G DATA MXDR

The Alert Graph

Alert Graph full view

The Alert Graph helps you better understand the complex structures of the involved processes. This is a useful feature when, for example, a security incident needs to be analyzed in detail.

Here you can review all processes in detail, specifically with regard to…​

  • general process details.

  • file operations.

  • operations in the Windows Registry.

  • network activities.

The Alert Graph is currently available only for systems with a Windows operating system.

Visualization of processes within an alert

Alert Graph course

This overview is the actual Alert Graph and displays the processes that belong to the alert. In this visualized display, you can see which processes invoked other processes and what then occurred within them.
Which process invoked other processes, and which processes exactly?
What happened to which files on the system?
Were changes made in the Windows Registry and, if so, what exactly changed there?
Was there communication to external destinations and, if so, to where?
All of these questions can be subjected to an in-depth analysis.

The graph can contain a large number of individual processes and therefore take up a significant amount of space. You can pan the view within the window with the left mouse button and zoom out and in within the graph using the mouse wheel. Alternatively, you can use the buttons provided next to the current zoom level (Zoom level).
To the left of the zoom level buttons is a button for resetting the viewport position (Reset button) to the initial view position and the original zoom level.

A process marked with a warning symbol represents the core of the Detection for the respective alert. The processes can be selected individually and are then highlighted in blue. All detailed information displayed below the graph refers to the process selected in the graph and highlighted in blue. By default, the Alert Graph view is centered on the currently selected process. You can adjust this behavior by clicking the gear icon (Settings icon).

The graph refers to the processes that belong to one alert, not to the processes of all alerts that belong to an incident!

Detailed information on the processes

  • The information on the processes is subdivided into the sections Process details, File operations, Registry operations, and Network operations.

  • Not suspicious operations provide context information about the processes; suspicious operations have direct connections to the Detection.

  • The "Show only suspicious operations" button displays only suspicious entries in the File operations and Registry operations sections.

The entries within the sections can be sorted alphanumerically in ascending or descending order by left-clicking the column name.

Some information is displayed in abbreviated form for improved readability. The full information can always be viewed via mouseover and copied out if required.

Mouseover tooltip

Process details

General information about the process is listed here.

This includes…​

  • the file location on the system.

  • the exact command line, including all arguments.

  • the file size.

  • the process start time.

  • whether execution was performed with admin privileges.

Process details

The "Suspicious?" field indicates whether the overall process has been classified as suspicious by the Agent.

File operations

All file operations related to the respective process are listed here. The information listed includes file path, Created, and type of operation.

File operations

File path

Path of the file on the system to which the operation refers.

Operation

Exact type of file operation. The options are…​

  • "File closed"

  • "File created"

  • "File deleted"

  • "File executed"

  • "File opened"

  • "File read"

  • "File renamed"

  • "File information changed"

  • "File written"

Created

Exact time at which the operation was started.

Suspicious?

Indicates whether this is an operation that played a role in the Detection.

Registry operations

Information about changes in the Windows Registry that were initiated by the process is displayed. This includes all information relating to the key itself, as well as Created and type of operation.

Registry operations

Key path

Path of the key within the Windows Registry to which the operation refers.

Name

Name of the value within the key in the Registry to which the operation refers.

Value

Value after the operation, if present.

Operation

Type of operation. The options are:

  • "Key created"

  • "Key opened"

  • "Key deleted"

  • "Value deleted"

  • "Value set"

Created

Exact time of the operation.

Suspicious?

Indicates whether this is an operation that played a role in the Detection.

Network operations

If present, all operations triggered by the process within the network are listed here. In addition to Created and type of operation, this also includes all relevant connection details.

Network operations

IP address

For the "Connection established" operation, the IP address to which the connection was established. If the "Opened for inbound connections" operation is present, your own IP address is displayed here.

Port

Port that was used for the connection.

Protocol

Protocol that was used for the connection. Options are TCP or UDP.

Operation

Type of network operations. The options are:

  • "Connection established"

  • "Opened for inbound connections"

Created

Exact time of the network operations.