Investigating Hygiene and Detected Indicators
Findings for Hygiene and Detected Indicators are raised when:
AND/OR
|
NOTE:Hygiene indicates that objects are susceptible to an adversary attack. Detected indicates that an action took place that could possibly be an adversary attack.
-
Detected TTP (tactics, techniques and procedures) Indicators are search-based.
-
Detected Anomaly Indicators are based on statistical analysis. |
The top of an Investigation page identifies the object being investigated, along with the following information:
-
the Severity of the Finding
-
the Finding Type (Hygiene, Detected TTP, Detected Anomaly)
-
the Finding Status (Active or Inactive)
-
MITRE ATT&CK TTP (if applicable)
|
NOTE: Up to three TTPs may be returned for the finding. If "+ [number]" is shown to the right of the displayed TTP, hover over the icon to view the additional values. |
-
the number of Affected Objects
-
Last Updated (that is, the last time the Finding was detected)
|
NOTE: Last Updated displays a relative time. However, you can hover over the clock icon to see an exact date and time (which displays the local date and time of the signed-in user). |
What Happened?/What Is Wrong?
The What Happened? (for Detected Indicators) or What Is Wrong? (for Hygiene) page provides a description of the Finding and lists the objects that are affected. The following information is included for each object:
-
Object Name (with a link that allows you to display object details)
|
exception: If an Object Type is trustedDomain, Container or dnsZone, object details cannot be displayed from the Investigation page and the Object Name link will be disabled. |
-
Principal Name (which is searchable)
-
Object Type
-
First Discovered date and time
|
NOTE: This field displays the signed-in user's local date and time. |
-
Certification Status, which may be
|
NOTE: A status of "Status Not Available" may occur if the object has been deleted from Active Directory or the Object ID cannot otherwise be identified. |
This section also includes a series of links to help you complete your investigation, as described in the following table.
For Selected Objects in the list |
Object Name
(for a single object) |
The properties of the object, including whether or not it is Tier Zero, identifiers used for the object within Active Directory, the date the object was added and the date its information was last updated.
|
NOTE: This field displays the signed-in user's local date and time. | |
Mute Object button |
See Muting Findings for Hygiene and Detected Indicators. |
View Activity button
(for a single object) |
This link opens the Quick Search page in On Demand Audit, which lists event data for the object being investigated. |
View Assessment button
(for a single object) |
If the indicator was raised by a Security Guardian Assessment, this link opens the Assessment Results Vulnerability Detail page that includes the selected object.
|
NOTE: This button is enabled only when a single object is selected. | |
View critical activity link |
If the indicator was raised by an On Demand Audit critical activity event, this link opens Critical Activity event details in On Demand Audit. |
Escalate this Finding |
Copy |
This link allows you to copy the text of the Finding to the clipboard so that you can share it with others. |
Send email |
This link allows you to prepare and send an escalation email to recipients with whom you want to share the Finding. |
How Do I fix this?
This section provides the recommended remediation.
Muting Findings for Hygiene and Detected Indicators
You can mute Findings for Hygiene, Detected TTP, and Detected Anomaly Indicators, or individual objects within those Findings, to prevent future Findings from being raised for the object(s), or individual objects within those Findings, to prevent future Findings from being raised for the object(s).
To mute Findings:
From the Findings Investigation page or Findings list (if you are dismissing multiple Findings), dismiss the Finding.
When prompted to confirm the dismissal, check the Mute this Finding box.
|
NOTES:
-
Tier Zero [object] Detected Findings cannot be muted. If your selection includes these the mute option will be unavailable.
-
Because Findings are muted at the time they are dismissed and therefore no longer display in the Findings list, they can only be unmuted from the All Indicators page. |
To mute Findings for individual objects:
-
From the Findings Investigation What Happened?/What Is Wrong? section, select the object(s) you want to mute.
-
Click Mute Object.
Dismissing Findings
When you dismiss a Finding, the Finding will no longer display in the active Findings list.
-
For a Hygiene, Detected TTP, or Detected Anomaly Indicator, the Finding will continue to be monitored and any new Finding for the indicator will be raised unless it is .
-
For a Tier Zero indicator, the Finding will not be raised again unless the object is re-added as a Tier Zero object.
|
NOTES:
-
Only certified Tier Zero objects can be dismissed. If a Tier Zero object is not certified, the Dismiss option will be disabled. However, you can dismiss a Tier Zero Finding as part of the certification process.
-
When you dismiss a Finding, the Finding Status is changed from Active to Inactive and can be viewed when the Findings list is filtered by Status = Inactive. |
To dismiss a Finding after investigation:
From the Investigate Finding page, click Dismiss Finding.
You will be prompted to confirm the dismissal. For a Hygiene, Detected TTP, or Detected Anomaly Indicator, the confirmation dialog also includes a check box that allows you to mute the Finding at the same time.
To dismiss one or more Findings from the Findings list:
-
Select the Finding(s) you want to dismiss.
-
Click the Dismiss button.
|
NOTE: If your selection contains only Hygiene, Detected TTP, and/or Detected Anomaly Indicators, you will also have the option to mute the Finding(s). If the selection includes Tier Zero Findings, the option to mute will be unavailable. Any uncertified Tier Zero objects in the selection will not be dismissed. |
Viewing Finding History
You can view the history of all actions associated with a Finding from the Findings list or the Findings Investigation page.
|
NOTE: Once a Finding is dismissed, history will no longer be recorded, although it still can be viewed. If a new Finding is raised for the same indicator, a new history for the Finding will be created. |
To view a Finding's history from the Findings list:
-
Select the Finding whose history you want to view.
-
Click the View History button.
|
NOTE: If more than one Finding in the list is selected, the button will be disabled. |
To view a Finding's history from the Findings Investigation page:
Click the View History button.
For each action associated with the Finding (listed from newest to oldest), the following information displays:
-
Date
|
NOTE: This field displays the signed-in user's local date and time. |
-
Action
-
Source
-
Actor
For a Tier Zero [object indicator, the history will include:
For a Hygiene, Detected TTP, or Detected Anomaly Indicator the history will include:
- when a Hygiene, Detected TTP, or Detected Anomaly object was detected and whether the source was Assessments or On Demand Audit.
- when the Finding was created by Security Guardian.
- when any objects within the Finding were muted/unmuted.
- for an unprotected Tier Zero object Finding, when the object was protected (if applicable).