecting the alert for which you want to view the details.

  • Clicking Browse_icon.JPG > Open Alert Details for the alert you want to view the details.

Additionally, you can select multiple alerts by using the checkboxes beside each entry and perform its related actions.