Fidelis User Guide 801
Fidelis User Guide 801
Version 8.0.1
Copyright © 2002–2015 by General Dynamics Fidelis Cybersecurity Solutions, Inc.
All rights reserved worldwide.
Revised 2015
Users are granted permission to copy and/or distribute this document in its original electronic form
and print copies for personal use. This document cannot be modified or converted to any other
electronic or machine-readable form in whole or in part without prior written approval of General
Dynamics Fidelis Cybersecurity Solutions, Inc.
While we have done our best to ensure that the material found in this document is accurate,
General Dynamics Fidelis Cybersecurity Solutions, Inc. makes no guarantee that the
information contained herein is error free.
Fidelis XPS includes GeoLite data created by MaxMind, available from [Link]
Preface ........................................................................................................................................................... 1
Intended Audience ..................................................................................................................................... 1
Available Guides ........................................................................................................................................ 2
Technical Support ...................................................................................................................................... 2
Fidelis XPS™ Overview ................................................................................................................................ 3
The Threat Life Cycle ................................................................................................................................. 3
Use Cases ................................................................................................................................................. 3
Use Case 1: Advanced Malware Protection .......................................................................................... 4
Use Case 2: Network Security Analytics ............................................................................................... 5
Use Case 3: Data Theft Protection ........................................................................................................ 6
Fidelis XPS Components ........................................................................................................................... 7
Fidelis XPS CommandPost ................................................................................................................... 7
Fidelis XPS Direct.................................................................................................................................. 9
Fidelis XPS Internal ............................................................................................................................... 9
Fidelis XPS Web.................................................................................................................................... 9
Fidelis XPS Mail ...................................................................................................................................10
Fidelis XPS Collector ............................................................................................................................10
Fidelis XPS BladeArray ........................................................................................................................10
SSL Inspector (Blue Coat) ....................................................................................................................11
Fidelis XPS Component Roles ..................................................................................................................11
Fidelis XPS CommandPost ..................................................................................................................11
Console ................................................................................................................................................12
Master CommandPost ..........................................................................................................................12
Subordinate CommandPost..................................................................................................................13
Primary CommandPost ........................................................................................................................13
Secondary Policy Manager ...................................................................................................................13
Alert Failover CommandPost ................................................................................................................14
Fidelis XPS Sensor...............................................................................................................................14
Secondary Sensor ................................................................................................................................14
Fidelis XPS Collector ............................................................................................................................14
Fidelis XPS Collector Controller ...........................................................................................................15
Fidelis XPS Failover Collector Controller..............................................................................................15
Chapter 1 Getting Started............................................................................................................................17
Access CommandPost ..............................................................................................................................17
Intended Audience
This information is intended for network system administrators familiar with networking, computer
security, and with the security requirements and practices of their enterprises. This help system
and related guides are intended for users that fit into at least one of the following major categories:
• The alert and quarantine managers are frequent users of the system, likely to visit the
CommandPost GUI several times each day. Both roles are usually filled by system
administrators responsible for reviewing alerts (or quarantined emails) and managing any
action required within the enterprise. Alert and quarantine management require high level
data analysis and the ability to delve into the details of any single violation.
• The network IT manager will be the first to touch the CommandPost, but is expected to rarely
use Fidelis XPS after initial installation. The IT manager might need to adjust sensor network
settings and CommandPost to sensor communications, manage users and their credentials,
and monitor network statistics to verify connectivity.
Technical Support
For all technical support related to this product, check with your site administrator to determine
support contract details. Contact your reseller or if you have a direct support contract, contact the
General Dynamics Fidelis Cybersecurity Solutions support team at:
Phone: +1 301.652.7190*
Toll-free in the US: 1.800.652.4020*
*Use the customer support option.
Email: support@[Link]
Web: [Link]
Use Cases
To mitigate attacks across the threat life cycle, Fidelis XPS provides Advanced Malware Protection,
Data Theft Protection, and Network Security Analytics in a single, tightly integrated system for
continuous protection and response across the enterprise. Customers use this technology for one
or more of the following use cases:
• Advanced Malware Protection to effectively identify and stop targeted persistent attacks on
the network.
• Network Security Analytics to analyze and correlate data on your network for proactive
event detection and remediation.
• Data Theft Protection to detect and prevent the unauthorized flow of sensitive, valuable, or
classified information out of the network.
• Visually monitor and analyze network alerts and other metadata in real time.
• Enable, disable, or customize policies and analytics as required.
• Add, configure, and manage sensors, Collectors, and the Console itself.
• Create users using the granular access control capabilities in several user authentication
mechanisms including integration with a user directory server.
• Export information to a third-party network alert aggregation system.
• Use the built-in reports or customize reports to your requirements. Reports can be scheduled
for automatic delivery or run in real time with click-through drill down capability.
Typical bandwidth requirements for CommandPost are approximately 10Mbps. However, the
bandwidth can increase based on your environment. Consider:
• The size of an alert is equivalent to the size of the violating network session in bytes. The
sensor can be configured to limit the maximum size of the alert recorded object limit to
between 0 and 32MB per alert (this limit is increased to 50MB for the Mail sensor).
Refer to Direct>Advanced.
• Enabling Fidelis feeds uses approximately 250 MB of data every hour between the
CommandPost and the sensor,. If you are at a lower bandwidth, then it is advisable to
adjust the feed frequency interval to 10-20 hours. Enabling malware detection on the sensor
can add up to 500 MB on startup and up to 50MB on an hourly basis.
Refer to chapter 10 in the Guide to Creating Policies.
• CommandPost can receive alerts at a rate of approximately 10-15 alerts per second.
Compressing alerts can increase the needed bandwidth by up to 1Gbps.
Refer to Alert Compression.
• If Packet capture is enabled, the size of an alert can increase by 16MB. Refer to Direct.
chapter 13 of the User Guide.
• If Malware>Execution Forensics is enabled, the bandwidth between sensor and
CommandPost is not impacted because the file is sent as part of the recorded session.
Execution Forensics will increase the bandwidth of CommandPost to external sites.
Refer to Execution Forensics.
• The minimum system requirements for the CommandPost to enable a Demo Collector are:
16 GB RAM
2 CPUs
200 GB disk
50 GB free disk
The amount of storage for the Demo Collector is approximately 60GB (This could be lower
on VMs with low total disk space.) The maximum allowed input rate is 1Mbps of metadata.
Depending on the traffic, 100 Mbps of monitored traffic may or may not exceed that 1Mbps
metadata rate.
Also, if CommandPost is overloaded with high alert rates or many concurrent users, adding
a Demo Collector would put an additional load on the CommandPost. Users; however, can
limit the metadata rate by entering specific IP address or can disable the Demo Collector.
The days of metadata storage for the Demo Collector depends on type of traffic and how
much the monitored rate is limited. Users can expect 2 weeks of metadata storage with a
reasonable rate.
Refer to the section: Demo Collector for details.
Refer to Direct>Advanced to set up the Demo Collector.
The network requirement is therefore a factor of your policies, the size of violating network
sessions, the percentage of alerts generated with the Packet Capture option, and Fidelis XPS
sensor configurations.
• Prevention can be accomplished by redirecting the user to a customizable web page that
states their violation and other applicable information.
• When combined with an ICAP-enabled SSL proxy, the Web component can access
unencrypted data destined to secure web sites.
Refer toWeb.
For information about setting up and configuring this sensor, refer to chapter 6 in the Enterprise
Setup and Configuration Guide.
Demo Collector
The Collector is also available as a built-in Collector enabled on the CommandPost. The Fidelis
XPS Demo Collector can only accept metadata from one sensor at a time and has limited storage
capability, but provides the full capability of an actual Collector. The Demo Collector is available to
any CommandPost that does not have a registered Collector. To use the Demo Collector to its full
potential, configure the sensor to send data from a small IP Address range.
Refer to the section: Fidelis XPS CommandPost for details about CommandPost system.
requirements for a Demo Collector.
Refer to Direct>Advanced to set up the Demo Collector.
Console
Every Fidelis XPS CommandPost provides the same web-based user interface. When you access
CommandPost, the system to which you are logged in is referred to as the Console. In a
hierarchical management deployment, the relationship between CommandPosts is relative to the
Console. If you access the Master CommandPost, you can see and manage Subordinate
CommandPosts. If you access a Subordinate CommandPost, you can manage the access rights of
the Master. In an environment where there is only a single CommandPost controlling one or more
sensors, all access is to the Console.
Master CommandPost
A Master CommandPost can push information about users, policies, reports, and software
upgrade packages to a Subordinate CommandPost. A Master CommandPost may have many
Subordinate relationships. In the figure below, CP 1 is a Master CommandPost to CP 2 and to CP
A.
To an enterprise with a large deployment of Fidelis XPS, the Master offers a single point to control
users, reports, policies, and software upgrades. Changes made at the master can then be pushed
to all subordinates. In the case of policies, you may configure your subordinates to automatically
push new policies to all sensors. In case of software upgrades, the Master CommandPost can
transfer upgrade packages to and initiate software upgrades of Subordinate CommandPosts and
all their registered sensors or Collectors.
Primary CommandPost
This CommandPost controls sensor configuration and is the CommandPost to which the sensor is
registered. All sensors must have one primary CommandPost, but can have multiple Secondary
Policy Managers. In the illustration, Secondary and Alert Failover Relationships, CP 1 is the
Primary CommandPost for Sensor 1.
The Primary CommandPost can fully configure and control all registered sensors and Collectors.
Additional CommandPosts may be designated to a sensor in a limited role.
Secondary Sensor
A CommandPost may act as a Primary CommandPost to some sensors and a Secondary Policy
Manager to others. The sensors that are connected in a secondary mode are Secondary Sensors
to this CommandPost.
Secondary Sensors are registered to another, Primary CommandPost, but can receive policies
from a CommandPost designated as a Secondary Policy Manager. In our example, Sensor 1 is a
Secondary Sensor to CP 3 and has CP 1 as a Primary CommandPost. Refer to Secondary Policy
Manager and Sensor Management.
A Collector Controller collects metadata, maintains the database, and ensures the availability of
metadata to users. A Controller has multiple Collector XAs connected to it that host the metadata
database. The Collector XAs communicate with each other and with the Collector Controller.
After adding the Controller to CommandPost and registering it, proceed to Collector Configure to
configure the Controller and then link it to a sensor. The Controller and the XAs will appear as a
single Collector to the CommandPost and to other Fidelis XPS Components.
Access CommandPost
You can access CommandPost from anywhere on your network, by using a web browser that
supports SSL. Communications between the sensors, Collectors, and CommandPost and between
CommandPost and the web-based GUI are encrypted SSL communications.
CommandPost has been verified with recent versions of Microsoft Internet Explorer, Mozilla
Firefox, Google Chrome, and Apple Safari.
For CommandPost to work properly, your client workstation must have the following installed:
• Adobe Flash Player – obtain a recent version of Adobe Flash Player free of charge from the
Adobe web site at [Link].
• WinSCP – available free of charge from the WinSCP web site at [Link]. WinSCP
transfers files to CommandPost for policy creation and verification. All other aspects of
CommandPost function properly without WinSCP.
Mouse over the time to view the date, time zone, and time zone offset for this
CommandPost.
• After logging in successfully to the CommandPost, you can open another tab without logging
in again.
Lock Icon
Fidelis XPS CommandPost and sensors communicate over encrypted SSL connections, using
self-signed certificates and an internal authentication method. This mode can be overridden by
installing externally generated certificates that use the Public Key Infrastructure (PKI). Refer to the
1
Enterprise Setup and Installation Guide for information about installing PKI certificates to run in
this mode.
When operating with PKI certificates, a lock icon appears at the top right of the CommandPost
menu bar. You can mouse over the lock icon to see the expiration date for the certificate.
CommandPost Navigation
With the exception of Dashboard and Metadata, clicking a main menu option in the CommandPost
GUI displays subnavigation menus. A highlighted option from the subnavigation menu indicates
which page is currently accessed. CommandPost navigation is "sticky" meaning that if you later
return to the same major heading, the page last accessed displays.
Note: Users need permissions to see many of the menu options. If a user does not
have the appropriate permissions for a menu option, that option does not display.
Refer to User Roles.
System Status
2
System Status provides information about Fidelis XPS components and their statuses that you
can access from any GUI page. The diamond next to System Status reflects the status of the
component with the highest severity. Mouse over the System Status diamond to see the list of
components. The component list that displays is the CommandPost Console and all sensors and
Collectors that have been registered and that are within a user’s access privileges. Refer to Define
User Profiles. Mouse over a component in the list to see a message about that component's status.
Each component has a green, yellow, or red diamond next to it to indicate severity.
If your environment uses a hierarchy of CommandPosts, you will see the status of all components
from the Master CommandPost, including those components registered to a Subordinate
CommandPost.
Note: Users need permissions to see system status. Refer to User Roles.
Green indicates that the component is operational.
A red diamond indicates a condition with critical severity. A yellow diamond indicates a condition
with high severity.
A grey diamond indicates that there is no available information about the component.
Clicking will set the status to green. At the next attempt to use the component status will
change. For example, a feed fetched once a day will not change status until the next attempt after
clicking .
Clicking fora Subordinate CommandPost or its registered components may take several
minutes.
1
Public Key Infrastructure (PKI) is a set of hardware, software, people, policies, and procedures
needed to create, manage, distribute, use, store, and revoke digital certificates.
2
Components enables you to set up licensing and configure Fidelis XPS components. This includes
adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail, and
setting up user notification and LDAP among other features.
Fidelis XPS User Guide 20
T a bl e 1. C o m p o n e nt St a t us M es s a g e s a n d S ev e ri ty
The following table describes some of the more common conditions that can cause system status
messages and their severities.
Alert Export Critical Cannot start exporter, see log for details
Feed fetch Critical Cannot start feed handler(s), see log for details
Insight High New policies are available from the Insight feed
Spooler Critical Dropped spool file due to queue buildup. See log
for details
Spooler Critical Skipped spool file due to queue buildup. See log
for details
Spooler Critical Low disk space. Spooling stopped. See log for
details
Spooler High Rate of logging too high, spooler cannot keep up.
See log for details
Logout
To securely log out of CommandPost, click the logout link at the top of the page. Logging out will
end your browser session to CommandPost.
To securely log out of CommandPost, click to log out. Logging out will end your browser
session to CommandPost.
Note: If inactive for 15 minutes, CommandPost will log you out. The 15 minute value
can be changed at Session Timeout.
Click the empty tab on the right to add a tab. Type a name for the tab and press Enter. The
tab is saved under this name. Double click the tab name to change it.
to view the Dashboard in full screen mode. In this mode, all browser controls are removed.
Full screen mode is appropriate for display on a large monitor used for constant information display
of Fidelis XPS operations. Press ESC to exit full screen mode.
to add a widget. A list of available widgets will appear after you click. The list displays with an
example and description of each available widget.
Click or to navigate through the available widgets. Click Add at the desired
widget to add it to the Dashboard. Click X at the list of widgets to remove the list. The list of
available widgets depends on your role, therefore not all widgets are available to all users.
To remove a widget from the dashboard, click the X at the top right of the widget's title bar.
to reset the Dashboard to the default Overview layout. Click Reset at the confirmation dialog
box.
The Dashboard is specific to each user. Changes made to your Dashboard will not affect the
Dashboard of any other CommandPost user.
T a bl e 2. Us e r P e r mi ss i o n s f or D a s h b o ar d Wi d g e ts
Each user role is defined by a set of permissions. The available widgets depend upon the View
access to the permissions listed below.
Refer to Define User Roles for more information.
Radar Alerts
Widget Controls
Each widget offers controls to change the behavior of the widget. The controls available vary
depending on the widget.
Click in the title bar of the widget to expand the widget. When expanded the chosen widget
will occupy the entire dashboard space.
Click to return the widget to the original size and return all other widgets to the dashboard.
Click to start auto refresh. The frequency of the auto refresh differs per widget. By default, all
widgets begin in an auto refresh state. Widgets also refresh automatically within 2 to 5 minutes
depending on the duration time selected for the widget. If the selected Duration is hours, refresh
will occur approximately every 2 minutes. If the selected Duration is days, refresh will occur
approximately every 5 or more minutes.
Click to stop auto refresh. After stopping and starting data refresh, an immediate update
request will be sent to the server to refresh the data.
Click to retrieve the latest data for a widget. Move your mouse over to see the last time data
was updated.
Select a time frame: Click and select a time frame from 1 minute up to 30 days.
Select a CommandPost: If your environment uses hierarchical CommandPosts, you can access
data from Subordinate CommandPosts from the Master. Click and select a
CommandPost.
Select a Collector: Click and select a new Collector, if available.
Slider bar: Many widgets include a slider bar along the top or right side of the widget. This bar can
be used to zoom in or out of the data displayed. Click if available, to expand the widget to show
all data.
1. Click to access the edit popup. At the pop up, you can select a report, graph type, and
trending.
Note: If the button is active, the data in the report will not change if a new report is
closed. Click to stop refresh before changing the report.
Reports that contain group by information can display information either by groups or by trending
date. Reports without group by, can only display trending information.
For group by reports:
You can click the Trending checkbox to display trending information in the main chart. The legend
to the right of the chart displays group information. Uncheck the Trending checkbox to display
information by group, summarized by the selected time period.
For all other reports:
The Trending checkbox is selected by default and is greyed out.
3. Select the graph type: either Bar or Line chart. This is how your results will display in the
widget even if another view such as pie chart was originally selected for the report. If the
report returns no alerts, you will see a message stating: No results found. If more alerts are
found during a refresh, the count increases.
4. Either enable or disable trending. Trending enables you to see alerts over time.
5. Click Apply. The edit pop up goes away and your results display based on any selections
you made in the pop up. Clicking Cancel closes the pop up without applying your
selections.
You can mouse over a bar or line point to view a pop up that lists the information by group or by
date. If ellipses (...) display, this indicates that more information is available than what can be
displayed in the pop up. You can use the slider bar to see another portion of the graph.
1. Click to access the edit popup. At the pop up, you can select a metadata report, and
graph type. You can also select how to group metadata and select trending.
2. Select a saved Metadata report. Note: If the button is active, the data in the report
will not change if a new report is closed. Click to stop refresh before changing
the report.
3. Select the graph type: either Bar or Line chart to determine how your results display in the
widget
4. Enable or disable Group by. Enabling Group by displays the Column drop down so that you
can select columns to group your results.
5. Select Group by columns. Refer to Metadata>Explore for descriptions of columns.
Metadata results display by column. Column labels list on the right of the chart. You can
change how the chart looks by clicking on a column name to select or deselect.
Globe
The Globe widget shows incoming alerts as they arrive and alert activity for the last hour displayed
by shades of colors for countries.
Alerts are shown as they arrive with their source or destination country including any custom GeoIP
information. The globe will spin to show the country of each alert as it arrives. Clicking the alert ID
takes you to the Alert Detail page for that alert. If an alert is malware related, the icon displays
next to alert severity on the globe. Small countries that are not visible on the globe are represented
as large dots. After pausing and resuming data refresh, an immediate update request will be sent to
the server.
Note: If the source or destination country is not available for an alert, then Unknown
is listed as the source or destination and will be placed in the middle of the Atlantic
ocean. This often occurs if the alert is from an internal network. To fix this, access
CommandPost>Config>GeoIP and set internal IP address ranges and assign a flag.
Refer to Custom GeoIP.
World Map
The World Map widget displays alerts and enables you to view an Alert List based on country
source and destination. You can zoom in to focus on a specific area or zoom out. You can select a
time frame at the drop down.
Moving your mouse over a country highlights the country and shows the total number of alerts for
the selected time period and the total number of alerts for source and destination.
Radar
The Radar widget graphically represents alerts occurring on your network, grouped by common
characteristics into an alert cluster. Clusters are a visual presentation of similar alerts. When
creating a cluster, CommandPost considers the sender and receiver of the information transfer, the
time of the transfer, the sensor on which the alert was detected, the rule violated, and the priority of
an alert.
CommandPost creates clusters based on similar information, but not necessarily equivalent or
related information. For example, alerts with similar, but not equal, source IP addresses may be
grouped in a single cluster, which may be indicative of a problem generated by a location rather
than an individual. Also, alerts from a similar time period during normal working hours may be
grouped together while others occurring during non-working hours may be grouped into a different
cluster.
A cluster is represented by a dot or a line on the alert radar. A dot appearing in the center of the
radar is the most recent alert in CommandPost. Over time, the dot will migrate toward the outer
edges of the [Link] line represents a cluster that contains several alerts over time. The line
connects the oldest and most recent alerts within the cluster. A dot represents a single alert or
several alerts that were detected at the same time.
The clusters are intended as a visual representation of alert activity and are not necessarily
presented in the best form for investigation into network behavior. The radar widget refreshes with
new data periodically. The refresh cannot be disabled for this widget
The cluster details portion of the widget is relative to your mouse position
on the widget. As you move your move over the radar, a portion of the
radar will be highlighted in grey. The Cluster details will reflect the time
range and the number of clusters per severity within the scope of your
mouse.
3
Clicking on an alert cluster takes you to the Alert List for that cluster.
3
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 29
Top Alert (or Malware) Hosts
The Top Alert Hosts widget displays an interactive bar chart for alerts grouped by host IP address.
The Top Malware Hosts displays an interactive bar chart for alerts with malware grouped by host IP
address. You can select a time frame at the drop down.
Alert Trend
The Alert Trend widget displays an interactive stacked bar chart that shows alerts grouped by
severity and date for the selected time [Link] can select a time frame at the drop down.
Moving your mouse over the chart displays the number of alerts by severity level for that date. You
can move the slider bars to select a time period. Below the graph you can click a severity to
remove it from the chart. Click it again to add it.
Malware Trend
The Malware Trend widget displays an interactive line chart that shows malware grouped by
malware type and date for the selected time period. You can select a time frame at the drop-down.
Malware trends display by date and counts are shown by malware type. Moving your mouse over
the chart displays the number of malware by malware type for that date. You can move the slider
bars to select a time period. Below the graph you can click a malware type to remove it from the
chart. Click it again to add it.
System Status
The System Status widget displays the total number of alerts per CommandPost, sensor, and
Collector. The component list and numbers represent only those alerts the user is permitted to see
based on the user’s role, alert management group assignments, and sensor assignments. Refer to
Define User Profiles.
If you are logged into a Master CommandPost, system status will display also all Subordinate
CommandPosts and all components registered to each Subordinate CommandPost.
Hold your cursor over the green, yellow, or red diamond to see useful information about a
component: for example, if a license is expiring, if the sensor needs updating, or if the sensor is
System Totals
The System Totals widget provides the total number of sensors, secondary sensors, Collectors,
and CommandPosts, added to the CommandPost. This widget also shows the total alert count --
regardless of user permissions.
Network Statistics
The Network Statistics widget displays Kbits per second by transport protocol, [Link] can
select a time frame at the drop down.
The Network Statistics widget provides an interactive graph that you can use to closely examine
what is occurring on your network at specific times. The data represents the sum of all sensors
registered to the selected CommandPost. You can highlight an area of activity to expand that
portion of the report, mouse over a line to see what occurred at that point, or use the slider bar to
zoom into or out of the graph. Refer to Network Reports for more details on using the performance
graph and the slider bar.
Disk Space
The Disk Space widget displays the total disk space, high water mark, and current used disk space
for CommandPost.
Disk space utilization depends on the alert rate and the alert retention settings at the
CommandPost configuration page for Alert Retention. CommandPost will delete alerts when
necessary to avoid filling the disk.
Collector Metadata
The Collector Metadata widget displays an interactive bar chart that shows the total amount of
metadata in GBytes stored by the selected Collector.
Daily storage is displayed in GBytes for each day that data is available on the Collector. The
current day's storage data refreshes periodically. Moving your mouse over a bar displays the exact
amount of data stored for a specific day. Each bar is labeled with the date in the year-month-day
format. Fidelis XPS Collector storage can be configured for managing the oldest data. Refer to
Configure Collector. The Total Collector Metadata graph provides a view of the oldest data
currently stored by Collector as well as an indication of daily traffic rates.
• Manage an Alert
• Read and examine the details of an alert, including the original transmission that caused the
violation.
• Export summary alert information to Microsoft Excel or any other application that accepts tab-
separated files.
• Purge alerts.
Users with full access to the Quarantine function may:
• Read and examine the details of every quarantined email, including the original email that
caused the quarantine.
• Move an alert from its current alert management group to another. This action makes the alert
accessible to another group of users.
• Add comments to the alert workflow log.
4
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 32
Handle Alerts
To find all alerts currently assigned to you, use the My Alerts view on the Alert List page. Refer to
System Reports for Alerts.
To find all alerts owned by a specific user:
1. Click Search.
2. Enter the user name in the Search for text box.
3. Select Owner and click Go.
To find all unassigned alerts:
1. Click Search
2. Enter unassigned in the Search for text box.
3. Select Owner and click Go.
• Assign one or more alerts to another user with access to the sensors that generated the alerts
and have access to the alert management group(s) to which these alerts belong. When an
alert is assigned, an email is sent to the new alert owner.
• Close an alert. You can close an alert and select Allowed, Action taken, No action taken, or
False positive. This action may be performed by anyone with access to the alert. When the
alert is closed, a resolution is entered to the alert workflow log.
• Change Management Group will make the alert accessible to a different group of users. When
the group is changed, an email is sent to the group mailing list, to make members of the new
group aware of the alert.
The workflow can be accessed from the Alert Details page of any alert. You may also change the
workflow for multiple alerts by choosing Change Ticket Status or Change Management Group from
the Actions button on the Alert list page.
For any workflow action, the alert manager has the option to fill out the Subject and Comment fields
which will be added to the alert workflow log. The alert workflow log will display the full history of
the alert with all comments as it changes from group to group, owner to owner, and finally to a
closed state.
When the ticket is assigned, the subject and comment information will be included in the body of an
email sent to the newly assigned user. When the management group is changed, the subject and
comment information will be included in the body of an email sent to the address associated with
the newly assigned group.
The same options are available in the Quarantine and Quarantine Details pages; however, the alert
workflow log only applies to alerts – not to quarantined email. When managing alerts from the
Quarantine Details page, the action will apply to all alerts associated with the email. When
managing alerts from the Quarantine page, the action will apply to all alerts associated with all
selected quarantined email messages.
If you have a hierarchical environment with Master and Subordinate CommandPosts, the
following applies:
If you are working from the Master CommandPost Alert List page, then the users and management
groups available will only be those available to the Master CommandPost.
5
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 33
If you are working from the Master CommandPost and access the Alert Details page of an alert
from a Subordinate CommandPost, then the users and management groups available to you will be
from the Subordinate CommandPost.
Change Status
• Enter a Subject or Comment.
• Click Assign to and select a user from the list to assign the alert. The list of users includes
those with access to the sensor that generated the alert and have access to the alert
management group to which the alert belongs. After you submit the change, the selected user
receives an email reflecting the assignment.
• Click Add comment to add comments to the ticket log without changing the ticket status or
ownership. After you submit the change, information entered in the Subject and Comment text
boxes will be appended to the comment.
• Click Close as and select a reason from the list. Your options are Allowed, Action taken, No
action taken, and False positive. The alert is closed.
Note: Closing an alert marks you as the owner of the alert.
6
An alert is the recorded and displayed incidence of at least one event.
7
Alert Details is the most granular level for examining alert data.
8
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
9
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 34
T a bl e 3. A c ti o ns l i st o pti o ns
You can access these options from the Alert List and Quarantine Management pages.
Management Description
option
Note: From the Alert List you can also apply labels, purge, and export selected alerts.
These functions do not impact the ticketing system and are described in Understand
and Manage Alerts.
From the Quarantine Management page you can discard or deliver selected quarantine
emails. Refer to Deliver or Discard Quarantine Email.
• Alert List
• Navigate Alert Pages
• Alert List—a list of all alerts displayed according to the selected report and any actions taken
at the Alert page.
• Page Navigation
• Actions—Enables you to take action on selected alerts.
• Alert List controls—Enables you to search, group, change the display settings of the page,
and retrieve a custom report. Click in the upper right corner of the Alert page to show or
hide the controls.
10
CommandPost groups related network alerts into an alert cluster. Clusters are a visual
presentation of similar alerts. When creating a cluster, CommandPost considers the sender and
receiver of the information transfer, the time of the transfer, the sensor on which the alert was
detected, the rule violated, and the priority of an alert. CommandPost creates clusters based on
similar information, but not necessarily equivalent or related information. For example, alerts with
similar, but not equal, source IP addresses may be grouped in a single cluster, which may be
indicative of a problem generated by a location rather than an individual.
Fidelis XPS User Guide 36
Click above the list to access the Investigator. Refer to Investigator.
Alert List
11
An Alert List is created from all alerts available within your assigned groups and sensors. The list
can be greatly customized by choosing the columns to display, by reducing the alerts to those that
match specified criteria, by summarizing, and by choosing to display the results in a chart or as a
table.
In all cases, the list is highly interactive. Rows in a table and sections in a graph can be clicked to
obtain further information; specific details of any alert can be obtained; actions can be taken on
single alerts or groups of alerts; and alerts can be purged.
Selecting a list restores settings for that report, including:
• The columns available in your list represent summaries of alert attributes. Primary columns
are shown on your report. Secondary columns become available when you click on a row
within the list to view the quick summary of the alert. For attributes that contain large amounts
of data, the list column may be truncated.
• Data criteria including Searches, Filters, and Time Selections. These serve to reduce the
number of alerts in the list.
• Grouping and sorting of the list. Alerts can be grouped by any one or multiple primary
columns to produce a summary of the data. Sorting can be applied to any primary column
whether grouped or not.
• The list results can be displayed as a chart or table. Charts are available only for grouped
lists.
• A trending chart can be saved with any type of list. The trending chart will show alerts per time
above the report.
After running a report, you can use the controls on the Alert List to further manipulate the
information. When you make changes, you are changing the list into an Unnamed Report. By
clicking Customize list you can save this new list with your new settings. Alternatively, you can use
the Unnamed list to analyze and drill down into your information as you would any other report.
The time required to generate a list is greatly influenced by the Time Selection. Reports based on
Insert time using a short timeframe will be optimal. Reports based on selecting all alerts or based
on the recorded alert time may run substantially slower, depending on the total number of alerts
stored on CommandPost.
12
At the Quick Summary, you can click to view the Alert Details page for the selected alert.
You can also choose to filter alerts based on the value of the available information.
Many of the items that display in the Quick Summary are clickable. Clicking one of these items
takes you to the configuration page for that item where you can view more information or make
changes. For example, clicking a sensor name at Quick Summary takes you to the Sensor page.
You can see details for that sensor, and if needed make changes. Clickable items include Policy,
Rule, Sensor, and Alert Management Group. Some items might not be clickable based on your
role. Refer to Roles.
The Quick Summary of an alert shown below is from the Alert List.
11
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
12
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 37
Figure 9. Alert Report: Quick Summary
Filter Alerts
You can filter alerts by selecting items at the Quick Summary page. Filters are used to reduce the
list to only those alerts that match your filter criteria. For example, you can choose to filter by
Protocol = HTTP, the result will be a list of all alerts from the HTTP protocol. This list would not
include alerts from any other protocol.
To set a filter:
1. Click the check box next to one or more values in the Quick Summary page.
2. Click Filter.
3. CommandPost finds all alerts that exactly match the filtered value and display only these
alerts.
• If you selected multiple fields, all are applied to the filter. The more filters that you select, the
more narrow your results.
If one or more Subordinate CommandPosts are selected at the Alert List, navigation changes for
the Alert List. You can click the < or > arrow buttons to move to the next page in either direction.
Other navigation options such as clicking on individual page numbers or clicking << or >> to
advance to the first or last page are not available.
13
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 39
Alert Actions
14
Click the check box next to one or more alerts to select them. Clicking the check box at the top of
15
the Alert List page selects (or deselects) all alerts on the current page.
• Export to Microsoft Excel, Evidence Package, zipped PDF, or zipped text. Refer to Export
Actions.
Alert Labels
Labels are tags that a CommandPost user can apply to an alert. By using labels, you can
categorize alerts into meaningful names for your enterprise. You can later search or filter by label to
retrieve alerts that contain your label.
Labels can be applied from the Alert List page or from the Alert Details page. From the Alert List
page you can select multiple alerts and apply the same label to each.
To apply a label from the Alert List page:
1. Click the checkbox next to the alert or alerts that you wish to label.
2. From the Actions list, select Change Label. The Change Label dialog box displays where you
can select an existing label or create a new one.
3. The Existing Labels text box lists all previously used labels. You may choose a label from this
list and click Apply Label.
14
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
15
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 40
4. If you wish to create a new label, type it into the New Label text box and click Apply Label.
You can also click to add the new label without applying it.
To remove a label from an alert: You can choose a new label using the steps above and overwrite
the label with the new label. To clear the label for all selected alerts, click Clear Label.
To remove a label that is no longer required: Select the label in the Existing Labels text box and
click . Labels can only be removed if there are no alerts that use the label.
If you are working in a hierarchical environment, the following applies:
When working from the Master CommandPost, the list of available labels will only include those
that have been previously applied from the Master. Any label that was applied to an alert by logging
into a Subordinate CommandPost will only be available by logging into the Subordinate
CommandPost.
Export Actions
To Excel
Export selected alerts to Excel (or other application) that can accept a tab-separated file.
Evidence Package
Evidence Package gathers selected alerts and their associated files and into one compressed tar
(.tgz) or zip file. Refer to Evidence Package for details.
Purge Alerts
Purge Alerts removes selected alerts from CommandPost. Once a purge starts, you can perform
other actions at the CommandPost, but you cannot start another purge.
1. Click Purge Alerts.
2. Click Ok at the confirmation dialog box. Alert purge will permanently remove the selected
alerts and all associated information about the selected alerts. This operation cannot be
undone.
• Report—Enables you to select a report from the drop-down list. All other functions available
on the Alert List are based on this initial setting. You may choose from multiple system reports
plus any report that you create and save.
• Search—Enables you to reduce an Alert List to alerts that match your search criteria.
Searches are performed as case-insensitive partial string matches, whereas Filters are
performed as exact matches. Refer to Search for Alerts. The Search dialog box also contains
the CommandPost, Time Range, and Group By sections.
CommandPost—If available, this section enables you to select one or more Subordinate
CommandPosts. Refer to Select CommandPosts.
Time Range—This section enables you to reduce an Alert List to alerts that occurred during a
specified time period. Refer to Time Range.
Group By—This section enables you to summarize alerts by selected columns. The result will
display the selected columns and the number of alerts that match each available value within
those columns. Grouped information can be displayed in a table or graph form. Refer to
Group By.
• Filtered By—Displays what you have selected at Search or at Quick Summary to filter alerts.
Refer to Filter Alerts. Click an x to delete a filter.
• Refresh—Refreshes the Alert List [Link] can also specify auto refresh. Mouse over
the button. The Refresh select box displays.
Click the checkbox next to Refresh and enter a time period. The Alert List automatically
refreshes for the time period specified.
New incoming alerts display when the Alert List is refreshed. The time stamp next to Last
Search Results updates to reflect the last time that the Alert List page was refreshed.
The Alert List also refreshes whenever you conduct a search, group alerts, or run a report.
Accessing Alert Details or the Quick Summary for an alert, then returning to the alert list will
not refresh the list if not selected.
• Trending—Enables you to view and control alert trend charts. Refer to Trending.
• Fixed (Relax) Columns—When the report contains many columns, you can select Fixed
Columns to resize columns to better fit within your page size, truncating some of the data in
the columns and replacing it with ellipses. Mouse over the ellipses to view the hidden
information. Relax Columns displays all information in each column which may require
horizontal scrolling in your browser window to view all information.
T a bl e 4. Sys t em R e p or ts
Report Description
Default Report The default report provides crucial alert information that will be useful to most
users. This report will display all alerts sorted by Alert ID.
Alert The alert management report provides a summary of alert tickets and their
Management status. This report is most useful to alert managers who fully use the
Report CommandPost ticketing system. This report will display all alerts sorted by
Alert ID and lists the owner and the alert management group associated with
each alert. This report is only available to users whose role provides access to
tickets.
Label Report The label report displays label information in the primary rows. This enables
users to see alerts that users tagged with specific labels. This report will
display all alerts sorted by Alert ID.
Malware The malware report displays information about detected malware. The
information includes the alert severity, alert ID, time, malware name, malware
type, host IP address, network application protocol, and file format type.
Malware by The malware by host report provides a summary of all alerts grouped by the IP
Host address of the infected host machine.
Malware by The malware by type report provides a summary of all alerts grouped by the
Type malware type.
My Alerts My Alerts is identical to the Alert Management report, but includes data criteria
to reduce alerts to only those alerts assigned to the user.
16
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 44
17
If the alert control buttons are not visible, click in the upper right corner of the Alert List page
to display them.
Searches differ from filters in the manner that the data is matched:
17
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 45
6. If desired, select one or more items in the Group By section. Group By enables you to group
alerts by information available in one or more of the primary columns of your current alert
18
page. For example, if you select protocols, alerts are grouped by protocols. Refer to Group
By.
7. If desired, you can select how the Group By results display by selecting options at the View
Results list.
8. Click Go.
• Searching for term will match any alert containing term in the chosen field. This will match
alerts with words such as term, terminate, and exterminate.
Entering multiple words such as:
term1 term2
matches alerts containing both term1 and term2. The terms can be found in any order and
with any amount of separation between them.
• You can search on multiple Alert IDs, Threat Grid Scores, and for multiple Any, Source, or
Destination Ports by separating entries with a comma. For example, entering
AlertID1,AlertID2 would find alerts with both ID numbers.
• You can specify a range for Alert ID, Threat Grid Scores, and for multiple Any, Source, or
Destination Ports by using a hyphen.
• The use of quotes around a phrase will be treated as a single search term. The phrase "term1
term2” will match any alert containing the exact phrase within the quotes. Any spaces in the
phrase will match any space characters in the alert, including a space, a tab, a new line, etc.
Matching is done on the character boundaries, not word boundaries. Therefore, a phrase of
“top secret” will match an alert containing a phrase such as “stop secrets.”
• Multiple phrases such as a “literal phrase 1” and a “literal phrase 2” can be included in the
Find field. This will match any alerts containing all of the phrases listed.
• You can combine word-terms and phrase-terms. Any combination is allowed, such as:
• Matching does not consider the order of the terms, only that all are found within the search
field.
• Placing a minus sign (-) before a word or a literal phrase changes the meaning to “match all
alerts that do not contain” the specified word or phrase. Any combination of positive (no
minus) and negative (minus) terms is supported.
For example:
Top –secret matches alerts that contain the word top but do not contain the word secret.
“top secret” –confidential –personal matches alerts that contain the phrase “top secret” but
contain neither confidential nor personal.
top secret –“confidential document” matches alerts that contain the words top and secret but
do not contain the phrase “confidential document.”
- [Link] excludes the specified IP addresses [Link] from a search.
Important: the following also applies to all searches:
18
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 46
• There is a limit of 40 terms (words or literal phrases). If more terms are entered, the 41st and
beyond will be ignored.
• If Go is pressed without entering a search term, the Alerts List reappears. However, entering
unknown in the Find text box, substitutes for an empty string in the Country, Filename, From,
To, and User fields.
• Search performance is typically fast, even with very large alert databases. With a database of
over 2 million alerts, search will typically respond in a few seconds. Exceptions are searches
over Forensic Data, Session Attributes, and Owner fields, which may require considerable
time to execute.
T a bl e 5. A l e rt s e a rc h fi el d s
Alert Management The search is applied over the alert management group field. An alert can
Group belong to only one alert management group. If you search for multiple
groups, the search will match an alert containing any one of the groups
(most other search fields require a match of all terms). For example, a
management group search for: Group1 Group2 yields all alerts belonging to
either Group1 or Group2.
Country: Any Searches for the specified country in either the source or destination
country.
Entering two or more countries in search criteria returns all entries with any
of the countries entered. For example if you do a country search for France
Afghanistan the search will return entries that have either France or
Afghanistan.
This applies to all country searches.
Country: Source Searches for the specified country in the source country.
Current Search Enables you to use the simple Search interface to modify time,
CommandPosts, grouping, and display without changing search items that
were entered on the Customize Report interface.
You will see this option only when Customize Report was used to enter
search terms against multiple searchable fields. The text box will display:
Current Search and cannot be edited. If you select a different field, the text
box will become enabled and you may enter new search terms against the
selected field.
Execution Searches alerts based on their execution forensics status. You can select
Forensics Status from: Failed, Not Submitted, Pending, Received, or Rejected.
Filename Searches the name of the file that caused the violation. Will be empty if no
file was involved in the violation.
Format Type Searches for the Format Type of the content whether it is sent within a file,
in the body of an email, or in any other form.
Forensic Data The search is applied over the data field of the alert, as shown in the Alert
Host Activity Searches alerts for Host Activity information from Carbon Black. You can
selected Detected or Not Detected to identify alerts with or without Host
Activity data.
IP: Any Searches for any IP address: source or destination. Refer to Search IP
Addresses.
Note: Selecting IP Pair overrides Any IP and Source and Destination
IP.
IP: Destination Searches for the receiver’s IP address. Refer to Search IP Addresses.
IP: Source Searches for the sender’s IP address. Refer to Search IP Addresses.
Label Searches for an alert label. The label search has one special feature: A
search for the term unassigned (with or without quotes) will display all alerts
that have not been assigned a label
MD5 Searches the MD5 hash value associated with the [Link] can enter
multiple search criteria separated with a comma.
Policy The search by policy is applied over the name of the violated policy per
alert. There are no special features for policy searches.
Port: Any Searches on any port, either source or destination.
Port: Destination Searches on the sender's port number.
Port: Source Searches on the recipient's port number.
Protocol An alert can only contain one protocol. Therefore, a search containing
multiple terms will match an alert that matches any one of the terms (most
other search fields require a match of all terms). For example, a protocol
search for: ssh http yields all alerts found over either SSH or HTTP.
Resolved IP Searches for any IP address: source or destination that matches the
Address: Any resolved DNS name. Refer to Search Resolved IP Addresses.
Resolved IP Searches for the receiver’s resolved IP address. Refer to Search Resolved
Address: IP Addresses.
Destination
Resolved IP Searches for the sender’s resolved IP address. Refer to Search Resolved
Address: Source IP Addresses.
19
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 48
Alert search Description
fields
Session Attributes This search is performed over the session attributes of the alert. Session
attributes include the Channel Attributes and the Matched On information
about the Rule Violation of alerts. The value in the Find text box will match
the name of a protocol, file format, fingerprint, or matched content.
Refer to chapter 4 in the Guide to Creating Policies for details about
protocol or file formats and their attributes.
Refer to chapter 7 in the Guide to Creating Policies for information about
rule violation data.
Summary The search by summary is applied over the summary field of the alert.
Target Target refers to the destination of the information. The value is protocol
specific. Examples include the destination URL, share name, or host name.
Target is based on extracted protocol information and not based on the IP
address of the data. In many network configurations, the IP address may be
an internal address corresponding to a local NAT server or proxy, whereas
the target represents the intended destination of the data.
Threat Score Searches for alerts that match the specified threat score. Enter search
values between 0 -100. If the alert does not include execution forensics, the
value is empty.
To search for alerts with a specific score enter the value. For example, enter
4 to find alerts with a threat score of 4.
To search for alerts with a list of specific scores, enter a comma-separated
list of values. For example, enter 4,37,82,100 to find alerts with a threat
score of either 4, 37, 82, or 100. Do not enter spaces between the commas.
To search for alerts within a range of scores enter the range separated by a
hyphen. Be sure to not include spaces in your search text. For example, to
find all alerts with a score greater than 50, enter 51-100 into the search text.
To find all alerts with a threat score, enter 0-100 into the search text.
Ticket Content Searches the content of the alert ticket Subject and Comment fields. This in
the Alert Workflow Log section of the Alert Details page.
Ticket Owner An alert can belong to only one owner. However, if you enter a search with
multiple terms, the search will match an alert containing any one of the
terms (most other search fields require a match of all terms). For example,
a search for: Owner1Owner2 yields all alerts belonging to either Owner1 or
Owner2.
Also, a search for the term unassigned (with or without quotes) will display
all alerts that have not been assigned.
• Alert source
• Alert destination
• Resolved IP address
• IP Host
• [Link] finds this exact IP address within the selected field (source, destination, or
both).
• [Link]/24 applies an IP address mask of 24 bits to the address. This includes all IP
addresses within the 192.167.10 subnet, from [Link] through [Link]. Replace
“24” with any value 0-31 to obtain the appropriate mask.
• Any IP address or range can be used to match multiple IP addresses if the IP address entries
are separated by spaces or commas. For example, entering “[Link]/24
[Link]/24” would match any IP address in the range [Link] through
[Link] or IP addresses in the range [Link] through [Link].
• Links available in secondary columns and alert details will connect to the Subordinate
CommandPost if the alert is stored on a Subordinate. A login will be required if you do not
have a current open browser session to the Subordinate.
• Actions available at the Alert list page will be reduced to Export and Evidence Package. For
other actions (Change Ticket Status, Change Management Group, Change Label, and Purge
Alerts) you must login to the Subordinate CommandPost directly. For the local
CommandPost, all actions are available if only the local CommandPost is used in the report
generation.
• From a Master CommandPost you may directly access the details of any alert on the
Subordinate CommandPost without login. The Tune Rule wizard will not be available in this
mode. To use Tune Rule, log in directly to the Subordinate CommandPost. Note that rule
changes made on the Subordinate will not be reflected on the Master CommandPost.
Time Range
20
To specify a time period for alerts , click Search at the alert control bar and select a value at the
Time Range section. When you click Go, all alerts during the selected time period will be listed.
20
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 51
• Last 24 Hours, 7 Days, or 30 Days: provide shortcuts to reduce alerts to the prior day, week,
and [Link] default setting of all system reports is 24 hours.
• Specific Hours: will display a text box to which you can enter a two digit number, N. Only
alerts occurring in the past N hours will be displayed. You can use this feature to reduce
alerts by partial days with granularity of one hour increments.
• Specific Days: will display a text box to which you can enter a two digit number, N. Only alerts
occurring in the past N days will be displayed. You can use this feature to reduce alerts to
those that occurred during a specific number of days.
• Specific Date: Click in the text box. A calendar displays from which you can select a date.
This reduces your alerts to those that occurred on the specified date.
• Date Time Range: You can enter a range by entering From and To dates and times. Click the
text box. A calendar displays from which you can select dates and times. This reduces your
alerts to those that occurred during the specified range, including the specified dates and
times.
Customize Report
Click Customize Report to access the Custom Report page. From this page, you can search
multiple fields at the same time. Customize Report enables you to save current search, filter, time
range, or group by selections.
Using Customize Report to save criteria entered at the Alert List page as a Custom Report enables
you to access the report later at the Alert List page. Refer to Create Custom Reports.
The new Custom Report is also available at the Reports>Saved Reports. From the Report List, you
can edit the custom report, schedule it to run at specified times, or copy it to other users.
You can create other reports and make them available at the Alert List page.
Group By
This feature enables you to group alerts by information available in one or more of the primary
21
columns of your current alert page. For example, if you select protocols, alerts are grouped by
protocols. The total number of alerts for each protocol will be listed in the Count column.
The Grouped by page also includes the Last Seen column that shows the latest time stamp of each
group of alerts.
Grouped alerts can be displayed in tabular or graphical form. Graphical forms include pie charts,
bar charts, and stacked bar charts. You may choose the display most relevant to your analysis.
Group By enables you to more easily organize alert information. After grouping, the checkboxes on
22
the left side of the Alert List page apply to the whole group. With one click, you can manage,
purge, or label thousands or even millions of alerts at once. The more alerts that you select, the
longer it will take.
To group alerts:
1. Click Search. The Group By section displays in the Search dialog box .
21
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
22
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 52
Figure 16. Alerts Group By
Note: If the desired column is not displayed, select another report at Alerts.
2. Click one or more of the desired columns.
Note: Group by can take several minutes depending on the size of the alert database.
3. Select how the results will display at the View Results as list. You can select from Tabular, Pie
Chart, Bar Chart, and Stacked Bar Chart options.
4. Click Go.
When alerts are not grouped, these icons are not visible.
• Click Group Details to see a list of all alerts in the selected row. This action is identical to
clicking a section of the associated graph.
• Click one of the Group By links in the Distribution Summary to group alerts again using this
new element in the group analysis. A new group-by page is generated.
Group Details
When you click a section of a group by graph or click the Group Details button within the group
distribution summary, you are taken to a page with ungrouped alerts, filtered by the criteria
associated with the graph section or row in the group table.
You may change the filter, search, and sort criteria as designed. The Group row displays a link to
Return to Group List. Clicking this link will restore the Group By settings that started your flow.
If you change the Group settings, the Return to Group List link will no longer be valid.
Mouse over to see the options: Generate or Customize PDF. Both options enable you to
create a PDF file of all alerts on the current Alert List page.
You can also
Generate PDF
Select Generate PDF to create a PDF file. Simply clicking the PDF icon is equivalent to choosing
Generate PDF. The file will be downloaded.
Customize PDF
Customize PDF enables you to specify a title, description, footer, add a logo, and choose the
number of columns to include in the report.
23
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 55
4. To include a footer in the report, you can select the default footer, or type the desired footer
text into the box and click Save.
To create a footer for single use:
Click the checkbox next to Use: and enter a name in the checkbox.. This footer will only be
used in the current report and is not saved.
To use the default footer:
Select the checkbox next to Footer: Use: [previously saved footer]. Once you select the
default footer, the option to enter and use another footer will not be available.
To change the default footer:
Click to change the footer. The PDF Config tab opens. Enter the desired text into the
text box.. Click Save as Default. This footer is available for other PDFs and for all other
users until changed. Click Reset to Default to restore the previous default.
To disable the footer without changing it, uncheck the box.
5. To include a corporate logo or image: choose a .jpg, .gif, or .png file from your workstation
and click Save to upload the image to CommandPost. This image will be inserted into the
PDF at the top left of the report. The size of the logo file should be less than 500 kB.
Select the checkbox next to the previously saved footer to use in your report . Click
and choose the image file from your workstation. Click Save to upload the image. The logo
is available for other PDFs and for all other users until changed.
To disable the footer without changing it, uncheck the box.
To disable the image without changing it, uncheck the box.
6. Select the page orientation: portrait or landscape.
7. Click Export PDF. The resulting PDF file contains up to 50 alerts on the current Alert List
page. Export PDF does not save changes, but these changes will be available for other
Alert page PDF reports until you log out or until these settings are changed.
T a bl e 6. S e cti o ns i n A l ert D et ai l s
Alert Provides basic information about the alert including: time and date of detection,
Information age (elapsed time since detection), the sensor that detected the alert, the
application protocol, and format, source and destination data. Other
information includes: the alert label, the status of the associated alert ticket,
and the action taken by the sensor.
The data format includes a Format Type and Format Data size if the alert
includes forensic data. Format information may not be present when an alert is
based on channel information and not on content.
Source and destination information includes IP addresses, TCP ports
(presented as the service), and data flow direction. The Host IP represents the
computer or workstation that resides within your network – the system that may
Violation Provides the names of the policy and rule that were violated, and results of all
Information fingerprints within the rule in addition to the rule summary.
The Policy and Rule names can be clicked to redirect you to the Policy or
Rules page if you have a role that provides access to Policies.
The Policy and Rule names can be clicked to redirect you to the Policy or
Rules page if you have a role that provides access to Policies.
Refer to chapters 7 and 8 in the Guide to Creating Policies.
Selecting a fingerprint, rule, or policy from a Subordinate CommandPost.
If the Policy or Rule has been deleted from CommandPost, the link will take
you to the Policy or Rules list page displaying all current polices or rules loaded
on CommandPost.
Note: Policies and Rules created by the DNS Decoder will not be
available under Policies. To access DNS Decoder configuration
page, click System>Components and select the appropriate Direct
or Internal sensor and click Config. At the Config page for the
Direct or Internal sensor, click the DNS Decoder tab. The Violation
Information will display the DNS Policy and Rule names, but they
will not be clickable.
Note: Alerts generated by the Malware Detection Engine will
display the rule and policy as Malware Detection Engine. Neither
the rule nor the policy will be clickable.
The summary displayed in Alert Details is limited to 100 characters and will be
truncated if that limit is exceeded. Keep this in mind when using keywords such
as %TO% within your rule definitions. The summary associated with a Malware
Detection Engine alert will reflect the analysis method used by the MDE for
malware determination.
The Matched on table provides a table of all fingerprints in the violated rule,
along with the fingerprint true/false match result. When the result is true, the
table will include a table of fingerprint matches that were detected. This table
will vary by fingerprint type.
For example, if the fingerprint is a keyword content fingerprint, you will see a
table of all keywords that were found. If the fingerprint is an identity profile
content fingerprint, you will see a table of all pattern sets that were detected.
Click on a fingerprint name to go to the fingerprint page. Refer to Refer to
chapter 2 in the Guide to Creating Policies.
Each fingerprint in the Matched on table will be associated with a color code,
representing the highlight color for this fingerprint. Refer to Alert Highlighting
below. The highlighting can be disabled per fingerprint in this table. Alert
highlighting can be turned on or off. Click the icon next to Highlighting.
Fidelis Insight Policy feeds may include encrypted fingerprints. If an encrypted
fingerprint is matched on, the Matched On information and highlighting is not
available for that fingerprint.
If a fingerprint contains a NOT clause, the Matched On information displays but
highlighting is not available for that fingerprint.
Refer to the Fingerprint Page ( chapter 2 in the Guide to Creating Policies).
In a hierarchical CommandPost environment, the following applies:
When operating from a Master CommandPost, you may access alerts that are
stored on a Subordinate CommandPost. Clicking the fingerprint, policy, or rule
name tells CommandPost to check the Master CommandPost to see if the
Master has the same fingerprint, rule, or policy. If the selected item is the same
on the Master and Subordinate CommandPosts, a pop up displays that
enables you to select either Subordinate or Master. If the information differs,
the pop up displays, but you can only select Subordinate. If you select
Subordinate, you will be directed to the login page of the Subordinate
CommandPost if you do not have an active session to the Subordinate
CommandPost.
Related Alerts A single network event can create multiple alerts. When this occurs, related
alerts section will list all alerts generated by the same network transaction.
There are multiple scenarios where this may occur:
• When multiple rules are violated. For example, you may have a rule to
alert on webmail and another to alert on the detection of Personally
Identifiable Information (PII). A user who sends PII data over webmail
would violate both rules and generate two related alerts (if both rules
contained Alert in the action).
• A user may violate the same rule multiple times. For example, consider a
PII rule. If a user sends one webmail message with five attached files
containing PII, this will result in five related alerts, since each file violated
the rule.
• A rule that uses a flagged host fingerprint will show the original alert as a
related alert. . (Refer to chapter 3 in the Guide to Creating Policies.).
When related alerts exist, a list appears showing the severity, alert ID,
summary, time of the alert, and an indication of whether the alert contains
malware or not. The Alert ID of a related alert can be clicked to access the
details of that alert.
Malware This section contains the name, type, behavior, and description of the
Information malware. If the alert does not include malware, this section will state: No
malware detected by MDE.
Execution Files deemed malicious are automatically run through execution forensics.
Forensics Automatic submission may be configured by file type or disabled. Refer to
Execution Forensics. The execution process may take several minutes after
the alert appears in CommandPost.
This section may contain a button for manual submission of a file. The button
appears when the alert contains a file type that can be executed and either the
file was deemed non-malicious or it was deemed malicious but the file type
was excluded from automatic submission. When results are returned, the data
will replace the button in the Execution Forensics portion of the alert details
page.
If the alert does not include a file or it includes a file of type that cannot be
executed, this section will state: No Execution Forensics Report.
Alert Workflow Provides information about the alert ticket. Every alert includes an associated
Log ticket that can be assigned to a CommandPost user, moved to a different alert
management group, closed, and tracked by adding comments to a ticket.
The Alert Workflow log will display the history of the ticket and all associated
comments.
Refer to The Alert Workflow Log.
Decoding Path Provides the Decoding Path and the information extracted by the decoding
and Channel process executed by the Fidelis XPS sensor. The Decoding Path provides
Attributes access to the original data detected by the sensor, broken into each level of
protocol or file format extraction. Refer to Decoding Path and Channel
Attributes for a description of how you can use this information.
You may click each line of the decoding path that is displayed in red text. The
result is the output of the decoder at the line clicked. The decoding path will not
be clickable until the session recording is complete and the recorded session is
available to CommandPost. The decoding path (or portions of the decoding
path) may appear in black text and not be clickable if the recorded session is
truncated due to a session that exceeds the maximum configured recording
size, a prevented session, a corrupted session, or a session file that has not
yet transferred from the sensor to CommandPost.
Each line in the Decoding Path represents the output of a Fidelis XPS
decoder. These decoders also extract attributes from the protocol or file that is
being decoded. The Channel Attributes present a table, per decoder, listing all
extracted attributes.
Refer to Protocol and Format Decoder for more information.
Channel fingerprints are based on matching these attributes to those listed in
the fingerprint. Refer to (chapter 4 in the Guide to Creating Policies)
Alerts have clickable decoding paths only when there is a recorded session.
Because Collector alerts are based on metadata, there is no session,
therefore, the decoding path is not clickable if the alert is from a Collector.
When CommandPost is configured for LDAP (or Active Directory)
communication, user data and LDAP records are added. By default,
CommandPost looks up attributes based on FROM email [Link] an IP-
to-ID feed is configured,CommandPost uses the IP Address to determine the
user’s domain name based on the IP-to-ID information. The username is then
looked up in LDAP (or Active Directory) to determine the user data. In some
cases, IP-to-ID may return more information than one LDAP record. In this
case, all information is reported. Refer to CommandPost Configuration for
information about how to configure which attributes are extracted from your
directory server.
Packet Capture The Packet Capture section will only be populated if the violated rule contained
Information an action to capture packets.
When populated, the section provides information about network activity that
occurred up to 10 seconds before and 10 seconds after the alert. Refer to
Packet Capture for information about downloading Packet Capture files and
how to filter session information.
For the network traffic surrounding an alert to be captured, Packet Capture
must be enabled on a sensor with sufficient memory and enabled for a rule
with an alert action. Refer to information for the General page of the Direct
component chapter 7 of the Guide to Creating Policies). Note that there might
be a 10 second delay in getting the capture file relative to the time of the alert.
If you have a Solera Networks server available on your network and you have
configured CommandPost properly, the packet capture section will include a
link to the packet storage within your Solera server. Refer to Network
Forensics.
Forensic Data Forensic data is the information extracted by the last decoder in the decoding
path of the alert. You will see text, stripped of all formatting, that represents a
portion of the actual extracted data used by the sensor. You may view this
information in either a text or hexadecimal format.
Forensic data represents the decoded information available at the time of the
alert. If a rule is based purely on content or location information, the forensic
data section may be empty because content was not used to determine the
alert.
The displayed forensic data is limited to 4KB of data and will not display all
information used for analysis. If the size of the network data exceeds 4KB, the
display will begin approximately 100KB before the first content violation. The
entire forensic data may be obtained by clicking the last element in the
decoding path. Any portions of the data that match a content fingerprint will be
highlighted in the text view.
Viewing Forensic Data in text form is the default setting. When you change to
view the data as text, hexadecimal, or recorded session, your choice will
become your new default and will be applied the next time you access alert
details.
Recorded The recorded session is the session or object recorded up to the limits
Session/ Object configured for the sensor. This information is not stripped in any way and is
presented as it was recorded on the network (in client side and server side
data). By default, the first 4KB of the session is displayed. This can be
changed to view more of the session. Clicking Recorded Client Data or
Recorded Server Data will download the recorded data to your client
workstation.
Refer to Configure a Sensor for session limit settings.
If the recording was clipped because it exceeded the maximum configured size
at the sensor, or if there is any TCP prevention or time out information, a
message indicating one or more states displays.
Host Activity Provides Host Activity information from Carbon Black. Host Activity displays
information about malware that has been executed on the client workstation.
Click on a Process ID to display more information about the process including
the host name, process name start time, and endpoint IP. Network activity and
disk activity on the host is also provided.
This data is similar to the Execution Forensics section. However, Execution
Forensics provides information about what might happen if the malware was
execution, while Host Activity provides what did happen.
For access to this data, you need to enable integration with a Carbon Black
server. Refer to Host Activity.
Analytic Alert This section provides metadata for alerts generated by rules created at the
Info Metadata>Analytics rules.
Refer to Analytic Alert Info for details.
Alert Highlighting
Every alert is triggered by matching some element defined in a fingerprint to some aspect of the
data transaction. Each fingerprint displayed in the Matched on table will be associated with a color
code. Within the Alert Details page, some element will be highlighted in this color so that you can
easily determine the cause of the violation. An exception to this would be if the fingerprint is a
negated match (that is, a match not on certain criteria).
Note: All content to be highlighted might not be present on the Alert Details page.
Find Metadata
If CommandPost is connected to a Collector, you will see the Find Metadata link next to the Alert
UUID in the Alert Information section. Click the link to move to the Metadata page and locate the
collected session information associated with this alert.
The Find Metadata link is not available for alerts generated by the DNS decoder or from the Web
module. Refer to DNS Decoder and Web.
If you are operating in a hierarchical environment, the following applies:
If you are logged onto the Master CommandPost, the link: find metadata will take you to the
Metadata page of a Collector where the data resides. If the Collector is registered to the Master
CommandPost, you will be redirected to the page. If the metadata resides on a Collector registered
to a Subordinate CommandPost, you will be redirected to the Metadata page on the Subordinate
CommandPost and will need to login if you do not have an active session with the Subordinate.
Change Label
Within the Alert Information section, you will see the label applied to the alert. To change the label
or to delete labels, click Change Label. The process is identical to that described in Alert Labels.
Alert Compression
In cases of high event activity, the sensor may compress multiple, very similar events into a single
alert to reduce the network communication load on the CommandPost-to-sensor connection.
When one alert represents several events, the Alert Details will include the Events/Compression
data in the Alert Information section. The associated value indicates the number of additional
events represented by this alert. For example, if the value is 8, then there were nine similar events,
the one displayed in the Alert Details plus eight similar events.
If the alert contains no compression, you will not see the Events/Compression data. This is the
typical case.
The total number of transactions associated with the alert is also provided. Click to go
to Metadata>Explore and see information for all transactions associated with the alert. At
Metadata>Explore, the most recent transactions associated with the alert display first.
The bottom portions provide information about the latest metadata transactions associated with the
alert. The most recent eleven transactions can be viewed within the Analytic Alert Info. Click
Previous or Next to view all metadata from each of these transactions.
• Full Page Report: The Full Page report presents the full results of the execution of the
malicious files.
• PCAP File: The Packet Capture (PCAP) file provides details of network transactions spawned
by the analyzed file. The pcap file can be reviewed in an application such as Wireshark.
• Video: The video file shows video of the desktop during execution of the file.
Behavioral Indicators:
These indicators are characteristics of the file during execution that reflect typical heuristics
observed in malicious samples. The presence of behavioral indicators alone does not indicate the
sample was malicious, rather it is the combination of these indicators that determines if the file was
malicious.
DNS Traffi c
All observed DNS queries will be listed in this section.
TCP/IP Stream
Any TCP/IP traffic not detected as HTTP that was active during the execution of the file will be
listed here. This area could include traffic like DHCP queries, IRC connections, and other raw TCP
connections.
Processes
All processes that were initiated based on execution of the sample will be listed in this area along
with the Process Identification number (PID) and other useful data. Please note that the presence
of a process in this area does not indicate maliciousness of that process. For example, if you
analyze a file type like Adobe PDF, some processes listed will be due to the initialization of Adobe's
PDF Reader.
Artifacts
All artifacts created, modified, read, or deleted on the file system during the analyzing of the
sample will be listed here. There is a large amount of expandable content regarding each artifact,
including PE sections and import/export symbols for executable files, a hash of each artifact, and
the process that used that artifact.
Registry Activity
This section is divided into three subsections: Created Keys, Modified Keys, and Deleted Key
Values. Each subsection lists the associated information pertaining to each registry key-value pair.
Filesystem Activi ty
Each file object on the system that was created, modified, read, or deleted during the execution of
the sample will be listed in this section. Details contained here include the full file path, PID of the
process that took action on the file, and the associated file.
T a bl e 7. D e c o di n g p at h s
MIME([Link]) The MIME attachment without the part header (in this case,
a Base64-encoded file).
It is important to note that whether an entire file can be downloaded depends on how much of the
session is recorded in the CommandPost alert database. The maximum amount of the session
that is recorded is specified in the TCP session forensics limit setting. Refer to Configure a
Sensor>Direct for information on setting the TCP session forensic limit or the recorded object size
limit. If prevention is turned on, the file will be truncated at the point where the session was
terminated. Similarly, Fidelis XPS decoders can deal with some number of missing network packets
and still decode file content. The file application may not be able to open a file with missing content.
If the recording of a session ends in the middle of a file you wish to download, you may get a partial
file that cannot be read by the original application. For example, Fidelis XPS decoders and
analyzers can read a partial zip file even though the WinZip Windows application cannot. Similarly,
Fidelis XPS decoders can deal with some number of missing network packets and still decode file
content. The file application may not be able to open a file with missing content.
If the recording of a session ends before a file you wish to download, that part of the decoding path
will not be clickable, and that file cannot be downloaded.
The export list enables you to create, customize, or email a PDF file of the current Alert Details
page. You can also download alert information in an Evidence Package, Text File, or OpenIOC.
Click at the Export List to download this file for the selected alert.
At the dialog box, click either tgz format or zip format with password. If you select the zip format,
enter a password into the text box. Click Download.
You can also select up to 20 alerts at the Alerts List page and click Actions>Evidence Package to
download a .tgz or zip file that contains the information listed above for each selected alert. The
information in the file is organized by alert ID. The file name contains the CommandPost's IP
address. If alerts in the file are from multiple CommandPosts, then all CommandPost IP addresses
are appended to the file name.
The .tgz or zip file can be useful to send alert reports and Alert Details via email or to save for
future reference
OpenIOC
PDF Options
Click at the Export list to generate a PDF report of a single Alert Details page
using either the default or the saved customized options. Saved options include the footer, logo
image, and Alert Details sections.
Click Alert Details... to customize the PDF report or to send it via email.
Click to change the footer. The PDF Config tab opens. Enter the desired text into the
text box.. Click Save as Default. This footer is available for other PDFs and for all other
users until changed. Click Reset to Default to restore the previous default.
To disable the footer without changing it, uncheck the box.
5. To include a corporate logo or image: for the report, choose a .jpg, .gif, or .png file from
your workstation and click Save to upload the image to CommandPost. This image will be
Text Options
Click to open a text file of the Alert Details. This feature can be useful for
sending details of an alert by email, allowing for redaction of some details before sending.
Click Alert Details... and select the Text tab to choose sections for the text file or to send it via
email.
Figure 29. Alert Details: Select sections for the text file
2. Click Export Text. The resulting text file contains Alert Details of the selected alert.
Click to download the PCAP file to your workstation. If any filters have been applied, the
PCAP file is truncated based on those selections. Filters can be unselected by unchecking the
checkboxes at the bottom of the screen.
Click to download the PCAP in Evidence mode. The result is a compressed tar file containing
the original PCAP file and a text file. The text file includes :
• The MD5 of the PCAP file. The MD5 is created by the Fidelis sensor when the file is created.
• Information about the date and user name associated with the creation of the compressed tar
file
• All relevant information about the alert associated with the PCAP file.
Click to apply the selected values as filters and display the Alerts Reports page showing the
result of these filters. For example, clicking a source port displays a list of alerts filtered by the
source port. You must select at least one IP address or port number for Find Alerts to be
active.
between the specified source IP address to the specified destination IP address. Click to
switch the source and destination IP addresses. Selecting Any provides all packets for each IP
address or IP address range that you enter. The same options are available for Src/Dst or Any TCP
Ports.
For IP Protocol, you can select from TCP, UDP, and Any protocol to access the associated packets
from Solera. The IP Protocol filter is not supported by Solera for IPv6. You can still filter on TCP
and UDP ports. However, if an IPv6 address filter is specified and the Port fields are left empty, the
protocol filter will be ignored.
You may also specify one or more Ethernet Interfaces on the Solera appliance. By selecting
interfaces, you can access the packets captured from only those interfaces.
Select Start and End times as needed to narrow your packet information to a specified time span.
The page defaults to 10 minutes before the time of the Fidelis alert to 5 minutes after the alert.
Click to extract a PCAP file from Solera that contains the data associated with
your selections. .
Click to open the Solera browser interface to review packet data associated
with your selections.
Forensic Data
The forensic data represents the unformatted text on which Content fingerprint analysis is
performed. When there is a match to a content fingerprint, you will see the matched information
highlighted.
Note: Extracted hyperlinked URLs in office and html formats are displayed at the
beginning of Forensic Data. Extracted hyperlinked URLs in PDF documents for each
page are displayed at the end of contents for that page in Forensic Data.
Show Amount
It is possible to vary the length of the transcript displayed in the recorded TCP
Session page. Enter the number of kilobytes you wish to see in the Show KB text box and press
enter. This setting only affects the number of bytes displayed in this page.
24
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 79
Whitelist refers to a rule with the whitelist action. The whitelist will apply to every rule in the
policy. If you choose to use or create a whitelist, a new rule will be created and added to the
policy violated by the alert. An alternative is to modify an existing whitelist rule.
If you choose to modify the rule, the rule that was violated in the alert will be modified by
changing the rule expression. The tuning will only impact this single rule..
Whitelist is the recommended option. The created rule will be part of a single policy, however
the Policy page can be used to easily add this rule to other policies. Over time, you will likely
create lists of IP addresses, countries, URLs, and other applicable attributes that can be
easily modified to quickly whitelist certain network activities in your environment.
Use rule tuning only when the desired outcome is to modify a single rule, without affecting
any other rule on the system.
After selecting a tuning method, select the attributes of the alert that will be used to create the
exception.
Select a tuning method either use a whitelist in a policy or modify the rule.
If you choose to use or create a whitelist, you can add to a fingerprint within a whitelist rule,
create a new whitelist rule and fingerprint, add to a fingerprint and add a new whitelist rule.
Refer to the options described in step 3 . You can also select to modify the rule. If you modify
a Fidelis XPS rule, the user expression is modified, not the Fidelis expression.
After selecting a tuning method, select the fingerprint type and attributes for the fingerprint.
• IP Address enables you to create an exception based on the alert source and destination IP
addresses. Choosing both will create an exception for transfers from the source IP to the
destination IP, but not the reverse. Choosing one will create an exception for all transfers
from/to the source/destination IP address.
• Country enables you to create an exception based on the alert source and destination
countries. Choosing both will create an exception for transfers from the source country to the
destination country, but not the reverse. Choosing one will create an exception for all
transfers from/to the source/destination countries.
• Alert Information enables you to create an exception based on the source and destination
TCP ports and the application protocol. Selecting more than one option will create an
exception when all selected items are found in network traffic. For example, selecting Source
TCP port 8080 and protocol HTTP will create an exception for HTTP detected from port 8080
T a bl e 8. Pr ot o c ol d e c o d er a ttri b u t es a n d va l u es
Filename
From
To
User
To
User
Encrypted
From
Midstream
SQL
To
User
Subject
To
UID
User
Profile
Subject
To
UID
User
User
peer-to-peer network
Content is not decoded.
User
User
Location
Midstream
Mode
Proxy
Proxy Port
Referer
Server
Status Code
To
Tunnel
URL
User
User Agent
Via
X-Forwarded-
For
User
IPTUNNEL Used when one network Tunnel String with a defined format
protocol (the delivery (TYPE IP1:PORT1 IP2:PORT2)
protocol) encapsulates a
different payload PORT 1 and PORT 2 apply only
protocol. to Teredo tunnels. Type can be
Prevention is disabled one of the following:Teredo, 6in4,
for this decoder. 6to4, GRE, IPIP, IPsec
User
User
Mode
Subject
To
UID
User
To
User
SQL.
Content is not decoded.
Mode
Subject
To
UID
User
Mode
Subject
To
UID
User
Version
POP3 Post Office Protocol User
(POP) is an application-
layer Internet standard
protocol used by local
email clients to retrieve
email from a remote
server over a TCP/IP
connection.
Version
Server
Subject
To
User-Agent
Via
Share
User
Server
To
User
Quality
Hash
Hash
Mode Unused
Mode
To
User
User
T a bl e 9. F or m at d e c o d er a ttr i b u t es
Filename
Hash
Modification
Date
Quality
Type Anti-Item
Quality
Subject Name
Type
X509 Certificate or
Unrecognized Certificate
image An image
To
To
User
XHeader
(Customizable)
Creation Date
Filename
Modification Date
Quality
To
Header/Footer
Modification Date
Creation Date
Filename
Header/Footer
The header or footer found
within a Microsoft PowerPoint
Modification
document.
Date
Filename
Header/Footer
The header or footer found
within a Microsoft rich text format
document.
Modification Date
Creation Date
Filename
Header/Footer
Modification Date
Filename
The header or footer found within
Header/Footer a Microsoft Word document
Modification Date
Quality
Filename
The header or footer found within
Header/Footer an Openoffice text document
Modification Date
Filename
Header/Footer
Modification Date
Title
Modification
Date
Start Date
Subject
An encoding method
intended for forms.
Mode
To
User
Quality
T a bl e 1 0. Pr ot o c ol a n d f or m at de c o d er a tt ri b ut es
Command Protocol specific commands such FTP, HTTP, LDAP, SIP, SSL,
as get or put TLS
Compression Algorithm used to compress a file 7z, air, exe, rar, zip
Method
Encrypted Flag denoting that session was AIM, DB2, Exchange, IPsec,
encrypted MSNIM, Oracle, Poison Ivy,
SMTP, SSH, SSL, TLS
From User that initiated the email, chat, All email and chat protocols,
or transaction including:
AIM, AIMEXPRESS,
AOLMAIL, COMCASTMAIL,
DB2, EARTHLINKMAIL,
EMUMAIL, EXCHANGE,
FACEBOOK, GOOGLEMAIL,
GOOGLETALK,
GOOGLE_WEBIM,
HORDEMAIL, HOTMAIL,
HTTP, IMAP4, IRC, JABBER,
LINKEDIN, MSNIM,
MSN_WEBIM, MYSPACE,
NEOMAIL, ORACLE,
OWAMAIL, PLAXO, SIP,
SMTP, SQUIRRELMAIL,
VERIZONMAIL,
YAHOOMAIL,
YAHOO_WEBIM, YMSG,
mail, mime, ms-msg, tnef,
ymsg
Modification Date Date when a file was modified 7z, ms-excel, ms-office, ms-
powerpoint, ms-rtf, ms-visio,
ms-word, oasis-document,
oasis-presentation, oasis-
Server The server to which the host has Exchange, Fix, HTTP, Oracle,
connected SIP, SMTP, WebSocket
Server port The port on which the server is HTTP
listening
or not
Version Version of the protocol being used PoisonIvy, RFB, SMB, SSL,
TLS
• Quarantined: The email is currently held in quarantine on the Fidelis XPS Mail sensor.
• Admin Discarded or Admin Delivered: The quarantine manager has discarded or delivered the
quarantined email. Refer to Deliver or Discard Quarantined Email.
• Auto Discarded or Auto Delivered: The email has expired and was delivered or discarded
according to the rule that was violated. Refer to chapter 7 in the Guide to Creating Policies.
• User Discarded or User Delivered: The sender of the email has discarded or delivered it
through quarantine user self management. Refer to Quarantine Management by End-Users.
• Imported: The quarantined email is imported with the associated alert.
• Prevent has first priority. Any email that violates one or more rules with the Prevent action will
be prevented.
• Quarantine takes second priority. Any email that violates one or more rules with the
Quarantine action will be quarantined.
• Reroute has third priority. If other actions such as quarantine are detected, they are taken.
If the quarantine action is taken, the following occurs:
• The email is placed in the quarantine queue on the Mail sensor. It remains here until a person
responsible for quarantine management decides to deliver or discard it, or until the message
expires. Contact Technical Support to change the default expiration of 14 days, if needed.
• Information about the email message, and all associated alerts, is transferred to
CommandPost where it can be viewed by a quarantine manager. The action for each alert
refers to the action taken by the Mail sensor.
Note: This action may be different than the action specified by the rule due to the
prioritization described above.
• Each alert is assigned to the alert management group defined by the rule.
• The quarantine manager must have full quarantine permissions and also needs to belong to
the same alert management group of one of the alerts generated by the quarantined email. All
members of the alert management group, with the appropriate quarantine role can view the
message and take an action to deliver or discard the message. Refer to Manage Users,
Roles, and Groups.
• If the violated role has enabled Quarantine User Self-Management, the sender of the email
will be able to take an action to deliver or discard the email. Refer to Quarantine Management
by End-Users.
• Alerts and quarantined email are managed independently. Email actions will remove an email
from quarantine and optionally, all associated alerts. Removing all alerts associated with a
quarantined email purges these alerts from CommandPost. Refer to Deliver or Discard
Quarantined Email.
• Most quarantined email will have at least one alert. The only exception will be when alert
compression becomes active. Refer to Alert Compression for details. When the sensor
generates many alerts, it will begin to compress similar alerts to relieve congestion between
CommandPost and the sensor. In some rare cases, all alerts from one email will be
compressed together with other similar alerts, and therefore not be available on
CommandPost. The quarantined email will be available to all alert management groups in this
case.
Quarantined email is another key difference between the Mail sensor and other sensor types. Other
sensors make a decision to prevent, alert, or throttle immediately, based on analysis. The Mail
sensor offers the quarantine option, which defers the final decision to a person who reviews the
offending message. Therefore, persons with quarantine management responsibility may need to
take immediate action to avoid unnecessary delays in business communication. The Mail sensor
offers the ability to notify quarantine managers immediately upon taking the quarantine action.
Refer to Mail for configuration options.
• Quarantine Details: Click next to the email to see the Quarantine Details page for that
email. Refer to Quarantine Details.
• Alert Details: Quarantined emails can have alerts associated with them. Click an alert number
at the Quarantine Details page or at the Quick Summary for the quarantined email. The Alert
Details page displays with information for the alert. Refer to Alert Details for more information.
• Deliver or Discard the message. Refer to Deliver or Discard Quarantined Email. These
options also enable you to purge alerts associated with the quarantined email.
• If deliver is chosen, the email is sent from the quarantine queue to the original recipient. An
email is also sent to the original sender of the email notifying them that their email was
delivered.
• If discard is chosen, the email is removed from the quarantine queue and not sent to its
original recipient. An email is sent to the original sender of the email notifying them that their
email violated policy and was not delivered.
• A dialog box displays asking if you want to remove all of the alerts associated with this
message. If you choose All, the alerts are purged from CommandPost. Make sure that you
really want to discard all alerts before proceeding.
26
If you select None, any associated alerts remain available on the Alert List page. The
quarantined email is delivered or discarded.
• If the quarantined email does not contain associated alerts, a dialog box asks if you want to
continue. Click OK to continue to deliver or discard the quarantined email.
25
Users enables you to create and manage users, their roles, and user access.
26
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
T a bl e 1 1. Q u ar a n t i n e d Em a i l : s e a rc h fi el ds
Alert Management Any part of the alert management group associated with alerts.
Group
Forensic data Any part of the data captured from the email.
Justification Text Any part of the justification text. When the user replies to an
email notification, the reply is stored as justification text and
displays in the Quarantine Details page.
Refer to Alert Search Fields for more specific information about how these searches are applied.
3. Include or exclude Incoming quarantined emails.
Every access to the Quarantine page presents live data as it is reported to CommandPost. If
new quarantine emails are occurring on your network, this may distort your view of the data.
For example, you may click Next Page only to see the same set of quarantined emails from
the first page. This occurs because the first set of quarantined emails has been superseded
Fidelis XPS User Guide 120
by new quarantined emails, moving them to the next page. You will notice similar effects any
time you perform searches, or if you access Quarantine Details then return to the Quarantine
Management page.
You can change this behavior by clicking the Include Incoming Quarantine in the Search
dialog box. By default, this option is checked, meaning new quarantined emails will be
considered. To change this behavior, uncheck the Include Incoming Alerts box.
4. Click Go. You can search without specifying a time period.
T a bl e 1 2. Q u ar a n t i n e d Em a i l : a dv a n c e d s e a r c h fi el ds
Sensor(s) From the sensor box, choose a sensor or Ctrl-click to choose multiple
sensors.
Alert Management Any part of the alert management group associated with alerts.
Group
Status The status of the quarantined email. Select from the following:
Admin Discarded
Admin Delivered
Auto Discarded
Auto Delivered
User Discarded
User Delivered
Quarantined
Imported
Justification Text Any part of the justification text. When the user replies to an email
notification, the reply is stored as justification text and displays in the
Quarantine Details page.
3. Click Run Report to retrieve reports that match your search.
Quarantine Details
Click next to the quarantined email to access Quarantine Details. You can view the original
email message, a list of any attachments, and alerts associated with this email.
Note: Quarantine Details is only available to users with the correct privileges. Refer to
User Roles.
27
Users enables you to create and manage users, their roles, and user access.
28
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 124
Chapter 6 Investigator
Investigator enables you to bookmark alerts, alert searches, metadata sessions, searches, and
transactions for further investigation. This allows you to group disparate items together with
comments for easy retrieval and review by other users. For example, if an alert includes related
metadata, you can include the alert and any related metadata sessions in an investigation.
Information about the bookmarked alert and related metadata is saved in the investigation and is
available even after the original alert or metadata sessions are deleted.
For example, you can include alerts and an alert search in an investigation. Information about the
bookmarked alerts and the alert search is saved in the investigation and is available even after the
original alerts are deleted.
Note: To access Investigator, you need View access to Alerts and Full access to
Details or View access to Metadata.
To print or export search results, you need Full access to Alerts or Full access to
Metadata. Refer to User Roles.
From above the Alert List or Metadata>Explore page :
Click to open Investigator. Once enabled, you may drag and drop alerts and alert searches
to begin using the Investigator. Initially, the default investigation displays and all items dropped into
the Investigator are added to the default investigation. The default investigation is private.
Investigations can be added, made public, closed, and modified. To change the status of the
default investigation, you need to save it under another name. Refer to Open an Investigation.
If you navigate to another page, the last investigation accessed displays. Click the investigation
name to display a list of investigations available to you.
• Alerts: From the Alert list page, drag and drop any row in the investigation. This action will
insert the alert with a name: Alert – N where N is the alert ID. The Comments associated with
the alert include relevant information about the alert including the UUID, source, destination,
protocol, file type, rule, and policy. The name and comments can be modified after dragging
the row to the investigation.
Once added, the alert will have a icon next to it in the Alert list. The icon only displays
when the investigation to which the item belongs is selected.
• Alert Search: There is often a need to include all alerts that meet certain criteria in the
investigation. This can be accomplished by executing a Search on the list page. Move your
mouse to the top left of the Alert list page where the search criteria is described and the
mouse icon will change to a hand. You can grab the search criteria and drop it to your
investigation. The search criteria includes search, filter, time range, and group information. If
your search includes group by information, the Return to Group List will not be available. The
entry into the investigation will be named: Alert Search – Date and the Comments will include
• Metadata Transaction: At Filter Results, click next to the appropriate transaction and
select Add Transaction to Investigation. This action will insert the metadata transaction with a
name: Transaction – N where N is the transaction ID. The Comments associated with the
metadata transaction include relevant information about the session including the protocol,
source, destination, and time of the session. The name and comments can be modified after
adding the transaction.
• Metadata Search. There is often a need to include all sessions that meet certain criteria in the
investigation. This can be accomplished by executing a Search on the Metadata page. At the
Metadata page, click and select Add Filter to Investigation. The entry into the investigation
will be named: Metadata Search – Date and the Comments will include all search criteria. The
name and comments can be modified later but the search criteria cannot.
Note that running these searches in the investigator at a later time may yield different results
if the search had an open-ended end time (e.g. last 24 hrs) because of metadata purging.
• Metadata Session. At Metadata Details, click the session ID and select Add Session to
Investigation at the drop down list. The entry into the investigation will be named: Session –
Session ID and the Comments will include session information. The name and comments can
be modified later.
Click to edit the investigation. Click the name of the investigation to change to another. Click
Clicking at the bottom closes the investigation. If you open or close an investigation, this
selection remains if you navigate to another page.
When open, the investigation includes an interface to change an investigation, view a list of all
items in an investigation, and an interface to filter the list. You can also create a PDF file of the
investigation or export it to Excel.
Change an Investigation
Open the current investigation to select a different investigation. The following controls display:
Status enables you to search for all , open, or closed investigations. The selections available at the
Owner and Investigation selections will change based on the selected status.
Owner enables you to select investigations that were created by different users. Any user that has
created a public investigation will be displayed in the list, in addition to yourself. The selections
available at the Investigation selection will change to list those created by the selected user. Public
investigations can be accessed and modified by any user with the proper role.
To access and use Investigator, your role must include full access to Alerts, Alert details, and
reports.
Investigation enables you to select an investigation based on the Status and Owner selections in
the window.
The current investigation may also be changed by clicking the investigation name in the
Investigation icon at the top of the Alerts or Metadata>Explorepages :
Click to open the Metadata>Explore page and view sessions and transactions from the
Investigation.
Click to generate a PDF file of the current investigation. You will be able to create a PDF of
information to which you have Full access. For example if you have Full access to Alerts, but not to
Metadata, you will only be able to include alert information in the PDF. The PDF contains the
content of the selected Investigation and uses the footer and the logo specified at Alerts for PDF
reports. Refer to Create PDF Reports for Alerts to change the footer or the logo. The creation date,
time, and the user display for the investigation and for each item.
Choose to print the PDF with or without search results.
The PDF without search results provides a summary of each alert or metadata search and
summaries of alerts or metadata items.
The PDF with search results includes the search and item summaries and the search results.
When search results are included, they will be capped at 1,000 results per search and 5,000 results
in total. The number of results allowed will be equally distributed between searches. The search is
performed before generating the PDF. This operation may be time consuming.
Click to export the current investigation to Excel. Export runs any alert or metadata searches in
the investigation and places the results in Excel. You will be able to export information to which you
have Full access. For example if you have Full access to Alerts, but not to Metadata, you will only
be able to include alert information in the export. Each search result is put into a different
worksheet with the name of the search. You can have up to 100,000 entries for all searches. The
number of results allowed will be equally distributed between searches. This operation may be time
consuming.
The Excel spreadsheet also includes investigation comments and item names and comments.
You can export with Saved search columns or with All search columns. Your selection determines
which columns will display in the Excel spreadsheet.
• Exporting with Saved search columns uses the search columns saved in an alert or metadata
search.
• Exporting with All search columns uses all columns that are in the alert or metadata page. If
you select All search columns for a Metadata search, an ExtraData column displays that
contains information from the Metadata Details page.
Click to delete the selected investigation. At the dialog box, click Continue to proceed with the
deletion.
Using or controls presents the following controls:
Name: enter a unique name for a new investigation or modify the name of an existing investigation.
Status: Open or Closed
Access: Private or Public. Private investigations can only be accessed by the CommandPost user
who created the investigation. Public investigations can be accessed and modified by any
CommandPost user with a role that provides Full access to Alerts, Alert Details, and Reports.
Click to delete the selected item. At the dialog box, click Continue to proceed with the deletion.
Click to see details of the item open in another tab (or window depending on your browser).
The item must exist on your system for the item details to display. For example, if an alert is
purged, the Alert Details page will not be available for that alert.
Metadata Controls
The top of the Metadata>Explore page contains three rows.
Top Row
The top row provides information about the applied filters, including the current filters, a button to
save the filters, a control of your layout options, and the ability to Export data.
Enables you to select a previously saved filter at the drop-down list or
return to the default filter. Selecting another filter without saving existing search criteria and layout
information as a filter will delete your criteria. Click and enter a name to save search
criteria and layout information under that name.
Enables you to select a previously saved filter at the drop-down list or return to the
default filter. Selecting another filter without saving existing search criteria and layout information as
a filter will delete your criteria. An asterisk indicates that changes were made. Click
and enter a name to save search criteria and layout information under that name.
• Private – The author has full access to the filter. Other users have no access to private filters.
The author can copy Private filters to other users and those users will become the authors of
the copies.
• Public (Read Only) – These filters can be viewed and run by all users. The author of a Public
(Read Only) filter is the only user permitted to edit, schedule, or delete the filter.
• Public (Read-Write) – These filters can be viewed and modified by all users. Any user with
the same permissions as the original author can edit, copy, run, delete, or schedule the filter.
The last user to change the filter is listed as the author.
Filters you create and save are available for your use later. The saved filter will also be available as
a Metadata report at Reports>Saved reports. The report will be available to you to export or delete.
Refer to Saved Reports.
The Dashboard checkbox makes the filter available as a report at the Custom Metadata Widget on
the Dashboard.
To change the filter, refer to Metadata Search. If you change an existing filter, an asterisk (*)
displays next to the filter name. Click . You can choose to Update the existing filter or
to save your changes as a new filter.
Note: You can only save changes to the default filter under a new name.
To change the time filter, click the current time selection to display a drop down list. The
default for time is Today (from 12:00 am to the current time). You can select from time presets to
filter data from the last hour to the last 7 days. You can also select All Data. Your choice of time
period will impact the performance of the metadata search.
You can enter a specific time and date in the text boxes or click to select a date and time from
the calendar.
Use the sliding bars to select the hour, minute, or second. Click Done when finished.
To enter a range: enter a later time and date at the To text box. Click Apply when done.
Add Filter to Investigation: Click and select Add Filter to Investigation. Refer to Investigator.
Bottom Row
The bottom row includes information about the data including the last time new data was retrieved
from Collector, the number of rows to display per page, and the ability to move through the pages
of data.
Last Search: Indicates how long it has been since data was retrieved from the Collector. Click Last
Search to retrieve new results and refresh the Metadata page. By default, the last results are
cached and retrieved, even if you reload the page or navigate to another page then return to the
Metadata page. Clicking on last search or changing the search parameters initiates a new search.
Click Cancel Search to stop a running search, if desired. This cancels the search in all views. You
can click Refresh to resume the search.
Transactions per Page: You can select how many transactions display on each page. The options
range from 25 to 1000.
Previous, Next: Click Previous or Next to move to the next page in either direction. Clicking a page
number takes you to another page of transactions.
The Collector name This name will be on the top right of the Metadata page. If available and if
you have the proper user permissions, you can select another Collector.
You can resize each pane in a layout if needed and specify a view for each.
To change a view, access the drop down list at the top of each pane.
The data displayed in each pane reflects the applied filters and page size, except for the Group
Chart. As you manipulate the data within one view, it may impact the other views.
The Group Chart reflects all data available within Collector that matches the filter, but is not
influenced by the page size.
The view selection for each layout is saved. So if you choose Tabular and Details view for layout 2
and switch to layout 3 then switch back to layout 2, the Tabular and Details view will display. These
settings are kept even if you log out and log in again.
The sections below provide a description of each view.
In Layout 1, Tabular View contains a icon. Click to view Metadata Details for that transaction.
Click to return to the Tabular View. The only displays for Tabular View in
Layout 1
Click to see basic information about the session at the top of Metadata Details or click to
close this information. The basic information includes client and server IP address, port, and
country information and sensor name. The session ID is also displayed -- a unique identifier for
each session.
• Arrows indicate the direction of each transaction. The arrow indicates that the direction
is from the client to the server. The arrow indicates that the direction is from the server
to the client.
• The icon indicates that this node contains subnodes.
• The icon indicates that this node does not contain subnodes
If more information is available, you can click to expand. Click to close.
You can click an item name to add it to a search, exclude it from a search, or add it to an
investigation. Refer to Search by Item.
The Metadata Detail view displays 50 items by default. If there are more transactions in a session a
node with: load more … is displayed at the end. By clicking on this node 50 more transactions will
be loaded.
Graphical View
The Graphical View displays metadata that matches selected filters. This view contains a main
display with a y axis that displays IP addresses and an x axis that indicates time or sequence of
transactions. The x axis shows the time or sequence between the first and last transaction and is
relative to selected filters.
Vertical lines show individual transactions. Their colors correspond to the color of the individual
item type selected at Color Type in the right pane, such as protocol or file type. Each vertical line
provides high level details of the transaction within the view. Mousing over the vertical line will
display all metadata associated with the transaction. It will also highlight the client and server IP
addresses in the Connection View.
Click a vertical line to highlight the transaction in all views. This action will also reveal the and
icons. Click to add the transaction to an investigation. Click the to pin the transaction,
which will remove the popup while remaining on the highlighted transaction across all views.
After you have pinned a popup for a vertical line, you can click an item in the pop up and then
either select to add it to a search, exclude it from a search, or create a new search based on the
selected item.
Curved lines illustrate sessions.
You can zoom into a specific area to focus on specific transactions. As you zoom in, each
transaction line lists protocol and other information.
Navigation controls help you move around the display or zoom into or out of a specific
area. Clicking anywhere in the bottom view or in the upper view (not on items) will reset
the zoom.
Connection View
The Connection View displays flow information between hosts found in the metadata based on
current filters. A circle represents the IP address of a host or server. Lines between the circles
represent the transactions between the IP addresses.
Mousing over a circle displays a popup that lists the IP address represented by the circle. It will
also highlight the IP address in the Graphical View. If multiple connections emanate from an IP
address this is indicated by a cluster of dots.
Mousing over the line displays a tool tip that indicates the type of transaction and how many
transactions are on the current Metadata page. The transaction type is shown if you selected a
partition type.
Group Chart
Group Chart enables you to group data by selecting one or more columns to apply a grouping. The
data in the chart represents all transactions that match the filter criteria and is not limited by the
selection of the number of transactions per page.
If a search is running you can click Cancel to stop the search at a Group Chart. The search will
continue at other views.
Transactions are grouped by the selected columns.
The top pane of the Group Chart displays grouped data in rows. Click Limit to select between 10
and 1000 rows. The bottom pane displays data in a bar chant. The x axis displays the transaction
count. The y axis shows how transactions are grouped according to column selections.
Column Items
Column items listed below can be selected for Tabular View and Group Chart with the exception of
Transactions and Timestamp. Transactions applies to Group Chart and Timestamp applies to
Tabular View.
T a bl e 1 3. C ol u m n It e ms
Client Country The country information derived from IP address of the client.
Dir The data flow direction of the transaction: either client to server
or server to client.
From The From field extracted from email (if any) or other protocols.
Server County The country information derived from the IP address of the
server
Spool The Fidelis XPS sensor module that generated the event
Subject The Subject field extracted from email (if any) or other protocols
Tag The tag field inserted by the sensor when a transaction triggers
on a rule that has an action of Alert or Tag Metadata. A
transaction could have multiple tags associated with it.
Refer to chapter 7 in the Guide to Creating Policies.
Note that in such cases, the advanced search operators such
as: Equals, Isn't Equal, Contains, Doesn't Contain apply to any
of the tags associated with a transaction.
Timestamp The time when the session data was stored by the Fidelis XPS
Collector. Format is YYYY-MM-DD HH:MM:SS. Example: 2014-
07-02 :27:11
User The User field extracted by any protocol that carries a user field
X-Forwarded-For HTTP header field used for identifying the originating IP address
of client using an HTTP proxy
Metadata Search
Metadata includes multiple ways of searching: Simple Search, Search by Item, and Advanced
Search.
Simple Search
You can enter criteria into the Search text box and click Enter or . When you enter data,
CommandPost will parse the information, determine the information type, and apply the appropriate
filter value to the search. If you enter a new search value, the previous value will be overwritten.
Note that the search entry field is limited to 100 characters.
If no time range is specified Today’s data will be used. To change this, specify a time.
To provide multiple search criteria, use the Advanced Search feature.
Search by Item
You can add search criteria using individual items that display in the views. Nearly all items in rows
are available for search options. If a displays next to an item when you mouse over it, you can
click to open search options. A list of search options displays that enables you to add the item to a
search, create a new search based on this item, or exclude it from an existing search.
Note: Creating a new search eliminates any previously selected search items.
At the Graphical View, Group Chart, or Connection View, you can also select transactions, IP
addresses, or sessions for search options.
Individual display items to the right of the Graphical View or Connection View such as file types or
protocols are available for search options.
Your selection displays at the top of the Metadata page. Note how adding an item changes the data
in other views. For example, selecting a Server IP address at the Tabular View changes what is
displayed in the Graphical View and in the Connection View.
Advanced Search
The Advanced Search enables you to select multiple fields and values to narrow your search and
return transactions that meet all of the criteria.
Any search criteria previously entered in a simple search or time filters will display in the Advanced
Search. Click Clear to clear all search criteria.
To access the Advanced Search, click Advanced at the top of the Metadata page.
6. Click to add new line of search criteria. Click to delete a line. Clicking moves a
line of search criteria to a subsection of the previous line. Click returns search criteria to
7. Click Apply. You can also click Cancel to remove all values.
Metadata Search results display in a list at the top of the page.
Click to delete the search criteria. Click Refine or click in the advanced search results to
return to the advanced search. Advanced Search displays with the previously selected search
criteria.
Click Simple to start a simple search. This deletes the advanced search criteria previously
entered.
Any IP IP addresses
Export to Excel
Export Metadata to Excel or other application that can accept a tab-separated file.
Event Rate
The event rate analytic rule can detect multiple occurrences of a specific event within a time frame.
For example, consider an analytic rule that identifies users who use FTP more than ten times in an
hour.
Sequence
A sequence analytic rule is used to find events that occur in sequence. Each event in the sequence
may or may not generate an alert using the Policy engine, but the combination of multiple events
would lead to the creation of an alert by identification of a sequence.
Sequence analytic rules can be used for a variety of purposes including, but not limited to
identification of a kill chain, insider threat, and data leakage. The example below creates a
sequence looking for the word “password” followed by a password-encrypted file within ten
minutes. Event 1 relies on a tag, refer to Combining Policies with Metadata to insert content
analysis results into the metadata. Event 2 would identify the password-encrypted file based on
metadata. The two events are correlated by the Client IP, so that an alert would be generated when
both events are detected on the same Client IP within 10 minutes.
Analytic Rules
The Analytic Rules pane displays a list of analytic rules sorted by selected filters. You can also find
analytic rules by entering an analytic rule name at the Search text box. Any that are found display
at the top of the list.
Click to copy an analytic rule. You can make changes to the copy and save it under a new
name. A copied analytic rule is a new analytic rule and this enables you to change the rule type.
You can create a new analytic rule by clicking and select either Event Rate
or Sequence Rule. An example of your selection displays at the top of the rule pane.
A Sequence rule enables you to define an analytic rule by the occurrence of an event that you
specify.
An Event Rate rule enables you to define an analytic rule by a count of repeated events.
To edit an analytic rule, select it from the list.
Note: You cannot change the rule type for an existing analytic rule.
1. Enter a name for the rule.
2. Define an event. Each analytic rule needs at least one event. The event can be defined as
any combination of metadata using all available matching criteria available in the advanced
search of the Explore page. Refer to Advanced Search at the Explore page.
3. Specify the context in which one or more events violate the rule
For Event Rate rules:
• Specify a value to group the event by. For example, grouping by Client IP would look at all
events on each unique Client IP and apply the count to each value.
• Select the time period over which the time is applied. You can select a rate (using the
greater than option) or a range (using the between option)
• Specify a count for the rule.
For Sequence rules:
• Select a time for an event to occur after the preceding event.
• Provide the Event Correlation context. You may choose any metadata item over which all
events must occur within the provided times. For example, if you define three events and
correlate the events by Client IP, then the analytic rule will identify those three events all
occurring over the same client IP.
4. Add General rule parameters (optional):
Enter comments if desired and select a label for the analytic rule or enter a new label. Rule
labels can help you to organize and find them later.
The General tab also shows the rule type and whether or not it was automated.
5. Define the rule Action:
Select an Action Type either Alert or Save Results.
Alert: Select to generate alerts. Alerts display at Alerts>List page. You will also need to select
the Alert Severity from Low to Critical and assign an Alert Management Group.
You can choose to limit alerts by entering a number or keep the default of 100 alerts.
Save Results: Select to save the results in a list on the Metadata>Analytic Results page. You
can also choose to limit results by entering a number or keep the default of 100.
Click Send email notification and enter an email address, to receive email notices of results
when the analytic rule is run.
6. For a new analytic rule, click Save New Rule. The analytic rule will appear in the list of
analytics rules and the Automation tab will appear. The Run and Save buttons will also
appear.
7. Click Run to run the rule. A window will appear to define the run.
History
History provides you with a historical view of automated analytic rules. It should be used as a guide
to identify optimal time slots for scheduling automations.
Click to delete an automation and confirm the deletion at the confirmation dialog box.
Automation Details
Automation Details displays specific information about an automation selected at the Automation
pane.
To create a new automation:
1. Click ..
2. Select a type: either rule or feed.
Rule refers to analytic rules. To define a rule, refer to Analytic Rules.
Feed refers to Collector feeds.
Refer to chapter 10 in the Guide to Creating Policies.
If any Collector Feed is enabled, you can select Fidelis Insight Threat Feed to schedule the
time of day to run the feed analysis. This automation will be run daily. If no Collector Feed
is enabled, you cannot automate feed analytics.
3. Select a specific rule or feed.
The Action column displays the number and type of results with a icon next to the result.
If the automation has results, clicking takes you to the Analytics Results page. This page
provides additional information about each of the results. Refer to Analytics Results.
If the analytic rule action was alert, clicking or the number of alerts, takes you to the Alerts List
page. Alerts will be grouped by the rule, Collector, and by the run start time. Refer to Alert List. If
the alerts were deleted or purged, the Alert List will state, No data available.
Note The alert count is updated when the Collector generates the alerts and it may
take some time before the alerts are inserted in the CommandPost database and are
ready for viewing.
If there are no results, the Results column states None and the icon does not display.
Time Range
Time Range enables you to modify the view of your results. The time range is displayed at the top
of the page with the time selector on the left and a bar chart of results on the right. At the bar chart,
results are graphically displayed. You can mouse over the bar chart to see the total number of
results and the date and time that the results occurred. You can expand or contract the slider bar
as needed to focus on specific days or times. You can also select and
move the slider bar to view another portion of the bar chart. Note how the listed results change in
the table.
The time selector offers selections of 24 hours, 3, 7, or 30 days, and all data. The scale of the
horizontal axis of the bar chart will change as you modify the time selection..
Each bar in the chart may be clicked to view the results from that specific time frame. Depending
on the scale of the chart, the bar may represent one run or many.
If you select a bar, a refinement to the time range will appear below the selector. Click the to
remove the refinement from the chart. You will notice the refinement if you enter the Analytic
Results page by clicking on the results link or icon at the Automation or Analytics pages.
Group by Rules
Below the time range pane, to the left is the Group by Rules pane. If the results of the selected time
range include results from multiple rules, each will be listed. You may use the search interface to
find results from a specific rule. Clicking the rule name will change the data available in the Results
pane and will change the highlight on the left to associate the results with the rule that generated
them.
Click to expand the rule and show details of the past ten runs. You can click on any specific
run to limit the results to that single run..
Click to hide the Group by Rules pane. Click to show the pane.
Results
The Results table shows each analytic result in a separate row. Each row represents a violation to
an analytic rule. Information about each result includes event time (the date of the metadata that
violated the analytic rule) , the number of transactions in the result, the run time (the time that the
rule was run) and the unique context or group by item that violated the rule..
At each row, you can click to go the Metadata>Explore page to see detailed information about
the result.
The data in the table depends on the selections made at the time range, Group by Rules, and bar
chart.
analytic rule. Click to navigate through the first eleven transactions. Click
to go to the Metadata>Explore page to view all transactions in the rule violation.
The data provided here is the same available at the Alert Details page for analytic rules that specify
an action of Alert. Alerts are provided in the analyst workflow as alert tickets and can be exported to
third party SIEM systems. Results are not placed into the analyst workflow and provide a method to
develop and test analytic rules without overwhelming the analyst.
Write Throughput
This chart displays a trend line that indicates the number of metadata rows written per hour. The
bar chart in this section enables you to view performance trends over time. The performance will
normally fluctuate over time as the volume of data available on your network fluctuates.
Automations scheduled during peak network activity may run longer than automations scheduled
when network activity is less.
Automations
This chart graphically displays rule and feed automations for the selected time.
Click Name to display or hide all rule names and their results in the bar chart. You can also select
or deselect individual rule or feed names to narrow your results.
Mouse over a line in the bar chart to display information about the automation: name, status, start
time, duration, status, and the number of results. For details about rule statuses, refer to
Automation.
User Queries
User Queries graphically displays search run times associated with use of the Metadata>Explorer
page. The y-axis shows the number of parallel query executions while the x-axis is the same
timeframe as the other charts on the page. Mouse over a line in the bar chart to display more
detailed information for a user query: start time, duration, query parameters such as rule type,
sensor name or times, and whether or not the query is running (true) or not (false). You may want
to schedule automations for periods of low user activity.
• System Reports – These reports ship with Fidelis XPS and include: Default, Alert
Management, Malware, Malware by Host, Malware by Type, Label, and My Alerts. You can
run these reports or use them as the basis for a new custom report. If saved as a custom
report, the original system report is not affected. System reports are also available at the Alert
List page. Refer to System Reports for Alerts.
System Reports have the Public (Read Only) permission. You run these reports or copy and
save them under different names.
• Custom Reports – Customized reports allow you to control the contents and the display of
your report. From the Saved Reports page you can run, modify, and schedule these reports.
Refer to Create Reports.
• Saved Summary Reports – These are Summary Reports that were created and scheduled
at the Summary Reports page. From the Saved Reports page you can run, modify, and
change the execution schedule. Refer to Create Summary Reports.
• Metadata – These are reports created and saved at the Metadata page. You can export these
reports or delete them.
29
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 157
Figure 60. Saved Reports page
Report Permissions
Reports have one of the following permission levels described below. The report author refers to
the user that created the report.
• Private – The report author has full access to the report. Other users have no access to
private reports. The author can copy Private reports to other users and those users will
become the authors of the copies.
• Public (Read Only) – These reports can be viewed and executed by all users. The author of
a Public (Read Only) report is the only user permitted to edit, schedule, or delete the report.
All System Reports are Public (Read Only) and cannot be deleted by any user.
• Public (Read-Write) – These reports can be viewed and modified by all users. Any user with
the same permissions as the original author can edit, copy, run, delete, or schedule the
report. The last user to change the report is listed as the author of the report.
Public reports can be copied in a process known as Report Cloning. The new report is exactly the
same as the original, with the same report contents, and permissions. The author of the cloned
report will be the user that made the copy.
The permission of any report can be changed when the report is saved.
All reports execute under the permissions of the report author. Only those alerts available to the
author by sensor and alert management group assignment will be available in the report. In the
case of Public (Read-Write) reports, the author is the last user to modify the report.
• Run enables you to execute the report. This is active for all reports. Refer to Run Reports.
• Edit takes you to the Custom Report page to edit criteria and save the report. Refer to Create
Reports.
• Modify is available for saved Summary Reports and takes you to the Summary Reports page.
Refer to Create Summary Reports.
• Delete is available for Custom and Summary Reports. Refer to Delete Reports.
• Schedule enables you to enter scheduling information. This button is active for Custom
Reports.
• Modify Schedule also enables you to enter scheduling information and is active for Summary
Reports. Refer to Save and Schedule Reports.
• Export enables you to save the report definitions in a file on your client workstation. Exported
reports can be imported. Refer to Import.
• Export All enables you to save all report definitions to your client workstation.
Create Reports
Depending on the permissions of each report, reports can be modified, scheduled for automatic
execution, and copied to other users.
There are several ways to begin creating a report:
•
30
Click Customize Report at the Alerts>List page. All alert search, filter, time selection, and
group criteria is selected in the Custom Report page. You can change any parameter and
save it.
• Click the appropriate report at the Saved Reports page and click Edit. The Custom Report
page displays with any criteria selected for the saved report. This enables you to create a new
Custom Report based on a system report or an existing report.
• Click Create New Report at the Saved Reports page.
The Custom Report page contains the following sections that you can expand or collapse as
needed:
• Search provides an interface to identify alerts by a search rather than an exact match. Search
terms are typed into the available input fields.
• Filters provide an interface to identify alerts by an exact match of one or more alert fields.
Values are selected by choosing one or more values from the available lists.
• Time Range provides an interface to identify alerts by time.
30
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 160
• Columns provides a control for the information available in your alert report.
• Group By provides a control to summarize and chart the results of your report. The fields
available for grouping are those chosen as your primary columns for the report.
Search
To search, enter criteria into one or more of the text boxes within Search.
Alert ID Enter a single alert ID, a comma-separated list of alert IDs or a range.
Ranges are entered by a hyphen between the start and end of the range
File Name Searches the name of the file that caused the violation.
Forensic Data The search is applied over the forensic data field of the alert, as shown in
31
the Alert Details page. Note that some alerts will not contain forensic
data per policy definition.
IP: Pair Specify the IP addresses on which to filter alerts. Each IP address can be
source or destination. IP Pair is used to find alerts where the source AND
destination match the pair. It is used to find communication between
specified IP addresses.
Any IP is used to match alerts where the source OR destination is within
the defined range. Any IP is used to find communication that involves a
specified IP address.
Note: Selecting IP Pair overrides Any IP and Source and Destination
IP.
MD5 Searches the MD5 hash value associated with the file.
Port: Destination Enter a TCP port number, a comma-separated list of port numbers, or a
range. Ranges are entered by a hyphen between the start and end of the
range.
Port: Source Enter a TCP port number, a comma-separated list of port numbers, or a
range. Ranges are entered by a hyphen between the start and end of the
range.
31
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 162
Search fields Description
Resolved IP:Any Searches on any IP address: source or destination that matches the
resolved DNS name.
Resolved IP: Searches on any IP source address that matches the resolved DNS name.
Source
Session Attributes This search is performed over the Channel Attributes of the alerts. The
value will match the name of a protocol or file format for which attributes are
available, the attribute name, or the attribute value. Refer to chapter 4 in the
Guide to Creating Policies for details about protocol or file formats and their
attributes.
Refer to Protocol and Format Decoders.
Refer to Enter Search Terms.
Target Target refers to the destination of the information. The value is protocol
specific. Examples include the destination URL, share name, or host name.
Target is based on extracted protocol information and not based on the IP
address of the data. In many network configurations, the IP address may be
an internal address corresponding to a local NAT server or proxy, whereas
the target represents the intended destination of the data.
Threat Score Searches for alerts that match the specified threat score. Enter search
values between 0 -100. If the alert does not include execution forensics, the
value is empty.
To search for alerts with a specific score enter the value. For example,
enter 4 to find alerts with a threat score of 4.
To search for alerts with a list of specific scores, enter a comma-separated
list of values. For example, enter 4,37,82,100 to find alerts with a threat
score of either 4, 37, 82, or 100. Do not enter spaces between the commas.
To search for alerts within a range of scores enter the range separated by a
hyphen. Be sure to not include spaces in your search text. For example, to
find all alerts with a score greater than 50, enter 51-100 into the search text.
To find all alerts with a threat score, enter 0-100 into the search text.
Ticket Content Searches the content of the alert ticket Subject and Comment fields. This in
the Alert Workflow Log section of the Alert Details page.
Note: In searching IP addresses, the priority is IP Pair first, then Any IP, and finally
Source IP and Destination IP.
Note: Search terms entered for Summary, Forensic Data, and Session Attributes
follow the same syntax as described in Search for Alerts.
Filter Description
Alert Management Select one or more alert management groups to which the alerts belong. All
Groups groups available in CommandPost are listed.
Execution Searches on alerts based on their execution forensics status You can select
Forensics Status from: Failed, Not Submitted, Pending, Received, Rejected.
Format Type Select one or more file format types for the alerts.
Host Activity Select either detected or not detected on Carbon Black.
Labels Select one or more alert labels. Refer to Select Alert Actions to understand
how to apply labels to alerts.
Policies Select one or more policies. This list displays all policies on CommandPost.
Protocols Protocol refers to the network protocol over which the violation was
detected.
Rules Select one or more rules. This list displays all rules on CommandPost.
Severity Select one or more severity levels. Severity could be low, medium, high, or
critical.
Ticket Owner An alert can belong to only one owner. However, if you enter a search with
multiple terms, the search will match an alert containing any one of the
terms (most other search fields require a match of all terms). For example,
a search for: Owner1Owner2 yields all alerts belonging to either Owner1 or
Owner2.
Also, a search for the term unassigned (with or without quotes) will display
all alerts that have not been assigned.
• Last Login: reduces alerts to those that have occurred since the last time you logged into
CommandPost.
• Last 24 Hours, 7 Days, or 30 Days: provide shortcuts to reduce alerts to the prior day, week,
and month.
• Specific Hours: will display a text box to which you can enter a two digit number, N. Only
alerts occurring in the past N hours will be displayed. You can use this feature to reduce
alerts by partial days with granularity of one hour increments.
• Specific Days: will display a text box to which you can enter a two digit number, N. Only alerts
occurring in the past N days will be displayed. You can use this feature to reduce alerts to
those that occurred during a specific number of days.
• Specific Date: when you click the text box a calendar will appear. This reduces your alerts to
those that occurred on the specified date.
• Date Time Range: you can enter a range by entering start and end dates and times. When
you click a text box a calendar will appear. Select the desired date and use the sliders to
select a time. Click Done to enter the chosen date and [Link] reduces your alerts to those
that occurred during the specified range, including the specified dates and times.
Click Trending to graphically display the trend for all alerts within your current settings
Select time mode.
• Insert Time is the time when the alert was inserted into CommandPost.
• Alert Time is the time when the alert was created in the sensor.
Under normal operating conditions, these times should be relatively equal. Insert Time can differ
from Alert Time if alerts are imported from an archive file into CommandPost or if alerts are spooled
during database maintenance or CommandPost upgrade.
Selecting Insert Time will result in faster response from CommandPost.
• Column Choices lists all columns that you can include in a report. Refer to the table below
that describes report columns.
• The Primary Row contains the columns that will display as the main columns for the custom
report. These columns can be sorted or used to group alerts.
• The Secondary Row contains additional columns that can be used to provide extended
information on the Alert Report. When the report is run within CommandPost, each primary
column is shown per alert. You can click the alert to open the Quick Summary to access your
secondary information. Secondary row columns can be used to filter alerts and to navigate to
other pages by following clickable information fields. When the report is scheduled for
automatic delivery, secondary rows are not shown as part of the report.
• Sort By displays columns selected for the primary row or those selected for grouping. The
selection will determine the order of your report.
• To add a new column: Select one or more choices from Column Choices and click or
.
• To edit column order: Select one or more columns and click or until all columns are
in the desired order.
Available Description
columns
Alert Details
Icon Displays the icon at the location of your choice in the Alert List .
Alert Id Displays the alert ID. The alert ID is unique to a single CommandPost.
Refer to UUID for the alert ID unique across all components.
Alert Displays the alert management group to which the alert belongs.
Management
Group
Compression Indicates the number of additional events represented by an alert. Refer to Alert
Compression.
Filename Displays the name of the file that caused the violation. Will be empty if no file was
involved in the violation.
Format Type Displays the data format type that caused the violation.
From Displays the value of the extracted From field. The value is protocol specific and
most applicable to email or webmail. The value will be empty if the violation
occurred over a protocol that does not provide From.
Host Activity Displays host activity information as a red flag when the host reports activity
related to the malware detected on the network.. The column will be empty if there
was no activity on the host.
Insert Time Time when the alert was inserted into the CommandPost database.
IP:Destination The IP address of the recipient of the data. When available, both IP and resolved
host name are provided.
IP:Host The IP address of the host. The host usually identifies a workstation infected by
malware.
IP: Source The IP address of the sender of the data. When available, both IP and resolved
host name are provided.
Label Displays the label assigned to the alert.
Refer to Select Alert Actions to understand how to apply labels to alerts.
MD5 Displays the MD5 of the file with the malware. Information displays in this column
if a malware event occurred.
Owner The name of the CommandPost user to whom the alert has been assigned.
Resolution Displays the resolution to an alert ticket that was closed. Resolution can take the
following values: Allowed, Action taken, No action taken, and False positive. Refer
to The Alert Workflow Log.
Severity Displays a level of severity. Severity could be low, medium, high, or critical.
Status Provides the status of an alert ticket, which can be new, open, or closed. Refer to
The Alert Workflow Log.
Subject Displays the value of the email subject line. The value is protocol specific and only
applicable to email or webmail. The value will be empty if the violation occurred
over a protocol that does not include email.
Target Target refers to the destination of the information. The value is protocol specific.
Examples include the destination URL, share name, or host name.
Target is based on extracted protocol information and not based on the IP
address of the data. In many network configurations, the IP address may be an
internal address corresponding to a local NAT server or proxy, whereas the target
represents the intended destination of the data.
Time Displays the time when the alert was detected on the sensor.
To Displays the value of email recipients. The value is protocol specific and most
applicable to email or webmail. The value will be empty if the violation occurred
over a protocol that does not include email.
User Displays the value of the extracted User field. The value is protocol specific and
most applicable to protocols that require a login or user name. The value will be
empty if the violation occurred over a protocol that does not provide User.
UUID The Universal Unique ID (UUID) is an alert ID that will be unique over all Fidelis
XPS components. If an alert is archived and imported at a later date, the UUID will
not clash with the current set of CommandPost alert IDs, however the Alert Id
may.
Sort By
Sort By enables you to sort your report results by selecting an available column in either ascending
or descending order. Available columns can either be from the Primary Column entries if here is no
group by, or from the Group By list (with the Count and Last Seen columns). You can only select
one column at a time. Report results are sorted by your column and sort order selections and can
be saved..
If there is no group by in the report, Alert Time in descending order is used by default (most recent
to least recent alert time). You can change the sorting order to ascending, or you can select one of
the other Primary Columns.
If there is group by in the report, group results are sorted by Count in descending order (from
largest to smallest count) by default. You can change the sort order to ascending (smallest to
largest), or select one of the other group by columns (including Last Seen or Count).
Group By
Group by enables you to summarize your report by grouping selected values. The list of available
columns matches your selection of primary columns. Use CTRL-Click to select one or more
columns to group report results. You may also select a view for your report, either tabular, pie
chart, bar chart, or stacked bar chart. Refer to Group.
Report Controls
After entering criteria, you have the following options:
Edit Reports
To edit a report:
1. Click Reports>Saved Reports.
2. Select the appropriate report.
Note: You can edit private reports that you created or public (read-write) reports.
3. Click Edit. The Custom Report page displays with any previously selected criteria. Refer to
Create a Custom Report to make any needed changes.
4. Save your changes. Click Save to save your changes to this report. Enter a new report name
to save this report with a new name.
32
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 171
Save and Schedule Reports
You can save or schedule a custom report.
To schedule a system report, you must edit it and save it as a custom report. To schedule a
Summary report, refer to Schedule Summary Reports.
Save
To save a custom report:
1. After entering your report criteria, click Save at the Custom Report page.
2. Enter a unique report name with a maximum length of 40 characters.
3. Enter a description for this report, if desired.
4. If needed, ensure that the checkbox next to Alerts is selected. This option is selected by
default to make this report available at the Alerts List page.
5. If needed, ensure that the checkbox next to Dashboard is checked to make this report
available at the Custom Alerts widget on the Dashboard.
6. Select a new report permission, if needed or keep the current permission. Select from either:
33 34
private ,public (read only) , or public (read-write).
7. Click Save.
Your saved report displays in the Saved Reports page.
33
The private report permission gives users full access to the reports they created. Other
CommandPost users have no access to private reports. Private reports can be copied to other
CommandPost users.
34
Public (Read Only) reports can be viewed by all users. You can run a report with this permission
level or copy and save it with a new name. The author of a Public (Read Only) report is the only
user permitted to edit, schedule, or delete the report. All System Reports are Public (Read Only)
and they cannot be deleted.
35
The private report permission gives users full access to the reports they created. Other
CommandPost users have no access to private reports. Private reports can be copied to other
CommandPost users.
36
Public (Read-Write) reports can be viewed by all users. Any user with the same permissions as
the original author can edit, copy, run, delete, or schedule the report. The last user to change the
report is listed as the author of the report.
Fidelis XPS User Guide 172
6. Select a report delivery time.
7. Specify report frequency. This ranges from every day to specific days of the week or the
month. Report Frequency only determines the delivery schedule for the report and does not
change any times entered when creating the report.
Note: If you selected Date Range for the report, this date range will not change when
the report is executed. However, if you choose Last 24 hours, 7 days, or 30 days, the
time frame of the report will change with each execution.
8. Enter an email address for report delivery.
9. Choose to send the report as a pdf attachment to the email. You can also send the report as
HTML, text, or zipped alert details PDF. Click Save.
Note: If your report includes group by, trending, or pie or bar chart criteria, the Send
As option is not available. The report is sent as a pdf attachment.
To send as HTML: Click, HTML and select columns. Any columns that display in the column
list will send that information from your report in the email.
For more information about columns, refer to Columns.
To send as Text: Click Text. Select keywords and click Add Keyword. Keywords display in
the text box. If a user-defined format is chosen, type your format into the text box. Use
keywords to select the specific alert information to include in the report. If you desire a
comma-separated list, for example, enter each keyword from the drop-down list and type a
comma between each valid entry.
For more information about keywords, refer to Email user-defined.
To send as a zipped Alert Details PDF: Click Zipped Alert Details PDF. This creates a zip
file that contains a PDF of alert details for each alert in the report up to 50 alerts. You can
customize the PDF file. Refer to Customize the PDF for Alert Details.
10. Click Save.
Your saved report displays at the Saved Reports page. The Scheduled column at the Report List
indicates that your report is scheduled.
Note: the report will run under the permissions of the author, using their sensor and
alert management groups. For a Public (Read-Write) report the author is the user that
made the last change. This may change the alerts that are available in the report
output.
Delete Reports
To delete a report:
1. Click Reports>Saved Reports.
2. Click Delete next to the appropriate report.
Note: You can delete all reports that you created, whether public or private. You can
also delete any public (read-write) reports.
3. Click OK at the confirmation dialog box. The report is removed from the Saved Reports page.
If applicable, it is also removed from the Alerts Report List and from the Dashboard Custom
Report List.
37
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 174
Alerts Breakdown reports provide an analysis of your alerts.
• Choose from available data filters. Choose to view results based on the sender (source IP
address), receiver (destination IP address) or the transmission path (IP Pair).
• Choose to view results based on the sender (source IP address), receiver (destination IP
address) or the transmission path (any IP address).
• Select a date range. Select 24 hours, or 7 or 30 days or enter a date range.
• Select one or more sensors.
• Include the number of results to be considered, up to 99. The graphics will display the top
nine results individually and sum the remaining results into a tenth result. The chosen number
will influence the size of the associated data table, if selected. This option is not available for
the Malware by Time of Day report.
• Select the chart type: pie or a stacked bar chart.
T a bl e 1 8. S um m ar y r e p ort s
Tickets By Status The Tickets by Status report displays the total for tickets
grouped by the current ticket status: New, Closed, or Open.
Time selections and trend graphs refer to the alert creation
time.
Alerts By Policy The Alerts by Policy report displays the total for alerts
Breakdown generated during a selected time period grouped by policy.
By Severity The Alerts by Severity report displays the total for alerts
generated during the selected time period grouped by
severity. Severity includes Low, Medium, High, and Critical.
By Protocol The Alerts by Protocol report displays the total for alerts
generated during the selected time range summarized by
application protocol.
Note: The Traffic by Session and Traffic by Protocol reports are the only ways to view
the effects of policies that use the prevent option. This option prevents violating
sessions without generating an alert. The alert and alert and prevent options generate
alerts that display in all custom and alert reports.
PDF Controls
When you place your mouse over the Report button a window appears with PDF controls. From
this menu you may:
• Generate PDF, which is equivalent to clicking the Report button.
• Customize PDF.
• Email PDF.
Customize PDF
Customize PDF enables you to customize a PDF report for your needs. You can enter a title,
description, a footer, and add a logo.
1. Enter a title for the PDF report that will display on the top left.
Select the checkbox next to the previously saved footer to use in your report. Click and
enter the desired text. Click Save. This footer is available for other PDFs and for all other
users until changed.
To disable the footer without changing it, uncheck the box.
To disable the footer without changing it, uncheck the box.
5. To include a corporate logo or image: choose a .jpg, .gif, or .png file from your workstation
and click Save to upload the image to CommandPost. This image will be inserted into the
PDF at the top left of the report. The size of the logo file should be less than 500 kB.
Select the checkbox next to the previously saved footer to use in your report . Click
and choose the image file from your workstation. Click Save to upload the image. The logo
is available for other PDFs and for all other users until changed.
To disable the image without changing it, uncheck the box.
6. Select the page orientation: portrait or landscape.
7. Click Export PDF. The resulting PDF file contains the report information. Export PDF does
not save changes, but these changes will be available for other PDF reports until you log
out or until these settings are changed.
Email PDF
This option enables you to send a PDF report via email.
Note how the time changes in the button below the slider bar. Time
measurements also change on the graph.
• Mouse over a line to see what occurred at that point and how frequently.
• Clicking displays the information available for the maximum 14 day period,
even if you initially selected a shorter time period.
• Use the slider bar to see another portion of the graph.
Move the to expand or contract the time period being examined. You can also move to another
part of the performance graph. The time changes in the button and time
measurements on the graph also change.
Click any line in the legend to hide the associated line from the chart. As you hide lines, the scale of
the graph will change so that each line can be more visible,
• hash
• max payload
• payload limit
• descriptors
• payload handlers
• Shared memory
T a bl e 1 9. TC P R u n ti m e St a ti sti c s
The following table lists and defines TCP runtime statistics.
Processed Packets The total number of packets processed by a sensor. This value
provides a percentage of processed packets versus all received
packets. If the sensor is processing less than 100% of packets,
the sensor may be under too much traffic load.
Payload Faults The total number of payload faults for all sessions since the last
sensor software restart.
A payload fault occurs when a session was not allocated a
payload buffer. A payload buffer is used to save TCP and UDP
payloads in memory.
This fault is an indicator of low memory resources because of
sensor stress. One common cause of a payload fault are large
numbers of sessions with large amounts of traffic on each
session such as a large file transfer or a system backup.
Session Label Faults The total number of session label faults over all sessions since
the last sensor software restart. A session label fault is a session
for which a label descriptor was not allocated.
This fault is an indicator of low memory resources because of
sensor stress. A common reason for this fault may be large
numbers of simultaneous TCP or UDP sessions. This fault
should not happen often for sensors with greater than 32G of
memory installed.
Session Labels The total number of session descriptors over all sessions since
the last sensor software restart.
Session labels also known as session descriptors are
parameters that describe the parts of a session. Each parameter
will contain a value such as the session types: SSH, TELNET,
SSL, SMTP. These parameters are fed to the decoders that use
them to identify whether this is a session it should or should not
decode.
IPv6 Sessions The total number of IPv6 sessions processed by the sensor.
Midstream Sessions The total number of midstream sessions since the last sensor
software restart. The percentage represents the number of
midstream sessions as compared to all sessions.
A midstream session is a session where the sniffer process did
not detect both the SYN or SYN-ACK TCP handshake packets
for a session. This means that the beginning of the session was
not seen for the client or the server.
These faults will increment for a short period of time immediately
after the sensor boots because it will miss the first part of the
session while offline.
Persistent large numbers of midstream sessions are indicators
of a permanent or transient problem with the network traffic. The
sensor or upstream device, such as a TAP or SPAN port could
be dropping packets due to FCS errors or an overloaded device.
Midstream sessions are also typically seen in deployments
where there is asynchronous traffic routing and the sensor is
only provided one direction of the traffic..
Some midstream sessions can be detected and decoded,
however, any data attributes contained in the handshake will be
missed. This will result in loss of data for alerts and metadata.
A properly functioning sensor will report a high percentage of
midstream sessions when it starts. Over time, the percentage
should steadily decrease.
Holes Added When the sensor receives packets out of order, holes are
created in the session and filled when the out-of-order packet is
received. If the packet never arrives, the hold is marked as an
Unfilled Fault.
Holes Added represents the total number of hole descriptors
added over all sessions since the last sensor software restart
Holes Unfilled Faults Unfilled faults is a count of all lost packets. The percentage
provided is the number of unfilled holes over all holes added.
A small number of hole add faults and unfilled faults are
common because network traffic is not perfect and packets will
be lost.. A large number of these unfilled faults indicates a
problem with network traffic.
Sesring Faults The total number of session ring faults over all sessions since
the last sensor software restart.
A sesring fault is where a session was not assigned to the
• Runtime (information about the IP defragmentation alerts per minute over the selected time
period). Faults, frags, and rebuilt info for IPv4 and IPv6.
• Runtime information including the number of packets, queries, responses, success, total
38
errors, Name Not Found (NNF) errors, alerts , and events.
• DNS performance statistics per minute, graphically displayed
38
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 190
Inline Module
CommandPost shows the following information about inline and throttle modes.
Throttle provides the following information by packets and bytes
• Throttle TCP window cut: the number of packets (or bytes) on which the TCP window size
was reduced
• Packets per second and bytes per second displayed graphically
• Web Traffic: a graphical display and a numerical breakdown, Web traffic per minute
39
Internet Content Adaptation Protocol (ICAP) is a lightweight and extensible point-to-point protocol
used for requesting services for content inspection.
Fidelis XPS User Guide 192
Mail
CommandPost shows the following information about the Mail sensor:
• Events generated
• Messages prevented
• Messages rerouted
• Number of messages
• Messages quarantined
• Ignore Import File–will ignore the conflicting report in the import file. This is the default
option. All non-conflicting reports in the file will be imported.
• Import File Overwrites Database Entry–If there is a conflict with a Public read-only report
that is not owned by the user performing the import, the report will be rejected and will
not overwrite the database.
The import can take several minutes depending on the size of your import file. When complete, the
Import Result displays.
• Local users are defined within CommandPost. Using the System>Users page, you can
create a user profile, which includes the local password and all permission settings. Local
users obtain a CommandPost user name and password and are the easiest to configure and
manage. CommandPost includes one default local user (admin) which must be used to
configure all other settings. Fidelis recommends that you create local user accounts for all
persons responsible for the maintenance and support of the Fidelis products.
• LDAP users are created and managed by an external LDAP or Active Directory server.
RADIUS/TACACS+ users are created and managed at a RADIUS/TACACS+ server.
Directory attributes can be used to map users or user groups to CommandPost permission
settings. LDAP and RADIUS/TACACS+ users can access CommandPost using their directory
user names and passwords. LDAP and other non-local users are not provided a
CommandPost user name or a password. Some capability will be limited due to the lack of
these credentials. Management is performed by creating a user profile that maps directory
attributes, such as group names, to CommandPost access permissions.
Note: LDAP and other non-local users display in the Users>Profiles list after the first
login. This is used for user account management purposes only.
To create and manage LDAP users , refer to LDAP Configuration . To create and manage
RADIUS/TACACS+ users , refer toRADIUS/TACACS+ Configuration.
To understand CommandPost permissions, refer to Define User Roles.
To manage users , click System>Users. The Users page displays with the current list of
CommandPost user profiles and basic information about each user.
Note: The Users option is only available if you have access to user features. Refer to
Define User Roles.
• A role; required
Denotes a valid user. The user has a role and has at least one group and sensor
assignment.
Denotes a user with limited access to the system. This user may have a role, but lacks either
a group or sensor assignment
They may log into the system, but will not be able to execute their role.
This icon can also indicate a user who has been locked out of accessing CommandPost for
one of several reasons such as an expired password. Refer to Reset a Local User Account .
User Authentication contains more information about account lock and password age
settings.
Users Page
The Users page can be sorted by any column on a page in either ascending or
descending order.
To do this:
Click the column header to sort by that column.
The or icons display when a column has been sorted. You can only sort by one column at
a time.
40
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
41
In Fidelis XPS, refers to e-mails that were quarantined by a Fidelis XPS Mail Sensor and are
currently held in the quarantine queue.
Fidelis XPS User Guide 197
• Alert Management Groups can be used to divide the work of violation review and to segregate
violations by type.
The role is the first part of the access control system. Each CommandPost user is assigned one
role. This determines which parts of the system the user can access. Refer to User Roles.
Sensor access control is the second part of the access control system. Each user’s role provides
that user with access to certain CommandPost features. However, these features may only be
applied to the sensors to which the user is assigned. This control applies to all CommandPost
functions.
For example:
• A network operator may only configure and manage sensors to which that operator is
assigned.
• A Policy author may write policies, but may only install these policies on assigned sensors.
• An alert or quarantine manager may only view violations from sensors to which the manager
is assigned. The sensor access control serves to segregate data depending on where it was
found in the network.
The alert management group is the final component of the access control system. This is a group
of one or more users with a similar function, who should review similar network violations.
Examples might include a network administration group, Human Resources, or a network security
office.
Rules are associated with an alert management group. When a rule is violated, an alert or a
quarantined email may only be managed by persons in the assigned group. Once viewed, an alert
manager may move the alert or quarantined email to a different group as needed.
Alert management groups allow you to segregate data based on the rule that was violated. For
example, PII (personally identifiable information) violations may be sent to one group of users,
while violations involving inappropriate use of network resources are sent to a different group. It
also helps to split the workflow involved with alert management across one or more teams of
individuals.
• The System Administrator role provides full access to the system. The admin user has access
to all groups, all sensors, and all system functions.
• All rules and all new users are initially assigned to the default group.
• When a sensor is registered to a CommandPost, no user will have access, except the admin
user and the user who created the sensor.
• Local users can be added, deleted, and managed from this page.
• LDAP users can be deleted at the Users>Profiles page. Management of these users is
performed by mapping your external LDAP or Active Directory server information to
CommandPost user access profiles. Refer to LDAP Configuration.
LDAP users are added to the table at their first login. The user name is extracted from their
entry at the login page. They will remain on the page as long as they remain active users or
until an administrator removes the account.
• RADIUS /TACACS+ users can be deleted at the Users>Profiles page. Management of these
users is performed at the RADIUS/TACACS page.
LDAP and other non-local users are added to the table at their first login. The user name is
extracted from their entry at the login page. They will remain on the Users page as long as they
remain active users or until an administrator removes the account.
To access user profiles:
Click System>Users>Profiles.
• Provide identifying information for the user to CommandPost. This information includes user
name, password, and email address. This information is stored and managed within
CommandPost.
• Assign the user to the appropriate groups and components to implement assigned roles. Alert
Management Groups can be used to divide the work of violation review and to segregate
violations by type
The following restrictions apply when creating or modifying users:
• Create users with permissions equal to or less than their own permissions.
• Assign users to groups to which they belong. For example, a user that belongs to group A and
group B can only assign new users to those groups. Use CTRL+click to choose multiple
groups. Select No Groups to unassign a user from every group.
• Assign users to components to which they belong. For example, a User Manager assigned to
component A and component B can only assign new users to those components. Use
CTRL+click to choose multiple components. Select No Components to unassign a user from
every component.
The following table provides an overview of how to make role, group, and component
assignments so that a user has access to the more frequently used features.
T a bl e 2 0. D e t er mi n e us e r a c c ess
Alerts Full or view access Users must be assigned to Users must be assigned to
to Alerts the same group as the alert the component that
and its associated rule to generated the alert.
access the alert.
Details Full or view access Users must be assigned to Users must be assigned to
to Details the same group as the alert the component that
and its associated rule to generated the alert.
access the alert.
Quarantine Full or view access Users must be assigned to Users must be assigned to
to Quarantine the same group as the alert component that generated
and its associated rule to the quarantined email.
access the quarantined
message. No impact If a
message violates multiple
rules, any user with access
to one of the associated
alert management groups
can access the quarantined
emails.
Tickets Full or view access Users must be assigned to Users must be assigned to
the same group as the alert the component that
Users Full or view access A new user may be added to A new user may be added to
to Users any group to which the user any component to which the
manager belongs. user manager belongs.
Delete a User
42
Before you can delete a user, you must first reassign all alerts assigned to the user. Deleting a
user will delete all items authored by the user. These include:
• Exports
• Reports (public or private)
• Retention plans
• Investigations (public or private)
Note – Ensure that any Exports, Reports, or Retention plans are not part of any
established workflow or critical business processes. To reassign an Export, Report,
or Retention plan simply have the user that will manage the object make a minor edit
and then save the object. This will change authorship to that user.
To delete a user:
1. Click Profiles.
2. Click the appropriate user. Click the appropriate user. The Delete button becomes available.
The Delete button will not be available if open alert tickets are assigned to the selected user
or if you do not have permission to delete this user. Permission to delete requires that the
user has a role that is a subset of your own role.
3. Click Delete.
4. Click OK at the confirmation dialog box.
The user is deleted from the list on the Users>Profiles page.
To prevent future login from an LDAP user, you will need to change or remove this user from your
directory server or alter or remove the profile to which this user belongs.
To prevent future login from a RADIUS/TACACS+ users, you will need to change or remove this
user. Refer to User Authentication.
42
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 203
Define Alert Management Groups
You can create alert management groups to which you can assign users and alerts.
43
Each rule is assigned to an alert management group. Alerts generated when a rule is violated are
assigned to this group and visible only to the users in the group associated with the rule.
The alert manager may later move an alert to a different alert management group so that it may be
managed by members of other Alert Management Groups.
To access alert management groups:
Click System>Users>Groups. The Alert Management Groups page appears with a list of existing
groups. You can click on any group name to see expanded information, and the Edit and Delete
buttons.
The user and rule names and Assigned to Alerts are links that you can click to access Users,
44
Rules, and Alert List pages.
43
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
44
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 204
1. Click Add Group. The New Alert Management Group page appears with empty text boxes. or
select an existing group and click Edit.
2. Enter a name and a description for a new group.
3. Enter an email address for the group. When an alert changes from one group to another, a
notice is sent to this email. Similarly, notifications of quarantined emails are sent to this
address if a Mail sensor has been configured for quarantine notification. The email address
must be a single address, which can be a group distribution list, and must conform to email
syntax requirements.
4. Click Save.
A new group displays in the list with other alert management groups. You can now assign users to
the new group, assign alerts to the group, and modify rules to place alerts into the group.
Role Description
System Provides full access to all Fidelis XPS features. This role can be applied to any
Administrat user.
or
Network Adjusts sensor network settings and communications between CommandPost and
Admin the sensor, monitors network statistics to verify connectivity, and installs software
upgrades to Fidelis XPS.
Full Control: for Details, Reports, Sensor Admin, CommandPost Admin, and
Metadata
45
View Only: for Alerts , Quarantine, Tickets, Policies, and Users.
None No access for Audit
Network Includes all the roles of the Network Admin plus full access to Users to add and
Admin manage local users.
Supervisor
Policy Creates and manages policies and rules to one or more sensors.
Author Full Control: for Details, Reports, Policies, and Metadata
View Only: for Alerts, Quarantine, and Tickets
None No access to Users, Sensor Admin, CommandPost Admin, and Audit
Policy Includes all the roles of the Policy Author plus full access to Users to add and
Author manage local users
Supervisor
Alert Reviews alerts (or quarantined emails) and manages any action required within the
Manager enterprise.
Full Control: for Alerts, Details, Quarantine, Tickets, Reports, and Metadata
View Only: access for Policies
None:No access for Users, Sensor Admin, CommandPost Admin, and Audit
Alert Includes all the roles of the Alert Manager plus full access to Users to add and
Manager manage local users.
Supervisor
A role’s (and a user’s) access to each feature is determined by the access levels specified for that
feature: Full, View, or None. The following table describes each access level.
45
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 206
T a bl e 2 2. Us e r a c c ess l ev el s
Full Provides read and modify access to the feature. Depicted by a full
green circle.
Access Roles
To access roles:
Click System>Users>Roles.
On the Roles page, the permission levels and user information are hidden by default. Click on a
row, or click expand all to reveal the access levels and any user information associated with a role.
The user names display in links that you can click to access the Users page and see expanded
information for that user.
T a bl e 2 3. A c c es s R ol e s
Access Permissions
Roles
Alerts Provides access to Alerts>List. View permission allows you to read and
manipulate the report. Full permission allows you to purge and export alert data.
Details Provides access to the detailed forensic data for alerts and quarantined email
messages. Without access to details, you cannot view the forensic data or
retrieve the data that caused an alert. Details access is only available as either
Full or None.
Quarantine Provides access to Alerts>Quarantine . View permission allows you to read the
list of messages. Full permission allows you to discard and deliver quarantined
email messages. Quarantine permissions also depend on the alert management
group. In addition to quarantine permissions, you must also belong to the same
alert management group of at least one of the alerts generated by the
quarantined email.
Tickets Provides access to the alert workflow. With Full privilege you can assign alerts,
change the alert management group and close alerts. With View privileges you
can read the workflow log of any alert, but may not change it.
Reports Provides access to reports and to report customization and management. You
may view, create, save, and schedule reports for automatic delivery. Access is
only available as either Full or None.
Policies Provides access to policies. Full access is required to edit or create policies,
rules, or fingerprints. View access allows you to view, but not change, existing
policies.
Users Allows access to System>Users. With Full access you can add, remove, and
modify user profiles (including passwords), alert management groups, and roles.
View access allows you to view, but not modify, user profiles, alert management
groups, and roles.
Sensor Admin Provides access to the sensor configuration pages at System>Components. Full
access is required to modify the configuration of sensors. With View access, you
may view the configuration, but not modify it. Access to Reports>Network is also
granted based on the Sensor Admin setting.
Audit Provides access to System>Audit . Audit access is only available as either Full or
None.
Note: Fidelis recommends that you restrict audit log access to
system administrators and network security personnel. A user with
Audit access can see all auditable actions.
Metadata Provides access to Metadata. Select either View or Full. View access provides
access to the Metadata page and with full access to Reports enables users to
save filters. Full access to Metadata is required for export.
• Details are available as either no access or full access. View-only is not available.
• Access to Audit is either no access or full access. View-only is not available.
• Access to Quarantine, Saved Reports/Summary reports, and Ticket functions requires View
or Full access to Alerts. If you choose access to one of these three functions, CommandPost
will raise the level of Alerts to an acceptable level.
Note: Not all options are available to all users. You may only create a role with less
than or equal privileges than your own role.
Status Lights
Shown as a green, red, yellow or grey diamond at the top of the GUI, the status light indicates
whether a component is operational. Green indicates that the component is fully operational.
Yellow indicates a warning message, which may indicate operational problems or the detection of a
condition that warrants attention. Red indicates that the component is not communicating. This can
mean that the component is unreachable, offline, or being updated with a new version of Fidelis
XPS.
Grey indicates that there is no information available for the component.
By mousing over the status light, you can see a short description of any detected problem or
warning. The same description is available in the details of the component status.
Details
Click a row to view details about a component. CommandPost information includes the Name,
Version, OS Version, CommandPost Time, Relationship, Setup, and any yellow or red
Notifications. The absence of notifications indicates that the component is fully operational.
Collector and Sensor information includes:
• Name– the name of the component which was given when it was added to CommandPost.
• Description – an optional field supplied when the component was added to CommandPost.
You can edit the description at any time.
• Version– provides the Fidelis XPS software version installed on the component.
• Patch Version – provides the patch version installed on the sensor. If no patch has been
applied, this field will be empty.
Fidelis XPS User Guide 211
• OS Version– provides the operating system version installed on the component.
• Alerts – is a current count of alerts generated by this sensor. Clicking the count will take you
to an Alerts List showing alerts from this sensor. This field does not appear within the
information for a Collector.
License Messages
The following license messages can display in the Notifications section for the Console or a sensor:
• Edit Sensor (Collector) – click to change basic information about a component, including
name, IP address, and description. If the component is currently registered, name and IP
address cannot be changed. This button is not available for embedded sensors.
• Delete Sensor (Collector) – click to remove a component from CommandPost. This button is
available only if there are no alerts in the database generated by this sensor and if the sensor
(or Collector) is currently unregistered. If you wish to delete a sensor with alerts in the
database, you must first go to the Alert Reports page and purge all alerts generated by this
sensor from CommandPost. Refer to Purge Alerts for more information. When you return to
the Components Config page, you will be able to remove the sensor. This button is not
available for embedded sensors.
Edit a Collector
You can change the name or IP address (if unregistered). You can also change the description as
needed.
To edit a Collector:
1. Click System>Components.
2. Select the appropriate Collector.
3. Click Edit Collector.
4. At the Edit Collector page, enter needed changes.
5. Click Save.
Edit a CommandPost
To edit a CommandPost:
1. Click System>Components.
2. Select an existing CommandPost and click Edit. Edit is not available for the Console. (This is
the CommandPost to which you are logged in.)
3. Change the CommandPost name, IP address, or description as needed. The IP address is
used to identify the CommandPost to other Fidelis XPS Components.
4. Select either Master or Subordinate if you need to establish hierarchical relationships.
5. Click Save.
6. Click Register.
After the CommandPost begins to communicate the status indicator turns green and the Last Seen
value indicates the time of the last communication.
You can now configure the CommandPost by selecting it and clicking Config.
License
License shows the Host ID information, the current license key, and an expiration date. Each
component requires a separate license.
To access the License page:
Click System>Components>CommandPost>Config and click the License tab.
When you initially install Fidelis XPS on CommandPost, CommandPost will run in demo mode. A
sensor or CommandPost remains in demo mode until a license key is entered.
46
Components enables you to set up licensing and configure Fidelis XPS components. This
includes adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail,
and setting up user notification and LDAP among other features.
Fidelis XPS User Guide 221
Figure 94. The License
Clicking Request License or the component's Host ID creates an email to
license@[Link], with the subject line automatically completed with the component’s
Host ID. Include in the body of the email your name, the location name and address, phone
number, and reseller name (if pertinent), and Fidelis Technical Support will respond within one
business day with a license key.
When you receive the license key, paste or type it exactly into the License Key box, and click Save.
If the information was entered correctly and matches the Host ID provided, the key will be
accepted. If there is a problem with the license, you will receive an error and the License Key field
will display <Invalid>.
You must enable Execution Forensics at Malware Detection before entering the Execution
Forensics Key.
Enter the Execution Forensics Key.
Expirati on
Fidelis XPS begins displaying notices that your license will expire starting 60 days before the
expiration date. If you receive this notice, contact Technical Support to obtain a new license.
Demo Mode
If no license key is detected, the sensor and the CommandPost will operate in demo mode. The
sensor does not function in demo mode. A CommandPost in demo mode will not accept alerts from
any sensor and will only accept statistics.
47
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 223
Database Maintenance will also remove data associated with the alerts selected with a plan. This
data includes recorded objects, PCAP files, and quarantined email.
Note: this data will be removed only after all alerts associated with the data are
purged.
For alerts that have been imported to the system from an archive file, the age of the alert is based
on the import date and not the timestamp associated with the alert. The system defines a single
plan named Default that purges all alerts older than 45 days as well as any remaining recorded
objects, PCAP files, and quarantined email. The number of days (45) can be changed.
If any plans have been defined, they will be listed above the Default plan on the page. The list
provides a descriptive name, the retention period for the plan (in days), the archive setting (Yes or
No), and the Author, which provides the user name of the person who last saved the plan. An Edit
button and a Delete button is available for each plan in the list.
To change the Default plan:
1. Click Alert Retention.
2. Change the number of days to a value between 1 and 999.
3. Click the Archive checkbox if you wish to archive alerts before purging. Refer to Retention
Archive.
4. Click Save Default.
Any number of retention plans can be added to change the behavior of the alert purge operation. A
plan can define alerts by one or more attributes and can be set to retain the matching alerts for a
period shorter or longer than the default setting. If two or more plans identify the same alert, the
longer retention period will apply and archiving will be done if any matching plan had the archive
checkbox set. You can access the Edit page by clicking Edit next to an existing plan or by clicking
New Plan.
To create a new plan or edit an existing plan:
1. Click Alert Retention.
2. Click Edit next to a plan in the list or click New Plan.
3. The Edit Alert Retention Plan page displays.
• Execution time can be configured by Daily Execution Time and Maintenance Days. The Alert
Purge and database Optimization processes will be executed at the chosen time on the
chosen days. Based on this configuration, Purge and Optimization will run at most once per
day or at least once per week. The settings do not change the normal hourly optimization of
statistics.
• Archive options include the External Archive Directory, the Maximum Archive Attempts, and
the setting for Archival of Recorded Objects. Refer to Retention Archive.
Click Update to save any changes made to the Alert Maintenance Configuration.
Retenti on Archive
CommandPost appliances contain a local hard drive for storage of alert data. The local storage
may not be adequate for your long term storage requirements, therefore alert archival may be an
important feature in your environment.
There are three methods available for archival:
• Archive creates a Fidelis-formatted archive file and sends it to an external system. The name
of the external system and login credentials are defined at the Archive page. Refer to Archive.
• When a plan includes the Archive option, the maintenance process creates an archive file and
attempts to send it to an external system. If archive fails, no alerts associated with this plan
will be purged. If a failure occurs, CommandPost status will indicate the problem. In this case,
you should correct the problem and visit the Archive page to test the correction. A successful
test will clear the CommandPost status error.
• If there are repeated failures of archive, CommandPost will increase the severity of the status
message. The setting for Maximum Archive Attempts defines the number of days for which
purge will be skipped upon archive failure. If archive fails for this number of days, alerts will be
purged without archive. The Maximum number of attempts can be set between 1 and 7 days.
• A successful archive transfers the archive file to the external system located in the directory
path provided by External Archive Directory. This must be a fully qualified path to the desired
location on the external system. Once the file is stored on the external system, you can move
it to any location required for long term storage. Refer to Archive for information about
importing archive files to CommandPost.
• The Alert Maintenance Configuration for Archive Recorded Object applies to all plans where
Archive is chosen. When this option is selected, the archive file will contain the recorded
objects associated with the alerts. You can select to Archive sessions when alerts are
archived or to Archive PCAPs when alerts are archived. Whether this option is selected or
not, the alert purge operation removes any recorded object associated with an alert subject to
removal.
Alert Storage
Alert storage provides a control to encrypt alert information within the CommandPost database. By
default, alert forensic data and the associated recorded objects are stored in plain text. The
information is only accessible through the CommandPost GUI or API. Access requires an
authenticated user with the proper privileges. Refer to Define User Profiles. Database encryption
can provide another level of protection.
When you change the encryption setting, forensic data and recorded objects already stored by
CommandPost will no longer be available. An encryption change will provide a warning regarding
the availability of current information.
If encryption is important to your organization, Fidelis recommends that you enable this feature
immediately upon receipt of your CommandPost. Fidelis uses AES 128-bit key encryption. For
existing installations, you should archive your alerts before changing encryption status.
To enable encryption:
1. Click System>Components>CommandPost>Config and click the Alert Storage tab.
2. Enter an encryption key in the text box. Retain this key for future use. You will need the
original encryption key to disable encryption or to enter a new key.
3. Click Encrypt. A dialog box warns that you will lose access to forensic data and recorded
objects.
4. Click OK to proceed.
Archive
Archive enables you to configure a name and login for a remote FTP server. CommandPost will
use the information to export archive files to the remote system. Refer to Export. Fidelis-formatted
archive files are encrypted. These files are decrypted upon import. Archive also enables you to
import files. Refer to Import from a Remote FTP Server.
Note: To see the CommandPost Config>Archive page, users need View privileges for
48 49
CmdPost Admin, Alerts , and Alert Details . With View privileges, the Archive page
header will display View Only and buttons will not be active.
To save configuration changes and access buttons, users need Full access to
CmdPost Admin, Alerts, and Alert Details.
Access to System>Export requires Alerts and CommandPost administration
privileges. This access allows you to export alert archives using the process set up
by the CommandPost administrator, as noted above.
48
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
49
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 228
Figure 98. CommandPost: Archive
2. Enter a name for the remote server.
3. Enter a login name and password for the remote server.
Note: Remote login name and password do not support the use of non-ASCII
characters.
4. To use an encrypted transmission channel, click Use Secure FTP. The remote server must
have an ssh service.
5. If needed, enter your encryption key to encrypt Fidelis archived alerts or leave this text box
blank to use the default encryption key. You will need the same encryption key to decrypt
Fidelis archived alerts.
6. Click Update Configuration.
After clicking Update Configuration, you may test communication between CommandPost and the
remote server. To test:
1. Click Test Archive Configuration.
Note: No alerts are transmitted during the test process, only test data.
2. Enter a directory name on the remote server where the archive file will be stored. The entry
must be a fully specified path. For example, on a Unix or Linux server: /home/Fidelis/archive.
If the remote directory does not exist, it will be created.
Be sure that the user name provided at the Archive page has permission to write to this
directory.
3. Click Execute Test.
The test process creates a small text file including a timestamp representing the exact time of
creation. This file is sent to the remote server, retrieved from the remote server, and compared to
the original. If the transfers complete and the file comparison passes, then the test succeeds. Any
failure represents problems with configuration of either CommandPost, your remote server, or
network problems that may prevent communication between the systems.
Following a test, the simple test file will reside on your remote server. You may remove it at your
convenience.
• Reject duplicate alerts in your import data. The alert UUID is used to determine duplicate
alert information and the Object ID is used to determine duplicate objects. This choice
will ignore the imported data and CommandPost information will remain unchanged.
• Overwrite CommandPost data with information from the import file. Note that
CommandPost maintains an alert ID and a UUID for every alert. The alert ID is
sequential, but not universal across all CommandPosts. The UUID is a uniqueID per
alert. If you choose to overwrite CommandPost data, the local alert ID will most likely be
changed after import. The UUID will be maintained from the import file.
• Restore Alerts as Original preserves the original insert time and alert ID.
4. Click Execute Import.
This operation can be time consuming, based on the network speed between CommandPost and
the remote server, the number of alerts in the imported file, and the number of duplicates detected.
Upon completion, results will be displayed.
Configure Audit
The CommandPost audit log tracks all user activity. Access is available to any user whose role
includes the audit privilege. A user that has both Audit and CommandPost privileges may configure
CommandPost to log only the activity of interest.
50
Note: To see the CommandPost Config>Audit page, users need View privileges for
CmdPost Admin and Audit. With View privileges, the Audit page header will display
View Only and buttons will not be active.
To save configuration changes and access buttons, users need Full access to
CmdPost Admin and Audit. Refer to Define User Roles.
The CommandPost Audit configuration page enables you to select audit levels for actions on the
CommandPost and any sensors registered to it.
To configure audit:
1. Click System>Components>CommandPost>Config and click the Audit tab.
50
Audit enables you to search for audit information.
Fidelis XPS User Guide 230
Figure 99. CommandPost: Audit
2. Enter the amount of time to retain audit records. The default is 190 days. Any audit record
older that this number of days will be removed.
Note: The audit log is stored on the CommandPost hard drive. When the allotted
audit space is full, old audits will be removed to make room for new entries to the
log. This event will also generate user notifications and turn the CommandPost
status to red. Adjusting the storage time can help avoid this situation.
3. Audit records can be exported to an external syslog server. To enable audit export, select
Enable and enter the IP address or host name for the syslog server. Audits will be written to
the external syslog as they are written locally to the CommandPost audit log.
4. Select Audit events as needed.
The audit system is broken into ten facilities with six events. By using the available
checkboxes, you can select the events of interest for your log. Checkboxes are available to
select or deselect all events within a facility as well as a checkbox to select or deselect all
events.
T a bl e 2 4. Ev e nt s t o A u di t
Event Description
Access Events Logs login and logout events, API access and access violations. Access
violations can be caused when a user attempts to access data forbidden by
their role, sensor assignments, or alert management assignments. Access
violation events are also logged when users attempt to load invalid licenses,
upload invalid files, or attempt other actions to circumvent CommandPost or
sensor security.
Addition Logs an addition to the system such as a new user, report, or policy.
For alerts and quarantined an addition is logged when there is an import.
Data Extraction Logs when data is exported from CommandPost. This may be the result of a
user action on the CommandPost GUI or the result of scheduled reports and
exports that occur in the absence of a GUI.
Page Access Logs when system information is viewed using the CommandPost GUI. This
applies to all pages of the CommandPost GUI.
T a bl e 2 5. F a ci l i ty R o ws
Facility Description
51
Alerts Items on the Alerts>List page including Alert Details
52
Quarantine Items on the Reports>Quarantine page including the details of any
quarantined emails
Automated Data Items exported, purged, or modified by scheduled events, such as Alert
Access Retention, exports, and feed updates
53
Reports and Includes Saved Reports, Summary, and Network Reports
Exports
Policies Items on the Policies page as well as policy modification on the sensor as a
result of sensor updates
54
Users Items on the System>Users page
Device Config Any component configuration changes including the CommandPost and all
sensors
Login, Logout, Includes: all login attempts, both valid and invalid, logout, and any attempt to
Access Denied access data not permitted by the user's role
API Audits API calls from external sources. These sources are any API not
accessed by Fidelis XPS Web or regular reporting processes.
51
Alert Details is the most granular level for examining alert data.
52
In Fidelis XPS, refers to e-mails that were quarantined by a Fidelis XPS Mail Sensor and are
currently held in the quarantine queue.
53
Network Reports display statistical information about the data flow observed by Fidelis XPS
sensors.
54
Users enables you to create and manage users, their roles, and user access.
55
Audit enables you to search for audit information.
Fidelis XPS User Guide 232
Backup and Restore
Backup enables you to back up configuration information for a CommandPost and any components
registered to it. The backup includes configuration information such as policies, reports, user
information but does not include data such as alerts. You can also include a system backup with an
automatic export, provided that you select the Fidelis Archive export method. Refer to Export
Methods.
Restore enables you to restore configuration information for a CommandPost and any components
registered to it.
Backup
To run backup:
1. Click System>Components>CommandPost>Config and click the Backup and Restore tab.
The System Configuration Backup and Restore page displays.
Restore
You can restore a CommandPost's configuration directly from the backup file or replicate the same
configuration to multiple CommandPosts. You can also select and restore configuration information
to components registered to the CommandPost.
To restore a CommandPost:
1. Select a backup file and click Upload restore file. The name of the Restore File displays.
2. If the Restore File name is correct, click Verify. The host ID , the version number, backup
time, and user information display. If the host IDs match, the license is automatically
restored.
Custom GeoIP
Custom GeoIP provides the ability to customize Location information for IP addresses. Location
information appears in Dashboard widgets, Alert List, and in Alert Details and may be used to
create a Location fingerprint. Refer to chapter 3 in the Guide to Creating Policies.
Public IP addresses show the location provided by Maxmind. The names of countries are
maintained by ISO 3166 and augmented by special codes provided by MaxMind. Refer to
[Link]
Private IP addresses will show the location as Unknown. You can use Custom GeoIP to change the
location information of both public and private IP addresses.
When you define locations, you may associate each with a flag using the ISO 3166 country codes
or one of the seven custom flags provided by Fidelis. Location information displayed on the World
Map and Globe dashboard widgets is based on the ISO 3166 flag. You may enter coordinates to
define a location for Unknown locations or any that use a custom Fidelis flag as the location
identifier.
After uploading the GeoIP file, you can click to download and view the file.
Click OK at the confirmation dialog box.
• ASCII mode will recognize ASCII characters in any file. When applied to a sensor, ASCII
mode provides the optimal performance. If your sensors are running ASCII mode, you
should perform fingerprint testing and generation in ASCII mode.
• International mode will recognize Unicode (UTF-8, UTF-16, and UTF-32) characters as
well as all supported extended ASCII character sets. When International mode is
selected, a list of summarized character sets will appear. The list of supported character
sets is available within each summary.
Many file formats will indicate the character set used within the file, although this
information may not be visible within the file processing or editing application. For these
files, CommandPost will correctly interpret the contents in International Mode.
If the character set is not specified in the file, CommandPost will utilize the character
sets that you specify on this page. For fingerprint generation, including Keyword and
Keyword Sequence generation, Identity Profile training, Exact and Partial Content,
CommandPost will use the first character set in the list. For fingerprint testing,
CommandPost will translate your file using each character set in your list and test it
against your fingerprint.
3. In International Mode, click a character set summary, such as Latin or Cyrillic. Each opens to
display a list of specific character sets. Select one or more and click Add. Your selection
displays in the text box on the right. Use the arrow keys to change the order of the selected
LDAP Configuration
You can configure CommandPost to interface with an LDAP or Active Directory server. After
configuration, CommandPost will be able to authenticate logins via directory authentication, to use
directory information in policy definitions, and to associate user information detected within alerts to
directory information.
To correctly configure the CommandPost interface with LDAP, you must have thorough
understanding of your local directory server data structure and login access to all user records
stored on your server. You may use your favorite LDAP/AD browser software to gain the required
information for configuration.
Obtain the following information before you configure CommandPost to work with an LDAP server:
• To edit LDAP Lookup Parameters, click next to the Base and Filter entry you want to
change. Text boxes display that enable you to edit the base or filter entries. Enter your
changes and click Update.
• To remove LDAP Lookup Parameters: click next to the Base and Filter entry you wish to
remove. Click OK at the dialog box to continue with the deletion.
Enter IP2ID User Match information if you have an A10 Network Identity Management system.
When an alert is generated, the user ID will be matched against the provided LDAP attribute for a
match. If a match is found, user information from LDAP can be added to the alert information.
• Enter attributes into the text box and click . Use attributes defined in RFC 4519 or any
user-defined attributes.
The attributes name, email address, organization, organization unit, title, and user id are part
of the query to the server and are present by default.
Logs
Logs enables you to view log files from a sensor or from CommandPost that reside in different
directories, including/FSS/log and /var/log among others. Log files can help in troubleshooting
problems and are a valuable resource when interacting with Fidelis Technical Support. After
retrieving a log file, you can send it via email. Fidelis support is the default email recipient of all log
files.
To retrieve logs:
1. Click System>Components>[sensor or Collector name]>Config and click the Logs tab. You
can view logs for another component by selecting it at the Component list.
2. Select a file from the Log Files list.
3. Click Invert Log to reverse the order of log entries, if needed.
4. Click View Log. The selected log entry displays and the Email Log button is available.
2. Select the configuration that fits your network environment: either a single Solera system that
captures all traffic analyzed by each Fidelis XPS sensor in your environment or a different
Solera system where each captures traffic analyzed by one or more Fidelis XPS sensors.
If a single Solera server collects all network traffic:
1. Enable Solera integration.
2. Enter the URL for the Solera server.
3. If desired, enter a login and password set up on the Solera server. This enables automatic
login for Solera versions 5 and below
If Solera servers are different per sensor:
1. Click Solera Servers are different per sensor.
56
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 248
In this environment, each alert will point to the Solera server associated with the sensor where the
alert was detected. If you do not enable Solera for a sensor, then alerts generated by that sensor
will lack the Solera interface on the alert details page.
Proxy Config
If external access from CommandPost goes through a proxy, you need to configure CommandPost
for proxy connectivity.
To configure the proxy server:
1. Click System>Components>CommandPost>Config and click the Proxy Config tab.
2. Ensure that Use Proxy is checked.
3. Enter the host name or the IP address for the proxy server
4. Enter the port number. Communication between CommandPost and the server usually
occurs on port 80.
5. If the proxy server requires authentication, enter a user name and a password.
6. Click Save Proxy Config.
When the proxy server is configured, you can enable its use by clicking Use Proxy for each
configured feed.
RADIUS/TACACS+
RADIUS/TACACS+ configuration enables you to configure CommandPost for RADIUS and
TACACS+ authentication support for login access to Fidelis XPS. RADIUS is Remote
Authentication Dial -In User Service and TACACS+ is Terminal Access Controller Access Control
System+ .
1. Click System>Components>CommandPost>Config and click RADIUS/TACACS+ .
2. Enter the name of the RADIUS or TACACS+ server.
3. Enter the shared secret, a key parameter that needs to be in sync with the RADIUS or
TACACS+ server.
4. Enter a timeout value in seconds.
5. Enter a test user name and password that is already stored on the RADIUS or TACACS+
server. This user name and password are used for testing and are not saved with the rest of
your configuration.
6. Click Test to verify the server name and the shared secret.
7. Click Update to save your changes.
8. Click System>Components>CommandPost>Config>User Authentication to enable
RADIUS or TACACS+ authentication. Refer to User Authentication.
Session Timeout
Session Timeout refers to the amount of time an inactive user account can remain logged into
CommandPost. User inactivity will cause the session to be timed out and the browser will return to
the login page. Inactivity is determined by contact with the server. For many sections of
CommandPost the action of opening and closing rows in the display will not cause interaction to the
server and may require accessing new pages to avoid session time out.
CommandPost Session Timeout can be configured in one of three modes of operation:
• Enable Timeout for All sessions. This is the default mode of operation with a timeout value of
15 minutes. You can change the timeout value to any number of minutes greater than zero.
• Disable Timeout for All sessions. In this mode, session timeout is completely disabled. This
setting is not recommended unless all users are well trained security professionals, diligent
about logging out from CommandPost if they leave their workstation.
Notificati ons
The Notifications page allows the configuration of Fidelis messages or notifications to be sent to
external entities. These notifications are produced by system monitor as it pertains to Fidelis
Software and system resources required for Fidelis software.
Notification Messages
Listed below are examples of notification messages that can be sent by System Monitor.
Critical:
spool writes stopped when partition < 1GB
if a process is dying repeatedly
invalid license
spool writers dying too fast netspool can't start spool writers
export writers dying too fast exportd can't start exporters
one or more registered sensors lost connection
Unable to make space for alerts, alerts & sessions not being inserted
Unable to make space for sessions, alerts & sessions not being inserted
Insufficient disk space, alerts & sessions not being inserted
Archive failed - alerts deleted anyway, check FTP connection
feed handlers are dying fast
repdcp cannot start feed handler<s> <feed names>
High
demo mode or license expired or expiring in < 14 days
no sensors registered.
if alerts/sessions/pcaps deleted to make space for new
alerts
<number> alerts, <number> sessions & <number> pcaps deleted to create space
if alerts are being spooled due to db maintenance running
Database maintenance running, alerts are being spooled
if archiving fails and it will be retried
Archive failed - alerts not deleted, check FTP connection
Archive failed - alerts deleted after next failure, check FTP
connection
problem running db_maint: see /var/log/messages
feed update error
feed "<feed name?" update error
Shutdown
This page enables you to restart all Fidelis Services.
• Clicking Restart, Shutdown, or Reboot on the Console Config logs you out of CommandPost.
• Order does not matter when shutting down or rebooting CommandPost with sensors and
Collectors.
• For Shutdown, you need physical access to the CommandPost to start it again.
• First, CommandPost checks the user name to see if matches against the database of current
users. If it matches a user, then the configured authentication method (local, *LDAP,
**RADIUS, or **TACACS+) is used. Refer to Define User Profiles.
To use LDAP or Active Directory authentication, you must also configure communication
between CommandPost and your directory server. Refer to LDAP Config.
57
Linux Pluggable Authentication Modules (PAM) provide dynamic authorization for applications
and services in a Linux system.
Fidelis XPS User Guide 255
Enabl e LDAP Authentication
If you would like to authenticate users via LDAP or Active Directory, you must enable LDAP
authentication and create a profile. To correctly setup authentication, you must have a thorough
understanding of your local directory server data structure. This can be obtained by using your
favorite LDAP/AD browser software.
Note: You also need to configure CommandPost to LDAP communication. Refer to
LDAP Configuration.
To enable LDAP Authentication:
1. Click Enable LDAP authentication and click Update.
The Login prepend setting can therefore be thought of as another filter which is internally
applied by the authentication process for each LDAP profile. In our example, joeUser must
be a unique value for LDAP attribute sAMAccountName for both sales and engineering
groups.
58
An event refers to a network violation detected by the sensor.
Fidelis XPS User Guide 259
receive the notification.
If you do not enter a domain email is sent for every email alert. This may cause notification
messages to leave the local network.
4. Select one or more email protocols from the list. CommandPost will send user notification
email for all alerts generated by the selected protocols. User notification would be generated
for the SMTP protocol if no email protocols are selected from the list.
5. Enter a subject for the notification email. The default value is “You have violated company
protocol....”
6. Enter the body of the email by either entering text into the text box or by uploading a file.
7. Click Update.
Note: Some email systems will not deliver email when the sender cannot be
identified. If you have not properly configured CommandPost email, users may not
receive the notifications.
Runtime Information
The table at the top of a sensor configuration page shows runtime information for the sensor, the
time since last restart, name, and how much activity has occurred. The type of activity depends on
the sensor type. Time since last restart is the time since the last restart of Fidelis XPS software.
The information will automatically refresh every few seconds.
Config Page
The configuration page provides access to the tabs listed below.
For products that contain an embedded CommandPost and an embedded sensor, the configuration
is located at CommandPost Config. Refer to Components.
License & Time
Sensor configuration. The label indicates the sensor product type.
Refer to the config page of each sensor to set recorded object or session limits.
Alert Failover
Email Relayhost
Language Config
Logs
Secondary Managers
System Monitor
59
Components enables you to set up licensing and configure Fidelis XPS components. This
includes adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail,
and setting up user notification and LDAP among other features.
Fidelis XPS User Guide 261
Figure 122. The License and Time
Clicking Request License or the component's Host ID creates an email to
license@[Link], with the subject line automatically completed with the component’s
Host ID. Include in the body of the email your name, the location name and address, phone
number, and reseller name (if pertinent), and Fidelis Technical Support will respond within one
business day with a license key.
When you receive the license key, paste or type it exactly into the License Key box, and click Save.
If the information was entered correctly and matches the Host ID provided, the key will be
accepted. If there is a problem with the license, you will receive an error and the License Key field
will display <Invalid>.
Expirati on
Fidelis XPS begins displaying notices that your license will expire starting 60 days before the
expiration date. If you receive this notice, contact Technical Support to obtain a new license.
Demo Mode
If no license key is detected, the sensor and the CommandPost will operate in demo mode. The
sensor does not function in demo mode. A CommandPost in demo mode will not accept alerts from
any sensor and will only accept statistics.
Sensor Time
Click Sync time to synchronize sensor and CommandPost times. This can be done for each sensor
that has no access to other time synchronization methods such as NTP. If the sensor is
synchronized with CommandPost, a message displays indicating this and the Sync time button will
not be available. If the sensor and CommandPost are not synchronized, a message indicates this
status and the Sync time button becomes available.
General
You can configure your Direct or Internal component to operate in either inline or out-of-band
mode.
Refer to chapter 5 in the Enterprise Setup and Configuration Guide for more information about
these modes and how to set up and connect hardware to the network.
T a bl e 2 6. D i r e ct a n d I nt e r na l : G e n er al p a r am e t ers
Inline Mode/Out-of- Choose the setting that reflects the network configuration of your module.
Band Mode Out-of-Band mode is used for monitoring via a network tap or SPAN port,
while inline is used when the component is directly in the network flow.
When a component is deployed inline, prevention is performed by
dropping packets received on offending sessions.
Note: To activate inline mode, the component must also be
operating in full duplex mode.
Inline mode also enables you to use a Bypass NIC, if supported by your
appliance.
After clicking the checkboxes for the Bypass NIC, select the failure mode:
either Drop Packets or Fail-to-wire.
Refer to chapter 5 in the Enterprise Setup and Configuration Guide.
Throttle Mode When Inline Mode is chosen the Throttle Mode checkbox displays if
available. Throttle is typically used to identify applications (such as peer-
to-peer or instant messenger) that are allowed on the network, but to
control their use by throttling activity to an acceptable level. Throttle
mode enables the Direct/Internal component to react to throttle rule
actions. If throttle mode is disabled, the component will ignore the throttle
action.
Link Failure In Inline mode, if one link is down, the sensor cannot forward traffic.
Propagation When Link propagation is enabled, if one link goes down (link 1) the other
link (link 2) will be brought down so that the other device will know that
the link is broken. The sensor then starts sending notifications to
CommandPost. If link 1 recovers, it will restore link 2 and the sensor will
stop sending error notifications.
Primary TCP Reset When checked, TCP Resets are enabled to provide prevention, as
indicated by the action setting when a rule is violated.
When used in out-of-band mode TCP resets used for prevention, you
must specify the dedicated Ethernet interface (Prevent /eth1) used for
packet injection. Make this choice at the drop-down menu. When used in
Inline Mode, the Direct/Internal component will inject TCP Reset packets
(in addition to dropping received packets) to implement prevention. In
Inline Mode, the component will choose the correct Active interface for
injection of reset packets based on the information flow.
Secondary TCP
Reset When a second reset is enabled, resets will also be sent to the chosen
Ethernet interface. This setting should only be used when the sensor is
physically connected to a redundant network.
Active Interfaces Active Interfaces determine which Ethernet adapters the component will
monitor. Click the appropriate checkboxes to select interfaces. One
adapter, such as Monitor A/eth2, indicates that the component is listening
in half duplex mode. Two adapters, such as Monitor A/eth2 and Monitor
B/eth3, indicate full duplex mode.
The information within the brackets indicates the interface type and its
operating status.
Packet Capture Packet Capture enables you to capture alert-related network traffic just
before and after an alert. This option displays if you have a Direct,
Internal, or Edge component capable of supporting Packet Capture.
Refer to product tables in chapter 1 in the Enterprise Setup and
Configuration Guide.
Packet Capture can be selected as an action for each rule for which
traffic information is required. Refer to chapter 7 in the Guide to Creating
Policies.
MDE on Sensor Indicates either Available or Not Available. Available means that the
sensor is capable of supporting the Malware Detection Engine.
If MDE is Not Available on this sensor, malware detection will execute on
the CommandPost.
Malware Detection must be enabled to execute on the sensor. Refer to
Malware Detection.
Bypass Card on Indicates either Available or Not Available .If your appliance supports
Sensor this capability, the sensor configuration page on CommandPost will
indicate: Bypass Card on Sensor: Available.
Select Failure Mode Configuration of the Bypass NIC includes the operation in case of a
for the Bypass NIC power or software failure. If needed, you can also immediately set the
NIC into bypass mode.
After clicking the checkboxes for the Bypass NIC monitors on your
appliance, select the failure mode: either Drop Packets or Fail-to-wire.
Refer to chapter 5 in the Enterprise Setup and Configuration Guide.
T a bl e 2 7. D i r e ct a n d I nt e r na l : A dv a n c e d p ar a m et e rs
Advanced Description
parameters
Alert Recorded Object This setting determines the maximum length (in KB) of data recorded
Limit (0-32768): from the network session associated with each alert. It is important to
keep in mind that a larger limit might substantially increase the size of
your database, which will require more available disk space on
CommandPost. The default is set at 4096 KB because most useful
forensic information occurs in the beginning of a recorded session. It may
be useful, however, to have more data recorded.
Checksum setting A check beside the protocol name under Checksum instructs the software
to verify the checksum of each network packet of that protocol type.
Deselecting a protocol means that packets will always be accepted which
increases performance.
Send metadata to Enables this sensor to send metadata to a Collector selected from the
collector drop down list.
If hierarchical management is enabled, you can select to send metadata
from a sensor registered to a Subordinate CommandPost to a Collector
registered to a Master CommandPost.
Metadata Inclusion IP The feature enables you to limit metadata sent to the Collector by the
List sensor to a set of IP addresses defined in the Metadata Inclusion IP list.
This feature is useful when you need to reduce the amount of data sent to
your Collector from your sensors.
If you are using the built in Demo Collector on CommandPost you need to
use this feature to prevent data overload on CommandPost.
Enter the list of IP addresses singly or specify a subnet using subnet
masks in the Metadata Inclusion IP List text box. Each entry must be
separated by either a space or on a separate line. For example:
Separated by a space:
[Link]/8 [Link]/12 [Link]/16
On a separate line:
[Link]/8
[Link]/12
[Link]/16
Network B order
The Network Border is used to limit the sensor analysis to specific data flows, depending on your
sensor type. Applying a Network Border to a Direct sensor will effectively eliminate any alerts
generated from data flows initiated outside of the defined IP address [Link] a Network
Border to an Internal sensor will effectively eliminate any alerts generated from data flows that
cross the defined IP address ranges. If the purpose of the sensor is to monitor all network data
flows, do not configure the Network Border. Depending on the type of sensor the behavior of the
Network Border varies.
• A Fidelis XPS Direct sensor will detect and analyze all session data flows that originate
from within the defined network and are destined to a host that resides outside the defined
network. The Direct sensor will ignore all session data flows originating outside of the
defined network and all data flows that remain inside the defined network.
• A Fidelis XPS Internal sensor will detect and analyze all session data flows where both the
source and destination of the data are within the defined network.
Note: The network border is based on the direction of the data flow. It is not based on
the network TCP/IP source and destination IP addresses. Therefore, it handles data
movement regardless of the application protocol and the mode of operation.
DNS Decoder
At this page, you can enable and configure settings for the DNS Decoder for Direct and Internal
modules. The DNS Decoder works at the packet level and can generate DNS alerts. Note that DNS
alerts are different from the alerts generated by rules built using fingerprints. DNS alerts are not
configured in the Policy section of the Fidelis XPS GUI, but at the DNS Decoder page for Direct or
Internal sensors.
To access this page, click System>Components and select the appropriate Direct or Internal
sensor and click Config. At the Config page for the Direct or Internal sensor, click the DNS Decoder
tab.
At the DNS Decoder page, you can define anomalies that represent possible DNS exploits in your
60
network and generate alerts when these packets are detected on the network.
Note: The DNS Decoder must be enabled for Channel fingerprints that use the DNS
Protocol attribute.
Prevention can be enabled for requests to blacklist malicious sites. For this operation to be
possible, the sensor must be configured for prevention. Refer to the Direct General page.
60
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 269
Figure 127. Direct/Internal: DNS Decoder settings
T a bl e 2 8. G e n er al P ar a m et ers
Enable DNS Decoder Click to enable the decoder on the Direct or Internal module.
Monitor DNS over Select to detect and analyze when DNS requests are coming over TCP.
TCP
Monitor DNS on Ports Specify one or more ports to inspect for DNS packets. You can enter
single numbers separated by commas or ranges. If you do not specify a
port, the DNS Decoder defaults to the standard DNS port (53).
DNS will only be inspected for the ports specified here.
Alert Management Select an alert management group for any DNS alerts that are generated..
Group
Choose to generate an alert based on the selected criteria. Default settings are provided for each
DNS alert configuration. Change the values as required for your environment. Each alert
configuration item and any settings are described in the following table.
Assign an alert severity to each selected item.
Not port 53 Select to detect when DNS requests are found on a port other than 53.
Q/A Bounds Specify the upper and lower bounds for Question/Answer (Q/A). Q/A
bounds between 100 and 200 percent are standard. A much greater
difference between the Question/Answer ratio can indicate a problem.
DNS/TCP Ratio Specify the ratio of DNS to TCP packets within a 1 minute timeframe. If this
ratio is too high, this can indicate a possible security breach.
Name Length Enter the maximum number in bytes for a name segment.
Unprintable Selecting this option will trigger an alert when the number of non-ASCII or
Characters in Name non-printable ASCII characters exceeds the setting for Maximum
unprintable characters per label. The default setting is 40 characters.
Error/Success ratio Specify the upper bound percentage for the error to success ratio for DNS
responses. A zero indicates no errors.
Packet Length Enter the maximum number of bytes for the packet length of a query
packet. Alerts will be triggered for DNS requests that are longer than the
length specified.
Packet Parsing Select to check for any malformed packet such as one with a badly formed
name or resource record.
RR Not Allowed Select to not allow resource records except those types listed in the RR
Allowed List. Enter the numerical values for the resource types allowed.
RR Length Enter the maximum length in bytes for a resource record. Note: RR length
does not apply to DNSSEC records.
TTL Duration Specify upper and lower bounds in seconds to determine acceptable TTL
values.
Malware Target DNS This option will cause alerts to be raised for DNS requests made by hosts
Requests in your network that were detected to be the destinations of malware
transfers. The number of alerts is configurable. For example, if you enter
11 for (Alert on first 11 DNS requests), alerts will occur on the first 11 DNS
requests by each host after the malware transfer was detected.
Question Records If the number of questions in a single query is greater than the number
specified, an alert is generated. The default is 5. However, if you select
one or more feeds at Blacklist from Feeds, Fidelis recommends that you
enable this alert and set the upper bound on the number of Question
Records to 1. Blacklist feed matching is only performed on the first record.
The list of available feeds includes all Fidelis feeds that include DNS host
names, including Fidelis-provided feeds and custom feeds. Refer to
chapter 10 in the Guide to Creating Policies.
Click the Assigned checkbox to perform blacklisting against the host
names included in the feed.
If assigned, you can select Prevent to drop the DNS request of any
blacklisted host in the feed. For prevention to be effective, the sensor must
be configured properly, refer to Direct General.
If prevention is selected, you have the option to select Silent prevention. In
silent prevention, no alert will be generated for the blacklisted request. It
will be silently dropped.
Manual Blacklist Note: The Blacklist feature became obsolete with version 7.5.
Blacklists must be defined in feeds.
If you previously entered name strings in the Blacklist text box, a notice
displays stating that the feature is obsolete.
To remove this message, delete all entries from the text box and click
Save. The Blacklist section will no longer be available.
To blacklist sites, create a custom feed that contains the Blacklist entries.
Refer to
chapter 10 in the Guide to Creating Policies.
Whitelist Entries added to the Whitelist will be excluded from any DNS alerts
Mail
The Mail page is available if the sensor includes a Mail module.
The Mail component can be deployed in one of two modes:
Restrict interface If you select milter mode, this checkbox appears. By default, Mail listens
for traffic over all ports including the admin port which is used for
communication to CommandPost. Click Restrict interface to choose a
single interface for milter traffic.
Mailer port If you select milter mode, you need to enter a Mailer port. You may
configure the TCP port number for use in milter mode. Enter any unused
port. The default is 10025. You can use this default value or make
another entry. When run in milter mode, the third-party email server must
be configured to run the milter interface on this port.
Notify quarantine Click to have email sent to the alert management group assigned to the
manager rule that was violated. Refer to Add or Edit an Alert Management Group
for information about entering and managing group email addresses.
Subject to Quarantine Enter Subject information for the email to the alert management group.
Manager
From Address for all Enter the From address for the notification email that is sent to the user
notification messages or the quarantine manager or use the default.
Email Subject to End Enter Subject information for the email to the end-user.
User
Instructions to End This is the text for the notification email to be sent to the user. This text
User should provide all information needed to send an email to the sensor to
release the quarantined email.
You can keep the default text or modify it.
These instructions will be included with any rule-specific sender
notification text entered at the Rules page. Refer to chapter 7 in the
Guide to Creating Policies.
Reroute server Enter a fully qualified host name or an IP address for an email server. If
the rule action on an email is reroute, the email will be marked for
downstream rerouting and sent to the server specified here by the next-
hop mail server. Consult Technical Support for more information on the
mail infrastructure topology requirements needed to use this feature.
Alerts Recorded This setting determines the maximum length (in KB) of data recorded
61
from the email message associated with each alert . It is important to
Object Limit (0-
51200): keep in mind that a larger limit might substantially increase the size of
your database, which will require more available disk space on
CommandPost. The default is set at 4096 KB.
My networks This text box enables you to specify multiple networks in CIDR format:
separated by commas. For example: [Link]/16, [Link]/24
Note: The CIDR notation should only have relevant bits in the
subnet representation. For example, [Link]/16 is valid but
[Link]/16 is not valid.
The Mail sensor will accept messages only from mail clients on these
trusted networks.
Send metadata to Enables this sensor to send metadata to a Collector selected from the
collector drop down list.
If hierarchical management is enabled, you can select to send metadata
from a sensor registered to a Subordinate CommandPost to a Collector
registered to a Master CommandPost.
For the Demo Collector:
An IP address of [Link] displays. The Demo Collector can only accept
metadata from one sensor at a time. Ensure that the IP address for the
Demo Collector is selected at only one sensor. Other sensors should
have None selected.
Metadata Inclusion IP The feature enables you to limit metadata sent to the Collector by the
List sensor to a set of IP addresses defined in the Metadata Inclusion IP list.
This feature is useful when you need to reduce the amount of data sent
to your Collector from your sensors.
If you are using the built in Demo Collector on CommandPost you need
to use this feature to prevent data overload on CommandPost.
Enter the list of IP addresses singly or specify a subnet using subnet
masks in the Metadata Inclusion IP List text box. Each entry must be
separated by either a space or on a separate line. For example:
Separated by a space:
[Link]/8 [Link]/12 [Link]/16
On a separate line:
[Link]/8
[Link]/12
61
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 275
Mail parameters Description
[Link]/16
Web
The Web page is available if the sensor includes a Web module.
When a Web component inspects traffic it can generate alerts, prevent transmission by dropping
traffic, or both. If the Web stops traffic because that traffic violates a rule, by default, it sends an
HTTP status 403 (forbidden) to the client's web browser. If the enterprise has provided a valid,
absolute HTTP URL, then Web sends an HTTP redirect as the response to the prevented traffic.
Note: The third-party proxy must be configured properly to work with ICAP.
T a bl e 3 0. W e b p ar a m et er s
Squid Click to enable Squid compatibility mode. This must be enabled if the
client uses the Squid proxy. By default, this is turned off.
Web prevention Enter a valid, absolute HTTP URL for browser redirection.
redirect URL
Note: This URL does not support the use of non-ASCII characters.
You can create several URLs and force redirection if you include
attributes of the alert information in your URL. For example, you may
have a URL for each policy running on the Web module. The keyword
select box can be used to craft a URL for redirection based on alert
attributes.
To use the module's ability to redirect based on alert attributes, select
one or more keywords from the list and click Add Keyword. The keyword
and the percent signs around it will be replaced with a real value at
runtime. For example, if you add the %SENSOR% keyword, the actual
Alert Failover
When the sensor cannot reach a CommandPost, its default operation is to store data locally until
the connection is restored. If an Alert Failover is configured, the sensor will begin to send data to a
backup CommandPost.
To set up a backup CommandPost:
1. Identify a primary and a backup CommandPost for each sensor.
2. Add the sensor to both the primary and backup CommandPost systems. Refer to Add a
Component. The sensor name should be the same on the primary and the backup
CommandPosts. If the sensor names differ, spools from the sensor are rejected by the
backup CommandPost.
Note: Do not register the sensor to the backup CommandPost.
3. On the primary CommandPost, register the sensor. Refer to Add a Component. The
registration process identifies the primary CommandPost.
4. On the primary CommandPost: Click System>Components>[sensor or Collector
name]>Config and click the Alert Failover tab.
62
Internet Content Adaptation Protocol (ICAP) is a lightweight and extensible point-to-point protocol
used for requesting services for content inspection.
Fidelis XPS User Guide 277
b. The sensor then attempts to connect to the backup CommandPost. If successful, data will
be sent to the backup CommandPost. All alerts will be sent to the backup until the sensor
reconnects to the primary CommandPost. The sensor will repeatedly attempt to reconnect
to the primary CommandPost.
If neither the primary nor the backup CommandPost can be reached, data will be stored on
the sensor.
During failover operations, the sensor will continue to operate under its most recent configuration
change. Configuration changes, including policy updates, cannot be performed by the backup
CommandPost. Failover data refers to all data sent from a sensor to a CommandPost including
alerts network statistics data.
Email Relayhost
Email Relayhost will direct email from System Monitor for each sensor to the email server you
specify. Email from the Fidelis XPS Mail sensor is also sent to a server specified at Email
Relayhost. Only one entry is allowed for Relayhost.
To access this page:
Click System>Components>[sensor or Collector name]>Config and click the Email Relayhost tab.
• In ASCII mode, the sensor will recognize ASCII characters in any file. This mode provides the
optimal performance of your sensor and works well with most files written in English. Files
written in another language may be interpreted as binary files and the content will not be
decoded.
Many files and Internet protocols will indicate the character set used within the content,
although this information may not be visible within user application. For these files and
protocols, the sensor will correctly interpret the content in International Mode, as long as the
character set is supported.
If the character set is not specified in the file or protocol, the sensor will attempt to translate
the content using the character sets that you specify on this page. If you specify many
character sets, the sensor will use each one, first translating, then decoding, and analyzing.
This process may be time consuming and may impact sensor performance.
Secondary Managers
Secondary Managers enables you to set up CommandPosts as Secondary Policy Managers on a
sensor. You can also configure a failover CommandPost for each Secondary Policy Manager.
To do this:
1. Click System>Components>[sensor or Collector name]>Config and click the Secondary
Managers tab.
T a bl e 3 1. C ol l ec t o r: G e n e r al p ar a m et er s
Delete old data after The number of days to save data. Data older than the specified number of
(1-180) days will be deleted. The default of 30 days is recommended and a
maximum of 180 days can be specified.
Before increasing the number of days, consider the aggregate bandwidth
of the sensor linked to the Collector and the storage requirements of your
enterprise. The rule of thumb is 20 gigabytes of storage required per day
per 1 gigabit per second of sensor throughput. This can vary depending on
the traffic seen by the sensor. To meet your enterprise storage
requirements, you may need to add Fidelis XPS Collector XA appliances
to a Fidelis XPS Collector Controller to appropriately scale to meet your
storage requirements and performance needs.
Note: Adequate Disk space has priority over the number of days
specified. Therefore, if disk space is exceeded, data will be deleted
even if it is not old.
Deletions occur on a day's worth of data.
Note: You will not be able to unregister the Primary Controller until
you remove the IP address of the Failover Controller.
Execution Forensics
Execution Forensics uses an external sandbox technology to execute files and determine if the
behavior is malicious. When Execution Forensics is enabled, confirmed hits from the Malware
Detection Engine (MDE) are sent to Execution Forensics for analysis. In addition, highly suspicious
files are sent to Execution Forensics to determine if the behavior is [Link] can manually
submit any file from the Alert Details page for analysis. You can change the default so that only
specified file types are automatically analyzed. You can select from three options:
• All supported file types (the default) – automatically sends all supported files to Execution
Forensics for analysis. For a list of supported file types, click Selected file types to view.
• No files – No files will be automatically sent for analysis. You still have the option of sending
files for analysis at the Alert Details page if execution forensics is enabled and a valid
execution forensics license has been entered.
• Selected file types – Click and select file types from the list. The files you select will be sent
automatically for analysis. You can send other files for analysis at the Alert Details page.
When the Malware Detection Engine on a Fidelis XPS sensor determines that a file is highly
suspicious, but cannot determine if the file is malicious, the file will be sent to Execution Forensics
for determination. The rationale for sending the file and the determination of malicious behavior is
embedded within the MDE. You may disable this function by unchecking the checkbox: Use for
Determination at System>Malware>Malware Detection. This checkbox will only appear if Execution
Forensics is enabled.
Note: Execution Forensics is only performed when a valid Execution Forensics key is
entered. This applies to automatic and manual file submissions.
Reaction
Reaction enables you to select an action and assign an Alert Management Group for malware
alerts detected by the Fidelis XPS sensor. Malware Reaction is configured for each of the four alert
severities. By default, all alerts are assigned to the default alert management group and the
reaction is Alert.
If your sensor is incapable of Malware detection, then detection is performed by CommandPost and
the configuration on this page does not apply. To verify that your sensor is capable of detecting
Malware, check the sensor.
Malware Detection must be enabled. Refer to Malware Detection.
2. Select an action: Alert, Alert and Prevent, Alert and Reroute, Alert and Quarantine, or Alert
and Remove Attachments.
• Prevent takes first priority. Any email that includes malware with a prevent action will be
prevented.
• Quarantine has second priority. Any email that includes malware with the Quarantine action
will be quarantined (unless it also includes malware with the Prevent action).
• Reroute has third priority. If other actions such as Quarantine or Prevent are detected, they
are taken instead. Remove Attachments has fourth priority. If other actions are detected, they
are taken instead.
• Remove attachments has fourth priority. If other actions are detected, they are taken instead.
• Append Message: The message from each violated rule or malware will be added to the email
body. If the email has violated multiple rules or contains malware of multiple severities and
each has an append message, all the append messages are appended in single file.
• X-header: The X-header for each violated rule or malware will be inserted into the email
header. If the email has violated multiple rules or contains malware of multiple severities, and
each has an X-header, all X-headers will be inserted.
Carbon Black
By integrating with the Carbon Black server, Host Activity Monitor Configuration can detect if
malware seen on the network actually reaches the endpoint and if it is written to disk or executed.
The Host Activity report from Carbon Black is only available when actual malware (whose md5
matches the alert md5) is saved to disk or executed. If the malware is contained in a zip, tar, or
other container file; however, then saving the container file will not trigger a Host Activity report.
Even when a report is triggered, a delay can occur in receiving a Host Activity report depending on
the Carbon Black client.
You need to enable and configure access to the Carbon Black server at CommandPost. To do this:
1. Click the checkbox for Carbon Black Integration.
2. Enter the URL for the Carbon Black server.
3. Enter the token for authentication on the server.
4. Click Use Proxy if the server is outside of your network.
5. Click Verify Certificate if the Carbon Black server uses a verifiable certificate.
6. Click Save.
Bit9
By integrating with the Bit9 server, the Alert Details page will show a link to Bit9 server next to the
MD5 in alerts for exe files. The link will take users to the Bit9 console and search for that MD5.
You need to enable and configure access to the Bit9 server integration at CommandPost. To do
this:
1. Click the checkbox for Bit9 integration.
2. Enter the server name. Server names must start with an alphanumeric character.
Alphanumeric characters and special characters such as _ - . and : are allowed.
3. Click Save.
• The sensor name will be set to [CommandPost]. This name will not appear as a sensor
elsewhere in the system.
• The Target column at the Alert List will display File Upload.
• The rule, policy, and summary are set to UPLOAD if no malware is detected. These values
cannot be clicked because they do not refer to a user-created policy. If malware is detected,
rule and policy are set to Malware Detection Engine. The summary states: Detected malware
using UPLOAD.
• The Alert details will not include a Violation Information section.
• The Malware Information section will always be present. If Malware was not detected, the
Malware section will state this.
• Files will not be automatically sent for Execution Forensics, regardless of the configuration at
System>Malware>Execution Forensics. All alerts will include a button to submit the file
manually. The execution will determine if the file can be executed and will return an error for
files than cannot be executed.
• One alert will be created for the uploaded file, which will contain results. If the file is an archive
file, such as a zip, rar, or tar file, one alert for each malicious file will be generated. These
alerts will appear as related alerts on the Alert Details page. Note that benign files within the
archive file will not create new alerts.
• Major releases provide new capabilities for Fidelis XPS. These releases are identified by
two-digit version numbers, for example, versions 7.0, 7.1, and 7.2. Updates must be installed
on systems running the last major release.
Updates should always be applied in sequence from version 7.0 to 7.1 to 7.2 and so on.
Refer to the latest Release Notes for information.
• Minor releases provide minor features and correct known software problems. These releases
are identified by the third number in the version, for example 7.2.1 and 7.2.2. Updates are
usually applied to the last major release, not necessarily the last minor release. For example,
you may install version 7.2.3 on a system running 7.2.1 without installing the 7.2.2 version.
Prepare to Install
Before proceeding with the installation, refer to the Release Notes associated with the software
version. Release Notes contain information specific to the software version and describe any
procedures you might need to follow before installing.
To prepare for the installation:
If you plan to manually download installation files:
• Download the Fidelis XPS update installation file from: [Link]/support to
a folder on your local workstation. Refer to File Management.
To use automatic downloads:
• Setup credentials and configure automatic downloads at Download Control.
Install
The Install page enables you to install software that is available. If you have enabled automated
notifications at Download Control, available software will include all applicable software versions
listed on the Download Center. If you have not enabled automated notifications, available versions
are relative to the file uploaded at File Management.
The page will list all components accessible from CommandPost. This includes the CommandPost
Management Console (the CommandPost that you are currently logged into), all registered sensors
and Collectors, all Subordinate CommandPosts, and all sensors and Collectors registered to
Subordinate CommandPosts. Unregistered components will not be listed.
The Release Notes for all available versions are available by clicking the button on the bottom left
of the page. If no new versions are available, there will not be a Release Notes button. Click the
button to view a list of all available versions and release notes. Click Download Release Notes to
download the PDF of the release notes to your workstation. For the version available on the local
disk, the release notes will be extracted from the package and provided to you. For all other
versions, the release notes will be downloaded from the Download Center.
For each component, the following information is displayed:
If Available Version displays: Not Operational, this indicates that the component is not
available for software installation. Check the component status by hovering the cursor over
the System Status and then hovering over the component health diamond.
63
Version Control enables you to update the CommandPost and Fidelis XPS sensors.
Fidelis XPS User Guide 294
Figure 142. Install
Install Now
To perform an installation:
1. Select the components you wish to install by using the checkbox next to each component.
Note: To install from a Master to a Subordinate CommandPost, both must be at least
at version 7.3.
2. Select the version to install for each selected component. The same selection must be made
for all components.
Note: It is possible to reinstall the current version if the update package for the
version is currently stored on the local disk.
3. Click Install Now to proceed with the install.
4. Click Install at the confirmation dialog box to proceed or Cancel to stop.
If you are installing to a Subordinate CommandPost, or any component registered to a
Subordinate CommandPost, any install packages that had previously been stored to the
Subordinate at File Management are obsolete. If all components are already running version
7.7 or higher, these files will be removed by the install process. If you are not currently
running version 7.7, you should log into the Subordinate and remove the obsolete files.
For all components, other than the CommandPost Management Console, you can click the
component name to monitor the installation progress. The information that appears will
update approximately once every 10 seconds. For most of the installation time, the
component will not be accessible and status cannot be obtained. Operations on
CommandPost are not impacted by installations being performed on registered components.
For an installation on the CommandPost Management Console, all CommandPost operations
become unavailable. You will be diverted to an installation status screen until the process is
complete.
Upon completion, you can access the login screen. All users attempting to access
CommandPost during installation will see the same status page.
5. After the Install completes, information about the last installation will appear in place of the
status. A pop up message will tell you that the install is complete.
6. Click OK at the popup to reload the Install page. Click View Log to see details.
Schedule an Install
Software installation can be scheduled for a date and time in the future.
To schedule an install:
1. Click System>Version Control>Install.
2. Select the appropriate components.
3. Select an available version for each component.
4. Click Schedule Install.
Update Progress
Status screens display for all components and these screens vary for each.
Scheduled Installs
Click to see a list of scheduled installs.
Download Control
At Download Control, you can enable CommandPost to automatically check for and download the
latest update packages. When configured, CommandPost will periodically access the Download
Center to check for new updates. If a new update is detected, will appear on the top right of
every CommandPost page.
If you do not want to set up automatic downloads, ensure that Never is selected at Check for
Updates. Never is the default setting. You can manually download updates from Technical Support
and save them to your workstation. Refer to File Management.
Before configuring downloads, you must set up credentials.
To configure downloads:
1. Determine when you want to check for updates. You can select daily, weekly, or monthly.
For daily, select a time. For weekly, select a day of the week and a time. For monthly,
specify the day of the month (1 through 31) and a time. Simply checking for updates does
• ArcSight
• Email HTML table
• Email user-defined
• Email Excel File (TSV attachment)
• Fidelis Archive
• SNMP traps
• Syslog
• Syslog LEEF
• Syslog Splunk
• McAfee ESM
• Verdasys Digital Guardian
You need to be a CommandPost administrator with alerts and alert details permissions. All saved
exports are available to users with these privileges. Refer to Define User Roles.
Refer to Define Exports for instructions on setting up a new export.
Export Methods
This topic provides specific information for each of the export methods. For general instructions
about creating an export, refer to Define Exports.
Fidelis Archive
For this export method, the remote server name, login, and directory information need to be set up
at the System>Components>CommandPost Config>Archive page. Refer toArchive.
Specify the remote directory for export at Destination.
Select Include Sessions or Include PCAPs to include in the export, if desired.
Select Include Configuration Backup to add a configuration backup. A separate backup file will be
created and exported to the same directory as the archive file. Refer to Backup and Restore for
more information.
When exported, a file named archive.<extension> will be created and sent to your remote system
and placed into the directory specified in the Destination field. Notes about Fidelis Archive exports:
[Link]
The destination for email is provided by a single or comma-separated list of email addresses. The
destination for Syslog or Syslog Splunk is the name or IP address of your external Syslog server.
For Syslog and Syslog Splunk, you can also specify a port, for example [Link]:::1800
Syslog Splunk has a preformatted key=value message format that is parsed by Splunk server. You
can also modify this format if needed.
T a bl e 3 2. A l e rt E x p or t k ey w or d s
%ACTION% The action taken by the sensor in String: Can be alert, quarantine,
response to the violation. prevent, or throttle.
Can also include valid
combinations of actions, such as
quarantine and notify.
64
An alert is the recorded and displayed incidence of at least one event.
65
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 302
Keywords Description Type (values)
%TIME% Time when the alert was detected. String in the format: YYYY-MM-
DD hh:mm:ss
Syslog LEEF
Similar to Syslog, but in LEEF (Log Event Enhanced Format). When this export method is selected,
you do not need to enter keywords as in Syslog, but need to specify destination, event criteria for
alerts and malware events, and export frequency.
The destination for Syslog LEEF is the name or IP address of your external Syslog LEEF server,
and an optional port number for example: [Link] or [Link]:::1800.
McAfee ESM
McAfee Enterprise Security Manager (ESM) is a predefined Syslog format designed for use with
the McAfee server. For McAfee ESM, you do not need to enter keywords as in Syslog, but need to
specify destination, event criteria for alerts and malware events, and export frequency.
The destination for is the name or IP address of your external McAfee ESM server.
For McAfee ESM, you can also specify a port for example: [Link]:::1800.
Define Exports
This topic provides instructions on setting up an export. Refer to Export Methods for information
specific to each export delivery method.
1. Click System>Export. A list of available exports displays. The first time Exports is accessed,
the list is empty.
2. Click New to create a new export or click next to the appropriate export. The Export
Editor displays. (Click to delete an existing Export.)
66
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 305
Figure 151. Export Editor
3. Select an export delivery method. The Export Editor changes to reflect your choice. Refer to
Export Methods.
If you select Fidelis Archive, you can select Include Configuration Backup to back up during
an automatic export. Refer to Backup and Restore.
4. Enter a Destination. This can be an email address, directory name, IP address, or port
depending on the export method.
Note: Destination does not support the use of non-ASCII characters.
5. Select to export either All alerts, alerts By Criteria, or None.
• All–enables you to select all available alerts. Exporting all alerts in your database can
take time. With this option, you might want to limit this export by selecting a maximum
number of alerts.
• By Criteria–enables you to select alerts based on multiple search criteria. These criteria
vary depending on the export method.
• None–No alerts will be exported.
6. Select alert criteria as needed to determine the alerts you want to export. You can select
multiple entries.
For sensors, no selection means all sensors are selected. If user permissions or sensor
assignments change, assignments for the export will not change.
For Time Range, you can select a specific time such as 24 hours or 7 days or enter a date or
date range. Refer to Time Range. You can also select Oldest Alerts to include alerts older
than a specified amount of time (1 - 99 days). If you enter 99, you get alerts older than 99
days.
Other export criteria include severity, rules, policies, labels, and actions associated with the
alert. Refer to Filters for specific information about these criteria.
7. Select the Export Frequency.
• Manually–exports only when you run the export by clicking the Run Now button. This
method is useful to test communication with the external system and for Fidelis Archive.
It is less useful for other export methods.
• Every Alert–exports all new alerts that meet selected criteria. Exporting for each new
alert is guaranteed to export each alert exactly once. The Export occurs immediately
Fidelis XPS User Guide 306
when the alert is received from the sensor. This method is recommended for integration
with external systems. It is not available for Fidelis Archive.
• Periodically–enables you to specify a time and day to run the export. This method is
recommended only for Fidelis Archive, email, and Syslog exports. All other types of
exports should be performed on Every Alert to provide synchronization between the
Fidelis system and the external system.
ArcSight and Syslog export methods support using transport protocols for message delivery.
If you select an Export Frequency of Manual or Periodically the UDP protocol is available. If
you select Every Alert, then UDP, TCP, and TLS are available.
To use TLS with Fidelis XPS, you need to upload certificates (in PEM format) into the
appropriate directory: /usr/local/syslog-ng/3.5.6/etc/ca.d/
You also need to run the following command:
/usr/sbin/cacertdir_rehash /usr/local/syslog-ng/3.5.6/etc/ca.d/
8. Select the maximum number of alerts to be sent. This option is very useful when testing
communication to external systems and is not recommended in any other case. When you
choose this option, the selected alerts will be random, based on your criteria. You should not
depend on the exact alerts exported when this option is selected.
9. Enter a name for the export in Save As. You must save the Export before you can run it.
Clicking Reset restores settings to what was last saved.
10. Click Run Now to export.
• If the Export Frequency is set to Every Alert, Run Now will export exactly one alert, if one can
be found to match the criteria of the alert. This alert will be transported to the external system
and handled accordingly.
• If the Export Frequency is set to Manual or Periodic, all alerts that match your criteria will be
exported to the external system. Note that this can be millions of alerts and can take a very
long time to execute. You can use the maximum number of alerts to limit the size of the
export for testing purposes.
Run Now can only be performed after the Export is saved. If you make any changes on the Export
page, the Run Now button will be disabled until you either Reset or Save.
• CommandPost user actions that change system configuration, including sensor and
CommandPost configuration, sensor registration, and policy updates to sensors.
• CommandPost user actions to remove or export data from the system. This includes alert
purge, alert export, and user-generated reports.
•
67
CommandPost user actions to add, modify, or delete system components such as policies
and policy components, users, groups, roles, etc.
• User actions taken at sensor or CommandPost front panel keypad and LCD display. Actions
performed at the sensor will be recorded to the CommandPost to which the sensor is
registered.
You can access the Audit Log from the CommandPost GUI to find audit entries.
Note: Fidelis recommends that you restrict audit log access to system administrators
and network security personnel. A user with Audit access can see all auditable actions.
67
Components enables you to set up licensing and configure Fidelis XPS components. This
includes adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail,
and setting up user notification and LDAP among other features.
Fidelis XPS User Guide 309
Access Audit
Click System>Audit at the main menu. The Audit Log displays.
T a bl e 3 3. A u di t L o g c ol u m ns
Column Description
Category The general type of action that occurred. For example, roles, users, and
audit.
Action The specific action that occurred. Most actions relate to the section of the
CommandPost used to trigger the action. For example, Alerts, Policies,
and Reports. The Action column may also include information about what
occurred, such as a login.
Click a row to display more detailed information about an audit log entry. Expand all displays more
details about all rows. Detailed information includes the effect and a description of the action.
Search Terms
Entering an ID number returns one and only row. For example, entering 21 matches only 21 and
not 211. Ranges are not supported for ID searches.
Enter specific terms in the Find: text box. Searching for term will match any audit entry containing
term in the chosen field. This will match audit entries with words such as term, terminate, and
exterminate.
Entering multiple words such as
term1term2
matches any audit entry containing both term1 and term2. The terms can be found in any order and
with any amount of separation between them.
The use of quotes around a phrase will be treated as a single search term. The phrase “term1
term2” will match any audit entry containing the exact phrase within the quotes. Any spaces in the
phrase will match any space characters in the audit entry, including a space, a tab, a new line, etc.
Matching is done on the character boundaries, not word boundaries. Therefore, a phrase of “top
secret” will match an audit entry containing a phrase such as “stop secrets.”
Multiple phrases such as a “literal phrase 1” and a “literal phrase 2” can be included in the Find
field. This will match any audit entries containing all of the phrases listed.
You can combine word-terms and phrase-terms. Any combination is allowed, such as “literal
phrase 1” word word1 word2 “literal phrase 2”
Matching does not consider the order of the terms, only that all are found within the search field.
1. If the sensor is linked to a Collector (at in the diagram), you need to unlink it from the
Collector.
a. Select the sensor at the System>Components page and click Config.
b. At the Advanced tab, select None at Send metadata to collector.
c. Click Save.
6. If this sensor links to a CommandPost that is a Secondary Policy Manager , add the
sensor to the Secondary Policy Manager.
Click System>Components>Add Component. Refer to Add Component.
7. If this sensor links to an Alert Failover CommandPost , add the sensor to the Alert
Failover CommandPost.
Click System>Components>Add Component. Refer to Add Component.
8. Link to a Collector . Refer to Link a Collector to Sensors.
9. If needed, assign policies to the sensor. Refer to chapter 8 in the Guide to Creating
Policies.
Fidelis XPS User Guide 315
Mail Sensors
Follow the steps above to change the IP address of a Mail sensor.
In milter mode, the MTA is sending data to the Fidelis XPS Mail sensor. If the MTA is
communicating with the Mail sensor on the admin interface, then the MTA needs the new IP
address for the Mail sensor.
Web Sensors
Follow the steps above to change the IP address of a Web sensor.
If the third-party proxy is communicating with the Fidelis XPS Web sensor on the admin interface,
then the third-party proxy needs the new IP address for the Web sensor.