G DATA XDR

The alert details page

MeldungenDetail

A key part of operating G DATA XDR is the continuous monitoring of the alerts displayed in the G DATA Web Portal.
These must be reviewed regularly, assessed, and addressed promptly. The user independently decides whether further measures or action are necessary.

To be able to make an evidence-based decision, this page provides you with all important information at a glance.

The details page is divided into two tabs: the Details tab and the Alert graph tab.

The Details tab

Under the Details tab, you will find various tiles that provide an overall view of the security event.

The Details tile

In the details tile, you can see the most important information. This differs depending on whether it is an alert for a file or for a process.

The alert refers to the file type.

Detail tile type File

ID

Unique ID of the alert. Assigned when the alert is created.

Detections

Name (label) of the alert.

MITRE tactics

Detected tactics for the detections.

Such tactics can be, for example:

  • Initial Access (Initial Access):
    These are methods an attacker uses to gain access to the network (e.g., phishing).

  • Execution (Execution):
    Malicious code is executed on the system.

  • Persistence (Persistence):
    Establishing a foothold in the system to retain access even after restarts.

  • Privilege Escalation (Privilege Escalation):
    Attempts to obtain administrative privileges.

  • Defense Evasion (Defense Evasion):
    Techniques to deceive or disable security software.

  • Credential Access (Credential theft):
    Capturing usernames and passwords.

  • Discovery (Discovery):
    Reconnaissance of the system and network architecture.

  • Lateral Movement (Lateral movement):
    Spreading within the network to compromise additional devices.

  • Collection (Collection):
    Collecting data prior to theft.

  • Command and Control (C2): Communication between the attacker’s system and the infected network.

This field may be missing if no tactic was detected.

Severity

Severity of the alert (Low, Moderate, High).

Triggered by

Path to the detected file.

Type

File or process.

File size

Size of the file.

SHA256

Signed by

Party that signed the file. If the file is not signed, the field contains Not signed.

Executable files should always be signed. Do not run unsigned files. This is especially true if G DATA XDR has already been triggered by them.

Exercise particular caution with these file types:
.sys, .cat, .msi, .exe, .dll, .ocx, .ps1.

Only a valid signature guarantees that the manufacturer is known and that the file has not been tampered with.

Customer

The name of the customer where the endpoint is located (partner feature)

User

User in whose session the detection was triggered.

If the user account could not be read for technical reasons, the field contains "Information nicht verfügbar". This can happen, among other things, if a process was terminated before the G DATA Agent could read the user information.

Endpoint

Endpoint on which the detection was triggered.

Created

Time when the detection was triggered, based on the endpoint’s system time.

The alert refers to the process type.

Detail tile type Process

ID

Unique ID of the alert. Assigned when the alert is created.

Detections

Name (label) of the alert.

MITRE tactics

Detected tactics for the detections.

Such tactics can be, for example:

  • Initial Access (Initial Access):
    These are methods an attacker uses to gain access to the network (e.g., phishing).

  • Execution (Execution):
    Malicious code is executed on the system.

  • Persistence (Persistence):
    Establishing a foothold in the system to retain access even after restarts.

  • Privilege Escalation (Privilege Escalation):
    Attempts to obtain administrative privileges.

  • Defense Evasion (Defense Evasion):
    Techniques to deceive or disable security software.

  • Credential Access (Credential theft):
    Capturing usernames and passwords.

  • Discovery (Discovery):
    Reconnaissance of the system and network architecture.

  • Lateral Movement (Lateral movement):
    Spreading within the network to compromise additional devices.

  • Collection (Collection):
    Collecting data prior to theft.

  • Command and Control (C2): Communication between the attacker’s system and the infected network.

This field may be missing if no tactic was detected.

Severity

Severity of the alert (Low, Moderate, High).

Triggered by

Path to the file that started the detected process.

Type

File or process.

Command line

Command used to start the detected process.

Customer

The name of the customer where the endpoint is located (partner feature)

User

User in whose session the detection was triggered.

If the user account could not be read for technical reasons, the field contains "Information nicht verfügbar". This can happen, among other things, if a process was terminated before the G DATA Agent could read the user information.

Endpoint

Endpoint on which the detection was triggered.

Created

Time when the detection was triggered, based on the endpoint’s system time.

The action button in the details tile

In the lower-right corner of the details tile, there is an action button that you can use to either …​

  • set an Exclusion Add Exclusion.

    When you use this button, you access the same function that you can use to manually create the Exclusion.

    The difference is that the required information is already defined. At this point, it is possible to expand the scope of the Exclusion and to increase the scope using placeholders.

    For example, you can expand a file in the user directory of the user admin to all users with this directory:

    Create Exclusion via alert
  • restore artifacts from Quarantine Restore artifact

  • delete artifacts from Quarantine Delete artifact.

Click Selection button and select which button you want to use.

Selecting the action button for alerts

The corresponding button is displayed. Click the button to open the corresponding function.

If no artifact is present, or if the artifact in Quarantine has already been restored or deleted, selecting the action button is no longer possible. An Exclusion can still be created.
The Status tile

The selection menu for changing the status of the alert is also located in the details tile.

The following status values are possible:

  • Open

  • Closed

  • False positive

  • Reopened

Setting a status has no technical impact. The status is used to label an alert. This labeling makes it easier to categorize and filter alerts. Processed alerts are closed so that they are no longer displayed in the overview. However, if you search for them specifically, the alerts are still available.
This allows you to review past events again if needed. If you set an alert to False positive, you can keep track of which alerts did not report a real security incident.
This is helpful if you want to set or delete Exclusions.

Never treat an alert as a false positive and do not set the corresponding Exclusion unless you are sure that it is actually a false positive alert.

Setting Exclusions based on an assumption represents a high security risk.
In this context, also note our explanations of PUP detections and our Einsendeformular.

For customers who need help from an experienced SecOperations team, G DATA offers the product G DATA MXDR .

Relevant alerts

Here you can view all other alerts related to the accessed alert. Alerts are displayed

  • that were reported on the endpoint earlier or at the same time.

  • that occurred with the same event on other endpoints.

Relevant alerts

The following columns are displayed:

  • Status

  • Name of the detection

  • Severity

  • Created

  • Action button alert details page

Relevant alerts

The following columns are displayed:

  • Status

  • Name of the detection

  • Severity

  • Created

  • Action button for switching to the details page.

Using the action button (Lupe) behind an alert in this tile, you can switch to the respective alert.

With this function, you can link information that may provide indications of a company-wide outbreak of an infection. If the same infection occurs repeatedly on a computer, it is very likely that the source of the infection has not yet been found and eliminated.

For customers who need help from an experienced SecOperations team, G DATA offers the product G DATA MXDR .
The Stopped processes tile
Stopped processes

If the G DATA Agent has stopped one or more processes during an event, they are listed in this tile.

By default, you first see the Path and Command line columns. This information is also included in the details tile.

You can show or hide any additional columns you want to see using the columns icon Columns icon.

The following additional columns are available:

  • SHA256

  • Signed by

    Party that signed the file. If the file is not signed, the field contains Not signed.

    Executable files should always be signed. Do not run unsigned files, especially if G DATA XDR has already been triggered by them.

    Exercise particular caution with these file types:
    .sys, .cat, .msi, .exe, .dll, .ocx, .ps1.

    Only a valid signature guarantees that the manufacturer is known and that the file has not been tampered with.

  • Administrative privileges
    Indicates whether the process was run with administrative privileges.

  • Process start time
    Indicates when the process was started.

The Affected artifacts tile
Affected artifacts

In this tile, the artifacts affected by this alert are listed.

By default, you first see the Type, Path, SHA256/Key, and Status columns. The information from Type, Path, and SHA256/Key is also included in the details tile.

You can show or hide any additional columns you want to see using the columns icon Columns icon.

The following columns are available:

  • Type
    File or process

  • Path
    Path to a file or a registry key.

  • SHA256/Key
    SHA256 value for a file, path to a key for a registry entry.

  • Key value
    If it is a file, this column is empty.
    For registry entries, you see here the value of the key entered in the SHA256/Key column.

  • Modified key value
    The change that was prevented by the G DATA Agenten.

    Example of how the SHA256/Key, Key value, and Modified key value values are populated for an event:

    In this example, there is a registry entry as follows:
    - Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
    - Registry key: MyProgram
    - Key value: C:\Programs\MyProgram.exe

    An attacker then attempts to change the key value to the following value in order to start their own infected file:
    - Key value: C:\Users\admin\Downloads\?malware.exe

    This would change the path of a program that would normally be permitted at system startup to an executable file that presumably originates from an attacker.

    Our Agent prevents this and moves this registry operation to Quarantine.
    The corresponding artifact is then:

    • Path: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    • Key: MyProgram

    • Key value: C:\Programs\MyProgram.exe

    • Modified key value: C:\Users\admin\Downloads\malware.exe

  • Signed by
    Party that signed the file. If the file is not signed, the field contains Not signed.

  • Status

  • the status of the alert.

    • In Quarantine

    • Being restored

    • Restored

    • Being deleted

    • Deleted

    • Delete failed

    • Restore failed

      If it was not possible to restore an artifact, the artifact is stored unencrypted in the following directory on the endpoint:

      • on Microsoft Windows endpoints: C:\ProgramData\G DATA\Agent\quarantine\storage.

      • on Linux and Mac endpoints: /var/lib/gdata/agent/quarantine/recovery.

      Remember that after it has been restored, a file will be detected again by the G DATA Agenten if

  • the customer for which the detection occurred (G DATA partner feature).

  • the name of the endpoint on which the detection occurred.

  • the original path and the name of the artifact that was moved to Quarantine.

  • the name of the detection due to which the artifact was moved to Quarantine.

  • the created time of the detection.

  • an action bar for editing the artifact (details page, restore, delete artifact).

The Comments tile
Comments details page

Here you can enter free text.

At this point, you can note any considerations, insights, or documentation regarding this incident that you want to keep for a later time or for your colleagues.

The Alert graph tile
The Alert graph tile

This tile provides you with a quick overview of the affected processes.

Alert Graph course

This overview is the actual Alert Graph and displays the processes that belong to the alert. In this visualized display, you can see which processes invoked other processes and what then occurred within them.
Which process invoked other processes, and which processes exactly?
What happened to which files on the system?
Were changes made in the Windows Registry and, if so, what exactly changed there?
Was there communication to external destinations and, if so, to where?
All of these questions can be subjected to an in-depth analysis.

The graph can contain a large number of individual processes and therefore take up a significant amount of space. You can pan the view within the window with the left mouse button and zoom out and in within the graph using the mouse wheel. Alternatively, you can use the buttons provided next to the current zoom level (Zoom level).
To the left of the zoom level buttons is a button for resetting the viewport position (Reset button) to the initial view position and the original zoom level.

A process marked with a warning symbol represents the core of the Detection for the respective alert. The processes can be selected individually and are then highlighted in blue. All detailed information displayed below the graph refers to the process selected in the graph and highlighted in blue. By default, the Alert Graph view is centered on the currently selected process. You can adjust this behavior by clicking the gear icon (Settings icon).

The graph refers to the processes that belong to one alert, not to the processes of all alerts that belong to an incident!

Using the button Switch to alert graph, you can switch to the Alert graph tab. There you will find additional information.

The Alert graph tab

Alert graph full view

The Alert Graph helps you better understand the complex structures of the involved processes. This is a useful feature when, for example, a security incident needs to be analyzed in detail.

Here you can review all processes in detail, specifically with regard to…​

  • general process details.

  • file operations.

  • operations in the Windows Registry.

  • network activities.

The Alert Graph is currently available only for systems with a Windows operating system.
Visualization of an Alert’s processes
Alert Graph course

This overview is the actual Alert Graph and displays the processes that belong to the alert. In this visualized display, you can see which processes invoked other processes and what then occurred within them.
Which process invoked other processes, and which processes exactly?
What happened to which files on the system?
Were changes made in the Windows Registry and, if so, what exactly changed there?
Was there communication to external destinations and, if so, to where?
All of these questions can be subjected to an in-depth analysis.

The graph can contain a large number of individual processes and therefore take up a significant amount of space. You can pan the view within the window with the left mouse button and zoom out and in within the graph using the mouse wheel. Alternatively, you can use the buttons provided next to the current zoom level (Zoom level).
To the left of the zoom level buttons is a button for resetting the viewport position (Reset button) to the initial view position and the original zoom level.

A process marked with a warning symbol represents the core of the Detection for the respective alert. The processes can be selected individually and are then highlighted in blue. All detailed information displayed below the graph refers to the process selected in the graph and highlighted in blue. By default, the Alert Graph view is centered on the currently selected process. You can adjust this behavior by clicking the gear icon (Settings icon).

The graph refers to the processes that belong to one alert, not to the processes of all alerts that belong to an incident!
Detailed information about the processes
  • The information on the processes is subdivided into the sections Process details, File operations, Registry operations, and Network operations.

  • Not suspicious operations provide context information about the processes; suspicious operations have direct connections to the Detection.

  • The "Show only suspicious operations" button displays only suspicious entries in the File operations and Registry operations sections.

The entries within the sections can be sorted alphanumerically in ascending or descending order by left-clicking the column name.

Some information is displayed in abbreviated form for improved readability. The full information can always be viewed via mouseover and copied out if required.

Mouseover tooltip
Process details

General information about the process is listed here.

This includes…​

  • the file location on the system.

  • the exact command line, including all arguments.

  • the file size.

  • the process start time.

  • whether execution was performed with admin privileges.

Process details

The "Suspicious?" field indicates whether the overall process has been classified as suspicious by the Agent.

File operations

All file operations related to the respective process are listed here. The information listed includes file path, Created, and type of operation.

File operations

File path

Path of the file on the system to which the operation refers.

Operation

Exact type of file operation. The options are…​

  • "File closed"

  • "File created"

  • "File deleted"

  • "File executed"

  • "File opened"

  • "File read"

  • "File renamed"

  • "File information changed"

  • "File written"

Created

Exact time at which the operation was started.

Suspicious?

Indicates whether this is an operation that played a role in the Detection.

Registry operations

Information about changes in the Windows Registry that were initiated by the process is displayed. This includes all information relating to the key itself, as well as Created and type of operation.

Registry operations

Key path

Path of the key within the Windows Registry to which the operation refers.

Name

Name of the value within the key in the Registry to which the operation refers.

Value

Value after the operation, if present.

Operation

Type of operation. The options are:

  • "Key created"

  • "Key opened"

  • "Key deleted"

  • "Value deleted"

  • "Value set"

Created

Exact time of the operation.

Suspicious?

Indicates whether this is an operation that played a role in the Detection.

Network operations

If present, all operations triggered by the process within the network are listed here. In addition to Created and type of operation, this also includes all relevant connection details.

Network operations

IP address

For the "Connection established" operation, the IP address to which the connection was established. If the "Opened for inbound connections" operation is present, your own IP address is displayed here.

Port

Port that was used for the connection.

Protocol

Protocol that was used for the connection. Options are TCP or UDP.

Operation

Type of network operations. The options are:

  • "Connection established"

  • "Opened for inbound connections"

Created

Exact time of the network operations.