Events
Events
An event is something a TTP detection rule found in the loaded evidence — the records it matched, collected into one thing a person can read.
Searching
Pick the project and host in the filter bar and search. Nothing is returned until a host is selected.
| Column | What it shows |
|---|---|
| Priority | The rule's severity. Three bars is high, two medium, one low |
| First seen · Last seen | The time span of the records this event was cut from |
| Project · Host · Image | Which case, which host, which piece of evidence it came from |
| Message | The rule's message template with the actual values filled in |
| Rule | The rule that produced it |
The time filter is compared against the event's own span. An event whose span falls outside the range drops out of the list, so widen the range if what you are looking for is missing. Events with no usable timestamp are always shown, regardless of the range.
The evidence panel
Click a row and the Evidence panel opens below it: the records the event was cut from, with their original fields.
Values are written out as field=value pairs that wrap, and nothing is abbreviated. Which fields
a rule emits differs from rule to rule, so fixed columns cannot hold them — and truncating would
hide the value you need in order to judge.
behavior, then move to Artifacts and see what was happening around that time.
How records are grouped into an event
The field names in the rule's message template are what the grouping is keyed on.
If the template reads $computer$ raised $event_id$, the rule's result is sorted by those two
fields and a new event is cut wherever the combination changes. A hundred records of the same
event id on the same computer are therefore one event with a hundred records of evidence behind
it.
A template with no fields at all collapses everything the rule matched into a single event.
This is why how you write the template decides how readable the results are. See Administration for the details.
Looking around a moment
Right-click a first-seen or last-seen cell for Search ±10 minutes. It sets the time range to that instant plus and minus ten minutes and searches again, which is the quickest way to see what surrounded a detection.
The range is shared, so moving to Artifacts or Logs from there shows you the same window from a different angle.
Running detection again
Detection runs by itself when loading finishes. Run it by hand when:
- you have added or edited a rule
- you want to rerun only some of them
Go to Administration → TTP Detection Rules, check the rules to run, and click Scan. With nothing checked, every enabled rule runs. Choose a project and an image in the dialog, and progress is shown as it goes.
same rule twice leaves two copies of the same event. Re-importing the evidence is different — the
tables are recreated, so the events are cleared with them.
Next: digging into the evidence, in Artifacts.