0% found this document useful (0 votes)
18 views329 pages

Fidelis User Guide 801

The Fidelis XPS User Guide, version 8.0.1, provides comprehensive instructions for using the Fidelis XPS cybersecurity solution, including its components, functionalities, and management features. It covers various topics such as alert management, user roles, and system configuration, along with detailed procedures for accessing and utilizing the system effectively. The document is intended for users seeking to understand and operate the Fidelis XPS platform efficiently.

Uploaded by

Andrew Kupiec
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views329 pages

Fidelis User Guide 801

The Fidelis XPS User Guide, version 8.0.1, provides comprehensive instructions for using the Fidelis XPS cybersecurity solution, including its components, functionalities, and management features. It covers various topics such as alert management, user roles, and system configuration, along with detailed procedures for accessing and utilizing the system effectively. The document is intended for users seeking to understand and operate the Fidelis XPS platform efficiently.

Uploaded by

Andrew Kupiec
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

User Guide

Version 8.0.1
Copyright © 2002–2015 by General Dynamics Fidelis Cybersecurity Solutions, Inc.
All rights reserved worldwide.

Fidelis XPS™, version 8.0.1

User Guide, version 8.0.1

Revised 2015

Users are granted permission to copy and/or distribute this document in its original electronic form
and print copies for personal use. This document cannot be modified or converted to any other
electronic or machine-readable form in whole or in part without prior written approval of General
Dynamics Fidelis Cybersecurity Solutions, Inc.
While we have done our best to ensure that the material found in this document is accurate,
General Dynamics Fidelis Cybersecurity Solutions, Inc. makes no guarantee that the
information contained herein is error free.
Fidelis XPS includes GeoLite data created by MaxMind, available from [Link]

General Dynamics Fidelis Cybersecurity Solutions, Inc.


4416 East West Highway, Suite 310
Bethesda, MD 20814
Table of Contents

Preface ........................................................................................................................................................... 1
Intended Audience ..................................................................................................................................... 1
Available Guides ........................................................................................................................................ 2
Technical Support ...................................................................................................................................... 2
Fidelis XPS™ Overview ................................................................................................................................ 3
The Threat Life Cycle ................................................................................................................................. 3
Use Cases ................................................................................................................................................. 3
Use Case 1: Advanced Malware Protection .......................................................................................... 4
Use Case 2: Network Security Analytics ............................................................................................... 5
Use Case 3: Data Theft Protection ........................................................................................................ 6
Fidelis XPS Components ........................................................................................................................... 7
Fidelis XPS CommandPost ................................................................................................................... 7
Fidelis XPS Direct.................................................................................................................................. 9
Fidelis XPS Internal ............................................................................................................................... 9
Fidelis XPS Web.................................................................................................................................... 9
Fidelis XPS Mail ...................................................................................................................................10
Fidelis XPS Collector ............................................................................................................................10
Fidelis XPS BladeArray ........................................................................................................................10
SSL Inspector (Blue Coat) ....................................................................................................................11
Fidelis XPS Component Roles ..................................................................................................................11
Fidelis XPS CommandPost ..................................................................................................................11
Console ................................................................................................................................................12
Master CommandPost ..........................................................................................................................12
Subordinate CommandPost..................................................................................................................13
Primary CommandPost ........................................................................................................................13
Secondary Policy Manager ...................................................................................................................13
Alert Failover CommandPost ................................................................................................................14
Fidelis XPS Sensor...............................................................................................................................14
Secondary Sensor ................................................................................................................................14
Fidelis XPS Collector ............................................................................................................................14
Fidelis XPS Collector Controller ...........................................................................................................15
Fidelis XPS Failover Collector Controller..............................................................................................15
Chapter 1 Getting Started............................................................................................................................17
Access CommandPost ..............................................................................................................................17

Fidelis XPS User Guide Table of Contents iii


Change your Account................................................................................................................................17
Access System Information.......................................................................................................................19
Access the Online Help, the Guides, Support, and Time information........................................................19
Using Multiple Tabs...................................................................................................................................19
Lock Icon ...................................................................................................................................................20
CommandPost Navigation ........................................................................................................................20
System Status ...........................................................................................................................................20
Database Encryption Status ......................................................................................................................23
Logout .......................................................................................................................................................23
Using Non-ASCII Characters in Fidelis XPS .............................................................................................23
Chapter 2 Dashboard...................................................................................................................................24
Widget Controls.........................................................................................................................................25
Custom Alerts Widget ...............................................................................................................................26
Custom Metadata Widget..........................................................................................................................27
Globe ........................................................................................................................................................28
World Map .................................................................................................................................................28
Radar ........................................................................................................................................................29
Top Alert (or Malware) Hosts ....................................................................................................................30
Top Alert (or Malware) Sources ................................................................................................................30
Alert Trend ................................................................................................................................................30
Malware Trend ..........................................................................................................................................30
Application Protocol Trends ......................................................................................................................30
System Status ...........................................................................................................................................30
System Totals ...........................................................................................................................................31
Network Statistics......................................................................................................................................31
Alert Insertion Rate ...................................................................................................................................31
Disk Space ................................................................................................................................................31
Collector Disk Space .................................................................................................................................31
Collector Metadata ....................................................................................................................................31
Chapter 3 Understand and Manage Alert Workflows ................................................................................32
Access to Alerts and Quarantined Emails .................................................................................................32
Handle Alerts.............................................................................................................................................33
The Alert Workflow Log .............................................................................................................................33
Manage a Single Alert ...............................................................................................................................34
Change Status ......................................................................................................................................34
Change Alert Group..............................................................................................................................34
Manage Multiple Alerts..............................................................................................................................34
Chapter 4 List: Understand and Manage Alerts ........................................................................................36
Alert List ....................................................................................................................................................37
Fidelis XPS User Guide Table of Contents iv
Alert Quick Summary............................................................................................................................37
Filter Alerts ...........................................................................................................................................38
Navigate Alert Pages ................................................................................................................................39
Alert Actions ..............................................................................................................................................40
Alert Labels...........................................................................................................................................40
Export Actions ......................................................................................................................................41
Purge Alerts ..........................................................................................................................................43
Alert List Page Controls ............................................................................................................................43
System Reports for Alerts .....................................................................................................................44
Search for Alerts ...................................................................................................................................44
Enter Search Terms .............................................................................................................................46
Select CommandPosts..............................................................................................................................51
Time Range ..........................................................................................................................................51
Customize Report .................................................................................................................................52
Group By ..............................................................................................................................................52
Group Details........................................................................................................................................54
Create PDF Files for Alerts .......................................................................................................................55
Generate PDF ......................................................................................................................................55
Customize PDF ....................................................................................................................................55
Email the PDF ......................................................................................................................................56
Trending ....................................................................................................................................................57
Alert Details ...............................................................................................................................................58
Alert Sources ........................................................................................................................................63
Alert Highlighting ..................................................................................................................................63
Scroll through Alert Details ...................................................................................................................63
Find Similar Alerts ................................................................................................................................64
Find Metadata.......................................................................................................................................64
Find File on Hosts.................................................................................................................................64
Change Label .......................................................................................................................................64
Purge this Alert .....................................................................................................................................65
Alert Compression ................................................................................................................................65
Analytic Alert Info..................................................................................................................................65
Execution Forensics .............................................................................................................................66
Decoding Path and Channel Attributes.................................................................................................68
Export Alert Details ...............................................................................................................................69
Evidence Package ................................................................................................................................70
OpenIOC ..............................................................................................................................................70
PDF Options .........................................................................................................................................70
Text Options .........................................................................................................................................72
Fidelis XPS User Guide Table of Contents v
Packet Capture Information ..................................................................................................................73
Forensic Data .......................................................................................................................................77
Recorded TCP Session ........................................................................................................................77
Tune Rules from an Alert ..........................................................................................................................79
Fidelis XPS Decoders ...............................................................................................................................85
Protocol Decoder Attributes and Values ...............................................................................................85
Format Decoder Attributes and Values...............................................................................................100
Attributes for Protocol and Format Decoders .....................................................................................109
Quality, Encryption String, and Hash Values ..........................................................................................115
Chapter 5 Understand and Manage Quarantined Emails .......................................................................116
Understand Fidelis XPS Mail Quarantine ................................................................................................116
Quarantine Management by End-Users ..................................................................................................118
The Quarantine Report ...........................................................................................................................118
Take Actions on Quarantined Emails ......................................................................................................119
Deliver or Discard Quarantined Email .....................................................................................................119
Search Quarantined Emails ....................................................................................................................119
Search Quarantined Emails using Time Range ......................................................................................121
Advanced Search for Quarantined Emails ..............................................................................................122
Quarantine Details ..................................................................................................................................123
Chapter 6 Investigator ...............................................................................................................................125
Include Items in an Investigation .............................................................................................................125
Using the Investigator .............................................................................................................................126
Change an Investigation .........................................................................................................................126
Open an Investigation .............................................................................................................................127
Access Data Stored in an Investigation...................................................................................................128
Search for Items .................................................................................................................................128
Edit Item Comments ...........................................................................................................................128
Chapter 7 Metadata ....................................................................................................................................129
Explore ....................................................................................................................................................130
Metadata Controls ..............................................................................................................................130
Layouts and Views .............................................................................................................................132
Tabular View.......................................................................................................................................133
Metadata Details.................................................................................................................................134
Graphical View ...................................................................................................................................135
Connection View.................................................................................................................................136
Group Chart ........................................................................................................................................137
Column Items .....................................................................................................................................138
Metadata Search ................................................................................................................................140
Advanced Search ...............................................................................................................................141
Fidelis XPS User Guide Table of Contents vi
Export to Excel ...................................................................................................................................143
Analytics ..................................................................................................................................................144
Analytic Rule Types ............................................................................................................................144
Analytic Rules .....................................................................................................................................146
Filters ..................................................................................................................................................149
Automation ..............................................................................................................................................150
History ................................................................................................................................................150
Automation .........................................................................................................................................151
Automation Details .............................................................................................................................151
Run History .........................................................................................................................................153
Analytic Results.......................................................................................................................................154
Time Range ........................................................................................................................................154
Group by Rules...................................................................................................................................154
Results ...............................................................................................................................................154
Result Details .....................................................................................................................................155
Performance Monitor...............................................................................................................................156
Write Throughput ................................................................................................................................156
Automations........................................................................................................................................156
User Queries ......................................................................................................................................156
Chapter 8 Saved Reports ..........................................................................................................................157
Report Permissions .................................................................................................................................158
Hierarchical Management of Reports ......................................................................................................159
Report Details and Buttons .....................................................................................................................160
Create Reports ........................................................................................................................................160
Search ................................................................................................................................................161
Filters ..................................................................................................................................................164
Time Range ........................................................................................................................................166
Columns .............................................................................................................................................167
CommandPosts ..................................................................................................................................170
Sort By ................................................................................................................................................170
Group By ............................................................................................................................................170
Report Controls ..................................................................................................................................170
Run Reports ............................................................................................................................................171
Edit Reports ............................................................................................................................................171
Save and Schedule Reports ...................................................................................................................172
Save ...................................................................................................................................................172
Save and Schedule ............................................................................................................................172
Delete Reports ........................................................................................................................................173
Chapter 9 Summary Reports.....................................................................................................................174
Fidelis XPS User Guide Table of Contents vii
Define Summary Reports ........................................................................................................................174
PDF Controls...........................................................................................................................................177
Customize PDF ..................................................................................................................................177
Email PDF ..........................................................................................................................................178
Schedule Summary Reports ...................................................................................................................179
Chapter 10 Network Reports .....................................................................................................................180
Network Statistics....................................................................................................................................182
Application Protocols...............................................................................................................................183
TCP Processor ........................................................................................................................................184
IP Defragmenter ......................................................................................................................................187
Average Alert Insertion Rate ...................................................................................................................188
TCP Resets .............................................................................................................................................189
DNS Processor .......................................................................................................................................190
Inline Module ...........................................................................................................................................191
Web.........................................................................................................................................................192
Mail .........................................................................................................................................................193
Interface Statistics ...................................................................................................................................194
Chapter 11 Import ......................................................................................................................................195
Chapter 12 Manage Users, Roles, and Groups .......................................................................................196
Users Page .............................................................................................................................................197
Reset a Local User Account....................................................................................................................197
Access Control in CommandPost............................................................................................................197
Small Security Teams .............................................................................................................................198
Hierarchical Management of Users .........................................................................................................198
Define User Profiles ................................................................................................................................199
Expand User Information ....................................................................................................................200
Add or Edit a Local User .........................................................................................................................201
Delete a User ..........................................................................................................................................203
Define Alert Management Groups ...........................................................................................................204
Add or Edit an Alert Management Group............................................................................................204
Delete an Alert Management Group ...................................................................................................205
Define User Roles ...................................................................................................................................205
Access Roles ......................................................................................................................................207
Add or Edit a Custom Role .................................................................................................................208
Delete a Custom Role ........................................................................................................................209
Chapter 13 Configure Fidelis XPS Components .....................................................................................210
The Components Page ...........................................................................................................................210
CommandPost Management Console and Sensor Information ..............................................................211
Status Lights .......................................................................................................................................211
Fidelis XPS User Guide Table of Contents viii
Details ................................................................................................................................................211
License Messages ..............................................................................................................................212
Component Buttons for the Sensor ....................................................................................................212
Secondary Policy Manager and Sensor Management ............................................................................213
Set Up Secondary Policy Managers ...................................................................................................213
Component Buttons for the Secondary Sensor ..................................................................................214
Fidelis XPS Collector Management.........................................................................................................214
Fidelis XPS Collector Controller Health Monitoring .................................................................................214
Fidelis XPS Collector SA (Demo) ............................................................................................................215
Hierarchical Management of CommandPosts .........................................................................................216
CommandPosts: Master and Subordinates ........................................................................................216
CommandPost Component Buttons for Master and Subordinates .....................................................217
Add a Fidelis XPS Component ................................................................................................................217
Edit a Sensor...........................................................................................................................................218
Edit a Collector ........................................................................................................................................218
Edit a CommandPost ..............................................................................................................................218
Set up CommandPost Relationships.......................................................................................................219
Add and Register CommandPosts .....................................................................................................219
Set up a Subordinate Relationship .....................................................................................................220
Set up a Master Relationship..............................................................................................................220
Configure CommandPost ........................................................................................................................221
License ...............................................................................................................................................221
Alert Retention ....................................................................................................................................223
Alert Storage.......................................................................................................................................227
Archive ...............................................................................................................................................228
Configure Audit ...................................................................................................................................230
Backup and Restore ...........................................................................................................................233
Custom GeoIP ....................................................................................................................................235
Diagnostics .........................................................................................................................................238
Email Configuration ............................................................................................................................239
Configure Exchange ...........................................................................................................................240
CommandPost Language Configuration.............................................................................................241
LDAP Configuration ............................................................................................................................242
Logs....................................................................................................................................................245
Network Forensics ..............................................................................................................................248
Proxy Config .......................................................................................................................................249
RADIUS/TACACS+ ............................................................................................................................249
Session Timeout .................................................................................................................................249
System Monitor – CommandPost .......................................................................................................250
Fidelis XPS User Guide Table of Contents ix
User Authentication ............................................................................................................................254
User Notification .................................................................................................................................259
Configure Sensors ..................................................................................................................................261
Runtime Information ................................................................................................................................261
Config Page ............................................................................................................................................261
License & Time ...................................................................................................................................261
Direct and Internal ..............................................................................................................................263
Mail .....................................................................................................................................................272
Web ....................................................................................................................................................276
Alert Failover ......................................................................................................................................277
Email Relayhost..................................................................................................................................278
Sensor Language Configuration .........................................................................................................278
Logs....................................................................................................................................................280
Secondary Managers ..............................................................................................................................281
System Monitor – Sensor ...................................................................................................................282
Configure and Link a Collector ................................................................................................................283
Configure a Collector ..........................................................................................................................284
Link a Collector to Sensors .................................................................................................................285
Chapter 14 Malware ...................................................................................................................................286
Malware Detection Engine ......................................................................................................................286
Execution Forensics ................................................................................................................................286
Reaction ..................................................................................................................................................287
Configure Malware Reaction ..............................................................................................................287
Configure Malware Reaction for Mail ..................................................................................................288
Host Activity ............................................................................................................................................290
File Check ...............................................................................................................................................291
Chapter 15 Version Control.......................................................................................................................292
Fidelis Release Naming Conventions .....................................................................................................292
Installing Fidelis XPS Software ..............................................................................................................293
Prepare to Install .....................................................................................................................................293
Install.......................................................................................................................................................294
Install Now ..............................................................................................................................................295
Schedule an Install ..................................................................................................................................295
Update Progress .....................................................................................................................................296
CommandPost Management Console ................................................................................................296
Sensors, Collectors, and Subordinate CommandPosts ......................................................................297
Scheduled Installs ...................................................................................................................................298
Cancel Scheduled Installs .......................................................................................................................298
Download Control....................................................................................................................................298
Fidelis XPS User Guide Table of Contents x
File Management ....................................................................................................................................300
Chapter 16 Configure Exports ..................................................................................................................301
Export Methods .......................................................................................................................................301
Fidelis Archive ....................................................................................................................................301
Email User-Defined, Syslog, and Syslog Splunk ................................................................................302
Email HTML Table and Email Excel File (TSV attachment) ...............................................................303
Syslog LEEF .......................................................................................................................................304
McAfee ESM.......................................................................................................................................304
SNMP Trap and ArcSight ...................................................................................................................304
Verdasys Digital Guardian ..................................................................................................................305
Define Exports.........................................................................................................................................305
Available Export Buttons ....................................................................................................................307
Testing Export Communication...........................................................................................................307
Delete Exports.........................................................................................................................................308
Chapter 17 Audit ........................................................................................................................................309
Access Audit ...........................................................................................................................................310
Audit and Hierarchical Management...................................................................................................311
Search for Audit Entries ..........................................................................................................................311
Search Terms .....................................................................................................................................311
Notes about Search Options...............................................................................................................311
Time Periods ......................................................................................................................................312
Appendix A: Manual Transfer of Installation Files ..................................................................................313
Appendix B: Changing IP Addresses .......................................................................................................314
Changing a Sensor IP Address ...............................................................................................................315
Mail Sensors .......................................................................................................................................316
Web Sensors ......................................................................................................................................316
Changing a CommandPost IP Address...................................................................................................317
Changing a Collector IP Addresses ........................................................................................................318

Fidelis XPS User Guide Table of Contents xi


Preface
This guide describes how to use the Fidelis XPS™ CommandPost Management Console to
monitor and manage security alerts, to configure sensors, and to create and maintain users
This guide contains the following chapters:
The Overview describes Fidelis XPS: the CommandPost Management Console and other modules.
This section also briefly describes policies.
Chapter 1 Getting Started describes how to access and navigate CommandPost, change account
information, and access more information.
Chapter 2 describes the Dashboard widgets and how to use this feature.
Chapter 3 describes how to manage alert workflows .
Chapter 4 describes the Alert List and how to use alert features.
Chapter 5 describes the quarantine management list and how to manage quarantined emails.
Chapter 6 describes how to use the Investigator.
Chapter 7 describes how to use Metadata.
Chapter 8 describes how to manage saved reports.
Chapter 9 describes how to create and use Summary Reports.
Chapter 10 describes how to use network reports.
Chapter 11 describes how to import reports.
Chapter 12 describes how to create and modify user information.
Chapter 13 describes how to configure CommandPost and Fidelis XPS sensors.
Chapter 14 describes how to configure Malware.
Chapter 15 describes how to update and manage Fidelis XPS versions.
Chapter 16 describes how to configure exports.
Chapter 17 describes the Audit feature and how to run it from the CommandPost GUI.
Appendix A: describes manual transfer of Installation files.
Appendix B: describes changing IP addresses.

Intended Audience
This information is intended for network system administrators familiar with networking, computer
security, and with the security requirements and practices of their enterprises. This help system
and related guides are intended for users that fit into at least one of the following major categories:

• The alert and quarantine managers are frequent users of the system, likely to visit the
CommandPost GUI several times each day. Both roles are usually filled by system
administrators responsible for reviewing alerts (or quarantined emails) and managing any
action required within the enterprise. Alert and quarantine management require high level
data analysis and the ability to delve into the details of any single violation.

• The network IT manager will be the first to touch the CommandPost, but is expected to rarely
use Fidelis XPS after initial installation. The IT manager might need to adjust sensor network
settings and CommandPost to sensor communications, manage users and their credentials,
and monitor network statistics to verify connectivity.

Fidelis XPS User Guide 1


Available Guides
The following guides are available:
The Guide to Creating Policies describes how to define policies and the rules and fingerprints that
policies contain.
The Enterprise Setup and Configuration Guide describes how to set up and configure Fidelis XPS
hardware.
Release Notes are updated with each release to provide information about new features, major
changes, and bugs corrected.

Technical Support
For all technical support related to this product, check with your site administrator to determine
support contract details. Contact your reseller or if you have a direct support contract, contact the
General Dynamics Fidelis Cybersecurity Solutions support team at:
Phone: +1 301.652.7190*
Toll-free in the US: 1.800.652.4020*
*Use the customer support option.
Email: support@[Link]
Web: [Link]

Fidelis XPS User Guide 2


Fidelis XPS™ Overview
Since 2002, General Dynamics Fidelis Cybersecurity Solutions has been providing its commercial,
government, and defense customers around the globe with the real-time detection, prevention, and
continuous response necessary to defend against advanced threats. Built on a patented Deep
Session Inspection® platform, Fidelis XPS™ is the only comprehensive advanced threat defense
solution that stops advanced threats across all phases of the threat life cycle.

The Threat Life Cycle


Advanced, targeted attacks are not instantaneous events. They are complex processes with
multiple phases that occur over a period of time with an end goal of stealing information. Fidelis
XPS is uniquely positioned with DSI coupled with a powerful policy engine and dynamic threat
intelligence feeds to monitor an attack across the entire threat life cycle. .
The threat life cycle typically follows this path:
1. Infiltration
2. Command and Control (C2) Communication
3. Lateral Propagation
4. Data Exfiltration
Infiltration: An employee at a major enterprise is sent a targeted email that includes an attached
PDF file containing malware. Further analysis of the PDF—embedded in a Zip archive—shows that
it contains hostile JavaScript, obfuscated by a deflate stream.
C2 Communication: When opened, the malware in the PDF file will trigger downloads of
additional malware or create a tunnel for the adversary to gain access to your network.
Lateral Propagation: The attacker will move laterally throughout the network in an effort to acquire
higher levels of privilege and better access to sensitive information. Once the attacker has the
ability to move through your network, they will take control of internal assets such as domain
controllers and file servers, search for sensitive data on your network, and stage data for
exfiltration.
Data Exfiltration: Once data is staged it is then siphoned out across the network. The attacker
may obfuscate the data and transmit the information out of the network on standard outbound
network channels or circumvent the system by sending data using non-standard ports and/or
protocols.

Use Cases
To mitigate attacks across the threat life cycle, Fidelis XPS provides Advanced Malware Protection,
Data Theft Protection, and Network Security Analytics in a single, tightly integrated system for
continuous protection and response across the enterprise. Customers use this technology for one
or more of the following use cases:
• Advanced Malware Protection to effectively identify and stop targeted persistent attacks on
the network.
• Network Security Analytics to analyze and correlate data on your network for proactive
event detection and remediation.
• Data Theft Protection to detect and prevent the unauthorized flow of sensitive, valuable, or
classified information out of the network.

Fidelis XPS User Guide 3


Use Case 1: Advanced Malware Protection
The biggest challenge in protecting your enterprise from advanced threats is detecting and
recognizing a potential threat before it does any harm. To combat advanced attacks Fidelis XPS’
Advanced Malware Protection features include:
• Advanced Malware Detection – analyzing scores of inbound threats per second as they
flow over the network, maintaining a high malware detection rate with extremely low false
positives.
• Rich Malware Execution Forensics – detailed description of what the malware did when it
executed in the virtual execution environment such as registry, file system and operating
system changes, network call-out behavior, etc.
• Real-Time Threat Prevention – analyzing network traffic at multi-gigabit speeds, providing
real-time discovery and prevention.
• Automated Threat Intelligence – delivering a continuous stream of finely curated
reputational threat intelligence for automatic consumption; a key component in enabling the
solution to quickly identify suspicious and malicious activity.
• Flexible Policy (Rules) Engine – operationalizing known advanced threat indicators using
open industry standards, like YARA.
• Wire-Speed Performance – analyzing gigabits of network traffic in real time, providing
visibility, analysis, and protection from advanced threats before they harm your enterprise.
Threat Life cycle example: An enterprise's employee is sent a targeted email that includes
an attached PDF file containing malware.
Fidelis XPS analyzes the inbound email before it reaches an Inbox. To do this, Fidelis XPS uses
rule-based and dynamic list-based threat intelligence to identify threats to your network. Rule-
based threat intelligence is updated regularly by the Threat Research Team and provided
automatically via the Fidelis Insight cloud-based feed.
List-based threat intelligence includes Fidelis XPS feeds available as a subscription service. The
feeds consist of a dynamic list of IP Addresses and URLs of sites known to be involved with
phishing, malware distribution, and botnet command and control. Customers can add their own
source of intelligence as a dynamic or static feed of IP Addresses and URLs.
You can use Fidelis XPS' existing rules or create your own rules to alert and even prevent potential
malware that can be embedded in email, web content, file downloads, or any other method of
network data transmission. Rules can be as simple or as complex as needed. For example, you
could build a rule to alert on Adobe Flash content when it is embedded in a Microsoft Office file.
This rule would work regardless of the port or protocol, or where the Office file is in the decoding
tree. A more complex rule could alert on PDF files containing executables that have been renamed
and zipped. Refer to chapter 7 in the Guide to Creating Policies.
You can write broad-based rules using the MDE-Filtered action that will result in objects being sent
to the Malware Detection Engine (MDE) for analysis. An alert will be generated only if a malware
determination is made.
PDF, exe, and Flash files are common in enterprises but these file types are also frequently
misused by attackers in ways that can be detected using Fidelis XPS. Malware does not only hide
in JavaScript embedded in a PDF or in a Flash file in a Microsoft Office application, but in any of a
nearly infinite variety of content-borne threats rendered invisible to deep packet inspection by
obfuscation and layering.
You can select decoders for the PDF, exe, Flash and other commonly used file types to create one
or more channel fingerprints. Refer to chapter 4 in the Guide to Creating Policies.
You can search on file extensions or on file names by using a regular expression in a channel
fingerprint.
Recently compiled executables or misleadingly-named files can indicate malware. Narrow the
search by selecting Date Attributes for a decoder and entering a creation or modified date.
Transmissions matching certain characteristics that occur outside of normal business hours can
also pose a security risk. Define Conditions to alert on transmissions of specific file types or

Fidelis XPS User Guide 4


involving certain hosts or protocols that occur after hours or during weekends. Refer to chapter 4 in
the Guide to Creating Policies.
Create a rule that alerts on and quarantines email with a PDF attachment from suspicious locations
or known malware sites.
Refer to chapters 3 and 7 in the Guide to Creating Policies.
When alerts are generated and sent to the CommandPost, view Alert Details and Decoding Path
and Channel Attributes to see detailed information that will inform your response to the event.
You can also view metadata associated with a session that is captured by the sensor and stored on
the Collector. Using the controls available at the Metadata page, you can expand the view to
observe hosts on the Internet that are participating in the campaign and other internal hosts that
have been compromised. Armed with this information, you can write more focused rules with
prevent actions.

Use Case 2: Network Security Analytics


Threat actors have become increasingly sophisticated, and as such continue to evolve their attack
tactics. In an effort to stay ahead of the adversary, Fidelis XPS correlates and analyzes events and
actions across time for proactive event detection, incident response, and historical analysis. Fidelis
XPS’ Network Security Analytics features include:
• Full Metadata Capture – collecting details (metadata) about every network transaction. This
metadata is stored as historical network memory and leveraged to discover past incursions.
• Multi-dimensional Analysis – analyzing network content against multiple sources of threat
intelligence including reputation feeds, custom policies, and threat prevention policies that
are updated frequently.
• Advanced Visualization – delivering dynamic summaries and trends of your enterprise, by
host, alerts, location, and protocols to understand your organizations threat landscape.
• Customizable Reporting – standard and customizable reports on the rich metadata
collected over time.
• Correlated Alerting – correlating alert data for investigation with other transactions
potentially related to the threat.
Threat Life cycle Example: Further analysis of the PDF shows that it contains hostile
JavaScript, in a deflate stream, in a ZIP archive. The PDF also includes an embedded
executable.
Network Security Analytics provides greater ability to investigate threats by recording, investigating,
and analyzing network events. Malware leaves trails on hosts and on the network. Fidelis XPS
permits you to follow these trails and gain visibility across all phases of the threat life cycle,
enabling you to selectively block all paths to an adversary's command and control systems.
If you decide that one or more transmissions warrant a high degree of suspicion about the vector
(suspicious content and/or suspicious session metadata) you need to conduct further research.
In our example of a deflated JavaScript file embedded in zipped PDF, a security analyst can
recover the complete JavaScript or the PDF or ZIP file instantly with a single click on the
CommandPost graphical user interface. In Alert Details, you can see the decoding path and a clear
indication of executable content within the PDF, six layers down. You see all the metadata
associated with the protocol that was involved, right down to the attributes of the executable itself.
Even the compile time is there, and you can build rules around that to hunt for executables
compiled very recently. With a single click, you obtain forensic details that would take an analyst
many hours or days to extract from packet captures. The forensic data can be used to instantly
confirm that it is a Windows executable that should not be in a PDF file.
To access this information:
• View Alert Details on the CommandPost and click on Forensic Data to see information
extracted from the session that is used by Content fingerprint analyzers. You can also view
the entire session up to configured limits.

Fidelis XPS User Guide 5


• Extract files from the Decoding Path manually by clicking on file names. Alternatively you
can select Evidence Mode or Evidence Package to extract the file into a Zip that includes
the file as well as information about the file, including the Alert Details and a hash of the file.
• Packet Capture can provide additional information by capturing all information about
sessions immediately before and just after an alert. You can filter session information by
selecting source or destination IP addresses, source or destination ports, or protocols. You
can also select a time period. Your selections filter information can be used to find related
alerts.
• Use Export to send information to any of a variety of Security Information and Event
Management (SIEM) solutions, in real time or in batches to conduct further research on
suspect IP addresses or web sites.
• View Metadata to see rich information about every session that traverses your network. Use
Customize View to narrow metadata information to fit your investigation objectives and build
queries using Metadata Advanced Search.
An important aspect of network forensics is to become familiar with your network's normal activity
so that you can rapidly identify anomalies that might be genuine threats.

Use Case 3: Data Theft Protection


Data Theft Protection enables organizations to detect and prevent malicious infiltration of sensitive
information over standard or non-standard ports and protocols. It can also be used to detect and
prevent inadvertent leakage of sensitive data over standard communication channels (web and
email). To detect and prevent the unauthorized flow of sensitive, valuable, or classified information
out of the network, Fidelis XPS’ Data Theft Protection features include:
• Data Exfiltration Prevention – using sophisticated rules and techniques to prevent the theft
of sensitive and confidential data out of your network.
• Intellectual Property Protection – flexible and powerful policy engine to match the
characteristics of your intellectual property and block any unauthorized transfers of this
data.
• Compete Content Visibility – delivering network visibility, analysis, and control over all
protocols, applications, and file types to defend against advanced threats and prevent data
theft in real time.
• Flexible Data Profiling – Through a flexible, powerful policy engine, you can define the
characteristics of your most valuable data to identify sensitive data and keep it from leaving
your network.
• Actionable Alerts – alerts provide comprehensive, actionable information allowing you to
rapidly triage and remediate threats.
Threat Life cycle Example: When opened, the malware in the PDF file will trigger downloads
of additional malware that will propagate laterally throughout an enterprise's network in an
effort to acquire higher levels of privilege and better access to sensitive information. Once
malware propagates, it will take control of internal assets such as domain controllers and
file servers, search for sensitive data on your network, and exfiltrate this data to the
command and control system operated by the adversary.
Fidelis XPS products include a number of specialized content analyzers that can identify sensitive
information such as personal identity information (PII), classified data, and intellectual property.
To protect your organization's sensitive data, create a rule using Content fingerprints to identify
sensitive data. Content fingerprints can be used to define your sensitive data using a variety of
techniques available to the policy writer, including data registration and data profiling. Data
registration can be used to detect specific files by hash of the file contents. Profiling includes
keywords, regular expressions, file attributes, and Identity Profile which uses a statistical analysis
of multiple patterns to detect PII. Rules may include content, channel, and location fingerprints to
fine tune the detection of malicious or inadvertent data exfiltration. Refer to chapter 5 in the Guide
to Creating Policies.

Fidelis XPS User Guide 6


If any rule conditions are met, then Fidelis XPS generates alerts with comprehensive forensic
details and session metadata.
After alerts are generated and sent to the CommandPost, view Alert Details and click the Forensic
Data section to see detailed information about suspect DNS domains.
Fidelis XPS' ability to provide deep application and content decoding in real time (while network
sessions are occurring) allows for a policy-based remediation action such as changing a rule action
to Prevent to block potentially malicious JavaScript files embedded in a zipped PDF document.
Use information based on your analysis to:
• Create a Prevent rule to stop exfiltration of sensitive data from suspicious endpoints or from
suspicious countries. Refer to chapter 7 in the Guide to Creating Policies.
• Identify infected endpoints for reimaging.
• Use any evidence gathered to submit reports to relevant agencies or to perhaps begin legal
action.

Fidelis XPS Components


Fidelis XPS components include several types of sensors, Fidelis XPS Collectors, and the Fidelis
XPS CommandPost management system. The sensors can be deployed to specific areas of the
network as needed. This section describes how an enterprise might deploy the Fidelis XPS
components and provides an overview of all available components.

Figure 1. The Fidelis XPS solution

Fidelis XPS CommandPost


Fidelis XPS CommandPost is the management system for the Fidelis XPS solution, providing web-
based enterprise administration. It is also the integration point between the Fidelis XPS solution
and other third-party products in the enterprise network security infrastructure. The CommandPost
collects, aggregates, and stores data from a single to many Fidelis XPS sensors. Multiple
CommandPosts can operate in concert through a capability called Hierarchical Management.
CommandPosts can be set up to be Masters or Subordinates in the hierarchical management
architecture. Refer to Hierarchical Management of CommandPosts. All CommandPosts collect,
aggregate, and store data from multiple sensors.

Fidelis XPS User Guide 7


You can access the web-based, CommandPost GUI from anywhere on your network to:

• Visually monitor and analyze network alerts and other metadata in real time.
• Enable, disable, or customize policies and analytics as required.
• Add, configure, and manage sensors, Collectors, and the Console itself.
• Create users using the granular access control capabilities in several user authentication
mechanisms including integration with a user directory server.
• Export information to a third-party network alert aggregation system.
• Use the built-in reports or customize reports to your requirements. Reports can be scheduled
for automatic delivery or run in real time with click-through drill down capability.
Typical bandwidth requirements for CommandPost are approximately 10Mbps. However, the
bandwidth can increase based on your environment. Consider:
• The size of an alert is equivalent to the size of the violating network session in bytes. The
sensor can be configured to limit the maximum size of the alert recorded object limit to
between 0 and 32MB per alert (this limit is increased to 50MB for the Mail sensor).
Refer to Direct>Advanced.
• Enabling Fidelis feeds uses approximately 250 MB of data every hour between the
CommandPost and the sensor,. If you are at a lower bandwidth, then it is advisable to
adjust the feed frequency interval to 10-20 hours. Enabling malware detection on the sensor
can add up to 500 MB on startup and up to 50MB on an hourly basis.
Refer to chapter 10 in the Guide to Creating Policies.
• CommandPost can receive alerts at a rate of approximately 10-15 alerts per second.
Compressing alerts can increase the needed bandwidth by up to 1Gbps.
Refer to Alert Compression.
• If Packet capture is enabled, the size of an alert can increase by 16MB. Refer to Direct.
chapter 13 of the User Guide.
• If Malware>Execution Forensics is enabled, the bandwidth between sensor and
CommandPost is not impacted because the file is sent as part of the recorded session.
Execution Forensics will increase the bandwidth of CommandPost to external sites.
Refer to Execution Forensics.
• The minimum system requirements for the CommandPost to enable a Demo Collector are:
16 GB RAM
2 CPUs
200 GB disk
50 GB free disk
The amount of storage for the Demo Collector is approximately 60GB (This could be lower
on VMs with low total disk space.) The maximum allowed input rate is 1Mbps of metadata.
Depending on the traffic, 100 Mbps of monitored traffic may or may not exceed that 1Mbps
metadata rate.
Also, if CommandPost is overloaded with high alert rates or many concurrent users, adding
a Demo Collector would put an additional load on the CommandPost. Users; however, can
limit the metadata rate by entering specific IP address or can disable the Demo Collector.
The days of metadata storage for the Demo Collector depends on type of traffic and how
much the monitored rate is limited. Users can expect 2 weeks of metadata storage with a
reasonable rate.
Refer to the section: Demo Collector for details.
Refer to Direct>Advanced to set up the Demo Collector.
The network requirement is therefore a factor of your policies, the size of violating network
sessions, the percentage of alerts generated with the Packet Capture option, and Fidelis XPS
sensor configurations.

Fidelis XPS User Guide 8


For information about setting up CommandPost, refer to chapters 2 and 4 in the Enterprise Setup
and Configuration Guide.
To get started using CommandPost, refer to Getting Started. For more information about
CommandPost's configuration features, refer to Configure CommandPost.

Fidelis XPS Direct


The Fidelis XPS Direct sensor sees and manages bi-directional traffic at ingress and egress points
by monitoring and enforcing policy across all known and unknown network traffic, protocols, and
applications at wire-speed. Direct sensors are typically deployed at the network perimeter, inline or
out-of-band to monitor applications and protocols.
Direct sensor performance ranges from 50Mbps to 2.5Gbps in discrete 1U appliance platforms.
Direct sensors can be deployed in both out-of-band (TAP) and inline deployment scenarios. Sensor
performance up to 20Gpbs can be achieved through the scalable Fidelis XPS BladeArray chassis
and load balancing across multiple Fidelis XPS Direct sensor blades.
For more details, refer to Direct and Internal.
For information about setting up and configuring Direct, refer to chapter 5 in the Enterprise Setup
and Configuration Guide.

Fidelis XPS Internal


The Fidelis XPS Internal sensor monitors internal local network traffic, providing an unprecedented
level of visibility into, and control of, how information is used and misused across the enterprise.
Internal sensors are typically deployed in the network core to provide visibility and control of
information leaving data centers or transmitted between divisions. The Internal sensor operates bi-
directionally and provides prevention on all ports and all protocols.
Internal sensor performance ranges from 50Mbps to 2.5Gbps in discrete 1U appliance platforms.
Internal sensors can be deployed in both out-of-band (TAP) and inline deployment scenarios.
Sensor performance up to 20Gbbs can be achieved through the scalable Fidelis XPS BladeArray
chassis and load balancing across multiple Fidelis XPS Internal sensor blades.
For more details, refer to Direct and Internal.
For information about setting up and configuring this sensor, refer to chapter 5 in the Enterprise
Setup and Configuration Guide.

Fidelis XPS Web


The Fidelis XPS Web sensor offers an interface to a third-party HTTP or FTP proxy using the
Internet Content Adaptation Protocol (ICAP). ICAP is a lightweight and extensible point-to-point
protocol used for requesting services for content inspection.
This sensor offers the following advantages for HTTP traffic:

• Prevention can be accomplished by redirecting the user to a customizable web page that
states their violation and other applicable information.
• When combined with an ICAP-enabled SSL proxy, the Web component can access
unencrypted data destined to secure web sites.
Refer toWeb.
For information about setting up and configuring this sensor, refer to chapter 6 in the Enterprise
Setup and Configuration Guide.

Fidelis XPS User Guide 9


Fidelis XPS Mail
The Fidelis XPS Mail sensor monitors and enforces policy for email traffic, gracefully providing
quarantine, sender notification, attachment removal, and redirection options. You can deploy
products with the Mail sensor in an SMTP path in MTA mode or with a Milter-enabled email
gateway.
For more details, refer to Mail .
For information about setting up and configuring this sensor, refer to chapter 7 in the Enterprise
Setup and Configuration Guide.

Fidelis XPS Collector


The Fidelis XPS Collector serves as the Fidelis XPS solution’s network security analytics platform.
The Collector is the storage and access point for metadata extracted from all network sessions by
the sensors.
Typical bandwidth requirements for a Collector is approximately 2 percent of the monitored traffic of
each sensor. For example, if a sensor is monitoring traffic at 1Gbps, the Collector will receive
approximately 20Mbps of data. This depends on the type of traffic being monitored and is meant to
be a general rule of thumb.

Fideli s XPS C ollector SA and Fi del is XPS Coll ector


Controll er
The Collector is available as a standalone, single rack unit device, Fidelis XPS Collector SA, and
as a clustered solution combining a Fidelis XPS Collector Controller with one or more Fidelis
XPS Collector XAs. A Collector Controller with three or more XAs is a highly available solution that
can survive the failure of an individual XA with the ability to reconstruct the data when the XA is
replaced.
A Fidelis XPS Failover Controller can be implemented to make the controller function highly
available.
For more details, refer to Collector.
For information about setting up and configuring the Collector, refer to chapter 8 in the Enterprise
Setup and Configuration Guide.

Demo Collector
The Collector is also available as a built-in Collector enabled on the CommandPost. The Fidelis
XPS Demo Collector can only accept metadata from one sensor at a time and has limited storage
capability, but provides the full capability of an actual Collector. The Demo Collector is available to
any CommandPost that does not have a registered Collector. To use the Demo Collector to its full
potential, configure the sensor to send data from a small IP Address range.
Refer to the section: Fidelis XPS CommandPost for details about CommandPost system.
requirements for a Demo Collector.
Refer to Direct>Advanced to set up the Demo Collector.

Fidelis XPS BladeArray


The Fidelis XPS BladeArray provides a scalable, blade-based architecture for enterprises that need
to deal with large volumes of network traffic. Blades are available with both Direct and Internal
sensor capability. The BladeArray solution provides embedded load balancing and high-speed
switch connectivity for both out-of-band (TAP) and inline deployment options.
Each Fidelis XPS BladeArray is comprised of 14 blade slots. Each slot can contain a Fidelis XPS
Direct or Internal sensor with performance of 2Gbps, providing a maximum bandwidth that exceeds
20Gbps for the entire chassis.
For information about setting up and configuring the BladeArray, refer to chapter 10 in the
Enterprise Setup and Configuration Guide.

Fidelis XPS User Guide 10


SSL Inspector (Blue Coat)
The Blue Coat SSL Visibility Appliance is a transparent proxy for Secure Sockets Layer (SSL)
network communications. It enables a variety of applications to access the plain text (original
unencrypted data) in SSL-encrypted connections and has been designed for security and network
appliance manufacturers, enterprise IT organizations, and system integrators. The SSL Visibility
Appliance can be deployed with any of the Fidelis XPS options.
The SSL Inspector Appliance is a transparent proxy for Secure Sockets Layer (SSL) network
communications. It enables a variety of applications to access the plain text (original unencrypted
data) in SSL-encrypted connections and has been designed for security and network appliance
manufacturers, enterprise IT organizations, and system integrators. The SSL Inspector Appliance
can be deployed with any of the Fidelis XPS sensors.
Refer to chapter 11 of the Enterprise Setup and Configuration Guide.

Fidelis XPS Component Roles


This topic defines basic terms that describe roles that you can designate for Fidelis XPS
Components. The figure below shows several CommandPosts, sensors, a Collector, Collector
Controllers and illustrates possible deployment scenarios for each component. The subsequent
sections of this topic will define the terms in the figure.

Figure 2. Component Roles

Fidelis XPS CommandPost


Fidelis XPS CommandPost offers a web-based, user interface to control all components of your
Fidelis XPS implementation. CommandPost may control other CommandPosts in a hierarchical
manner where one CommandPost is a Master CommandPost while others are Subordinate.
Sensors are registered to one CommandPost, referred to as the Primary CommandPost. The
Primary CommandPost has control over all sensor operations. A sensor may designate other
CommandPosts as a Secondary Policy Managersor as an Alert Failover CommandPost.
If hierarchical management is enabled, you can elect to send metadata from a sensor registered to
a Subordinate CommandPost to a Collector registered to a Master CommandPost. In the
Component Roles illustration above, Sensor 2 sends metadata to the Collector registered to the

Fidelis XPS User Guide 11


Master CommandPost (CP1). You can access metadata information from the Collector at the
Master CommandPost.

Console
Every Fidelis XPS CommandPost provides the same web-based user interface. When you access
CommandPost, the system to which you are logged in is referred to as the Console. In a
hierarchical management deployment, the relationship between CommandPosts is relative to the
Console. If you access the Master CommandPost, you can see and manage Subordinate
CommandPosts. If you access a Subordinate CommandPost, you can manage the access rights of
the Master. In an environment where there is only a single CommandPost controlling one or more
sensors, all access is to the Console.

Master CommandPost
A Master CommandPost can push information about users, policies, reports, and software
upgrade packages to a Subordinate CommandPost. A Master CommandPost may have many
Subordinate relationships. In the figure below, CP 1 is a Master CommandPost to CP 2 and to CP
A.
To an enterprise with a large deployment of Fidelis XPS, the Master offers a single point to control
users, reports, policies, and software upgrades. Changes made at the master can then be pushed
to all subordinates. In the case of policies, you may configure your subordinates to automatically
push new policies to all sensors. In case of software upgrades, the Master CommandPost can
transfer upgrade packages to and initiate software upgrades of Subordinate CommandPosts and
all their registered sensors or Collectors.

Figure 3. CommandPost Hierarchical Relationships

Fidelis XPS User Guide 12


Subordinate CommandPost
Subordinate CommandPosts receive information about users, policies, reports, and software
upgrade packages from a Master CommandPost. Each Subordinate can have only one Master. A
Subordinate CommandPost can, in turn, be designated as a Master to other CommandPosts. In the
figure above, CP 2 is both a Master CommandPost to CP B and subordinate to CP 1.
Policies can be configured to be pushed from a Master to all sensors connected to a Subordinate
CommandPost. In our example above, CP 1 can assign policies to Sensor 2 and to Sensor A.
Refer to Hierarchical Management of CommandPosts.

Primary CommandPost
This CommandPost controls sensor configuration and is the CommandPost to which the sensor is
registered. All sensors must have one primary CommandPost, but can have multiple Secondary
Policy Managers. In the illustration, Secondary and Alert Failover Relationships, CP 1 is the
Primary CommandPost for Sensor 1.
The Primary CommandPost can fully configure and control all registered sensors and Collectors.
Additional CommandPosts may be designated to a sensor in a limited role.

Secondary Policy Manager


Secondary Policy Managers are used when multiple entities within your enterprise need to analyze
network traffic fed to a sensor. A CommandPost can be set up as a Secondary Policy Manager.
The sensor will accept policies downloaded from its Primary CommandPost and one or more
CommandPosts set up as a Secondary Policy Manager. When a violation is detected, the
associated alert will be set to the CommandPost that downloaded the violated policy. In our
example below, CP 3 is set up as a Secondary Policy Manager that can download polices to
Sensor 1 and receive alerts from that sensor when those policies are violated.

Figure 4 . Secondary and Alert Failover Relationships


CommandPosts that are Secondary Policy Managers (such as CP 3 in the illustration) will not have
any other rights on a Secondary Sensor.
The Secondary Policy Manager will have no knowledge of policies running on the sensor that were
downloaded from another CommandPost. Similarly, the Primary CommandPost will have no
knowledge of policies downloaded by a Secondary Policy Manager.

Fidelis XPS User Guide 13


Alert Failover CommandPost
In normal operation, alerts are created by a sensor and sent to CommandPost (either the Primary
or Secondary Policy Manager). If a CommandPost is down or unreachable, the sensor will store
alerts locally for a short time, then begin to drop alerts. To avoid this situation, an Alert Failover
CommandPost may be designated to receive alerts while the primary (or secondary)
CommandPost is down. You may designate an Alert Failover CommandPost for the Primary
CommandPost and each Secondary Policy Manager for each sensor. When the sensor determines
that the Primary (or Secondary) CommandPost is up, it will stop sending alerts to the Alert Failover
CommandPost and start sending new alerts to the Primary (or Secondary) CommandPost. The
Alert Failover CommandPost has no control over the sensor. It simply accumulates alerts while the
Primary (or Secondary) CommandPost is down.

Fidelis XPS Sensor


A Fidelis XPS sensor gathers network transmission and session data and performs analysis based
on the policies downloaded to the sensor from a CommandPost. The term Fidelis XPS Sensor
refers to any of the sensor modules including: Direct, Internal, Mail, or Web. Refer to Fidelis XPS
Components. The sensor will take action on policy violations, refer to chapter 7 in the Guide to
Creating Policies. If the violated policy requires an alert, the alert data is sent to CommandPost. A
Fidelis XPS Direct or Fidelis XPS Internal sensor may be configured to send all session metadata
to a Collector.

Secondary Sensor
A CommandPost may act as a Primary CommandPost to some sensors and a Secondary Policy
Manager to others. The sensors that are connected in a secondary mode are Secondary Sensors
to this CommandPost.
Secondary Sensors are registered to another, Primary CommandPost, but can receive policies
from a CommandPost designated as a Secondary Policy Manager. In our example, Sensor 1 is a
Secondary Sensor to CP 3 and has CP 1 as a Primary CommandPost. Refer to Secondary Policy
Manager and Sensor Management.

Fidelis XPS Collector

Figure 5. Fidelis XPS Collector Relationships

Fidelis XPS User Guide 14


A Fidelis XPS Collector receives session metadata from one or more Fidelis XPS sensors and
stores it. The Collector is registered to a CommandPost from which you can access metadata via
the GUI at the Metadata page. Refer to Collector.

Fidelis XPS Collector Controller

A Collector Controller collects metadata, maintains the database, and ensures the availability of
metadata to users. A Controller has multiple Collector XAs connected to it that host the metadata
database. The Collector XAs communicate with each other and with the Collector Controller.
After adding the Controller to CommandPost and registering it, proceed to Collector Configure to
configure the Controller and then link it to a sensor. The Controller and the XAs will appear as a
single Collector to the CommandPost and to other Fidelis XPS Components.

Fidelis XPS Failover Collector Controller

If a Primary Collector Controller has a hardware failure or is unreachable, a Failover Collector


Controller can control the Collector XAs, receive metadata from linked sensors, and communicate
with CommandPost. A Failover Controller shares Collector XAs with the Primary Controller. The

Fidelis XPS User Guide 15


Primary and Failover Controllers must both be on the same subnet as the Collector XAs and should
be connected to the same DB Switch (or DB VLAN). A Primary Controller can have just one
Failover Controller and a Failover Controller can only have one Primary Controller.
At the Components page of the GUI, the Failover Controller displays within the expanded row of
the Primary Controller. Only the Primary Controller is available to users at the Metadata page.
Failover occurs in the following situations:
If a sensor cannot send metadata to the Primary Controller, it will send metadata to the Failover
Controller. The CommandPost is also notified of the failover so that it can inform users via the
CommandPost GUI.
If CommandPost cannot get metadata from the Primary Controller, it will attempt to retrieve
metadata from the Failover Controller.
The Failover Controller receives constant configuration updates from the Primary Controller. If
communication is lost with the Primary, the Failover becomes the Primary Controller.

Fidelis XPS User Guide 16


Chapter 1 Getting Started
Fidelis XPS detects and prevents advanced cyber threats, network abuse, and data exfiltration in
real time. Fidelis XPS accomplishes this though one or more sensors and the CommandPost
Management Console. CommandPost enables you to manage and configure sensors and
Collectors.
This chapter provides information on how to get started using CommandPost including: accessing
and navigating CommandPost, changing your account information, and where to find more
information.

Access CommandPost
You can access CommandPost from anywhere on your network, by using a web browser that
supports SSL. Communications between the sensors, Collectors, and CommandPost and between
CommandPost and the web-based GUI are encrypted SSL communications.
CommandPost has been verified with recent versions of Microsoft Internet Explorer, Mozilla
Firefox, Google Chrome, and Apple Safari.
For CommandPost to work properly, your client workstation must have the following installed:

• Adobe Flash Player – obtain a recent version of Adobe Flash Player free of charge from the
Adobe web site at [Link].

• WinSCP – available free of charge from the WinSCP web site at [Link]. WinSCP
transfers files to CommandPost for policy creation and verification. All other aspects of
CommandPost function properly without WinSCP.

• Allow pop-up windows from the CommandPost server.

• Enable Javascript execution in your browser.


• Enable TLS communication.

Change your Account


From your browser, navigate to the IP address of the Console device and log in with the user name
and password that Technical Support provides. A CommandPost Dashboard page displays.
The top right of each CommandPost page displays the user name of the logged in user and the
CommandPost logged into.
Change the password for this account immediately after your first log in. If needed, you can also
change the start page that displays upon successful login.
If you receive a warning that your password is about to expire, change it before the expiration date
or your account will be locked.
Note: Only local users entered in System>Users>Profiles can change passwords.
Other users can change the full name, email, and the start page.
To change the password:
1. Click the user name at the top right corner. The Change Account Information dialog box
displays.

Fidelis XPS User Guide 17


Figure 6. Change Account Information
2. Click Change Password. The text boxes for the old and new passwords display.
3. Enter your old password and then enter your new password. For passwords, you can use
alphanumeric (a-z,A-Z,0-9), a space, and the following special characters:
~`!@#$%^&*()_+-={}|[]:;<>,./
Single and double quotes or back slashes are not allowed.
4. Re-enter your new password.
5. You can change the full name and the email address associated with this account.
6. Click Change. CommandPost saves the new password, name, and email address. If you
changed the password, the system will log you out.
7. Log in with your new password.
8. Add a new user for each CommandPost user. Fidelis recommends adding at least one new
user, even if you are the only one accessing the system. Refer to Users for more information.
To change the Start Page:
1. Select a new Start Page from the list.
2. Click Change. The new start page will display upon the next successful login.

Fidelis XPS User Guide 18


Access System Information
System Information is a popup accessed from the top right of the CommandPost GUI that enables
you to quickly check which software version is on your CommandPost, which patches were applied,
and if there are any available updates.
Available Update Version will display new software versions that have been released. This feature
must be enabled at Download Control.
This and other information listed can be useful when you contact Technical Support such as: the
OS version, system type, hardware revision, and the CommandPost CPU information, memory,
and serial number.

Figure 7. System Information

Access the Online Help, the Guides, Support, and Time


information
Click the help icon at the top of the CommandPost GUI. The online help system displays.
Click the PDF Downloads link in the Table of Contents to display the Guides page with its links to
the PDF files for the guides, the Release Notes, and the Redistribution Notice.

Click to open the Support login page.

Mouse over the time to view the date, time zone, and time zone offset for this
CommandPost.

Using Multiple Tabs


You can conduct two or more searches or run reports simultaneously in multiple tabs without
interfering with each other. You can also conduct a search (or run a report) in one tab, then open
another tab to make system changes such as adding or editing users.
Each tab would act as if it is in its own session and therefore independent of other tabs during
searches on alerts, quarantine, and metadata. Updates to the system (such as a new report or a
new or changed user profile) done at one tab may not be immediately reflected in other tabs. Click
Refresh or Reload to view recent changes.

• After logging in successfully to the CommandPost, you can open another tab without logging
in again.

Fidelis XPS User Guide 19


• Changing the page size for Alerts, Quarantine, or Metadata reports keeps the specified page
size at that tab. You can specify different page sizes for the same report at different tabs.

Lock Icon
Fidelis XPS CommandPost and sensors communicate over encrypted SSL connections, using
self-signed certificates and an internal authentication method. This mode can be overridden by
installing externally generated certificates that use the Public Key Infrastructure (PKI). Refer to the
1
Enterprise Setup and Installation Guide for information about installing PKI certificates to run in
this mode.
When operating with PKI certificates, a lock icon appears at the top right of the CommandPost
menu bar. You can mouse over the lock icon to see the expiration date for the certificate.

CommandPost Navigation
With the exception of Dashboard and Metadata, clicking a main menu option in the CommandPost
GUI displays subnavigation menus. A highlighted option from the subnavigation menu indicates
which page is currently accessed. CommandPost navigation is "sticky" meaning that if you later
return to the same major heading, the page last accessed displays.
Note: Users need permissions to see many of the menu options. If a user does not
have the appropriate permissions for a menu option, that option does not display.
Refer to User Roles.

System Status
2
System Status provides information about Fidelis XPS components and their statuses that you
can access from any GUI page. The diamond next to System Status reflects the status of the
component with the highest severity. Mouse over the System Status diamond to see the list of
components. The component list that displays is the CommandPost Console and all sensors and
Collectors that have been registered and that are within a user’s access privileges. Refer to Define
User Profiles. Mouse over a component in the list to see a message about that component's status.
Each component has a green, yellow, or red diamond next to it to indicate severity.
If your environment uses a hierarchy of CommandPosts, you will see the status of all components
from the Master CommandPost, including those components registered to a Subordinate
CommandPost.
Note: Users need permissions to see system status. Refer to User Roles.
Green indicates that the component is operational.
A red diamond indicates a condition with critical severity. A yellow diamond indicates a condition
with high severity.
A grey diamond indicates that there is no available information about the component.
Clicking will set the status to green. At the next attempt to use the component status will
change. For example, a feed fetched once a day will not change status until the next attempt after
clicking .
Clicking fora Subordinate CommandPost or its registered components may take several
minutes.

1
Public Key Infrastructure (PKI) is a set of hardware, software, people, policies, and procedures
needed to create, manage, distribute, use, store, and revoke digital certificates.
2
Components enables you to set up licensing and configure Fidelis XPS components. This includes
adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail, and
setting up user notification and LDAP among other features.
Fidelis XPS User Guide 20
T a bl e 1. C o m p o n e nt St a t us M es s a g e s a n d S ev e ri ty
The following table describes some of the more common conditions that can cause system status
messages and their severities.

Component Severity Status Message

Alert Export Critical Cannot start exporter, see log for details

Collector Critical Please contact Fidelis support. Vertica is


malfunctioning.

Collector Critical Collector database is not operational, please


contact Fidelis Support.

Collector Critical Database access error, please contact Fidelis


Support

Collector Critical Closing Session Error

Collector Critical Collector disk usage is high

Collector Critical Metadata insertion has stopped on the Collector,


disk usage is too high

Collector Critical Database Error

Collector Critical ODBC connection error on Collector node(s)

Collector Critical Collector memory usage exceeds limits, restarted


service

Collector High Collector database is not up yet.

Collector High Vertica is undergoing maintenance. Unable to


accept new meta-data.

Collector High Collector writer thread overloaded

Collector Medium Vertica is undergoing maintenance.

Collector Medium Closing Session

Collector DB Critical Collector DB maintenance is taking too long.


Maintenance Please contact Fidelis Support

DB Maintenance High DB maintenance

Execution High Execution Forensics has invalid proxy


Forensics configuration.

Execution High Execution Forensics communication error. Check


Forensics again in 10 seconds.

Execution High Execution Forensics license key is not valid.


Forensics Contact Customer Support for assistance.

Feed fetch Critical Cannot start feed handler(s), see log for details

Feed fetch High Feed "\feeds_fidelis\" refresh error

Fidelis XPS User Guide 21


Component Severity Status Message

Feed fetch High Feed update error

Host Activity High Host Activity authentication token is not valid.


Contact Customer Support for assistance.

Host Activity High Invalid configuration for Host Activity.

Host Activity High Invalid proxy configuration for Host Activity.

Host Activity High Communication Error for Host Activity.

Insight High New policies are available from the Insight feed

Insight High Failed to get valid policy feed data

Insight High Failed to import data from policy feed

Insight High Failed to update sensors after policy feed update

Insight High Failed to get valid Automatic Malware Policy feed


data

LDAP Fetch High Exchange encryption key fetch failed

License Critical License is invalid

License High License expired

License High License expiration is approaching

License High License Error

License High Using a demo license

License High License Refresh required

MDE Critical MDE is not initialized

MDE High MDE is running more than a day old signatures

MDE High Cannot initialize MDE

MDE Updater Medium MDE Update failed

Metadata High Could not connect to the Collector

Process Monitor Critical Cannot start a process

Sniffer Critical Direct sensor requires border definition to be


operational

Sniffer Critical Bandwidth usage exceeded

Sniffer Critical Incompatible interface settings.

Sniffer Critical Interface is in bypass mode.

Sniffer High Abnormal packets processing rate

Fidelis XPS User Guide 22


Component Severity Status Message

Sniffer High Network data processing errors

Spooler Critical Cannot start spool writers

Spooler Critical Dropped spool file due to queue buildup. See log
for details

Spooler Critical Skipped spool file due to queue buildup. See log
for details

Spooler Critical Low disk space. Spooling stopped. See log for
details

Spooler High Rate of logging too high, spooler cannot keep up.
See log for details

System Monitor Critical Disk is out of space.

System Monitor Critical WARNING system processing issues seem


persistent, attempting soft reset.

System Monitor High Disk space is low.

System Monitor High WARNING system is restarting.

Database Encryption Status


The Database Encrypted icon displays if Alert Storage is enabled at CommandPost. Refer to
Alert Storage.

Logout
To securely log out of CommandPost, click the logout link at the top of the page. Logging out will
end your browser session to CommandPost.

To securely log out of CommandPost, click to log out. Logging out will end your browser
session to CommandPost.
Note: If inactive for 15 minutes, CommandPost will log you out. The 15 minute value
can be changed at Session Timeout.

Using Non-ASCII Characters in Fidelis XPS


Fidelis XPS supports the use of non-ASCII characters in most input [Link] fields that do not
allow Unicode are: email addresses, host names, domain names, login names, and server directory
names. CommandPost user names and passwords also do not support Unicode characters.

Fidelis XPS User Guide 23


Chapter 2 Dashboard
The Dashboard contains multiple widgets that enable you to graphically analyze what is happening
on your Fidelis XPS sensors, CommandPosts, and Collectors. The first time you open the
Dashboard, the default Overview tab displays. You can customize the Overview tab by adding,
moving, and resizing widgets. You can add tabs and place any number of widgets within your tabs.
Click the empty tab on the right to add a tab. Type a name for the tab and press Enter. The tab is
saved under this name. Double click on the tab name to change it.

Click the empty tab on the right to add a tab. Type a name for the tab and press Enter. The
tab is saved under this name. Double click the tab name to change it.

Click to access Dashboard icons, click

to view the Dashboard in full screen mode. In this mode, all browser controls are removed.
Full screen mode is appropriate for display on a large monitor used for constant information display
of Fidelis XPS operations. Press ESC to exit full screen mode.

to add a widget. A list of available widgets will appear after you click. The list displays with an
example and description of each available widget.

Click or to navigate through the available widgets. Click Add at the desired
widget to add it to the Dashboard. Click X at the list of widgets to remove the list. The list of
available widgets depends on your role, therefore not all widgets are available to all users.
To remove a widget from the dashboard, click the X at the top right of the widget's title bar.

to reset the Dashboard to the default Overview layout. Click Reset at the confirmation dialog
box.
The Dashboard is specific to each user. Changes made to your Dashboard will not affect the
Dashboard of any other CommandPost user.

T a bl e 2. Us e r P e r mi ss i o n s f or D a s h b o ar d Wi d g e ts
Each user role is defined by a set of permissions. The available widgets depend upon the View
access to the permissions listed below.
Refer to Define User Roles for more information.

Dashboard Widget Permissions

Custom Alerts Widget Alerts and Reports


Custom Metadata Metadata and Reports
Widget

Globe Alerts and Details

World Map Alerts and Details

System Status None required

System Totals None required

Radar Alerts

Application Protocol Sensor Admin


Trends

Fidelis XPS User Guide 24


Dashboard Widget Permissions

Network Statistics Sensor Admin

Alert Insertion Rate Sensor Admin

Collector Metadata Sensor Admin

Top Alert (or Malware) Alerts


Hosts
Top Alert (or Malware) Alerts
Sources

Alert Trend Alerts

Malware Trend Alerts

Disk Space None required

Collector Disk Space Sensor Admin

Widget Controls
Each widget offers controls to change the behavior of the widget. The controls available vary
depending on the widget.

Click in the title bar of the widget to expand the widget. When expanded the chosen widget
will occupy the entire dashboard space.

Click to return the widget to the original size and return all other widgets to the dashboard.

Click to start auto refresh. The frequency of the auto refresh differs per widget. By default, all
widgets begin in an auto refresh state. Widgets also refresh automatically within 2 to 5 minutes
depending on the duration time selected for the widget. If the selected Duration is hours, refresh
will occur approximately every 2 minutes. If the selected Duration is days, refresh will occur
approximately every 5 or more minutes.

Click to stop auto refresh. After stopping and starting data refresh, an immediate update
request will be sent to the server to refresh the data.
Click to retrieve the latest data for a widget. Move your mouse over to see the last time data
was updated.
Select a time frame: Click and select a time frame from 1 minute up to 30 days.
Select a CommandPost: If your environment uses hierarchical CommandPosts, you can access
data from Subordinate CommandPosts from the Master. Click and select a
CommandPost.
Select a Collector: Click and select a new Collector, if available.
Slider bar: Many widgets include a slider bar along the top or right side of the widget. This bar can
be used to zoom in or out of the data displayed. Click if available, to expand the widget to show
all data.

Fidelis XPS User Guide 25


Custom Alerts Widget
The Custom Alerts widget enables you to extract and display System, Custom, and Alert reports.
You can select from a list of all public and any private Saved reports, alert reports, and system
reports to which you have access -- the same list that appears at Reports>Saved Reports. The
Dashboard checkbox must be selected for a report to be available at the Custom Alerts widget.
Refer to Saved Reports.
A default time value such as customized duration displays for the time selection until you change it.
This time value is the original time range or value selected at the Alert or Reports pages. You can
use the default value or select another value by choosing a time from a number of hours through 90
days. You selection is used to extract information for the widget and is not saved in the report or at
the widget. You will see all alerts that occurred during the selected time period.

1. Click to access the edit popup. At the pop up, you can select a report, graph type, and
trending.

2. Select a report for the Custom Alerts widget.

Note: If the button is active, the data in the report will not change if a new report is
closed. Click to stop refresh before changing the report.
Reports that contain group by information can display information either by groups or by trending
date. Reports without group by, can only display trending information.
For group by reports:
You can click the Trending checkbox to display trending information in the main chart. The legend
to the right of the chart displays group information. Uncheck the Trending checkbox to display
information by group, summarized by the selected time period.
For all other reports:
The Trending checkbox is selected by default and is greyed out.
3. Select the graph type: either Bar or Line chart. This is how your results will display in the
widget even if another view such as pie chart was originally selected for the report. If the
report returns no alerts, you will see a message stating: No results found. If more alerts are
found during a refresh, the count increases.
4. Either enable or disable trending. Trending enables you to see alerts over time.
5. Click Apply. The edit pop up goes away and your results display based on any selections
you made in the pop up. Clicking Cancel closes the pop up without applying your
selections.
You can mouse over a bar or line point to view a pop up that lists the information by group or by
date. If ellipses (...) display, this indicates that more information is available than what can be
displayed in the pop up. You can use the slider bar to see another portion of the graph.

Fidelis XPS User Guide 26


If the report includes group by and trending information, column labels appear on the right. You can
hide data in the chart by clicking on a column name to select or deselect.
To access more information, click a bar or portion of the line to go to the Alert List page to view a
list of alerts represented by that portion of the bar or line chart. For example, if you click on the
portion of the chart representing the HTTP protocol, a page displays with alerts that have HTTP
protocol violations. At the Alert List page you can then access Alert Details for individual alerts.
Click the link: Run saved alerts report to run the report and view the results in the Alerts List page.
Click the link: Edit saved alerts report to change criteria at the Create Custom Reports page. Refer
to Custom Reports.

Custom Metadata Widget


The Custom Metadata Widget enables you to extract and display filters created and saved at the
Metadata>Explore page.
The report default displays for the time selection until you change it. This time value is the original
time range or value selected at the Metadata>Explore page. You can use the default value or
select another value by choosing a time from a number of hours through 90 days. Your selection is
used to extract information for the widget and is not saved in the report or at the widget. You will
see all metadata transactions that occurred during the selected time period.

1. Click to access the edit popup. At the pop up, you can select a metadata report, and
graph type. You can also select how to group metadata and select trending.

2. Select a saved Metadata report. Note: If the button is active, the data in the report
will not change if a new report is closed. Click to stop refresh before changing
the report.
3. Select the graph type: either Bar or Line chart to determine how your results display in the
widget
4. Enable or disable Group by. Enabling Group by displays the Column drop down so that you
can select columns to group your results.
5. Select Group by columns. Refer to Metadata>Explore for descriptions of columns.
Metadata results display by column. Column labels list on the right of the chart. You can
change how the chart looks by clicking on a column name to select or deselect.

Fidelis XPS User Guide 27


6. Enable or disable trending. Trending enables you to see metadata transactions over time.
7. Click Apply. The edit pop up goes away and your results display based on any selections
you made in the pop up. Clicking Cancel closes the pop up without applying your
selections.
You can mouse over a bar or line point to view a pop up that lists information.
To access more information, click a bar or portion of the line to go to the Metadata>Explore page to
view a tabular list of transactions represented by that portion of the bar or line chart. For example, if
you click on the portion of the chart representing the HTTP protocol, a page displays with metadata
transactions that have HTTP protocol violations. At the Metadata>Explore page you can then
access Metadata Details to view more information about the transactions and their sessions.
Click the link: Run/Edit saved metadata report to run the report and view he results at
Metadata>Explore. You can also edit the filter values to change the report.

Globe
The Globe widget shows incoming alerts as they arrive and alert activity for the last hour displayed
by shades of colors for countries.
Alerts are shown as they arrive with their source or destination country including any custom GeoIP
information. The globe will spin to show the country of each alert as it arrives. Clicking the alert ID
takes you to the Alert Detail page for that alert. If an alert is malware related, the icon displays
next to alert severity on the globe. Small countries that are not visible on the globe are represented
as large dots. After pausing and resuming data refresh, an immediate update request will be sent to
the server.
Note: If the source or destination country is not available for an alert, then Unknown
is listed as the source or destination and will be placed in the middle of the Atlantic
ocean. This often occurs if the alert is from an internal network. To fix this, access
CommandPost>Config>GeoIP and set internal IP address ranges and assign a flag.
Refer to Custom GeoIP.

World Map
The World Map widget displays alerts and enables you to view an Alert List based on country
source and destination. You can zoom in to focus on a specific area or zoom out. You can select a
time frame at the drop down.
Moving your mouse over a country highlights the country and shows the total number of alerts for
the selected time period and the total number of alerts for source and destination.

A pie chart shows the distribution of alert severity levels.


Click on a country to run an alert search with the selected country being the source or the
destination of alerts for the selected time frame.
Arrows show alert volume between two countries, pointing from the source to the destination.
Arrows are placed on the map in order based on alert severity with arrows indicating alerts with
higher severity on top. The color of the line and the arrow show the highest severity alert for the
time frame. Arrow width indicates the alert volume compared to other country pairs: the thicker the
arrow, the more volume between the two countries.
Moving your mouse over a line highlights the line and displays a popup that indicates the direction
of the transmission that caused the alerts with a .

Fidelis XPS User Guide 28


Click a line to run an alert search with the selected countries being the source and destination
countries of alerts for the selected time frame.
Pins indicate location. Arrows emanating from or going to a pin indicate the direction of data
from or to that location. Pins take on the color of their respective arrows and are not clickable. If a
country map contains a pin but no arrows this indicates that the source and destination for all alerts
are within that country.
Note: If the source or destination country is not available for an alert, then Unknown
is listed as the source or destination and will be placed in the middle of the Atlantic
ocean. This often occurs if the alert is from an internal network. To fix this, access
CommandPost>Config>GeoIP and set internal IP address ranges and assign a flag.
Refer to Custom GeoIP.

Radar
The Radar widget graphically represents alerts occurring on your network, grouped by common
characteristics into an alert cluster. Clusters are a visual presentation of similar alerts. When
creating a cluster, CommandPost considers the sender and receiver of the information transfer, the
time of the transfer, the sensor on which the alert was detected, the rule violated, and the priority of
an alert.
CommandPost creates clusters based on similar information, but not necessarily equivalent or
related information. For example, alerts with similar, but not equal, source IP addresses may be
grouped in a single cluster, which may be indicative of a problem generated by a location rather
than an individual. Also, alerts from a similar time period during normal working hours may be
grouped together while others occurring during non-working hours may be grouped into a different
cluster.
A cluster is represented by a dot or a line on the alert radar. A dot appearing in the center of the
radar is the most recent alert in CommandPost. Over time, the dot will migrate toward the outer
edges of the [Link] line represents a cluster that contains several alerts over time. The line
connects the oldest and most recent alerts within the cluster. A dot represents a single alert or
several alerts that were detected at the same time.
The clusters are intended as a visual representation of alert activity and are not necessarily
presented in the best form for investigation into network behavior. The radar widget refreshes with
new data periodically. The refresh cannot be disabled for this widget
The cluster details portion of the widget is relative to your mouse position
on the widget. As you move your move over the radar, a portion of the
radar will be highlighted in grey. The Cluster details will reflect the time
range and the number of clusters per severity within the scope of your
mouse.

3
Clicking on an alert cluster takes you to the Alert List for that cluster.

3
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 29
Top Alert (or Malware) Hosts
The Top Alert Hosts widget displays an interactive bar chart for alerts grouped by host IP address.
The Top Malware Hosts displays an interactive bar chart for alerts with malware grouped by host IP
address. You can select a time frame at the drop down.

Top Alert (or Malware) Sources


The Top Alert Sources widget displays an interactive bar chart for alerts grouped by source IP
address. The Top Malware Sources widget displays an interactive bar chart for alerts with malware
grouped by source IP address. You can select a time frame at the drop down.

Alert Trend
The Alert Trend widget displays an interactive stacked bar chart that shows alerts grouped by
severity and date for the selected time [Link] can select a time frame at the drop down.
Moving your mouse over the chart displays the number of alerts by severity level for that date. You
can move the slider bars to select a time period. Below the graph you can click a severity to
remove it from the chart. Click it again to add it.

Malware Trend
The Malware Trend widget displays an interactive line chart that shows malware grouped by
malware type and date for the selected time period. You can select a time frame at the drop-down.
Malware trends display by date and counts are shown by malware type. Moving your mouse over
the chart displays the number of malware by malware type for that date. You can move the slider
bars to select a time period. Below the graph you can click a malware type to remove it from the
chart. Click it again to add it.

Application Protocol Trends


Application Protocol Trends shows sessions per minute by protocol, [Link] protocols
detected in alert data within the selected time frame display.
Only protocols with at least one data point with a session rate above zero will display.
Note that statistics are collected at 5 minute time intervals and rare occurrences of a
protocol that translates to session rates below 1 per minute may result in the
protocol being absent in the graph.
The Application Protocol Trends widget provides an interactive graph that you can use to closely
examine what is occurring on your network at specific times. The data represents the sum of all
sensors registered to the selected CommandPost. You can select a time frame at the drop down.
You can highlight an area of activity to expand that portion of the report, mouse over a line to see
what occurred at that point, or use the slider bar to zoom into or out of the graph. Refer to Network
Reports for more details on using the performance graph and the slider bar.

System Status
The System Status widget displays the total number of alerts per CommandPost, sensor, and
Collector. The component list and numbers represent only those alerts the user is permitted to see
based on the user’s role, alert management group assignments, and sensor assignments. Refer to
Define User Profiles.
If you are logged into a Master CommandPost, system status will display also all Subordinate
CommandPosts and all components registered to each Subordinate CommandPost.
Hold your cursor over the green, yellow, or red diamond to see useful information about a
component: for example, if a license is expiring, if the sensor needs updating, or if the sensor is

Fidelis XPS User Guide 30


experiencing traffic problems. Refer to System Status for explanations of conditions with critical and
high severity.

System Totals
The System Totals widget provides the total number of sensors, secondary sensors, Collectors,
and CommandPosts, added to the CommandPost. This widget also shows the total alert count --
regardless of user permissions.

Network Statistics
The Network Statistics widget displays Kbits per second by transport protocol, [Link] can
select a time frame at the drop down.
The Network Statistics widget provides an interactive graph that you can use to closely examine
what is occurring on your network at specific times. The data represents the sum of all sensors
registered to the selected CommandPost. You can highlight an area of activity to expand that
portion of the report, mouse over a line to see what occurred at that point, or use the slider bar to
zoom into or out of the graph. Refer to Network Reports for more details on using the performance
graph and the slider bar.

Alert Insertion Rate


The Alert Insertion Rate widget displays alerts per minute inserted to the selected
[Link] can select a time frame at the drop down.
The Alert Insertion Rate widget provides an interactive graph that you can use to closely examine
what is occurring on your Fidelis XPS sensors and CommandPost at specific times. You can
highlight an area of activity to expand that portion of the report, mouse over a line to see what
occurred at that point, or use the slider bar to see another portion of the graph.
Refer to Network Reports for more details on using the performance graph and the slider bar.

Disk Space
The Disk Space widget displays the total disk space, high water mark, and current used disk space
for CommandPost.
Disk space utilization depends on the alert rate and the alert retention settings at the
CommandPost configuration page for Alert Retention. CommandPost will delete alerts when
necessary to avoid filling the disk.

Collector Disk Space


The Collector Disk Space widget displays the total disk space, high water mark, and current used
disk space for the Collector.
Disk space utilization depends on the Collector type, the data rate, and the Collector data settings
at the Collector configuration page. The Collector will delete data when necessary to avoid filling
the disk. After Collector has been active for some time, it is common to see the disk space nearly
full all of the time.

Collector Metadata
The Collector Metadata widget displays an interactive bar chart that shows the total amount of
metadata in GBytes stored by the selected Collector.
Daily storage is displayed in GBytes for each day that data is available on the Collector. The
current day's storage data refreshes periodically. Moving your mouse over a bar displays the exact
amount of data stored for a specific day. Each bar is labeled with the date in the year-month-day
format. Fidelis XPS Collector storage can be configured for managing the oldest data. Refer to
Configure Collector. The Total Collector Metadata graph provides a view of the oldest data
currently stored by Collector as well as an indication of daily traffic rates.

Fidelis XPS User Guide 31


Chapter 3 Understand and Manage Alert
Workflows
4
From the Alert List or the Quarantine pages, you can assign, monitor, and manage alerts and
quarantined email.
This chapter covers the following topics:

• Access to Alerts and Quarantined email

• Assign a New Alert

• Manage an Alert

• Manage Multiple Alerts

Access to Alerts and Quarantined Emails


The Alert List page provides a list of all alerts accessible to the user. Accessibility to this
information is determined by the CommandPost user’s role, sensor assignments, and alert
management group assignments.
Refer to Access Control in CommandPost for details on assigned sensors, alert management
groups, and how these affect users. Refer to chapter 9 in the Guide to Creating Policies for details
on assigning policies and rules to sensors and to alert management groups.
Users with full access to the Alert function may:

• Read and examine the details of an alert, including the original transmission that caused the
violation.

• Export summary alert information to Microsoft Excel or any other application that accepts tab-
separated files.
• Purge alerts.
Users with full access to the Quarantine function may:

• Read and examine the details of every quarantined email, including the original email that
caused the quarantine.

• Deliver email from quarantine, sending it to its original recipient.


• Discard email from quarantine, removing it from the quarantine queue without delivery.
Users with full access to the ticket system may also:

• Assign alert tickets to another user with access to the alert.

• Close an alert ticket, providing a ticket resolution.

• Move an alert from its current alert management group to another. This action makes the alert
accessible to another group of users.
• Add comments to the alert workflow log.

4
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 32
Handle Alerts
To find all alerts currently assigned to you, use the My Alerts view on the Alert List page. Refer to
System Reports for Alerts.
To find all alerts owned by a specific user:
1. Click Search.
2. Enter the user name in the Search for text box.
3. Select Owner and click Go.
To find all unassigned alerts:
1. Click Search
2. Enter unassigned in the Search for text box.
3. Select Owner and click Go.

The Alert Workflow Log


Every alert has an associated alert ticket that can be referenced in the alert workflow. New alerts
5
are not assigned to an owner. A user with ticketing privileges and access to the alert may open,
close, and assign an alert. Alert Workflow Management includes:

• Assign one or more alerts to another user with access to the sensors that generated the alerts
and have access to the alert management group(s) to which these alerts belong. When an
alert is assigned, an email is sent to the new alert owner.

• Close an alert. You can close an alert and select Allowed, Action taken, No action taken, or
False positive. This action may be performed by anyone with access to the alert. When the
alert is closed, a resolution is entered to the alert workflow log.

• Add comments to the ticket log.

• Change Management Group will make the alert accessible to a different group of users. When
the group is changed, an email is sent to the group mailing list, to make members of the new
group aware of the alert.
The workflow can be accessed from the Alert Details page of any alert. You may also change the
workflow for multiple alerts by choosing Change Ticket Status or Change Management Group from
the Actions button on the Alert list page.
For any workflow action, the alert manager has the option to fill out the Subject and Comment fields
which will be added to the alert workflow log. The alert workflow log will display the full history of
the alert with all comments as it changes from group to group, owner to owner, and finally to a
closed state.
When the ticket is assigned, the subject and comment information will be included in the body of an
email sent to the newly assigned user. When the management group is changed, the subject and
comment information will be included in the body of an email sent to the address associated with
the newly assigned group.
The same options are available in the Quarantine and Quarantine Details pages; however, the alert
workflow log only applies to alerts – not to quarantined email. When managing alerts from the
Quarantine Details page, the action will apply to all alerts associated with the email. When
managing alerts from the Quarantine page, the action will apply to all alerts associated with all
selected quarantined email messages.
If you have a hierarchical environment with Master and Subordinate CommandPosts, the
following applies:
If you are working from the Master CommandPost Alert List page, then the users and management
groups available will only be those available to the Master CommandPost.

5
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 33
If you are working from the Master CommandPost and access the Alert Details page of an alert
from a Subordinate CommandPost, then the users and management groups available to you will be
from the Subordinate CommandPost.

Manage a Single Alert


6 7
You can manage an Alert at the Alert Workflow Log section of the Alert Details page. You can
8
access this page by clicking next to an alert at the Alert List page or from the Quarantine
Management page. This functionality enables users with ticketing privileges to do the following:

Change Status
• Enter a Subject or Comment.

• Click Assign to and select a user from the list to assign the alert. The list of users includes
those with access to the sensor that generated the alert and have access to the alert
management group to which the alert belongs. After you submit the change, the selected user
receives an email reflecting the assignment.

• Click Add comment to add comments to the ticket log without changing the ticket status or
ownership. After you submit the change, information entered in the Subject and Comment text
boxes will be appended to the comment.

• Click Close as and select a reason from the list. Your options are Allowed, Action taken, No
action taken, and False positive. The alert is closed.
Note: Closing an alert marks you as the owner of the alert.

Change Alert Group


Click Change Group to: and select the alert management group for the alert at the dialog box. If
you do not belong to the selected group, you will not have access to the alert after clicking Submit.
Note: Changing the alert management group, removes the assigned owner and
changes the status to new.

Manage Multiple Alerts


9
Multiple alerts can be managed from the Alert List and Quarantine pages by using checkboxes
and the Actions list at the top of the Alerts List.
To manage multiple alerts from both pages:
1. Select one or more alerts or one or more quarantine emails.
To select all alerts or emails on the page, click the checkbox at the top of the page.
2. Select a management option from the Actions list. The dialog box that displays depends on
the option selected.
3. Enter changes into the dialog box and click Submit.

6
An alert is the recorded and displayed incidence of at least one event.
7
Alert Details is the most granular level for examining alert data.
8
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
9
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 34
T a bl e 3. A c ti o ns l i st o pti o ns
You can access these options from the Alert List and Quarantine Management pages.

Management Description
option

Change Status Assign, Close, or add comments to the selected alert


tickets.

Change Changes the management group associated with


Management selected alerts. Enter a subject or a comment if desired.
Group

Note: From the Alert List you can also apply labels, purge, and export selected alerts.
These functions do not impact the ticketing system and are described in Understand
and Manage Alerts.
From the Quarantine Management page you can discard or deliver selected quarantine
emails. Refer to Deliver or Discard Quarantine Email.

Fidelis XPS User Guide 35


Chapter 4 List: Understand and Manage Alerts
Alerts>List displays a list of all alerts accessible to you. You can filter which alerts display, search
for specific alert attributes, and research details about alerts.
With ticketing privileges, you can also assign or close alerts. Refer to The Alert Workflow Log.
This chapter covers the following topics:

• Alert List
• Navigate Alert Pages

• Select Alert Actions


• Alerts Report Page Controls
• Alert Details
10
To access the Alert List, click Alerts>List or click an alert cluster in the Radar page. The first time
you access it, the Default Report displays. You can change the report to another system report or
to a Custom Report that you create. The last report that you view will be restored on your next
access.
When you access Alerts by clicking an alert cluster on the Radar page, you will see your last saved
report, filtered by the cluster that you selected.

Figure 8. Alert List


The Alert List contains the following major elements:

• Alert List—a list of all alerts displayed according to the selected report and any actions taken
at the Alert page.
• Page Navigation
• Actions—Enables you to take action on selected alerts.
• Alert List controls—Enables you to search, group, change the display settings of the page,
and retrieve a custom report. Click in the upper right corner of the Alert page to show or
hide the controls.

10
CommandPost groups related network alerts into an alert cluster. Clusters are a visual
presentation of similar alerts. When creating a cluster, CommandPost considers the sender and
receiver of the information transfer, the time of the transfer, the sensor on which the alert was
detected, the rule violated, and the priority of an alert. CommandPost creates clusters based on
similar information, but not necessarily equivalent or related information. For example, alerts with
similar, but not equal, source IP addresses may be grouped in a single cluster, which may be
indicative of a problem generated by a location rather than an individual.
Fidelis XPS User Guide 36
Click above the list to access the Investigator. Refer to Investigator.

Alert List
11
An Alert List is created from all alerts available within your assigned groups and sensors. The list
can be greatly customized by choosing the columns to display, by reducing the alerts to those that
match specified criteria, by summarizing, and by choosing to display the results in a chart or as a
table.
In all cases, the list is highly interactive. Rows in a table and sections in a graph can be clicked to
obtain further information; specific details of any alert can be obtained; actions can be taken on
single alerts or groups of alerts; and alerts can be purged.
Selecting a list restores settings for that report, including:

• The columns available in your list represent summaries of alert attributes. Primary columns
are shown on your report. Secondary columns become available when you click on a row
within the list to view the quick summary of the alert. For attributes that contain large amounts
of data, the list column may be truncated.
• Data criteria including Searches, Filters, and Time Selections. These serve to reduce the
number of alerts in the list.
• Grouping and sorting of the list. Alerts can be grouped by any one or multiple primary
columns to produce a summary of the data. Sorting can be applied to any primary column
whether grouped or not.
• The list results can be displayed as a chart or table. Charts are available only for grouped
lists.
• A trending chart can be saved with any type of list. The trending chart will show alerts per time
above the report.
After running a report, you can use the controls on the Alert List to further manipulate the
information. When you make changes, you are changing the list into an Unnamed Report. By
clicking Customize list you can save this new list with your new settings. Alternatively, you can use
the Unnamed list to analyze and drill down into your information as you would any other report.
The time required to generate a list is greatly influenced by the Time Selection. Reports based on
Insert time using a short timeframe will be optimal. Reports based on selecting all alerts or based
on the recorded alert time may run substantially slower, depending on the total number of alerts
stored on CommandPost.

Alert Quick Summary


Click a row on the Alert List to display a Quick Summary, which provides the information associated
with the columns in the secondary row of your report.

12
At the Quick Summary, you can click to view the Alert Details page for the selected alert.
You can also choose to filter alerts based on the value of the available information.
Many of the items that display in the Quick Summary are clickable. Clicking one of these items
takes you to the configuration page for that item where you can view more information or make
changes. For example, clicking a sensor name at Quick Summary takes you to the Sensor page.
You can see details for that sensor, and if needed make changes. Clickable items include Policy,
Rule, Sensor, and Alert Management Group. Some items might not be clickable based on your
role. Refer to Roles.
The Quick Summary of an alert shown below is from the Alert List.

11
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
12
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 37
Figure 9. Alert Report: Quick Summary

Note: If you have a hierarchical environment with Master and Subordinate


CommandPosts, the following applies:

Hierarchical Envi ronments


If you have a hierarchical environment with Master and Subordinate CommandPosts, the following
applies.
Operating from the Master CommandPost:
If an alert is from a Subordinate CommandPost, clicking the links within Quick Summary tells
CommandPost to check the Master CommandPost to see if the Master has the same rule, policy,
user, or alert management group. If the policy, rule, user, or group is the same on the Master and
on the Subordinate CommandPosts, a pop up displays that enables you to select either
Subordinate or Master. If the information differs, the pop up displays, but you can only select
Subordinate. If you select Subordinate, you will be directed to the login page of the Subordinate
CommandPost if you do not have an active session to the Subordinate CommandPost.
Operating from a Subordinate CommandPost:
If you log into a Subordinate CommandPost, you can only access alerts from sensors registered to
that Subordinate CommandPost. You will not have access to alerts from another CommandPost.

Filter Alerts
You can filter alerts by selecting items at the Quick Summary page. Filters are used to reduce the
list to only those alerts that match your filter criteria. For example, you can choose to filter by
Protocol = HTTP, the result will be a list of all alerts from the HTTP protocol. This list would not
include alerts from any other protocol.
To set a filter:
1. Click the check box next to one or more values in the Quick Summary page.
2. Click Filter.
3. CommandPost finds all alerts that exactly match the filtered value and display only these
alerts.

Figure 10. Filtered alerts

Fidelis XPS User Guide 38


When a filter is applied, the following occurs:

• If you selected multiple fields, all are applied to the filter. The more filters that you select, the
more narrow your results.

• The applied filters display above the table.


• The [x] next to the value in the filter list allows you to remove the filter.
Filtering performance is typically fast when filtering on one column, but can degrade as more filters
are applied.

Navigate Alert Pages


13
Because CommandPost may contain thousands or millions of alerts, the Alert List is presented
in pages. Each page initially contains 25 rows of alerts. You can change the number of rows per
page by entering the new amount in the text box at the bottom of the page. This value will be stored
as your new default page size.
Up to 10 page numbers display at the top and at the bottom of each page. Clicking a page number
takes you to that page. Click the < or > arrow buttons to move to the next page in either direction.
Click << or >> to advance to the first or last page. These buttons may be disabled when you are
currently at the beginning or the end of the alert report.

If one or more Subordinate CommandPosts are selected at the Alert List, navigation changes for
the Alert List. You can click the < or > arrow buttons to move to the next page in either direction.

Other navigation options such as clicking on individual page numbers or clicking << or >> to
advance to the first or last page are not available.

13
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 39
Alert Actions
14
Click the check box next to one or more alerts to select them. Clicking the check box at the top of
15
the Alert List page selects (or deselects) all alerts on the current page.

Figure 11. Alert actions


The following actions may be taken on selected alerts from a CommandPost:

• Change Ticket Status. Refer to The Alert Workflow Log.

• Change Management Group. Refer to The Alert Workflow Log.

• Change Label. Refer to Alert Labels.

• Export to Microsoft Excel, Evidence Package, zipped PDF, or zipped text. Refer to Export
Actions.

• Purge Alerts from the CommandPost database. Refer to Purge Alerts.


• Evidence Package. Refer to Evidence Package in Alert Details.

Alert Labels
Labels are tags that a CommandPost user can apply to an alert. By using labels, you can
categorize alerts into meaningful names for your enterprise. You can later search or filter by label to
retrieve alerts that contain your label.
Labels can be applied from the Alert List page or from the Alert Details page. From the Alert List
page you can select multiple alerts and apply the same label to each.
To apply a label from the Alert List page:
1. Click the checkbox next to the alert or alerts that you wish to label.
2. From the Actions list, select Change Label. The Change Label dialog box displays where you
can select an existing label or create a new one.
3. The Existing Labels text box lists all previously used labels. You may choose a label from this
list and click Apply Label.

14
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
15
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 40
4. If you wish to create a new label, type it into the New Label text box and click Apply Label.
You can also click to add the new label without applying it.
To remove a label from an alert: You can choose a new label using the steps above and overwrite
the label with the new label. To clear the label for all selected alerts, click Clear Label.
To remove a label that is no longer required: Select the label in the Existing Labels text box and
click . Labels can only be removed if there are no alerts that use the label.
If you are working in a hierarchical environment, the following applies:
When working from the Master CommandPost, the list of available labels will only include those
that have been previously applied from the Master. Any label that was applied to an alert by logging
into a Subordinate CommandPost will only be available by logging into the Subordinate
CommandPost.

Export Actions

Click at Alert Actions and the Export options will display.

Figure 12. Alert Actions: Export options

To Excel
Export selected alerts to Excel (or other application) that can accept a tab-separated file.

Figure 13. Export Alerts


1. Select criteria for the export file: You can choose alerts previously selected on the Alert List
page, specify a number of alerts, or all the alerts in the list.

Fidelis XPS User Guide 41


CommandPost limits number of rows that are included to 100,000. Users should also
understand limitations of their version of Excel (or other spread sheet applications) that may
require the reports to be limited using the options provided.
2. Click to compress the exported file, if desired.
Note: Large numbers of alerts can result in a large file. Using compression will
reduce download time.
3. Click Customize export columns to choose the columns to output, if desired. If you do not
select export columns, columns in the export file will be the same as the primary and
secondary rows in the Alert List. Refer to Columns in Create Custom Reports for more
information about column choices. If selected, the column item Alert Details Link lists the
URL for the alert details of each alert.
4. Click Export to Excel. You can choose to open or save the file.
If alerts are grouped, the dialog box changes to enable you to select groups.
Select Criteria, Data, File, and Column options to export groups of alerts. If you select the option:
Include alerts belonging to groups in export, alerts are included in the export and are listed by
group. If you do not select this data option, then only the group summary information is exported.

Figure 14. Export Grouped Alerts

Evidence Package
Evidence Package gathers selected alerts and their associated files and into one compressed tar
(.tgz) or zip file. Refer to Evidence Package for details.

Alert Details PDF


Click Alert Details PDF (Zipped) to create a zip file that contains PDF files of alert details for each
selected alert.

Customi zed Alert Details


Click Customized Alert Details (Zipped) to select Alert Details sections and to customize and email
the PDF report. This creates a zip file that contains a PDF report of alert details for each selected
alert up to 50.
Select the Text tab to choose sections for the text file or to send it via email.
Refer to Customize the PDF for Alert Details.

Fidelis XPS User Guide 42


Alert Details Text
Click Alert Details Text (zipped) to create a zip file that contains a text file of alert details for each
selected alert up to 50.

Purge Alerts
Purge Alerts removes selected alerts from CommandPost. Once a purge starts, you can perform
other actions at the CommandPost, but you cannot start another purge.
1. Click Purge Alerts.
2. Click Ok at the confirmation dialog box. Alert purge will permanently remove the selected
alerts and all associated information about the selected alerts. This operation cannot be
undone.

Alert List Page Controls


The Alert List page contains several options to modify Alert Lists, drill down into alert details, and
manipulate the presentation of alerts to facilitate investigations. The controls are located at the top
of the page. Click in the upper right corner of the Alert List page to open the control section. Click
to hide the controls.
Within this section the following controls are available:

• Report—Enables you to select a report from the drop-down list. All other functions available
on the Alert List are based on this initial setting. You may choose from multiple system reports
plus any report that you create and save.
• Search—Enables you to reduce an Alert List to alerts that match your search criteria.
Searches are performed as case-insensitive partial string matches, whereas Filters are
performed as exact matches. Refer to Search for Alerts. The Search dialog box also contains
the CommandPost, Time Range, and Group By sections.
CommandPost—If available, this section enables you to select one or more Subordinate
CommandPosts. Refer to Select CommandPosts.
Time Range—This section enables you to reduce an Alert List to alerts that occurred during a
specified time period. Refer to Time Range.
Group By—This section enables you to summarize alerts by selected columns. The result will
display the selected columns and the number of alerts that match each available value within
those columns. Grouped information can be displayed in a table or graph form. Refer to
Group By.
• Filtered By—Displays what you have selected at Search or at Quick Summary to filter alerts.
Refer to Filter Alerts. Click an x to delete a filter.

• Refresh—Refreshes the Alert List [Link] can also specify auto refresh. Mouse over
the button. The Refresh select box displays.

Click the checkbox next to Refresh and enter a time period. The Alert List automatically
refreshes for the time period specified.
New incoming alerts display when the Alert List is refreshed. The time stamp next to Last
Search Results updates to reflect the last time that the Alert List page was refreshed.
The Alert List also refreshes whenever you conduct a search, group alerts, or run a report.
Accessing Alert Details or the Quick Summary for an alert, then returning to the alert list will
not refresh the list if not selected.

Fidelis XPS User Guide 43


• PDF—Enables you to save the alert report as a PDF document, customize it, or email it.
The generated PDF will include all elements on the current page of your Alert Report. Refer to
Create PDF Reports for Alerts.

• Trending—Enables you to view and control alert trend charts. Refer to Trending.

• Fixed (Relax) Columns—When the report contains many columns, you can select Fixed
Columns to resize columns to better fit within your page size, truncating some of the data in
the columns and replacing it with ellipses. Mouse over the ellipses to view the hidden
information. Relax Columns displays all information in each column which may require
horizontal scrolling in your browser window to view all information.

System Reports for Alerts


System Reports are a built into CommandPost and available to all users whose role provides
access to the Alerts. All system reports use a Time Range of 24 hours to optimize
[Link] system reports are available:

T a bl e 4. Sys t em R e p or ts

Report Description

Default Report The default report provides crucial alert information that will be useful to most
users. This report will display all alerts sorted by Alert ID.

Alert The alert management report provides a summary of alert tickets and their
Management status. This report is most useful to alert managers who fully use the
Report CommandPost ticketing system. This report will display all alerts sorted by
Alert ID and lists the owner and the alert management group associated with
each alert. This report is only available to users whose role provides access to
tickets.
Label Report The label report displays label information in the primary rows. This enables
users to see alerts that users tagged with specific labels. This report will
display all alerts sorted by Alert ID.

Malware The malware report displays information about detected malware. The
information includes the alert severity, alert ID, time, malware name, malware
type, host IP address, network application protocol, and file format type.

Malware by The malware by host report provides a summary of all alerts grouped by the IP
Host address of the infected host machine.

Malware by The malware by type report provides a summary of all alerts grouped by the
Type malware type.
My Alerts My Alerts is identical to the Alert Management report, but includes data criteria
to reduce alerts to only those alerts assigned to the user.

Search for Alerts


16
Searching alerts can be done by entering criteria in the Search dialog box within the Alert page
controls. From the search interface you can enter search terms to be applied to any of the available
alert fields that may be searched. To search over multiple fields; however, you need to use
Customize Report .

16
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 44
17
If the alert control buttons are not visible, click in the upper right corner of the Alert List page
to display them.
Searches differ from filters in the manner that the data is matched:

• Filters use an exact match to find alerts.


• Searches use a case-insensitive, partial string match to find alerts. Refer to Alert Search
Fields.

Figure 15. Alert Search


1. Click Search within the Alert control bar.
2. Enter search terms in the Search For: text box. The search term is a simple phrase or set of
phrases to find within alert information.
3. Select a search field at the In: pull down menu.
Refer to Enter Search Terms.
If you have applied multiple search terms in a Customized Report, the option: Current Search
will appear. The Search For: text box will display Current Search and not be editable. The In:
selection will display Current Search. If you make no changes, the current search parameters
will be unchanged, enabling you to modify the time, CommandPosts, grouping, and display
options without modifying the search parameters. If you change the In: selection, you can
erase the current search with a new search term and field. To have complete control over
multiple search fields, use the Customized Report interface.
4. If desired, select one or more CommandPosts at the CommandPost section. This section is
available if you have one or more Subordinate CommandPosts registered. Refer to Select
CommandPosts.
5. Select a specific time period or enter a range at the Time Range section. Refer to Time
Range. If you do not select a time, the end date is the time the report is run and alert insert
time is used.

17
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 45
6. If desired, select one or more items in the Group By section. Group By enables you to group
alerts by information available in one or more of the primary columns of your current alert
18
page. For example, if you select protocols, alerts are grouped by protocols. Refer to Group
By.
7. If desired, you can select how the Group By results display by selecting options at the View
Results list.
8. Click Go.

Enter Search Terms


The following guidelines apply to entering search terms:

• Searching for term will match any alert containing term in the chosen field. This will match
alerts with words such as term, terminate, and exterminate.
Entering multiple words such as:
term1 term2
matches alerts containing both term1 and term2. The terms can be found in any order and
with any amount of separation between them.
• You can search on multiple Alert IDs, Threat Grid Scores, and for multiple Any, Source, or
Destination Ports by separating entries with a comma. For example, entering
AlertID1,AlertID2 would find alerts with both ID numbers.
• You can specify a range for Alert ID, Threat Grid Scores, and for multiple Any, Source, or
Destination Ports by using a hyphen.

• The use of quotes around a phrase will be treated as a single search term. The phrase "term1
term2” will match any alert containing the exact phrase within the quotes. Any spaces in the
phrase will match any space characters in the alert, including a space, a tab, a new line, etc.
Matching is done on the character boundaries, not word boundaries. Therefore, a phrase of
“top secret” will match an alert containing a phrase such as “stop secrets.”

• Multiple phrases such as a “literal phrase 1” and a “literal phrase 2” can be included in the
Find field. This will match any alerts containing all of the phrases listed.

• You can combine word-terms and phrase-terms. Any combination is allowed, such as:

“literal phrase 1” word word1 word2 “literal phrase 2”

• Matching does not consider the order of the terms, only that all are found within the search
field.
• Placing a minus sign (-) before a word or a literal phrase changes the meaning to “match all
alerts that do not contain” the specified word or phrase. Any combination of positive (no
minus) and negative (minus) terms is supported.
For example:
Top –secret matches alerts that contain the word top but do not contain the word secret.
“top secret” –confidential –personal matches alerts that contain the phrase “top secret” but
contain neither confidential nor personal.
top secret –“confidential document” matches alerts that contain the words top and secret but
do not contain the phrase “confidential document.”
- [Link] excludes the specified IP addresses [Link] from a search.
Important: the following also applies to all searches:

• All searches are case insensitive.

18
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 46
• There is a limit of 40 terms (words or literal phrases). If more terms are entered, the 41st and
beyond will be ignored.

• If Go is pressed without entering a search term, the Alerts List reappears. However, entering
unknown in the Find text box, substitutes for an empty string in the Country, Filename, From,
To, and User fields.

• Search performance is typically fast, even with very large alert databases. With a database of
over 2 million alerts, search will typically respond in a few seconds. Exceptions are searches
over Forensic Data, Session Attributes, and Owner fields, which may require considerable
time to execute.

T a bl e 5. A l e rt s e a rc h fi el d s

Alert search Description


fields

Action Search is applied over the action field.

Alert ID Enables you to search for specific alert ID numbers.

Alert Management The search is applied over the alert management group field. An alert can
Group belong to only one alert management group. If you search for multiple
groups, the search will match an alert containing any one of the groups
(most other search fields require a match of all terms). For example, a
management group search for: Group1 Group2 yields all alerts belonging to
either Group1 or Group2.

Country: Any Searches for the specified country in either the source or destination
country.
Entering two or more countries in search criteria returns all entries with any
of the countries entered. For example if you do a country search for France
Afghanistan the search will return entries that have either France or
Afghanistan.
This applies to all country searches.

Country: Searches for the specified country in the destination country.


Destination

Country: Source Searches for the specified country in the source country.

Current Search Enables you to use the simple Search interface to modify time,
CommandPosts, grouping, and display without changing search items that
were entered on the Customize Report interface.
You will see this option only when Customize Report was used to enter
search terms against multiple searchable fields. The text box will display:
Current Search and cannot be edited. If you select a different field, the text
box will become enabled and you may enter new search terms against the
selected field.

Execution Searches alerts based on their execution forensics status. You can select
Forensics Status from: Failed, Not Submitted, Pending, Received, or Rejected.

Filename Searches the name of the file that caused the violation. Will be empty if no
file was involved in the violation.
Format Type Searches for the Format Type of the content whether it is sent within a file,
in the body of an email, or in any other form.

Forensic Data The search is applied over the data field of the alert, as shown in the Alert

Fidelis XPS User Guide 47


Alert search Description
fields
19
Details page. Note that some alerts will not contain forensic data per
policy definition.

From Searches the value of the From field.

Host Activity Searches alerts for Host Activity information from Carbon Black. You can
selected Detected or Not Detected to identify alerts with or without Host
Activity data.

IP: Any Searches for any IP address: source or destination. Refer to Search IP
Addresses.
Note: Selecting IP Pair overrides Any IP and Source and Destination
IP.

IP: Destination Searches for the receiver’s IP address. Refer to Search IP Addresses.

IP Host Searches for the IP address of the host.

IP: Source Searches for the sender’s IP address. Refer to Search IP Addresses.

Label Searches for an alert label. The label search has one special feature: A
search for the term unassigned (with or without quotes) will display all alerts
that have not been assigned a label

Malware Name Searches for the malware name.

Malware Type Searches on the malware type.

MD5 Searches the MD5 hash value associated with the [Link] can enter
multiple search criteria separated with a comma.
Policy The search by policy is applied over the name of the violated policy per
alert. There are no special features for policy searches.
Port: Any Searches on any port, either source or destination.
Port: Destination Searches on the sender's port number.
Port: Source Searches on the recipient's port number.

Protocol An alert can only contain one protocol. Therefore, a search containing
multiple terms will match an alert that matches any one of the terms (most
other search fields require a match of all terms). For example, a protocol
search for: ssh http yields all alerts found over either SSH or HTTP.

Resolved IP Searches for any IP address: source or destination that matches the
Address: Any resolved DNS name. Refer to Search Resolved IP Addresses.
Resolved IP Searches for the receiver’s resolved IP address. Refer to Search Resolved
Address: IP Addresses.
Destination
Resolved IP Searches for the sender’s resolved IP address. Refer to Search Resolved
Address: Source IP Addresses.

Rule This search is applied on the Rule field.

19
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 48
Alert search Description
fields

Session Attributes This search is performed over the session attributes of the alert. Session
attributes include the Channel Attributes and the Matched On information
about the Rule Violation of alerts. The value in the Find text box will match
the name of a protocol, file format, fingerprint, or matched content.
Refer to chapter 4 in the Guide to Creating Policies for details about
protocol or file formats and their attributes.
Refer to chapter 7 in the Guide to Creating Policies for information about
rule violation data.

Subject Searches the value of the extracted Subject field.

Summary The search by summary is applied over the summary field of the alert.

Target Target refers to the destination of the information. The value is protocol
specific. Examples include the destination URL, share name, or host name.
Target is based on extracted protocol information and not based on the IP
address of the data. In many network configurations, the IP address may be
an internal address corresponding to a local NAT server or proxy, whereas
the target represents the intended destination of the data.

Threat Score Searches for alerts that match the specified threat score. Enter search
values between 0 -100. If the alert does not include execution forensics, the
value is empty.
To search for alerts with a specific score enter the value. For example, enter
4 to find alerts with a threat score of 4.
To search for alerts with a list of specific scores, enter a comma-separated
list of values. For example, enter 4,37,82,100 to find alerts with a threat
score of either 4, 37, 82, or 100. Do not enter spaces between the commas.
To search for alerts within a range of scores enter the range separated by a
hyphen. Be sure to not include spaces in your search text. For example, to
find all alerts with a score greater than 50, enter 51-100 into the search text.
To find all alerts with a threat score, enter 0-100 into the search text.

Ticket Content Searches the content of the alert ticket Subject and Comment fields. This in
the Alert Workflow Log section of the Alert Details page.

Ticket Owner An alert can belong to only one owner. However, if you enter a search with
multiple terms, the search will match an alert containing any one of the
terms (most other search fields require a match of all terms). For example,
a search for: Owner1Owner2 yields all alerts belonging to either Owner1 or
Owner2.
Also, a search for the term unassigned (with or without quotes) will display
all alerts that have not been assigned.

To Searches the value of the extracted To field.

User Searches the value of the extracted User field.


UUID Enables you to search for a specific alert UUID number. This is an exact
search.

With Malware Enables you to find alerts with related malware.

Fidelis XPS User Guide 49


Search IP Addresses
There are several methods available to search for an IP address:

• Alert source

• Alert destination

• Both source and destination

• Resolved IP address
• IP Host

Search Source, Destination, or Any IP address


Searching can be performed by entering an IP address in the Search For: text box using CIDR
representation. The following formats are supported for single addresses or address ranges. In all
cases, IPv6 addresses may be substituted for the IPv4 addresses shown in the following examples.

• [Link] finds this exact IP address within the selected field (source, destination, or
both).

• [Link]/24 applies an IP address mask of 24 bits to the address. This includes all IP
addresses within the 192.167.10 subnet, from [Link] through [Link]. Replace
“24” with any value 0-31 to obtain the appropriate mask.

• [Link]-[Link] provides a range of IP addresses and returns all matches within


the range and including the end points. In this example, the search matches any address
within the range of 5 through 15. Do not enter spaces around the dash (-).

• [Link],[Link],[Link] provides a list of specific IP addresses to match.


A comma or a space must be placed between each IP address in the list. The list has no limit
with regard to the number of IP addresses provided, however, long lists will require more
processing time.

• Any IP address or range can be used to match multiple IP addresses if the IP address entries
are separated by spaces or commas. For example, entering “[Link]/24
[Link]/24” would match any IP address in the range [Link] through
[Link] or IP addresses in the range [Link] through [Link].

Search Resolved IP Addresses


This search returns alerts where the source or destination address of the alert matches the
resolved DNS name. Note that the text provided to the search may match several resolved names.
Search results improve when the text entered in the Search text box is as specific as possible.

Notes on IP address searches


Comma and dash separated strings must contain no spaces for the parser to behave correctly. As
an alternative, the entry may be encapsulated in quotes (“) in which case the spaces do no impact
behavior. For example, “[Link] - [Link]” would create an IP address range.
If the search string contains malformed IP addresses, the search will ignore the entry. In the case
of a single address search, no alerts will be found. In the case of a list, malformed addresses will
be ignored. In the case of a range, the search will revert to a single address search using the one
legal address or will return nothing if both ends of the range are malformed.
Exercise caution when using spaces to search multiple ranges. Make sure that spaces are used
only to separate ranges. For example, if two ranges of IP addresses are to be searched such as
[Link] through [Link] and [Link] through [Link] then spaces
should be used to separate the two ranges: “[Link]-[Link] [Link]-
[Link]”

Fidelis XPS User Guide 50


Select CommandPosts
You can select one or more CommandPosts to include with other search criteria. Fidelis XPS
searches for alerts on all selected CommandPosts. If no CommandPost is selected, then Fidelis
XPS conducts the search and applies filters on your local CommandPost. This feature is available
only if you have at least one Subordinate CommandPost registered to your local CommandPost. If
available, the CommandPost section displays in the Search dialog box.
Click Search. The CommandPost section displays with a list of your local CommandPosts and any
direct Subordinate CommandPosts. Refer to Set up CommandPost Relationships.
Select one or more CommandPosts and click Go.
Selecting Subordinate CommandPosts affects how navigation operates and how links work in the
Alert Quick Summary and in Alert Details. Alert Actions also change so that only Export or
Evidence Package are available. Refer to Alert Actions.
Actions associated with alerts will differ when a subordinate CommandPost is included in the
search.
Specifically:

• Links available in secondary columns and alert details will connect to the Subordinate
CommandPost if the alert is stored on a Subordinate. A login will be required if you do not
have a current open browser session to the Subordinate.
• Actions available at the Alert list page will be reduced to Export and Evidence Package. For
other actions (Change Ticket Status, Change Management Group, Change Label, and Purge
Alerts) you must login to the Subordinate CommandPost directly. For the local
CommandPost, all actions are available if only the local CommandPost is used in the report
generation.
• From a Master CommandPost you may directly access the details of any alert on the
Subordinate CommandPost without login. The Tune Rule wizard will not be available in this
mode. To use Tune Rule, log in directly to the Subordinate CommandPost. Note that rule
changes made on the Subordinate will not be reflected on the Master CommandPost.

Time Range
20
To specify a time period for alerts , click Search at the alert control bar and select a value at the
Time Range section. When you click Go, all alerts during the selected time period will be listed.

Sel ect time mode


Insert Time is the time when the alert was inserted into CommandPost. Alert Time is the time when
the alert was created in the sensor. Under normal operating conditions, these times should be
relatively equal. Insert Time can differ from Alert Time if alerts are imported from an archive file into
CommandPost or if alerts are spooled during database maintenance or CommandPost upgrade.
Selecting Insert Time will result in faster response from CommandPost. The performance
difference can be significant when the specified time selection is small and the number of alerts in
the database is large.

Time Range Selections


These selections include:

• All Alerts: Includes alerts from all time periods.


• Last Login: reduces alerts to those that have occurred since the last time you logged into
CommandPost.

20
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 51
• Last 24 Hours, 7 Days, or 30 Days: provide shortcuts to reduce alerts to the prior day, week,
and [Link] default setting of all system reports is 24 hours.

• Specific Hours: will display a text box to which you can enter a two digit number, N. Only
alerts occurring in the past N hours will be displayed. You can use this feature to reduce
alerts by partial days with granularity of one hour increments.
• Specific Days: will display a text box to which you can enter a two digit number, N. Only alerts
occurring in the past N days will be displayed. You can use this feature to reduce alerts to
those that occurred during a specific number of days.
• Specific Date: Click in the text box. A calendar displays from which you can select a date.
This reduces your alerts to those that occurred on the specified date.
• Date Time Range: You can enter a range by entering From and To dates and times. Click the
text box. A calendar displays from which you can select dates and times. This reduces your
alerts to those that occurred during the specified range, including the specified dates and
times.

Customize Report
Click Customize Report to access the Custom Report page. From this page, you can search
multiple fields at the same time. Customize Report enables you to save current search, filter, time
range, or group by selections.
Using Customize Report to save criteria entered at the Alert List page as a Custom Report enables
you to access the report later at the Alert List page. Refer to Create Custom Reports.
The new Custom Report is also available at the Reports>Saved Reports. From the Report List, you
can edit the custom report, schedule it to run at specified times, or copy it to other users.
You can create other reports and make them available at the Alert List page.

Group By
This feature enables you to group alerts by information available in one or more of the primary
21
columns of your current alert page. For example, if you select protocols, alerts are grouped by
protocols. The total number of alerts for each protocol will be listed in the Count column.
The Grouped by page also includes the Last Seen column that shows the latest time stamp of each
group of alerts.
Grouped alerts can be displayed in tabular or graphical form. Graphical forms include pie charts,
bar charts, and stacked bar charts. You may choose the display most relevant to your analysis.
Group By enables you to more easily organize alert information. After grouping, the checkboxes on
22
the left side of the Alert List page apply to the whole group. With one click, you can manage,
purge, or label thousands or even millions of alerts at once. The more alerts that you select, the
longer it will take.
To group alerts:
1. Click Search. The Group By section displays in the Search dialog box .

21
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
22
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 52
Figure 16. Alerts Group By

Note: If the desired column is not displayed, select another report at Alerts.
2. Click one or more of the desired columns.
Note: Group by can take several minutes depending on the size of the alert database.
3. Select how the results will display at the View Results as list. You can select from Tabular, Pie
Chart, Bar Chart, and Stacked Bar Chart options.
4. Click Go.

Figure 17. Group By results in a pie chart


You can easily change the output between tabular and graphical output options.

Displays a pie chart.


Displays a bar chart.

Displays a stacked bar chart.

Displays the alerts in a tabular format.

When alerts are not grouped, these icons are not visible.

Fidelis XPS User Guide 53


The C column is a legend that indicates how the rows in the tabular section pertain to the pie or bar
chart illustrations. Each color represents a portion of a pie or bar chart above the rows. The C
column does not display if you select the tabular format.
You can click a section of the pie chart, bar chart, or stacked histogram to see a list of alerts
represented by that section. For example, if you click on the portion of the pie chart representing
the HTTP protocol, a page displays with alerts that have HTTP protocol violations. At the initial
group by list, click a row to see a Distribution Summary for all other elements in the view’s primary
and secondary rows. The distribution summary can provide insight into areas where further group
analysis may be beneficial. For example, a Distribution Summary indicates 499 alerts found with a
malware type of TROJWARE. Of these alerts, you can learn that all are from the same Host IP,
there are 4 different format types, and 13 different file names.

Figure 18. Group By Distribution Summary


At the Distribution Summary page, you can:

• Click Group Details to see a list of all alerts in the selected row. This action is identical to
clicking a section of the associated graph.
• Click one of the Group By links in the Distribution Summary to group alerts again using this
new element in the group analysis. A new group-by page is generated.

Group Details
When you click a section of a group by graph or click the Group Details button within the group
distribution summary, you are taken to a page with ungrouped alerts, filtered by the criteria
associated with the graph section or row in the group table.
You may change the filter, search, and sort criteria as designed. The Group row displays a link to
Return to Group List. Clicking this link will restore the Group By settings that started your flow.
If you change the Group settings, the Return to Group List link will no longer be valid.

Fidelis XPS User Guide 54


Create PDF Files for Alerts
23
You can create a PDF of an Alert List page. For alerts, the PDF report includes current alert
data such as:

• Alerts in the currently selected report.


• Trending information is included if selected. The trending chart displays with alerts in the PDF
report.
• Group by information is included if selected. For example, if you group by Host IP Address
and Protocol, then alerts are grouped by Host IP Address and Protocol. If you select a chart
to display with the alerts, the graphics are also included in the PDF report.
• The number of alerts in the current page size. For example, if you selected 25 for page size,
then 25 alerts will be included in the PDF report.
• The alerts on the selected page. If you are on page 2 of the Alert Report, those alerts are in
the PDF report, not alerts from other pages. If you desire a much larger number of alerts,
consider using the Export to Excel feature. Refer to Export Methods.
To create a PDF report:

Mouse over to see the options: Generate or Customize PDF. Both options enable you to
create a PDF file of all alerts on the current Alert List page.
You can also

Generate PDF
Select Generate PDF to create a PDF file. Simply clicking the PDF icon is equivalent to choosing
Generate PDF. The file will be downloaded.

Customize PDF
Customize PDF enables you to specify a title, description, footer, add a logo, and choose the
number of columns to include in the report.

Figure 19. Alerts: Customize PDF


1. For column options, you can keep the default selection of All Columns in the Report or
select First columns. Columns in the original Alert List are included from left to right.
2. Enter a title for the PDF report that will display on the top left.
3. If needed, enter a description to display under the title.

23
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 55
4. To include a footer in the report, you can select the default footer, or type the desired footer
text into the box and click Save.
To create a footer for single use:
Click the checkbox next to Use: and enter a name in the checkbox.. This footer will only be
used in the current report and is not saved.
To use the default footer:
Select the checkbox next to Footer: Use: [previously saved footer]. Once you select the
default footer, the option to enter and use another footer will not be available.
To change the default footer:

Click to change the footer. The PDF Config tab opens. Enter the desired text into the
text box.. Click Save as Default. This footer is available for other PDFs and for all other
users until changed. Click Reset to Default to restore the previous default.
To disable the footer without changing it, uncheck the box.
5. To include a corporate logo or image: choose a .jpg, .gif, or .png file from your workstation
and click Save to upload the image to CommandPost. This image will be inserted into the
PDF at the top left of the report. The size of the logo file should be less than 500 kB.

Select the checkbox next to the previously saved footer to use in your report . Click
and choose the image file from your workstation. Click Save to upload the image. The logo
is available for other PDFs and for all other users until changed.
To disable the footer without changing it, uncheck the box.
To disable the image without changing it, uncheck the box.
6. Select the page orientation: portrait or landscape.
7. Click Export PDF. The resulting PDF file contains up to 50 alerts on the current Alert List
page. Export PDF does not save changes, but these changes will be available for other
Alert page PDF reports until you log out or until these settings are changed.

Email the PDF


Click the Email checkbox. to send the PDF report via email. Refer to Email the PDF.

Fidelis XPS User Guide 56


Trending
Trending enables you to graphically display the trend for all alerts within your current settings.
Filtering alerts, entering search or time range values, and grouping alerts will change the trending
display accordingly. For example, if alerts are grouped by Malware Type and Host IP, then each
trend line displays the trend for each Malware Type. Trending charts match colors with the group
by charts and vary depending on the groups selected. If one group is selected, then one color
displays in the trending chart.

Click at the Alert Report. Alert trends displays.


Note: Response time can slow if trending is selected. This depends on the number of
alerts within the specified time period and the number of options selected.
Click to enable persistent trend graphs. This enables trending in all cases and can result in
slower response times. The icon changes to . If persistent trend graphs is selected, clicking
will hide or show trend graphs.
Click to disable persistent trend graphs.
If needed, click to close trend graphs.

Figure 20. Alert Trends

Fidelis XPS User Guide 57


Alert Details
The most granular level for examining data is the Alert Details page. To access alert details, click

at the selected alert.


Note: Alert Details is only available to users with the correct privileges. Refer to User
Roles.

Figure 21. The Alert Details page: Alert Information


The Alert Details page contains multiple sections, which can be hidden (or expanded) by clicking
the- or + on the title bar of the section.
Click expand all to display information in all sections. Collapse all hides all information.
You can change the order of sections in Alert Details by dragging the title bar of a section and
dropping it to the new position. Click to move that section to the top of the pane.
The selected order continues to display each time you log in until changed. Your selections do not
impact the order chosen by other users for their accounts.
Page View—Allows you display the Alert Details in one column or two or three columns. Viewing
the alert in multiple columns will maximize the information available and is most suitable for users
with wide monitors. The same information is presented in all views. Click the appropriate Page icon
to change the view.
If the resolution is less than 800 X 600, please set to a single column page view.

T a bl e 6. S e cti o ns i n A l ert D et ai l s

Alert Details Description

Alert Provides basic information about the alert including: time and date of detection,
Information age (elapsed time since detection), the sensor that detected the alert, the
application protocol, and format, source and destination data. Other
information includes: the alert label, the status of the associated alert ticket,
and the action taken by the sensor.
The data format includes a Format Type and Format Data size if the alert
includes forensic data. Format information may not be present when an alert is
based on channel information and not on content.
Source and destination information includes IP addresses, TCP ports
(presented as the service), and data flow direction. The Host IP represents the
computer or workstation that resides within your network – the system that may

Fidelis XPS User Guide 58


Alert Details Description

be infected by malware it received or propagated or the system that sent


sensitive information.
The country associated with the source or destination IP is also displayed. The
data is based on the country to which the IP address is registered or the
custom location presented to CommandPost, refer to Custom GeoIP.
Note: Source and Destination IP addresses and ports are relative
to the flow of the content that triggered the alert. It is not
necessarily the same as the TCP client and server definitions.
Data Flow Direction indicates the direction of data between the
client (TCP session initiator) and the server (recipient of a TCP
initiation request).
If alert compression has occurred, this table will include the number of events
that were compressed into this alert. Refer to Alert Compression below.
Several items have associated links to Find Similar, Change Label, Host
Presence, and Find Metadata. These links are described in the sections below.

Violation Provides the names of the policy and rule that were violated, and results of all
Information fingerprints within the rule in addition to the rule summary.
The Policy and Rule names can be clicked to redirect you to the Policy or
Rules page if you have a role that provides access to Policies.
The Policy and Rule names can be clicked to redirect you to the Policy or
Rules page if you have a role that provides access to Policies.
Refer to chapters 7 and 8 in the Guide to Creating Policies.
Selecting a fingerprint, rule, or policy from a Subordinate CommandPost.
If the Policy or Rule has been deleted from CommandPost, the link will take
you to the Policy or Rules list page displaying all current polices or rules loaded
on CommandPost.
Note: Policies and Rules created by the DNS Decoder will not be
available under Policies. To access DNS Decoder configuration
page, click System>Components and select the appropriate Direct
or Internal sensor and click Config. At the Config page for the
Direct or Internal sensor, click the DNS Decoder tab. The Violation
Information will display the DNS Policy and Rule names, but they
will not be clickable.
Note: Alerts generated by the Malware Detection Engine will
display the rule and policy as Malware Detection Engine. Neither
the rule nor the policy will be clickable.
The summary displayed in Alert Details is limited to 100 characters and will be
truncated if that limit is exceeded. Keep this in mind when using keywords such
as %TO% within your rule definitions. The summary associated with a Malware
Detection Engine alert will reflect the analysis method used by the MDE for
malware determination.
The Matched on table provides a table of all fingerprints in the violated rule,
along with the fingerprint true/false match result. When the result is true, the
table will include a table of fingerprint matches that were detected. This table
will vary by fingerprint type.
For example, if the fingerprint is a keyword content fingerprint, you will see a
table of all keywords that were found. If the fingerprint is an identity profile
content fingerprint, you will see a table of all pattern sets that were detected.
Click on a fingerprint name to go to the fingerprint page. Refer to Refer to
chapter 2 in the Guide to Creating Policies.

Fidelis XPS User Guide 59


Alert Details Description

Each fingerprint in the Matched on table will be associated with a color code,
representing the highlight color for this fingerprint. Refer to Alert Highlighting
below. The highlighting can be disabled per fingerprint in this table. Alert
highlighting can be turned on or off. Click the icon next to Highlighting.
Fidelis Insight Policy feeds may include encrypted fingerprints. If an encrypted
fingerprint is matched on, the Matched On information and highlighting is not
available for that fingerprint.
If a fingerprint contains a NOT clause, the Matched On information displays but
highlighting is not available for that fingerprint.
Refer to the Fingerprint Page ( chapter 2 in the Guide to Creating Policies).
In a hierarchical CommandPost environment, the following applies:
When operating from a Master CommandPost, you may access alerts that are
stored on a Subordinate CommandPost. Clicking the fingerprint, policy, or rule
name tells CommandPost to check the Master CommandPost to see if the
Master has the same fingerprint, rule, or policy. If the selected item is the same
on the Master and Subordinate CommandPosts, a pop up displays that
enables you to select either Subordinate or Master. If the information differs,
the pop up displays, but you can only select Subordinate. If you select
Subordinate, you will be directed to the login page of the Subordinate
CommandPost if you do not have an active session to the Subordinate
CommandPost.

Related Alerts A single network event can create multiple alerts. When this occurs, related
alerts section will list all alerts generated by the same network transaction.
There are multiple scenarios where this may occur:
• When multiple rules are violated. For example, you may have a rule to
alert on webmail and another to alert on the detection of Personally
Identifiable Information (PII). A user who sends PII data over webmail
would violate both rules and generate two related alerts (if both rules
contained Alert in the action).
• A user may violate the same rule multiple times. For example, consider a
PII rule. If a user sends one webmail message with five attached files
containing PII, this will result in five related alerts, since each file violated
the rule.
• A rule that uses a flagged host fingerprint will show the original alert as a
related alert. . (Refer to chapter 3 in the Guide to Creating Policies.).
When related alerts exist, a list appears showing the severity, alert ID,
summary, time of the alert, and an indication of whether the alert contains
malware or not. The Alert ID of a related alert can be clicked to access the
details of that alert.

Malware This section contains the name, type, behavior, and description of the
Information malware. If the alert does not include malware, this section will state: No
malware detected by MDE.

Execution Files deemed malicious are automatically run through execution forensics.
Forensics Automatic submission may be configured by file type or disabled. Refer to
Execution Forensics. The execution process may take several minutes after
the alert appears in CommandPost.
This section may contain a button for manual submission of a file. The button
appears when the alert contains a file type that can be executed and either the
file was deemed non-malicious or it was deemed malicious but the file type
was excluded from automatic submission. When results are returned, the data
will replace the button in the Execution Forensics portion of the alert details

Fidelis XPS User Guide 60


Alert Details Description

page.
If the alert does not include a file or it includes a file of type that cannot be
executed, this section will state: No Execution Forensics Report.

Alert Workflow Provides information about the alert ticket. Every alert includes an associated
Log ticket that can be assigned to a CommandPost user, moved to a different alert
management group, closed, and tracked by adding comments to a ticket.
The Alert Workflow log will display the history of the ticket and all associated
comments.
Refer to The Alert Workflow Log.

Decoding Path Provides the Decoding Path and the information extracted by the decoding
and Channel process executed by the Fidelis XPS sensor. The Decoding Path provides
Attributes access to the original data detected by the sensor, broken into each level of
protocol or file format extraction. Refer to Decoding Path and Channel
Attributes for a description of how you can use this information.
You may click each line of the decoding path that is displayed in red text. The
result is the output of the decoder at the line clicked. The decoding path will not
be clickable until the session recording is complete and the recorded session is
available to CommandPost. The decoding path (or portions of the decoding
path) may appear in black text and not be clickable if the recorded session is
truncated due to a session that exceeds the maximum configured recording
size, a prevented session, a corrupted session, or a session file that has not
yet transferred from the sensor to CommandPost.
Each line in the Decoding Path represents the output of a Fidelis XPS
decoder. These decoders also extract attributes from the protocol or file that is
being decoded. The Channel Attributes present a table, per decoder, listing all
extracted attributes.
Refer to Protocol and Format Decoder for more information.
Channel fingerprints are based on matching these attributes to those listed in
the fingerprint. Refer to (chapter 4 in the Guide to Creating Policies)
Alerts have clickable decoding paths only when there is a recorded session.
Because Collector alerts are based on metadata, there is no session,
therefore, the decoding path is not clickable if the alert is from a Collector.
When CommandPost is configured for LDAP (or Active Directory)
communication, user data and LDAP records are added. By default,
CommandPost looks up attributes based on FROM email [Link] an IP-
to-ID feed is configured,CommandPost uses the IP Address to determine the
user’s domain name based on the IP-to-ID information. The username is then
looked up in LDAP (or Active Directory) to determine the user data. In some
cases, IP-to-ID may return more information than one LDAP record. In this
case, all information is reported. Refer to CommandPost Configuration for
information about how to configure which attributes are extracted from your
directory server.

Packet Capture The Packet Capture section will only be populated if the violated rule contained
Information an action to capture packets.
When populated, the section provides information about network activity that
occurred up to 10 seconds before and 10 seconds after the alert. Refer to
Packet Capture for information about downloading Packet Capture files and
how to filter session information.
For the network traffic surrounding an alert to be captured, Packet Capture
must be enabled on a sensor with sufficient memory and enabled for a rule
with an alert action. Refer to information for the General page of the Direct

Fidelis XPS User Guide 61


Alert Details Description

component chapter 7 of the Guide to Creating Policies). Note that there might
be a 10 second delay in getting the capture file relative to the time of the alert.
If you have a Solera Networks server available on your network and you have
configured CommandPost properly, the packet capture section will include a
link to the packet storage within your Solera server. Refer to Network
Forensics.

Forensic Data Forensic data is the information extracted by the last decoder in the decoding
path of the alert. You will see text, stripped of all formatting, that represents a
portion of the actual extracted data used by the sensor. You may view this
information in either a text or hexadecimal format.
Forensic data represents the decoded information available at the time of the
alert. If a rule is based purely on content or location information, the forensic
data section may be empty because content was not used to determine the
alert.
The displayed forensic data is limited to 4KB of data and will not display all
information used for analysis. If the size of the network data exceeds 4KB, the
display will begin approximately 100KB before the first content violation. The
entire forensic data may be obtained by clicking the last element in the
decoding path. Any portions of the data that match a content fingerprint will be
highlighted in the text view.
Viewing Forensic Data in text form is the default setting. When you change to
view the data as text, hexadecimal, or recorded session, your choice will
become your new default and will be applied the next time you access alert
details.

Recorded The recorded session is the session or object recorded up to the limits
Session/ Object configured for the sensor. This information is not stripped in any way and is
presented as it was recorded on the network (in client side and server side
data). By default, the first 4KB of the session is displayed. This can be
changed to view more of the session. Clicking Recorded Client Data or
Recorded Server Data will download the recorded data to your client
workstation.
Refer to Configure a Sensor for session limit settings.
If the recording was clipped because it exceeded the maximum configured size
at the sensor, or if there is any TCP prevention or time out information, a
message indicating one or more states displays.

Host Activity Provides Host Activity information from Carbon Black. Host Activity displays
information about malware that has been executed on the client workstation.
Click on a Process ID to display more information about the process including
the host name, process name start time, and endpoint IP. Network activity and
disk activity on the host is also provided.
This data is similar to the Execution Forensics section. However, Execution
Forensics provides information about what might happen if the malware was
execution, while Host Activity provides what did happen.
For access to this data, you need to enable integration with a Carbon Black
server. Refer to Host Activity.

Analytic Alert This section provides metadata for alerts generated by rules created at the
Info Metadata>Analytics rules.
Refer to Analytic Alert Info for details.

Fidelis XPS User Guide 62


Alert Sources
Alerts can be generated from many different sources and can have different characteristics
because of this. Alert sources include:
Fidelis XPS sensors, based on a rule
Fidelis XPS Collectors, based on a Collector feed. The decoding path is not clickable for alerts
based on a Collector feed.
Fidelis XPS Collectors based on a Metadata analytic rule. The alerts represents behavior detected
by analyzing metadata over many network transactions, as opposed to most other alerts that are
generated based on a single network transaction. Therefore, the alert details page will lack much of
the information available for other alerts. IP Addresses, port numbers, decoding path and channel
attributes, forensic data, recorded session, packet capture information, malware information, host
activity, and execution forensics will not be available.

Alert Highlighting
Every alert is triggered by matching some element defined in a fingerprint to some aspect of the
data transaction. Each fingerprint displayed in the Matched on table will be associated with a color
code. Within the Alert Details page, some element will be highlighted in this color so that you can
easily determine the cause of the violation. An exception to this would be if the fingerprint is a
negated match (that is, a match not on certain criteria).
Note: All content to be highlighted might not be present on the Alert Details page.

Figure 22. Alert Details: Violation Information and Highlighting


You will find highlighted information within Alert Information, Decoding Path and Channel Attributes,
and Forensic Data (in text mode) sections of the Alert Details page.
It is possible that a single element can match more than one fingerprint. In these cases, the
highlight will be dashed lines over the text.
Moving your mouse over any highlighted element will display the name of each fingerprint that
matched this element. You can also click on a highlighted element to focus on it. Hitting TAB will
move the focus to the next highlight.
Highlighting may be disabled per fingerprint, by clicking the color coded box next to the fingerprint
name within the matched on section.
Note: Highlighting is not available for encrypted fingerprints provided by policies
from General Dynamics Fidelis Cybersecurity Systems, Inc. Refer to Violation
Information.

Scroll through Alert Details


From the Alert List page, you can create a list of alerts by searching, filtering, or sorting. When you
enter the Alert Details page of any alert, CommandPost remembers the original list so that you can
scroll through it by clicking Previous and Next at the top of the page. As you move through alert
pages, the title refers to the location of the specific alert within the list.
Click Back to Alert List to return to the Alert List page at the location of the current alert.

Fidelis XPS User Guide 63


Find Similar Alerts
Click on the Find Similar links within the Alert or Violation Information sections to find similar alerts.
This action will apply the selected values as filters and return you to the Alert List page showing the
result of a search after applying these filters. For example, clicking the Find Similar link next to
Sensor displays a list of alerts on the same sensor.

Find Metadata
If CommandPost is connected to a Collector, you will see the Find Metadata link next to the Alert
UUID in the Alert Information section. Click the link to move to the Metadata page and locate the
collected session information associated with this alert.
The Find Metadata link is not available for alerts generated by the DNS decoder or from the Web
module. Refer to DNS Decoder and Web.
If you are operating in a hierarchical environment, the following applies:
If you are logged onto the Master CommandPost, the link: find metadata will take you to the
Metadata page of a Collector where the data resides. If the Collector is registered to the Master
CommandPost, you will be redirected to the page. If the metadata resides on a Collector registered
to a Subordinate CommandPost, you will be redirected to the Metadata page on the Subordinate
CommandPost and will need to login if you do not have an active session with the Subordinate.

Figure 23. Finding similar alerts: clickable fields

Find File on Hosts


The Find File on Hosts displays if MD5 for the alert is available and if Bit9 Integration is enabled.
Refer to Host Activity for more information about configuring Bit9. This link would be available only
when file type is exe.

Change Label
Within the Alert Information section, you will see the label applied to the alert. To change the label
or to delete labels, click Change Label. The process is identical to that described in Alert Labels.

Fidelis XPS User Guide 64


Purge this Alert
Clicking Purge this alert will remove the alert you are viewing and the display will move to the next
alert in the list. If you purge the last alert in the list, you will be returned to the Alert List page. Once
purged, the alert cannot be restored.

Alert Compression
In cases of high event activity, the sensor may compress multiple, very similar events into a single
alert to reduce the network communication load on the CommandPost-to-sensor connection.
When one alert represents several events, the Alert Details will include the Events/Compression
data in the Alert Information section. The associated value indicates the number of additional
events represented by this alert. For example, if the value is 8, then there were nine similar events,
the one displayed in the Alert Details plus eight similar events.
If the alert contains no compression, you will not see the Events/Compression data. This is the
typical case.

Analytic Alert Info


The Analytic Alert section is available at alert details if the alert is generated by a Metadata analytic
rule. Refer to Metadata>Analytics.

Figure 24. Alert Details: Analytic Alert Info


The top portion provides rule information including the rule's name, type, and correlation
information. You can click the rule name to go to the Metadata>Analytics page to view details about
the rule or to change it.

The total number of transactions associated with the alert is also provided. Click to go
to Metadata>Explore and see information for all transactions associated with the alert. At
Metadata>Explore, the most recent transactions associated with the alert display first.
The bottom portions provide information about the latest metadata transactions associated with the
alert. The most recent eleven transactions can be viewed within the Analytic Alert Info. Click
Previous or Next to view all metadata from each of these transactions.

Fidelis XPS User Guide 65


Execution Forensics
Files deemed malicious by the Malware Detection Engine (MDE) are automatically run through
execution forensics. Any files deemed non malicious can be manually executed by clicking
to obtain execution forensics.
If the alert does not have any files available for analysis, the section will state that no files are
available for execution.
To use this feature, you must enter a license key at the License page and enable it at Malware
Detection.

Figure 25. Alert Details: Execution Forensics


File execution results are displayed at the Alert Details page. Links to a PCAP file, MP4 video and
full screen also display in the Execution Forensics. File execution can take a few minutes to
complete, during which a status of Analysis pending would be displayed for the report.

• Full Page Report: The Full Page report presents the full results of the execution of the
malicious files.
• PCAP File: The Packet Capture (PCAP) file provides details of network transactions spawned
by the analyzed file. The pcap file can be reviewed in an application such as Wireshark.
• Video: The video file shows video of the desktop during execution of the file.

Analysi s Report ( Metadata)


This section contains metadata information about the file analyzed and the system conducting the
analysis. Details like SHA256 hash and Magic Type are some of the metadata found in the section.
The metadata section also displays any warnings about the file.

Behavioral Indicators:
These indicators are characteristics of the file during execution that reflect typical heuristics
observed in malicious samples. The presence of behavioral indicators alone does not indicate the
sample was malicious, rather it is the combination of these indicators that determines if the file was
malicious.

Fidelis XPS User Guide 66


HTTP Traffic
All observed HTTP traffic during the execution of the file will be listed here. Please note that the
presence of HTTP traffic alone is not an indication that the destination is malicious or should be
blocked. For example, some malicious files will test connectivity before executing by reaching out
to web sites with a high probability of being active (like Google or Yahoo).

DNS Traffi c
All observed DNS queries will be listed in this section.

TCP/IP Stream
Any TCP/IP traffic not detected as HTTP that was active during the execution of the file will be
listed here. This area could include traffic like DHCP queries, IRC connections, and other raw TCP
connections.

Processes
All processes that were initiated based on execution of the sample will be listed in this area along
with the Process Identification number (PID) and other useful data. Please note that the presence
of a process in this area does not indicate maliciousness of that process. For example, if you
analyze a file type like Adobe PDF, some processes listed will be due to the initialization of Adobe's
PDF Reader.

Artifacts
All artifacts created, modified, read, or deleted on the file system during the analyzing of the
sample will be listed here. There is a large amount of expandable content regarding each artifact,
including PE sections and import/export symbols for executable files, a hash of each artifact, and
the process that used that artifact.

Registry Activity
This section is divided into three subsections: Created Keys, Modified Keys, and Deleted Key
Values. Each subsection lists the associated information pertaining to each registry key-value pair.

Filesystem Activi ty
Each file object on the system that was created, modified, read, or deleted during the execution of
the sample will be listed in this section. Details contained here include the full file path, PID of the
process that took action on the file, and the associated file.

Fidelis XPS User Guide 67


Decoding Path and Channel Attributes
The Decoding Path displays each level of decoding performed by the Fidelis XPS sensor during
analysis of a data transmission. Many levels of the decoding path can be clicked to provide a file of
the decoded transfer from that stage of the decoding process.

Figure 26. Alert Details: Decoding Path and Channel Attributes


If you click the Evidence Mode checkbox before clicking the link for the file, the file will be
downloaded in Evidence Mode. Evidence mode provides the original decoding path file in a [Link]
container file along with a text file that includes an MD5 signature of the selected file, information
about the user who downloaded the file, and a summary of the alert details information.
If Evidence Mode is not selected, the file format will depend on which line of the decoding path was
clicked. The result will either be a text file or binary file revealing the decoded content.
If you click on the line that includes a file name, the file will be opened. Your browser will choose
the appropriate application for the file, based on the file extension. Note that the file name is the
exact name used in the original transaction which may indicate an incorrect file type. Your browser
may not be able to handle this situation.
In some cases, if the file has been encrypted, clicking on the file name will not provide the original
file. Usually, the next item in the Decoding Path list will provide the unencrypted file. Base64
encryption is the most common cause of this problem.
For example, consider the decoding path of an MS Word document that was zipped, attached, and
sent in an email with multiple attachments. You can click on any part of the decoding path to
download the file as decoded up to that point. The table below describes what file is downloaded
for each part of the path.

T a bl e 7. D e c o di n g p at h s

Decoding path Files downloaded

SMTP[1] The entire SMTP message (including complete SMTP


headers)
The result will be a .eml file which can be viewed in you
email application to see the entire original email (unless the
recorded session was truncated when it exceeded the
configured maximum recorded object parameter for the
sensor).

MIME The body of the full MIME (Multipurpose Internet Mail


Extensions) message. This includes all MIME attachments.

Fidelis XPS User Guide 68


Decoding path Files downloaded

multipart[3] The particular MIME attachment that contains the file


(including the part header).

MIME([Link]) The MIME attachment without the part header (in this case,
a Base64-encoded file).

Base64 The Base64-decoded file (in this case, a zip file)

zip([Link]) The unzipped file (in this case, an MS Word file).

ms-word The core content stripped of all Microsoft Word formatting


(analogous to copying the contents of the Word document
and pasting them into Notepad). The data from the last
element in the Decoding Path will match the Forensic Data
for the alert.

It is important to note that whether an entire file can be downloaded depends on how much of the
session is recorded in the CommandPost alert database. The maximum amount of the session
that is recorded is specified in the TCP session forensics limit setting. Refer to Configure a
Sensor>Direct for information on setting the TCP session forensic limit or the recorded object size
limit. If prevention is turned on, the file will be truncated at the point where the session was
terminated. Similarly, Fidelis XPS decoders can deal with some number of missing network packets
and still decode file content. The file application may not be able to open a file with missing content.
If the recording of a session ends in the middle of a file you wish to download, you may get a partial
file that cannot be read by the original application. For example, Fidelis XPS decoders and
analyzers can read a partial zip file even though the WinZip Windows application cannot. Similarly,
Fidelis XPS decoders can deal with some number of missing network packets and still decode file
content. The file application may not be able to open a file with missing content.
If the recording of a session ends before a file you wish to download, that part of the decoding path
will not be clickable, and that file cannot be downloaded.

Export Alert Details


Mouse over at the Alert Details page to see a list of export options for that page.

The export list enables you to create, customize, or email a PDF file of the current Alert Details
page. You can also download alert information in an Evidence Package, Text File, or OpenIOC.

Fidelis XPS User Guide 69


Evidence Package
This feature saves administrators time by gathering alert details and multiple files into one
compressed tar (.tgz) or zip file that contains the following:
• The Original Packet capture file. This is included in the package only if it exists for the alert.
• The decoded file for each decoding path (If the decoding path generates archive files such
as gzip, tar, rar, zip, bzip2, or deflate, the archive file will not be further decoded.)
• Recorded client and server data
• A text file that includes MD5s of all files in the package, the alert details, a description of the
package, the name of the user that created the packages, and time of the package creation.

Click at the Export List to download this file for the selected alert.
At the dialog box, click either tgz format or zip format with password. If you select the zip format,
enter a password into the text box. Click Download.
You can also select up to 20 alerts at the Alerts List page and click Actions>Evidence Package to
download a .tgz or zip file that contains the information listed above for each selected alert. The
information in the file is organized by alert ID. The file name contains the CommandPost's IP
address. If alerts in the file are from multiple CommandPosts, then all CommandPost IP addresses
are appended to the file name.
The .tgz or zip file can be useful to send alert reports and Alert Details via email or to save for
future reference

OpenIOC

Click to open (or save) an OpenIOC file. OpenIOC (Indicators of Compromise) is an


extensible XML schema that enables you to describe the technical characteristics that identify a
known threat, an attacker’s methodology, or other evidence of compromise. Refer to
[Link]

PDF Options

Click at the Export list to generate a PDF report of a single Alert Details page
using either the default or the saved customized options. Saved options include the footer, logo
image, and Alert Details sections.

Click Alert Details... to customize the PDF report or to send it via email.

Fidelis XPS User Guide 70


Customi ze the PDF for Alert Detail s
1. Select at least one Alert Details section for the PDF report. By default, all sections are
selected. Click Save after selecting Alert Details sections. These changes are saved under
your user login and will be included in Alert Details PDF reports that you create until
changed. Changes other users make to Alert Details sections are saved under their user
logins and are available to them.

Figure 27 . Alert Details: Select sections for the PDF


2. Enter a title for the PDF report that will display on the top left.

Figure 28. Alert Details: Customize the PDF


3. If needed, enter a description to display under the title.
4. To include a footer in the report, you can select the default footer, or type the desired footer
text into the box and click Save.
To create a footer for single use:
Click the checkbox next to Use: and enter a name in the checkbox.. This footer will only be
used in the current report and is not saved.
To use the default footer:
Select the checkbox next to Footer: Use: [previously saved footer]. Once you select the
default footer, the option to enter and use another footer will not be available.
To change the default footer:

Click to change the footer. The PDF Config tab opens. Enter the desired text into the
text box.. Click Save as Default. This footer is available for other PDFs and for all other
users until changed. Click Reset to Default to restore the previous default.
To disable the footer without changing it, uncheck the box.
5. To include a corporate logo or image: for the report, choose a .jpg, .gif, or .png file from
your workstation and click Save to upload the image to CommandPost. This image will be

Fidelis XPS User Guide 71


inserted into the PDF at the top left of the report. The size of the logo file should be less
than 500 kB.
6. Select the page orientation: portrait or landscape.
7. Click Export PDF. The resulting PDF file contains Alert Details of the selected alert.

Email the PDF


This option enables you to send a PDF report via email.
1. Click the Email checkbox. The email portion displays.
2. Enter an email address.
3. Enter a subject or keep the default.
4. Enter information for the email body, or keep the default text.
5. Click Export PDF. The PDF report is sent as an attachment to the specified email address.

Text Options

Click to open a text file of the Alert Details. This feature can be useful for
sending details of an alert by email, allowing for redaction of some details before sending.
Click Alert Details... and select the Text tab to choose sections for the text file or to send it via
email.

Customi ze the Text file for Alert Details


1. Click Alert Details....
At the Text tab, select at least one Alert Details section for the text file. By default, all
sections are selected. Click Save after selecting. These changes are saved under your user
login and will be included in Alert Details text files that you create until changed. Changes
other users make are saved under their user logins and are available to them.

Figure 29. Alert Details: Select sections for the text file
2. Click Export Text. The resulting text file contains Alert Details of the selected alert.

Email the Text Fi le


This option enables you to send a text file via email.
1. Click the Email checkbox. The email portion displays.
2. Enter an email address.
3. Enter a subject or keep the default.
4. Enter information for the email body, or keep the default text.
5. Click Export Text. The text file is sent as an attachment to the specified email address.

Fidelis XPS User Guide 72


Packet Capture Information
When a rule indicates Packet Capture, a PCAP file will be created by the sensor and the Packet
Capture Information section will display the captured data. The PCAP file includes the session that
caused the alert as well as all communication involving both the client and server involved in the
alert. The PCAP file will include 10 seconds of information before and after the alert, up to a
maximum file size of 16 MB.
Note: Packet Capture is only available for Direct and Internal sensor modules with
sufficient hardware resources. Those sensors with sufficient resources will show an
enable option on the sensor configuration page.
The Packet Capture Information window provides four tabs: Sessions, Lists, Overview, and Solera.
The Sessions tab contains a list of all sessions that occurred around the alert in chronological
order. The session marked with the red flag is the one that caused the alert. Click to see more
information about a session including the protocol, number of packets and bytes, and ports. The
time stamps indicate the time of the first and last packet for the session that is captured in the file.
Clicking or clicking on a listed session selects the session and enters information for the
checkboxes near the bottom of the Sessions tab. Changing the time period at the time bar changes
the sessions listed.
On the sessions tab, information refers to the TCP client/server addresses and ports.

Figure 30. Alert Details: Packet Capture Information


The Lists tab provides further details about the PCAP, including the source and destination IP
addresses, source and destination ports, and protocols. Changing selections allows you to filter the
PCAP file.
The Overview tab provides the total number of packets and bytes and displays them by protocol in
pie charts. Adjusting the time period changes the pie charts and the counts for packets and bytes.

Fidelis XPS User Guide 73


The Solera tab provides details of the alert as an interface into the full network capture files stored
by a Solera Networks system on your network. This tab will appear if Solera is enabled at the
CommandPost>Network Forensics page.

Filtering Session Information


You can filter session information by selecting source or destination IP addresses, source or
destination ports, or protocols at the Lists tab. You can also select a time period. Your selections
filter information that will be in the downloaded PCAP file or used to find related alerts. Filtering
does not affect the original PCAP file that is downloaded in evidence mode.

Figure 31. Alert Details: Packet Capture Lists tab


The left pane in the Lists tab provides a list of all items (IP addresses, ports, or protocols) for all
sessions in the packet capture. Items marked with a icon indicate items that triggered the
current alert. The items listed change depending on what is selected at the drop down list at the top
of the pane. You can select from source or destination IP addresses, source or destination ports, or
protocols.
The right pane displays items filtered by what is selected on the left pane. For example, selecting a
source IP address in the left pane displays items associated with that selected IP address. You can
select from the drop down list at the top of the right pane to find IP addresses, ports, or the
protocols associated with the item selected in the left pane. Note how the checkboxes at the bottom
of the Lists tab change based on your selections. You can make another selection or uncheck the
boxes to change the filter.
The time bar represents the time related to the packets in the file. The red bar indicates when the
alert occurred. Use the sliders to move to the desired time frame. Note how the time stamps
change as you move the sliders. The count also changes in the Expand button to
indicate the total period of time selected. Click to fully expand the time frame.

Fidelis XPS User Guide 74


Figure 32. Alert Details: Packet Capture time bar

Download the PCAP File


You can download the original PCAP file or filter by criteria such as time, IP address, or port.

Click to download the PCAP file to your workstation. If any filters have been applied, the
PCAP file is truncated based on those selections. Filters can be unselected by unchecking the
checkboxes at the bottom of the screen.

Download i n Evi dence Mode

Click to download the PCAP in Evidence mode. The result is a compressed tar file containing
the original PCAP file and a text file. The text file includes :

• The MD5 of the PCAP file. The MD5 is created by the Fidelis sensor when the file is created.
• Information about the date and user name associated with the creation of the compressed tar
file
• All relevant information about the alert associated with the PCAP file.

Find Al erts Rel ated to Sessi on I nf ormati on

Click to apply the selected values as filters and display the Alerts Reports page showing the
result of these filters. For example, clicking a source port displays a list of alerts filtered by the

source port. You must select at least one IP address or port number for Find Alerts to be
active.

Fidelis XPS User Guide 75


Accessing Solera Networks Forensics Data
If you have a Solera Networks Forensics Appliance on your network, you can access the data
relative to alerts triggered by Fidelis rules and policies. On the Solera screen you are presented
with the IP addresses, ports, protocols, and time associated with the alert. You can change these
values as necessary to access the packet data from the Solera appliance.

Figure 33. Alert Details: Packet Capture Solera tab


For IPv4 or IPv6 addresses you can select Src/Dst or Any. If you select Src/Dst, enter IP
addresses in the source and in the destination text boxes. This accesses Solera packet data found

between the specified source IP address to the specified destination IP address. Click to
switch the source and destination IP addresses. Selecting Any provides all packets for each IP
address or IP address range that you enter. The same options are available for Src/Dst or Any TCP
Ports.
For IP Protocol, you can select from TCP, UDP, and Any protocol to access the associated packets
from Solera. The IP Protocol filter is not supported by Solera for IPv6. You can still filter on TCP
and UDP ports. However, if an IPv6 address filter is specified and the Port fields are left empty, the
protocol filter will be ignored.
You may also specify one or more Ethernet Interfaces on the Solera appliance. By selecting
interfaces, you can access the packets captured from only those interfaces.
Select Start and End times as needed to narrow your packet information to a specified time span.
The page defaults to 10 minutes before the time of the Fidelis alert to 5 minutes after the alert.

Click to extract a PCAP file from Solera that contains the data associated with
your selections. .

Click to open the Solera browser interface to review packet data associated
with your selections.

Fidelis XPS User Guide 76


Printi ng Packet Capture I nformation
You can print the packet capture information that displays on the Sessions, Lists, or Overview tabs.
To print, right click and select Print from the menu. At the print dialog box, select a printer to print
the results or select Adobe PDF. Selecting Adobe PDF creates a PDF file that you can save for
future reference.

Forensic Data
The forensic data represents the unformatted text on which Content fingerprint analysis is
performed. When there is a match to a content fingerprint, you will see the matched information
highlighted.
Note: Extracted hyperlinked URLs in office and html formats are displayed at the
beginning of Forensic Data. Extracted hyperlinked URLs in PDF documents for each
page are displayed at the end of contents for that page in Forensic Data.

Figure 34. Alert Details: Forensic Data


The forensic data window is limited to 16K bytes of data. The information in the Matched on table
within the Violation Information section of the Alert Details page includes the entire analyzed buffer
which may be bigger than the data shown in the forensic data window. For this reason, in some
cases, the number of highlights in the forensic data may not match the numbers shown in the
Matched on table.
The forensic data buffer begins near the occurrence of the first matching data. In some cases, the
forensic data will only represent a portion of the original data transaction and it may not start from
the beginning of the data. The entire data transaction is available in the recorded TCP session.

Recorded TCP Session


A verbatim session recording is available from the Alert Details page. Click View recorded TCP
session link in the Forensic Data table to view the Recorded TCP Session.
The View recorded TCP session link will appear as soon as the session is terminated or completed.
In cases where the session is not complete or there is some other kind of session corruption, this
link will not appear.
The recorded TCP Session contains session information and verbatim transcripts of both the client
and server halves of the session.

Fidelis XPS User Guide 77


Figure 35. Alert Details: Recorded TCP Session

Session Inf ormation


Session information includes client and server IP address (with resolved DNS names if possible),
start and end times of the session, session duration, and the total size and number of packets of
both the client and server halves of the session.
Note that the total size and number of packets includes all packet retransmissions, so
this number may exceed the size of the recorded session.
If the recording was clipped because it exceeded the maximum configured size at the sensor, the
following Recording State displays: Exceeded maximum configured size
If there is any TCP prevention or time out information, the TCP State displays one or more of the
following values:
• RST packets sent
• Packets dropped
• Packet mangled
• Session timed out
If there is any payload missing for the session, the TCP State displays the following values:
• Session packet missing
In any of these states, you may not be able to click on all or part of the decoding path or obtain
execution forensics.

Client and Session Server Transcri pts


The client and server session transcripts are shown exactly as reassembled by Fidelis XPS. If the
total size of the session exceeds the Alert Recorded Object Limit setting, the transcript sizes may
be less than the total session. You can change this at the configuration page for your sensor. Refer
to Configure a Sensor.
The transcript is in raw form. No content decoding of any kind is shown, so if all or part of the
session is encrypted, encoded, compressed, or in some other way transformed it may not be
legible. Most high-level protocols like SMTP and HTTP are composed of largely human-readable

Fidelis XPS User Guide 78


exchanges so this information can be very useful in investigating network and information handling
policy violations.
It is possible to download the complete client and server transcripts by clicking on the Client Data
and Server Data links, respectively. The complete transcript is downloaded regardless of the Show
Amount setting below. The transcripts are downloaded as files with a .bin extension as the data
may be binary data.

Show Amount

It is possible to vary the length of the transcript displayed in the recorded TCP
Session page. Enter the number of kilobytes you wish to see in the Show KB text box and press
enter. This setting only affects the number of bytes displayed in this page.

Tune Rules from an Alert


When reviewing alert details, you can create a rule exception based on the alert's attributes. For
example, to suppress all alerts from a specific location, you can access Tune Rule at the Alert
Details page create a whitelist of modify the rule to make the identified location an exception. Tune
Rule is a wizard that enables you to create rule exceptions.
Note: Alerts generated by the DNS Analyzer Policy are created by the DNS Decoder
and cannot be tuned using this flow. To tune these alerts, you need to change the
configuration of the DNS Decoder. Refer to DNS Decoder.
24
From the Alert Details page:
1. Click Tune Rule.
If you are working in a hierarchical environment with Master and Subordinate
CommandPosts, you will have a choice to tune the rule at the Master CommandPost or the
Subordinate CommandPost. Tuning at the Master is recommended. Refer to Hierarchical
CommandPost Environments for additional information.
If you are not working on a Master CommandPost, this step will not exist.

Figure 36. Tune Rule: choose a tuning method


If you are not working from a Master CommandPost, step 1 will ask you to select a tuning
method: either use a whitelist in the policy or modify the rule. If you are working from a Master
CommandPost, this will be step 2.

24
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 79
Whitelist refers to a rule with the whitelist action. The whitelist will apply to every rule in the
policy. If you choose to use or create a whitelist, a new rule will be created and added to the
policy violated by the alert. An alternative is to modify an existing whitelist rule.
If you choose to modify the rule, the rule that was violated in the alert will be modified by
changing the rule expression. The tuning will only impact this single rule..
Whitelist is the recommended option. The created rule will be part of a single policy, however
the Policy page can be used to easily add this rule to other policies. Over time, you will likely
create lists of IP addresses, countries, URLs, and other applicable attributes that can be
easily modified to quickly whitelist certain network activities in your environment.
Use rule tuning only when the desired outcome is to modify a single rule, without affecting
any other rule on the system.
After selecting a tuning method, select the attributes of the alert that will be used to create the
exception.
Select a tuning method either use a whitelist in a policy or modify the rule.
If you choose to use or create a whitelist, you can add to a fingerprint within a whitelist rule,
create a new whitelist rule and fingerprint, add to a fingerprint and add a new whitelist rule.
Refer to the options described in step 3 . You can also select to modify the rule. If you modify
a Fidelis XPS rule, the user expression is modified, not the Fidelis expression.
After selecting a tuning method, select the fingerprint type and attributes for the fingerprint.

Figure 37. Tune Rule: Alert Attributes


2. Select the attributes to create the exception: IP Address, Country, Alert Information, or
Channel Attributes. The applicable alert values will change based on your selection.

• IP Address enables you to create an exception based on the alert source and destination IP
addresses. Choosing both will create an exception for transfers from the source IP to the
destination IP, but not the reverse. Choosing one will create an exception for all transfers
from/to the source/destination IP address.
• Country enables you to create an exception based on the alert source and destination
countries. Choosing both will create an exception for transfers from the source country to the
destination country, but not the reverse. Choosing one will create an exception for all
transfers from/to the source/destination countries.
• Alert Information enables you to create an exception based on the source and destination
TCP ports and the application protocol. Selecting more than one option will create an
exception when all selected items are found in network traffic. For example, selecting Source
TCP port 8080 and protocol HTTP will create an exception for HTTP detected from port 8080

Fidelis XPS User Guide 80


on the source. It will not match traffic from port 8080 on other protocols nor will it match HTTP
on other ports.
• Channel Attributes enables you to create an exception based on any channel attribute
extracted from the alert. Choosing more than one attribute will match any one of the attributes
found in network traffic. For example, choosing HTTP command = “GET” and HTTP URL = a
specific URL will match all HTTP get requests and all accesses (GET or POST) to the
selected URL. To match the combination, you will need to use the Policy interface, create
separate fingerprints for each attribute, and logically combine them in the rule expression.
Refer to Create an Expression in chapter 7 in the Guide to Creating Policies.
Select at least one attribute for the chosen fingerprint and click Next
3. Choose an option for the handling of the attributes selected in the previous step. The
available options will change depending on the violated rule and policy, and prior tuning
activity.
If you selected whitelist in step 1 (Step 2 if working from a Master CommandPost), your
options include:
• Create a new whitelist rule and fingerprint.
Enter names for the new rule and fingerprint. The new rule will consist of the new
fingerprint and will be added to the violated policy. This option is always available.
• Create a new whitelist rule and add attributes to an existing fingerprint.
The list of existing fingerprints is based on the attributes selected in the prior step. If
there are no applicable fingerprints that match your selection, this option is not
available.
Enter a name for a new rule and choose the fingerprint. The selected attributes will
be to the chosen fingerprint. The new rule will consist of the selected fingerprint and
will be added to the violated policy.
• Use an existing whitelist rule and fingerprint
If the violated policy includes a whitelist rule with a fingerprint application to the
options selected in the previous step, this option will be available. Choose the rule
and fingerprint that you wish to modify. The selected attributes will be added to the
fingerprint and no further changes will be made to the rule or the policy.
If you selected Modify Rule for the tuning method, the Modify Rule screen displays with the
current rule expression. Your options include:

Figure 38. Tune Rue: Modify Rule


• Add attributes to a new fingerprint.

Fidelis XPS User Guide 81


Enter a name for the new fingerprint. This new fingerprint will be added to the rule
expression as an exception. This option is always available.
• Add attributes to fingerprint [fingerprint name].
If the rule already includes fingerprints created by the tuning process, each applicable
fingerprint will be available as an option. If there are no such fingerprints in the rule, this
option is not available. Selecting this option will add the selected attributes to the chosen
fingerprint. The fingerprint will be modified and the rule expression will not be changed.
• Add attributes to a fingerprint already part of the rule.
If the rule contains a fingerprint applicable to the attributes chosen in Step 2 (Step 3 if
working from a Master CommandPost), this option will be available. Choose the fingerprint
that you wish to modify. The selected attributes will be added to the chosen fingerprint and
the rule expression will not be modified.
When using this option, pay attention to the current rule expression. The logic in the
expression will dictate how this choice will be applied.
Note: This list will not include fingerprints that were created by the tuning process.
Those fingerprints are available as separate options.
• Add attributes to an existing fingerprint and add it to the rule.
Fingerprints applicable to the selected attributes in Step 2 (Step 3 if working from a Master
CommandPost) are listed. The list will not include fingerprints that are already part of the
rule. The fingerprint will be added to the rule expression as an exception.
Click Next.

Figure 39. Tune Rule: Add Whitelist Rule


The tuning summary displays with details about the changes to the fingerprint, rule, and
policy that will be applied based on your selections. .

Fidelis XPS User Guide 82


Figure 40. Tune Rule: tuning summary
4. Review changes and do one of the following:
Click Back to modify your selections.
Click Cancel to exit the Tune Rule Wizard without submitting these changes. As a result of
Cancel, no changes will be made.
Click Submit to submit and save changes.

Figure 41. Tune Rule: Update Sensors


5. .If you clicked Submit, Step 5 will verify the save process and summarize the changes. If an
error occurs, it will be available on this screen.

Fidelis XPS User Guide 83


Click Update Sensors to push your changes to sensors.. This process is equivalent to
updating all sensors from the Policies->Assignments page. The update will include all
changes that exist on CommandPost, not only those created by the Tune Rule process.
Updates depend on Policy assignments, as configured at Policies->Assignments.
Click Done to exit the Tune Rule Wizard. Changes to the fingerprint, rule, and policy were
saved, but not applied to any sensor. To apply your changes, visit Policies->Assignments
and update the sensors.
6. At the last screen, the sensor update status displays. Click [Link] exit the Tune Rule
Wizard. The update process will continue in the background if you exit before all sensors
are updated.

Hierarchical CommandPost Environments


If your environment includes Master and Subordinate CommandPosts, all alerts can be tuned from
the Master CommandPost. The steps for tuning are the same, however, the following applies:
If the alert is from a Subordinate CommandPost, the Tune Rule process will check the Master
CommandPost to see if the rule exists on the Master. If the rule found on the Master, a pop up
displays that enables you to select either Subordinate or Master. The rule will be modified on the
chosen CommandPost.
If you choose to tune on the Subordinate, your changes will be overwritten if policies are assigned
from the Master CommandPost to a sensor registered to the Subordinate CommandPost. For this
reason, it is highly recommended that all tuning be performed on the Master CommandPost. If you
have reason to tune only on a Subordinate, it is recommended that you make a copy of the rule to
avoid future assignment collisions.
If the alert is from a Subordinate CommandPost, but the rule is not found on the Master
CommandPost, all changes will apply to the Subordinate.

Fidelis XPS User Guide 84


Fidelis XPS Decoders
Fidelis XPS contains protocol and format decoders, and each has specific attributes. All decoders,
however, include the MD5 attribute.
To support wildcards, the CommandPost GUI provides a menu of all attributes for all protocols and
file formats, however, only some are applicable to any given protocol. Within the Label drop down
menu, upper-case options refer to protocol decoders, while lower-case options refer to file format
decoders.

Protocol Decoder Attributes and Values


All supported protocols are listed in the table below. This table provides the complete list of all
attributes available for each supported protocol. In some cases, attributes have a well-defined list of
possible values and are represented in the Values column. When the attribute has an undefined
content, the Values column is left blank (in these cases, the value will be extracted from the
network transmission).
Different sensors decode different protocols depending on the sensor type and the license key.

T a bl e 8. Pr ot o c ol d e c o d er a ttri b u t es a n d va l u es

Protocol decoder Protocol decoder Attribute Definition/Values


description strings

AIM AOL Instant Messenger Encrypted

Filename

From

To

User

AIMEXPRESS A Web version of AOL Filename


Instant Messenger
From

To

User

AOLMAIL A Web version of AOL Filename The filename of the


mail
attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or
download file for the
detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

Fidelis XPS User Guide 85


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

BADOO A social networking web


site

BITTORRENT A peer-to-peer Filename


communications protocol
for file sharing
Content is not decoded.

COMCASTMAIL Webmail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or
download file for the
detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

CVS Concurrent Versions Root


System; a client-server
free software revision User
control system.

DB2 A relational model Cipher


database server
Database

Encrypted

From

Midstream

Quality True or False

SQL

To

User

DNS The Domain Name Host


System (DNS) is a
DNS is only supported hierarchical distributed
when the DNS naming system for
Decoder is enabled on computers, services, or
a Direct or Internal any resource connected
to the Internet or a

Fidelis XPS User Guide 86


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

sensor. private network. DNS


protocol translates host
names into IP
addresses.

EARTHLINKMAIL Webmail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or
download file for the
detected attachment
Subject Subject of the email
To Recipient's email address
User User's email address

EDONKEY A peer-to-peer file Host


sharing network
User
Content is not decoded.

EMUMAIL Webmail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read eamil for the detected
email body or upload or
Download file for the
detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

EXCHANGE Microsoft Exchange Cipher


provides email, calendar,
(Includes NT
and contacts on personal
Lan Manager
computers, phones, and
(NTLM) or
web browsers.
Kerberos
Includes MAPI authentication)
(Messaging Application
Program Interface) a Encrypted Refer to Quality, Encryption
Microsoft Windows String, and Hash Values.

Fidelis XPS User Guide 87


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

program interface that


Filename
enables users to send
emails from within a
From
Windows application
such as word Midstream
processors,
spreadsheet, and Quality
graphics applications.
Server

Subject

To

UID

User

FACEBOOK A social networking web From


site
Mode

Profile

Subject

To

UID

User

FIX The Financial Client


Information eXchange
(FIX) protocol is a Server
messaging standard
developed specifically for User
the real-time electronic
exchange of securities
transactions.

FRIENDSTER A social gaming site

FTP File Transfer Protocol; a Command Get or Put


standard network
protocol used to copy a Filename
file from one host to Passive or Normal
another over a TCP- Mode
based network
Stream Type Data Transfer or Control

User

GNUTELLA A large, decentralized

Fidelis XPS User Guide 88


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

peer-to-peer network
Content is not decoded.

GOOGLEMAIL Web mail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or
download file for the
detected attachment.

Subject Subject of the email

To Recipient's email address

User User's email address

GOOGLETALK Freeware instant Filename


messaging and voice
over Internet (VoIP) From
protocol client
application To

User

GOOGLE_WEBIM A chat widget for Google From


talk users to use on
various Google web sites Mode
such as gmail.
To

User

HI5 A social networking site

HORDEMAIL Webmail Filename The filename of the


attachment
From
Sender's email address
Mode
Indicates the send or
read email for the detected
email body or upload or
download file for the
detected attachment
Subject
Subject of the email
To
Recipient's email address
User

Fidelis XPS User Guide 89


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

User's email address

HOTMAIL Webmail Filename The file name of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or
download file for the
detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

HTTP Hypertext Transfer Command


Protocol, a
networking protocol Connection
that is the foundation
Filename
of data
communication for From
The World Wide Web
Host

Location

Malformed Client sends no data

Midstream

Mode

Proxy

Proxy Port

Referer

Server

Server Port Yes

Status Code

To

Tunnel

URL

User

User Agent

Fidelis XPS User Guide 90


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

Via

X-Forwarded-
For

IMAP4 Internet Message From


Application Protocol a
prevalent Internet Subject
standard protocol for
email retrieval To

User

IPTUNNEL Used when one network Tunnel String with a defined format
protocol (the delivery (TYPE IP1:PORT1 IP2:PORT2)
protocol) encapsulates a
different payload PORT 1 and PORT 2 apply only
protocol. to Teredo tunnels. Type can be
Prevention is disabled one of the following:Teredo, 6in4,
for this decoder. 6to4, GRE, IPIP, IPsec

IPsec Internet Protocol Encrypted ESP


Security (IPsec) is a
protocol suite for Mode Transport or Tunnel
securing IP
communications by Protocol AH,ESP or AH+ESP
authenticating and
encrypting each IP
packet of a
communication session.
IPsec also includes
protocols for establishing
mutual authentication
between agents at the
beginning of the session
and negotiation of
cryptographic keys to be
used during the session.
Prevention is disabled
for this decoder.

IRC Internet Relay Chat, a From


form of real-time,
Internet text messaging To

User

JABBER A protocol developed by Filename


the Jabber open source
community for near-real- From
time, extensible instant
messaging (IM), To
presence information,
and contact list. User

KAZAA Kazaa Media Desktop


was used to exchange

Fidelis XPS User Guide 91


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

MP3 music files and


other file types, such as
videos, applications, and
documents over the
Internet.
Content is not decoded.

LDAP The Lightweight Authentication SASL or SIMPLE


Directory Access
Protocol (LDAP) is an Command bind, search, add, delete, modify,
application protocol for search result
reading and editing
directories over an IP DN distinguished name or string
network.
Midstream True or False

Mode Add, replace, delete

User

LINKEDIN Social networking site From

Mode

Subject

To

UID

User

MSNIM Windows Live Encrypted


Messenger (formerly
named MSN Messenger) Filename
is an instant messaging
client created by From
Microsoft and is
designed to work with To
Microsoft Windows
platforms. User

MSN_WEBIM The web-based version From


of Windows Live
Messenger. Mode

To

User

MSSQL Microsoft SQL Server is


a relational model
database server. Its
primary query languages
are T-SQL and ANSI

Fidelis XPS User Guide 92


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

SQL.
Content is not decoded.

MYSPACE Social networking site From

Mode

Subject

To

UID

User

NEOMAIL Webmail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the sender or


Read email for the detected
email body or upload or
download file for the
detected attachment

Subject Subject of the email.

To Recipient's email address

User User's email address

NING Social networking site

ORACLE An object-relational Cipher Refer to Quality, Encryption


database management String, and Hash Values.
system (ORDBMS) Client
Note: By default the
Oracle decoder uses the Database
standard Windows CP
1252 character set for Encrypted
American English. For
international character From
sets, the Oracle decoder
Midstream
uses the first character
set defined in the Quality
Language Configuration
page of the sensor SQL
configuration. Refer to
chapter 13 in the User Server
Guide. These defaults
can be overwritten by To
editing the Oracle
configuration file. User

Fidelis XPS User Guide 93


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

ORKUT Social networking site

OWAMAIL Web mail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or
download file for the
detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

PLAXO Social networking site From

Mode

Subject

To

UID

User

POISON IVY A remote access tool Encrypted Camelia

Version
POP3 Post Office Protocol User
(POP) is an application-
layer Internet standard
protocol used by local
email clients to retrieve
email from a remote
server over a TCP/IP
connection.

RDP Remote Desktop


Protocol (RDP) is a
proprietary protocol
developed by Microsoft,
that provides a user with
a graphical interface to
another computer.
Content is not decoded.

RFB Remote Frame Authentication VNC, RA2 ,RA2ne, SSPI, SSPIne

Fidelis XPS User Guide 94


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

Buffer, an open , TightVNC, UltraVNC , TLS,


protocol for remote VeNCrypt TLS,
desktop GTK-VNC SASL,
MD5 Hash, Colin Dean xvp

Version

RTMP Recognizes and


decodes the Real Time
Messaging Protocol
(RTMP) was developed
for streaming audio,
video and data over the
Internet, between a
Flash player and a
server.
Content is not decoded.

RTSP Real Time Streaming


Protocol (RTSP) is a
network control protocol
designed for use in
entertainment and
communications systems
to control streaming
media servers. The
protocol is used for
establishing and
controlling media
sessions between end
points.
Content is not decoded.

SHAREPOINT collaboration software Filename Name of the file being


transferred

Mode Upload, download, post,


and view

Title Site name

User User name

SIP A signaling protocol CallID


widely used to set up
Voice over IP and Video Command INVITE, REGISTER,
over IP calls.
MESSAGE, etc.
SIP can create, modify
and terminate two-party Contact
or multiparty sessions.
Each session may From
consist of one or several
media streams. Media String with a defined format.
media port, protocol, codecs

Fidelis XPS User Guide 95


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

Server

Subject

To

User-Agent

Via

SKYPE An application that


allows users to make
voice calls and chats
over the Internet.
Content is not decoded.
Note: The Skype
decoder does not
provide content
decoding. To reduce the
number of alerts, Skype
provides one alert per
Skype client, not per
session. However, the
action (prevent or
throttle) is applied to all
the sessions from the
Skype client.

SMB Server Message Block Client


(SMB) operates as an
application-layer network Directory
protocol used to provide
shared access to files, Domain
printers, serial ports, and
miscellaneous Filename
communications
between nodes on a Midstream True or False
network.
Read/write Read, write, read& write

Share

User

Version SMB 1 and SMB 2

SMTP Simple Mail Transfer Client


Protocol (SMTP) an
Internet standard Encrypted TLS
foremail transmission
across IP networks. From

Malformed Client sent no data

Server

Fidelis XPS User Guide 96


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

To

User

SQUIRRELMAIL Webmail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email bode or upload or
download file for the
detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

SSH Secure Shell or SSH is a Cipher Refer to Quality, Encryption,


network protocol that String and Hash Values.
allows data to be
exchanged using a
Client
secure channel between
two networked devices. Encrypted SSH
Content is not decoded.
Hash

Quality

SSL Secure Sockets Layer Cipher Refer to Quality, Encryption


(SSL) is a cryptographic
protocol that provides String, and Hash Values.
communications security
Command
over the Internet.
Content is not decoded. Encrypted SSL or TLS

Hash

Malformed Bad record length from client


Bad record length from server

Mode Decrypted SSL (Only with SSL


Inspector)

Quality Refer to Quality, Encryption


String, and Hash Values.
Suspicious

Version 2.0 or 3.0

Fidelis XPS User Guide 97


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

TELNET Telnet is a network User


protocol that provides
communications using a
virtual terminal
connection.

TFTP Trivial File Transfer Filename


Protocol (TFTP) is a file
transfer protocol Mode netascii or oclet
generally used for
automated transfer of Read/Write Read or write
configuration or boot files
between machines in a To
local environment.
User User email address if used in the
Note: TFTP over UDP
obsolete mail mode
can only be prevented
when detected by a
network sensor
configured for inline
mode.

TLS Transport Layer Security Cipher Refer to Quality, Encryption


(TLS) is a cryptographic String, and Hash Values.
protocol that provides
communications security Command
over the Internet.
Encrypted SSL or TLS

Hash

Malformed Bad record length from client


Bad record length from server

Mode Unused

Quality Refer to Quality, Encryption


String, and Hash Values.
Suspicious

Version 1.0,1.1, and 1.2

TWITTER An online social


networking and
microblogging service

VERIZONMAIL Webmail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or

Fidelis XPS User Guide 98


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

download file for the


detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

WEBSOCKET WebSocket is a web Host


technology providing full-
duplex communications Server
channels over a single
TCP connection.

X11 A computer software


system and network
protocol that provides a
basis for graphical user
interfaces (GUI) for
networked computers.
Content is not decoded.

YAHOOMAIL Web mail Filename The filename of the


attachment

From Sender's email address

Mode Indicates the send or


read email for the detected
email body or upload or
download file for the
detected attachment

Subject Subject of the email

To Recipient's email address

User User's email address

YAHOO_WEBIM Yahoo instant Filename


messenger for the web
From

Mode

To

User

YMSG Yahoo Messenger Filename

Fidelis XPS User Guide 99


Protocol decoder Protocol decoder Attribute Definition/Values
description strings

Protocol is the From


underlying network
protocol used by the Mode
Yahoo Messenger
instant messaging client To File Transfer

User

Format Decoder Attributes and Values


Similar to protocol decoders, format decoders can extract specific attributes and values. The
following table defines each of the format decoders and lists any applicable attribute strings and
values.

T a bl e 9. F or m at d e c o d er a ttr i b u t es

Format Format decoder Attribute strings Values


decoder definition

7z A file that contains one Cipher Refer to Quality, Encryption


or more compressed String, and Hash Values
files. Attribute strings do
not apply to supported Compression
compression utilities Method
such as zip.
Creation Date

Filename

Hash

Modification
Date

Quality

Type Anti-Item

air Adobe AIR is a Refer to Quality, Encryption


Cipher
String, and Hash Values
developer's tool for
creating platform- Compression
independent web Method
applications that can be
run on a user's desktop. Filename

Quality

base64 An encoding method that Suspicious


converts binary data into
ASCII text and vice
versa.

binary A binary file Suspicious XOR (key value)


Pad (pad length)

Fidelis XPS User Guide 100


Format Format decoder Attribute strings Values
decoder definition

XOR (key value) and Pad (pad


length)

binhex BinHex, short for binary- Filename


to-hexadecimal, is a
binary-to-text encoding
system used on the Mac
OS for sending binary
files through email.

bmp Bitmap Image File

bzip2 An open source data Filename


compression program.

certificate An electronic document End Date


that uses a digital
signature to verify Extended Key Server Authentication
identity.
Usage Client Authentication
Code Signing
Email Protection
Time Stamping
OCSP Signing
Use Unknown if not
defined in RFC 3280

Issuer Name If the ON Entry in both the


Issuer and Subject fields are
the same, the value will be
ON Self-Signed Certificate

Key Length Number of bits


Key Usage
Digital Signature
Non-Repudiation
Key Encipherment
Data Encipherment
Key Agreement
Certificate Signing
CRL Signing
Encipher Only
Decipher Only
Use Unknown if not defined
in RFC 3280
Start Date

Subject Name

Type
X509 Certificate or
Unrecognized Certificate

Fidelis XPS User Guide 101


Format Format decoder Attribute strings Values
decoder definition

chunked An encoding method that


allow s data to be
returned in chunks.

deflate An algorithm that


compresses
data without any loss.

embedded- An embedded image Filename


image

embedded- Embedded text or file Filename


object
Stream type

exe The Executable file Binary Type Library or Executable


decoder will extract
attributes of the file,
Compression
including the Operating
Method
System, the file type
(library or executable),
Creation Date Can only be captured on Windows
and the creation date.
applications

Contents are decoded to ImpHash Import Table Hash


extract readable text or
strings from applicable OS Family Android, Linux/Unix, Windows or
sections of the DOS, MacOS/OSX
executable, such as
import table, export Packed The packer program used, such as
table, resource table, UPX
symbol table, and string
table, etc. Type

fix-format Financial Information Filename


eXchange (FIX) XML
and tag-value
messages.

flash Detects compressed and Filename


uncompressed Flash
files such as swf, flv, or
f4v files.
Text content is decoded
and any executable
ActionScript is extracted
for user analysis.

gif Graphics Interchange


File

gzip A file compression Filename


program

html Hyper Text Markup


Language

Fidelis XPS User Guide 102


Format Format decoder Attribute strings Values
decoder definition

image An image

java-class Detects and decodes


java class files.

javascript JavaScript is a scripting Filename


language that can be
embedded directly in
HTML source of Web
pages and also in PDF
applications outside of
web pages.

jpeg Joint Photographic


Experts Group, a
compression method for
digital images
keynote Presentation program for Author
Apple iWork
Filename

mail Email messages that do From


not include MIME
formatted data Subject

To

message Any set of transmitted


data
Searches for messages
transmitted in 7-bit, 8-bit,
and binary transfer
encodings.

mime Multipurpose Internet Filename


Mail Extensions, the
most common method of From
transmitting non-text files
via Internet email. Subject

To

User

XHeader
(Customizable)

ms-access-mdb Microsoft Excel Filename

ms-excel Microsoft Excel Author

Cipher Refer to Quality, Encryption


String, and Hash Values.

Fidelis XPS User Guide 103


Format Format decoder Attribute strings Values
decoder definition

Creation Date

Filename

Header/Footer The header or footer found within


a Microsoft Excel document

Modification Date

Quality

ms-msg Microsoft Outlook From


message
Subject

To

ms-office Microsoft Office Author


Includes the stream
format type extracted by Creation Date
ms-office decoders.
Filename

Header/Footer

Modification Date

ms-powerpoint Microsoft PowerPoint Author

Creation Date

Filename

Header/Footer
The header or footer found
within a Microsoft PowerPoint
Modification
document.
Date

ms-rtf Microsoft rich text format Creation Date

Filename

Header/Footer
The header or footer found
within a Microsoft rich text format
document.
Modification Date

Fidelis XPS User Guide 104


Format Format decoder Attribute strings Values
decoder definition

ms-visio Microsoft Visio Author

Creation Date

Filename

Header/Footer

Modification Date

ms-word Microsoft Word Author

Cipher Refer to Quality, Encryption


String, and Hash Values.
Creation Date

Filename
The header or footer found within
Header/Footer a Microsoft Word document

Modification Date

Quality

multipart Multipart mime decoder


– handles emails sent
with attachments.
numbers Spreadsheet program for Author
Apple iWork
Filename

oasis-document Openoffice text Creation Date


document decoder
Filename

Filename
The header or footer found within
Header/Footer an Openoffice text document

Modification Date

oasis- Openoffice presentation Creation Date


presentation decoder
Filename
The header or footer found within
Header/Footer an Openoffice presentation
document
Modification Date

oasis- Openoffice spreadsheet Creation Date


spreadsheet decoder
Filename
The header or footer found within
Header/Footer an Openoffice spreadsheet

Fidelis XPS User Guide 105


Format Format decoder Attribute strings Values
decoder definition

Modification Date document

pages Word processing and Author


page layout program for
Apple iWork Filename

pdf Portable Document Author


Format or PDF
documents are easily Cipher
Refer to Quality, Encryption
readable with freely- String, and Hash Values.
available Adobe Reader. Creation Date

Filename

Header/Footer

Modification Date

Title

pgp Pretty Good Privacy or Cipher Refer to Quality, Encryption


GNU Privacy Guard String, and Hash Values.
(gpg)
PGP-encrypted binary
and executable files can
be recognized by the
encrypted files analyzer,
with extraction of
encryption attributes.

pkcs The signature decoder Issuer Name Signed or name of


will extract attributes of signature certificate issuer
the file such as the
signature issuer name Signing Time Signature signing time
and the signing
time if the
file is signed.

postscript Postscript or standard


page description
language (PDL)
developed by Adobe.
Most printers support
PostScript with a built-in
interpreter.

png Portable Network


Graphics File Format

quoted- An encoding method that


printable converts binary data into
ASCII text.

rar A file format for data Compression


compression and Method
archiving.
Filename

Fidelis XPS User Guide 106


Format Format decoder Attribute strings Values
decoder definition

rfc822 A standard for the format


of Arpa Internet Text
Messages

soap Simple Object Access


Protocol

stream For multimedia that is


constantly received by
and presented to an
end-user while being
delivered by a streaming
provider.

tar Tape Archive, a UNIX Filename


utility that combines
several files into one.

text Text file

tiff Tagged Image File


Format

tnef Transport Neutral Creation Date String


Encapsulation Format or
TNEF is a proprietary End Date
email attachment format
used by Microsoft Filename
Outlook and by Microsoft
Exchange Server. From

Modification
Date

Start Date

Subject

torrent Detect and decode Creation Date


.torrent files which
are used to describe file
locations to the
BitTorrent protocol.

urlencode An encoding scheme


used in HTTP.

uuencode An encoding method that Filename


converts binary data into
ASCII text.

WebP image format that uses


compression

xfdl Extensible Forms Filename


Description Language

Fidelis XPS User Guide 107


Format Format decoder Attribute strings Values
decoder definition

An encoding method
intended for forms.

xml Extensible Markup


Language used to define
data elements on a Web
page.

ymsg Yahoo Instant Message Filename


Decoder
From

Mode

To

User

zip A file that contains one Refer to Quality, Encryption


Cipher String, and Hash Values
or more compressed
files. Attribute strings do
not apply to supported Compression
compression utilities Method
such as LHA.
Filename

Quality

Fidelis XPS User Guide 108


Attributes for Protocol and Format Decoders
The following table defines attributes for protocol and format decoders. These attributes are listed
with each applicable protocol or format decoder.

T a bl e 1 0. Pr ot o c ol a n d f or m at de c o d er a tt ri b ut es

Decoder Description Decoders that use the


attributes attribute

Authentication Authentication method in use for LDAP, RFB


the session

Author The author or creator of the file keynote, ms-excel, ms-office,


ms-powerpoint, ms-visio, ms-
word, numbers, pages, pdf

BinaryType The type of an executable program exe


file

CallID Caller ID as found in the SIP SIP


session

Cipher The algorithm used for encryption 7z, DB2, EXCHANGE,


of session or file ORACLE, SSH, SSL, TLS,
air, ms-excel, ms-word, pdf,
pgp, zip

Client Initiator host of the session Fix, Oracle, SMB, SMTP,


SSH

Command Protocol specific commands such FTP, HTTP, LDAP, SIP, SSL,
as get or put TLS

Compression Algorithm used to compress a file 7z, air, exe, rar, zip
Method

Connection Status of the HTTP connection: HTTP


closed or keep alive, etc.

Contact Contact information as found in the SIP


SIP headers

DN Distinguished name of an LDAP LDAP


object

Database Database name DB2, Oracle

Directory Directory being accessed in an SMB


SMB transaction

Domain Domain name associated with the SMB


SMB transaction

Encrypted Flag denoting that session was AIM, DB2, Exchange, IPsec,
encrypted MSNIM, Oracle, Poison Ivy,
SMTP, SSH, SSL, TLS

Fidelis XPS User Guide 109


Decoder Description Decoders that use the
attributes attribute

Evasion A technique for modifying attacks tunneling decoders


Technique to prevent detection

Extended Key Extended usage for public key in certificate


Usage X.509

Filename name of the file Almost all protocols and


wrapper file formats Including:
7z, AIM, AIMEXPRESS,
AOLMAIL, BITTORRENT,
COMCASTMAIL,
EARTHLINKMAIL, EMUMAIL,
EXCHANGE, FTP,
GOOGLEMAIL,
GOOGLETALK,
HORDEMAIL, HOTMAIL,
HTTP, JABBER, MSNIM,
NEOMAIL, OWAMAIL,
SHAREPOINT, SMB,
SQUIRRELMAIL, TFTP,
VERIZONMAIL,
YAHOOMAIL,
YAHOO_WEBIM, YMSG, air,
binhex, bzip2, embedded-
image, embedded-object, fix-
format, flash, gzip, javascript,
keynote, mime, ms-access-
mdb, ms-excel, ms-office, ms-
powerpoint, ms-rtf, ms-visio,
ms-word, numbers, oasis-
document, oasis-presentation,
oasis-spreadsheet, pages,
pdf, rar, tar, tnef, uuencode,
xfdl, ymsg, zip

From User that initiated the email, chat, All email and chat protocols,
or transaction including:
AIM, AIMEXPRESS,
AOLMAIL, COMCASTMAIL,
DB2, EARTHLINKMAIL,
EMUMAIL, EXCHANGE,
FACEBOOK, GOOGLEMAIL,
GOOGLETALK,
GOOGLE_WEBIM,
HORDEMAIL, HOTMAIL,
HTTP, IMAP4, IRC, JABBER,
LINKEDIN, MSNIM,
MSN_WEBIM, MYSPACE,
NEOMAIL, ORACLE,
OWAMAIL, PLAXO, SIP,
SMTP, SQUIRRELMAIL,
VERIZONMAIL,
YAHOOMAIL,
YAHOO_WEBIM, YMSG,
mail, mime, ms-msg, tnef,

Fidelis XPS User Guide 110


Decoder Description Decoders that use the
attributes attribute

ymsg

Hash Hash of an encrypted or 7z, SSH, SSL, TLS


compressed transmission

Header/Footer The header and footer of a file ms-excel, ms-office, ms-


(supplemental information at the powerpoint, ms-rtf, ms-visio,
beginning and end) ms-word, oasis-document,
oasis-presentation, oasis-
spreadsheet, pdf

Host A computer connected to a DNS, Edonkey, HTTP,


network. WebSocket,

ImpHash Import Table Hash exe

Issuer Name Name of the certificate issuer certificate, pkcs

Key Length Length of the public key certificate

Key Usage How the public key is used certificate

Location Location specified in HTTP HTTP


headers

Malformed Session containing a badly formed HTTP, SMTP, SSL,TLS


name, resource record, or other
error

Media Media information found in SIP SIP


headers

Midstream Flag indicating that session was DB2, Exchange, HTTP,


not captured from the beginning LDAP, Oracle, SMB

Mode Distinct method of operation within AOLMAIL, COMCASTMAIL,


a computer system EARTHLINKMAIL, EMUMAIL,
FACEBOOK, FTP,
GOOGLEMAIL,
GOOGLE_WEBIM,
HORDEMAIL, HOTMAIL,
HTTP, IPsec, LDAP,
LINKEDIN, MSN_WEBIM,
MYSPACE, NEOMAIL,
OWAMAIL, PLAXO,
SHAREPOINT,
SQUIRRELMAIL, SSL, TFTP,
TLS, VERIZONMAIL,
YAHOOMAIL,
YAHOO_WEBIM, YMSG,
ymsg

Modification Date Date when a file was modified 7z, ms-excel, ms-office, ms-
powerpoint, ms-rtf, ms-visio,
ms-word, oasis-document,
oasis-presentation, oasis-

Fidelis XPS User Guide 111


Decoder Description Decoders that use the
attributes attribute

spreadsheet, pdf, tnef

OS Family Operating system to which an exe


executable file pertains

Packed The packer program used, such as exe


UPX

Profile A link to the user Facebook profile Facebook

Protocol Application protocol for the IPsec IPsec, NetworkEvasion


session

Proxy HTTP Proxy server involved in the HTTP


session

Proxy-Connection Status of an HTTP connection to a


proxy server

Proxy port Port on which the HTTP proxy HTTP


server is listening

Quality Quality of encryption of a session 7z, DB2, EXCHANGE,


or file ORACLE, SSH, SSL, TLS,
air, ms-excel, ms-word, zip

Read/White Read/write permission on a file or SMB, TFTP


folder as found in protocol data

Reassembly Reassemble packets info proper NetworkEvasion


order at the receiving end of the
communication

Referer An HTTP header field that HTTP


identifies the address of the web
page (i.e. the URI) that linked to
the resource being requested

Root Top level directory of an RCS file CVS


system
SQL Structured Query Language (SQL): DB2, Oracle
a query language used for
accessing and modifying
information in a database

Server The server to which the host has Exchange, Fix, HTTP, Oracle,
connected SIP, SMTP, WebSocket
Server port The port on which the server is HTTP
listening

Session ID sub session of Rel Session ID tunneling protocols

Share A shared directory accessed over SMB


SMB

Fidelis XPS User Guide 112


Decoder Description Decoders that use the
attributes attribute

Signing Time Time that the certificate was signed pkcs

Start Date date started certificate, tnef

Status Code HTTP response status code HTTP

Stream type Whether the session was a control, FTP, embedded-object


data, or encrypted stream

Subject The subject of an email or AOLMAIL, COMCASTMAIL,


message EARTHLINKMAIL, EMUMAIL,
EXCHANGE, FACEBOOK,
GOOGLEMAIL, HORDEMAIL,
HOTMAIL, IMAP4, LINKEDIN,
MYSPACE, NEOMAIL,
OWAMAIL, PLAXO, SIP,
SQUIRRELMAIL,
VERIZONMAIL,
YAHOOMAIL, mail, mime,
ms-msg, tnef

Subject Name subject name in a certificate certificate

Suspicious File with suspicious formatting or binary, base64, SSL, TLS


structure

Title Sharepoint site Title Sharepoint, pdf

To Recipient of the information / email All email, chat, social


protocols including: AIM,
AIMEXPRESS, AOLMAIL,
COMCASTMAIL, DB2,
EARTHLINKMAIL, EMUMAIL,
EXCHANGE, FACEBOOK,
GOOGLEMAIL,
GOOGLETALK,
GOOGLE_WEBIM,
HORDEMAIL, HOTMAIL,
HTTP, IMAP4, IRC, JABBER,
LINKEDIN, MSNIM,
MSN_WEBIM, MYSPACE,
NEOMAIL, ORACLE,
OWAMAIL, PLAXO, SIP,
SMTP, SQUIRRELMAIL,
TFTP, VERIZONMAIL,
YAHOOMAIL,
YAHOO_WEBIM, YMSG,
mail, mime, ms-msg, ymsg

Tunnel A protocol in which one protocol is HTTP, IPTUNNEL


encapsulated within another (HTTP
Connect, IP tunnels)

Type Different types – 7z: anti-file, 7z, certificate, exe


certificate: root or not, exe: signed

Fidelis XPS User Guide 113


Decoder Description Decoders that use the
attributes attribute

or not

UID User ID used in various systems Exchange, Social protocols


and protocols including: EXCHANGE,
FACEBOOK, LINKEDIN,
MYSPACE, PLAXO

Url HTTP Uniform Resource Locator, HTTP


or web address

User A person or software using an Almost all protocols including:


information system AIM, AIMEXPRESS,
AOLMAIL, COMCASTMAIL,
CVS, DB2, EARTHLINKMAIL,
EDONKEY, EMUMAIL,
EXCHANGE, FACEBOOK,
FIX, FTP, GOOGLEMAIL,
GOOGLETALK,
GOOGLE_WEBIM,
HORDEMAIL, HOTMAIL,
HTTP, IMAP4, IRC, JABBER,
LDAP, LINKEDIN, MSNIM,
MSN_WEBIM, MYSPACE,
NEOMAIL, ORACLE,
OWAMAIL, PLAXO, POP3,
SHAREPOINT, SMB, SMTP,
SQUIRRELMAIL, TELNET,
TFTP, VERIZONMAIL,
YAHOOMAIL,
YAHOO_WEBIM, YMSG,
mime, ymsg

UserAgent Application using the HTTP as HTTP, SIP


transport

Version Version of the protocol being used PoisonIvy, RFB, SMB, SSL,
TLS

Via Via (proxies) information as found HTTP, SIP


in HTTP-like headers

X-Forwarded-For HTTP header field used for HTTP


identifying the originating IP
address of client using an HTTP
proxy

XHeader X-Headers field found in mime mime


headers

Fidelis XPS User Guide 114


Quality, Encryption String, and Hash Values
Quality and encryption string values are listed below.
Quality string values Encryption string values Hash values

256-bit Password MD5


192-bit Fortezza SHA1
128-bit RC4
120-bit RC2
112-bit Idea
104-bit Serpent
96-bit Twofish
88-bit Arcfour
80-bit Cast
72-bit Blowfish
64-bit Triple-DES
56-bit DES
48-bit AES
40-bit None
Weak Non-Standard
None RC4-DSS
Kerberos
RC4-DH
RC4_ENH
RC4-DSS_ENH
RC4-RSA-AES
RC4-RSA
RC4-STRONG
XOR
PGP

Fidelis XPS User Guide 115


Chapter 5 Understand and Manage
Quarantined Emails
The Quarantine Management page displays all emails that were quarantined by a Fidelis XPS Mail
Sensor. This page includes emails that are currently held in the quarantine queue and a record of
messages that have been discarded or delivered. Click Alerts>Quarantine to access this page.
Email is quarantined when it violates a rule that specifies the action of alert and quarantine.
Quarantined email resides on the Mail queue until a quarantine manager or the sender of the
quarantined email take action or until the email expires.

Figure 42. Quarantine Management


The information about each email includes a unique Message ID, Sender, Recipient, Subject, Time,
and Status. An email will have one of the following statuses depending on the action taken:

• Quarantined: The email is currently held in quarantine on the Fidelis XPS Mail sensor.
• Admin Discarded or Admin Delivered: The quarantine manager has discarded or delivered the
quarantined email. Refer to Deliver or Discard Quarantined Email.
• Auto Discarded or Auto Delivered: The email has expired and was delivered or discarded
according to the rule that was violated. Refer to chapter 7 in the Guide to Creating Policies.
• User Discarded or User Delivered: The sender of the email has discarded or delivered it
through quarantine user self management. Refer to Quarantine Management by End-Users.
• Imported: The quarantined email is imported with the associated alert.

Understand Fidelis XPS Mail Quarantine


The Mail sensor operates on email messages. Because of the nature of email, the Mail sensor can
analyze an entire email at once, and take action if policy violations are found.
Most other Fidelis XPS sensors operate on data in flight. They do not analyze an entire transfer,
but operate on data as it passes through the analyzer in real time. This is an important difference in
understanding how a Mail sensor works and how managing quarantined email differs from
managing alerts from other types of sensors.
As an example, consider a transfer of information that violates multiple rules. One example is an
email message containing attachments; the body of the email may violate one rule, while an
attachment violates another. A second example is an Instant Messenger session where the chat
content violates one rule, while a file transferred over the same IM session, violates a second rule.
The Direct sensor would detect the IM violations. It would issue an alert immediately after finding
the chat violation. It would issue a second alert at a later time, when the file transfer occurred.
These two rules may have required different actions and each action would be taken. For example,
the chat violation may result in an alert, while the file transfer may result in preventing the session.
Both actions are taken at the time the violation is determined.
The Mail sensor operates differently in this situation. Because email is delivered as a single entity
from mail server to mail server, the Mail sensor can analyze all content at one time. Therefore, only

Fidelis XPS User Guide 116


one action is taken for the email, even if multiple rules are violated and each rule requires different
action.
The Mail sensor applies the following priority to email actions:

• Prevent has first priority. Any email that violates one or more rules with the Prevent action will
be prevented.
• Quarantine takes second priority. Any email that violates one or more rules with the
Quarantine action will be quarantined.

• Reroute has third priority. If other actions such as quarantine are detected, they are taken.
If the quarantine action is taken, the following occurs:

• The email is placed in the quarantine queue on the Mail sensor. It remains here until a person
responsible for quarantine management decides to deliver or discard it, or until the message
expires. Contact Technical Support to change the default expiration of 14 days, if needed.

• Information about the email message, and all associated alerts, is transferred to
CommandPost where it can be viewed by a quarantine manager. The action for each alert
refers to the action taken by the Mail sensor.
Note: This action may be different than the action specified by the rule due to the
prioritization described above.

• Each alert is assigned to the alert management group defined by the rule.
• The quarantine manager must have full quarantine permissions and also needs to belong to
the same alert management group of one of the alerts generated by the quarantined email. All
members of the alert management group, with the appropriate quarantine role can view the
message and take an action to deliver or discard the message. Refer to Manage Users,
Roles, and Groups.
• If the violated role has enabled Quarantine User Self-Management, the sender of the email
will be able to take an action to deliver or discard the email. Refer to Quarantine Management
by End-Users.
• Alerts and quarantined email are managed independently. Email actions will remove an email
from quarantine and optionally, all associated alerts. Removing all alerts associated with a
quarantined email purges these alerts from CommandPost. Refer to Deliver or Discard
Quarantined Email.
• Most quarantined email will have at least one alert. The only exception will be when alert
compression becomes active. Refer to Alert Compression for details. When the sensor
generates many alerts, it will begin to compress similar alerts to relieve congestion between
CommandPost and the sensor. In some rare cases, all alerts from one email will be
compressed together with other similar alerts, and therefore not be available on
CommandPost. The quarantined email will be available to all alert management groups in this
case.
Quarantined email is another key difference between the Mail sensor and other sensor types. Other
sensors make a decision to prevent, alert, or throttle immediately, based on analysis. The Mail
sensor offers the quarantine option, which defers the final decision to a person who reviews the
offending message. Therefore, persons with quarantine management responsibility may need to
take immediate action to avoid unnecessary delays in business communication. The Mail sensor
offers the ability to notify quarantine managers immediately upon taking the quarantine action.
Refer to Mail for configuration options.

Fidelis XPS User Guide 117


Quarantine Management by End-Users
When User Self-Management is enabled by the rule definition, the sender of the email will be able
to deliver or discard the message from quarantine. The following process becomes available.
1. When a message is quarantined, the sender will be notified by email. This message will
include a unique quarantine message ID and instructions to the user. The instructions and the
subject line of the notification email can be customized at the Mail configuration page. Refer
to Mail.
2. The user can respond to the notification message with proper instructions and justification
text. The instruction is a simple keyword of release or delete presented as the first word in the
body of the reply. The unique message ID must be contained in the reply message.
3. Upon receipt of a message containing a message ID and the release or delete keyword, the
sensor will locate the quarantined message. Depending on your network configuration, the
message may be located on a different Fidelis XPS Mail sensor, and if so, the message will
be routed to the appropriate sensor. The email action, per user instructions, will be taken.
4. The sensor notifies CommandPost of the action taken by the user and will send the
justification email. CommandPost will append the justification to the quarantine information
and update the status accordingly.
5. The Quarantine Manager can access the information, including the updated status and
justification text on CommandPost.
6. The Quarantine Report can be managed similarly to the Alert Report, using Archive for long
term storage and Alert Retention Plans to prune the information based on alert criteria.
The quarantine manager can also deliver or discard quarantined email at any time if the status is
Quarantined. If no action is taken by the user or quarantine manager, the email will expire, per the
instructions associated with the rule.
Quarantine user self-management must be enabled for individual rules at the Rules page. Refer to
chapter 7 in the Guide to Creating Policies.

The Quarantine Report


The Quarantine report displays a summary of information for each quarantined email. The From,
To, Subject and Status columns provide information about the messages. You may click the row
of an email to view expanded information.
Note: Navigation is performed the same as it is in the Alert page. Refer to Navigate
Alert Pages.

Figure 43. Expanded quarantine information


The expanded information includes the message ID, time stamp, and the sensor. Information about
any corresponding alerts also displays.

• Quarantine Details: Click next to the email to see the Quarantine Details page for that
email. Refer to Quarantine Details.

• Alert Details: Quarantined emails can have alerts associated with them. Click an alert number
at the Quarantine Details page or at the Quick Summary for the quarantined email. The Alert
Details page displays with information for the alert. Refer to Alert Details for more information.

Fidelis XPS User Guide 118


Any changes made at the Alert Details page will only affect the selected alert and not the
quarantined email or any other alerts generated by the email.

Take Actions on Quarantined Emails


Click the check box next to one or more quarantined emails to select them. Clicking check boxes
again deselects the emails. Clicking the check box at the top of the Quarantine Management list
selects (or deselects) all emails on the current page.
25
Users with quarantine management privileges can take the following actions:

• Change Status. Refer to The Alert Workflow Log.


• Change Alert Management Group. Refer to The Alert Workflow Log.

• Deliver or Discard the message. Refer to Deliver or Discard Quarantined Email. These
options also enable you to purge alerts associated with the quarantined email.

Deliver or Discard Quarantined Email


You can choose to deliver or discard quarantined email when the status is Quarantined. Either
action will remove the quarantined message from the sensor and CommandPost. You may choose
to also remove all alerts associated with the message or to leave all alerts on CommandPost.

• If deliver is chosen, the email is sent from the quarantine queue to the original recipient. An
email is also sent to the original sender of the email notifying them that their email was
delivered.
• If discard is chosen, the email is removed from the quarantine queue and not sent to its
original recipient. An email is sent to the original sender of the email notifying them that their
email violated policy and was not delivered.
• A dialog box displays asking if you want to remove all of the alerts associated with this
message. If you choose All, the alerts are purged from CommandPost. Make sure that you
really want to discard all alerts before proceeding.
26
If you select None, any associated alerts remain available on the Alert List page. The
quarantined email is delivered or discarded.
• If the quarantined email does not contain associated alerts, a dialog box asks if you want to
continue. Click OK to continue to deliver or discard the quarantined email.

Search Quarantined Emails


Searching for quarantined emails can be done by entering criteria in the control section at the top of
the Quarantine page. If the page controls are not visible, click in the upper right corner to open
them. Searches use a case-insensitive, partial string match to find quarantine emails. The search
term is a simple phrase or set of phrases to find within quarantine information.
1. Enter search terms in the Search For: text box. Refer to Enter Search Terms for Alerts for
specific search guidelines.
2. Select a search field at the In: pull down menu.

25
Users enables you to create and manage users, their roles, and user access.
26
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.

Fidelis XPS User Guide 119


Figure 44. Searchable Quarantine fields
You can search for quarantined emails by searching for specific text strings in the following fields:

T a bl e 1 1. Q u ar a n t i n e d Em a i l : s e a rc h fi el ds

Quarantine search Description


fields

Message ID The ID the system assigns to the quarantined email.

Sensor Select the Mail sensor on which the email resides.

Sender Any part of the From line of an email message.

Recipient Any part of the To line of an email message.

Subject Any part of the subject line of an email message.

Alert Management Any part of the alert management group associated with alerts.
Group

Forensic data Any part of the data captured from the email.

Status The status of the quarantined email. Enter an exact or partial


phrase from the following:
Admin Discarded
Admin Delivered
Auto Discarded
Auto Delivered
User Discarded
User Delivered
Quarantined
Imported

Justification Text Any part of the justification text. When the user replies to an
email notification, the reply is stored as justification text and
displays in the Quarantine Details page.
Refer to Alert Search Fields for more specific information about how these searches are applied.
3. Include or exclude Incoming quarantined emails.
Every access to the Quarantine page presents live data as it is reported to CommandPost. If
new quarantine emails are occurring on your network, this may distort your view of the data.
For example, you may click Next Page only to see the same set of quarantined emails from
the first page. This occurs because the first set of quarantined emails has been superseded
Fidelis XPS User Guide 120
by new quarantined emails, moving them to the next page. You will notice similar effects any
time you perform searches, or if you access Quarantine Details then return to the Quarantine
Management page.
You can change this behavior by clicking the Include Incoming Quarantine in the Search
dialog box. By default, this option is checked, meaning new quarantined emails will be
considered. To change this behavior, uncheck the Include Incoming Alerts box.
4. Click Go. You can search without specifying a time period.

Search Quarantined Emails using Time Range


You can use Time Range to reduce the list of quarantined emails to those that occurred within a
specified time range. Time Range can be found in the control section at the top of the Quarantine
page. If the page controls are not visible, click in the upper right corner to open them.
1. Click Time Range to select a time period, If needed. The default value is all messages.

Figure 45. Quarantine time range


Time Range selections include the options described below. You can further refine your
search by selecting the Quarantine Date or Release Date of the email. The Quarantine or
Release Date options are available with all time range selections except All Messages.
• All Messages: the default setting of the Quarantine page.
• Last Login: reduces messages to those that have occurred since the last time you
logged into CommandPost.
• Last 24 Hours, 7 Days, or 30 Days: provide shortcuts to reduce the messages to the prior
day, week, and month.
• Specific Hours: will display a text box to which you can enter a two digit number. You
can use this feature to reduce alerts by partial days with granularity of one hour
increments.
• Specific Date: Click in the text box. A calendar displays from which you can select a date.
This reduces your messages to those that occurred on the specified date.
• Date Range: You can enter a range by entering From and To dates and times. Click the
text box. A calendar displays from which you can select dates and times. This reduces
your messages to those that occurred during the specified range, including the specified
dates and times.
2. Include or exclude Incoming quarantined emails.
3. Click Go.

Fidelis XPS User Guide 121


Advanced Search for Quarantined Emails
An advanced search gives the ability to search on two or more fields simultaneously.
1. Click Advanced Search. The Quarantine Report Editor displays.

Figure 46 . Quarantined email: advanced search


2. Enter search criteria into the search fields.

T a bl e 1 2. Q u ar a n t i n e d Em a i l : a dv a n c e d s e a r c h fi el ds

Field name Description

Sensor(s) From the sensor box, choose a sensor or Ctrl-click to choose multiple
sensors.

Sender Any part of the From line of the email message.

Recipient Any part of the To line of the email message.

Subject Any part of the subject line of the email message.

Forensic Data Enter search terms to search within Forensic Data.

Alert Management Any part of the alert management group associated with alerts.
Group

Status The status of the quarantined email. Select from the following:
Admin Discarded
Admin Delivered
Auto Discarded
Auto Delivered
User Discarded
User Delivered
Quarantined
Imported

Fidelis XPS User Guide 122


Field name Description

Justification Text Any part of the justification text. When the user replies to an email
notification, the reply is stored as justification text and displays in the
Quarantine Details page.
3. Click Run Report to retrieve reports that match your search.

Quarantine Details
Click next to the quarantined email to access Quarantine Details. You can view the original
email message, a list of any attachments, and alerts associated with this email.
Note: Quarantine Details is only available to users with the correct privileges. Refer to
User Roles.

Figure 47. Quarantine Details


If no action was taken on the quarantined email the Deliver and Discard buttons display in the
Message Management Information section. The Body of the quarantined email displays in

Fidelis XPS User Guide 123


27
Message Information. Users with full privileges to quarantine management can choose to deliver
or discard the quarantined emails. Refer to Deliver or Discard Quarantined Email.
If a quarantine manager has delivered or discarded an email, the Message Management
Information section displays the new queue status of the email and the date and time it was
released. The Body and attachment of the quarantined email no longer displays.
If the original sender released or discarded the quarantined email through quarantine user self-
management, Quarantine Details includes the Justification Text in addition to the release date and
time. The Justification Text includes the user's response to the self management instructions text
and the original self-management [Link] to Take Action on Quarantined Emails.
Alerts Information displays any alerts related to the quarantined email. Click the alert ID to see
28
Alert Details .
Users with ticketing privileges can access the Message Workflow Log to make changes to alerts
associated with the quarantined e-email. The alerts may be assigned to individuals or groups,
closed, or commented. Any ticket action applies to all alerts associated with the quarantined email.
Refer to The Alert Workflow Log.

27
Users enables you to create and manage users, their roles, and user access.
28
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 124
Chapter 6 Investigator
Investigator enables you to bookmark alerts, alert searches, metadata sessions, searches, and
transactions for further investigation. This allows you to group disparate items together with
comments for easy retrieval and review by other users. For example, if an alert includes related
metadata, you can include the alert and any related metadata sessions in an investigation.
Information about the bookmarked alert and related metadata is saved in the investigation and is
available even after the original alert or metadata sessions are deleted.
For example, you can include alerts and an alert search in an investigation. Information about the
bookmarked alerts and the alert search is saved in the investigation and is available even after the
original alerts are deleted.
Note: To access Investigator, you need View access to Alerts and Full access to
Details or View access to Metadata.
To print or export search results, you need Full access to Alerts or Full access to
Metadata. Refer to User Roles.
From above the Alert List or Metadata>Explore page :

Click to open Investigator. Once enabled, you may drag and drop alerts and alert searches
to begin using the Investigator. Initially, the default investigation displays and all items dropped into
the Investigator are added to the default investigation. The default investigation is private.
Investigations can be added, made public, closed, and modified. To change the status of the
default investigation, you need to save it under another name. Refer to Open an Investigation.

If you navigate to another page, the last investigation accessed displays. Click the investigation
name to display a list of investigations available to you.

Include Items in an Investigation


When an investigation is enabled you will notice your mouse pointer change to a hand as you
move over items that can be dragged. Click to select an item. As you drag the item toward the
Investigation icon, the icon will expand showing where to drag the item. Once you drop the item,
the investigation icon will indicate that an item was added.
After you include an item, a text box displays that enables you to enter a short comment to describe
the item. Any comments entered will display immediately before the more detailed comments that
are automatically generated for the item. If you do not enter comments, the text box disappears
after a few seconds. Refer to Edit Item Comments.
The following elements can be added to an Investigation:

• Alerts: From the Alert list page, drag and drop any row in the investigation. This action will
insert the alert with a name: Alert – N where N is the alert ID. The Comments associated with
the alert include relevant information about the alert including the UUID, source, destination,
protocol, file type, rule, and policy. The name and comments can be modified after dragging
the row to the investigation.
Once added, the alert will have a icon next to it in the Alert list. The icon only displays
when the investigation to which the item belongs is selected.
• Alert Search: There is often a need to include all alerts that meet certain criteria in the
investigation. This can be accomplished by executing a Search on the list page. Move your
mouse to the top left of the Alert list page where the search criteria is described and the
mouse icon will change to a hand. You can grab the search criteria and drop it to your
investigation. The search criteria includes search, filter, time range, and group information. If
your search includes group by information, the Return to Group List will not be available. The
entry into the investigation will be named: Alert Search – Date and the Comments will include

Fidelis XPS User Guide 125


all search criteria. The name and comments can be modified later but the search criteria
cannot be changed.
Note that running these searches in the investigator at a later time may yield different results
if the search had an open-ended end time (e.g. last 24 hrs) or because of alert purging.

• Metadata Transaction: At Filter Results, click next to the appropriate transaction and
select Add Transaction to Investigation. This action will insert the metadata transaction with a
name: Transaction – N where N is the transaction ID. The Comments associated with the
metadata transaction include relevant information about the session including the protocol,
source, destination, and time of the session. The name and comments can be modified after
adding the transaction.
• Metadata Search. There is often a need to include all sessions that meet certain criteria in the
investigation. This can be accomplished by executing a Search on the Metadata page. At the

Metadata page, click and select Add Filter to Investigation. The entry into the investigation
will be named: Metadata Search – Date and the Comments will include all search criteria. The
name and comments can be modified later but the search criteria cannot.
Note that running these searches in the investigator at a later time may yield different results
if the search had an open-ended end time (e.g. last 24 hrs) because of metadata purging.

• Metadata Session. At Metadata Details, click the session ID and select Add Session to
Investigation at the drop down list. The entry into the investigation will be named: Session –
Session ID and the Comments will include session information. The name and comments can
be modified later.

Using the Investigator


To access or modify the information gathered in an investigation, click the icon to open the
Investigator. The name of the current investigation will appear as well as the edit icon, . For
example:

Click to edit the investigation. Click the name of the investigation to change to another. Click

at the top of the screen to close the investigation.

Clicking at the bottom closes the investigation. If you open or close an investigation, this
selection remains if you navigate to another page.
When open, the investigation includes an interface to change an investigation, view a list of all
items in an investigation, and an interface to filter the list. You can also create a PDF file of the
investigation or export it to Excel.

Change an Investigation
Open the current investigation to select a different investigation. The following controls display:
Status enables you to search for all , open, or closed investigations. The selections available at the
Owner and Investigation selections will change based on the selected status.
Owner enables you to select investigations that were created by different users. Any user that has
created a public investigation will be displayed in the list, in addition to yourself. The selections
available at the Investigation selection will change to list those created by the selected user. Public
investigations can be accessed and modified by any user with the proper role.
To access and use Investigator, your role must include full access to Alerts, Alert details, and
reports.
Investigation enables you to select an investigation based on the Status and Owner selections in
the window.
The current investigation may also be changed by clicking the investigation name in the
Investigation icon at the top of the Alerts or Metadata>Explorepages :

Fidelis XPS User Guide 126


Open an Investigation
Open an investigation to add a new investigation or to edit, print, or delete an existing investigation.
You have the following options located next to the Investigation selection:
Click to start a new investigation.
Click to edit the name, status, access, or comment fields for the selected investigation. The
bottom of the investigation page shows when the investigation was created, when it was last
modified, and which user created or changed the investigation.
Select the status: either Private, Public (Read Only), or Public (Read-Write).
Click in the Comment text box to add, delete, or edit text. You can also select text and click on a
formatting button to underline text, change font color, or change the background color of the
selected text. Any formatting or editing changes display in the PDF file. You can also copy
comments to include them in an email or a text document.

Click to open the Metadata>Explore page and view sessions and transactions from the
Investigation.
Click to generate a PDF file of the current investigation. You will be able to create a PDF of
information to which you have Full access. For example if you have Full access to Alerts, but not to
Metadata, you will only be able to include alert information in the PDF. The PDF contains the
content of the selected Investigation and uses the footer and the logo specified at Alerts for PDF
reports. Refer to Create PDF Reports for Alerts to change the footer or the logo. The creation date,
time, and the user display for the investigation and for each item.
Choose to print the PDF with or without search results.
The PDF without search results provides a summary of each alert or metadata search and
summaries of alerts or metadata items.
The PDF with search results includes the search and item summaries and the search results.
When search results are included, they will be capped at 1,000 results per search and 5,000 results
in total. The number of results allowed will be equally distributed between searches. The search is
performed before generating the PDF. This operation may be time consuming.

Click to export the current investigation to Excel. Export runs any alert or metadata searches in
the investigation and places the results in Excel. You will be able to export information to which you
have Full access. For example if you have Full access to Alerts, but not to Metadata, you will only
be able to include alert information in the export. Each search result is put into a different
worksheet with the name of the search. You can have up to 100,000 entries for all searches. The
number of results allowed will be equally distributed between searches. This operation may be time
consuming.
The Excel spreadsheet also includes investigation comments and item names and comments.
You can export with Saved search columns or with All search columns. Your selection determines
which columns will display in the Excel spreadsheet.

• Exporting with Saved search columns uses the search columns saved in an alert or metadata
search.
• Exporting with All search columns uses all columns that are in the alert or metadata page. If
you select All search columns for a Metadata search, an ExtraData column displays that
contains information from the Metadata Details page.

Click to delete the selected investigation. At the dialog box, click Continue to proceed with the
deletion.
Using or controls presents the following controls:
Name: enter a unique name for a new investigation or modify the name of an existing investigation.
Status: Open or Closed
Access: Private or Public. Private investigations can only be accessed by the CommandPost user
who created the investigation. Public investigations can be accessed and modified by any
CommandPost user with a role that provides Full access to Alerts, Alert Details, and Reports.

Fidelis XPS User Guide 127


Comment: Provide a comment for the investigation.

Access Data Stored in an Investigation


Investigations may include individual alerts, alert searches, metadata sessions, or metadata
searches. When you open an investigation, the Type selection can be used to locate specific items.
For each item in an investigation, you have the following options:
Click to change the selected item's name or comments about the item.

Click to delete the selected item. At the dialog box, click Continue to proceed with the deletion.
Click to see details of the item open in another tab (or window depending on your browser).
The item must exist on your system for the item details to display. For example, if an alert is
purged, the Alert Details page will not be available for that alert.

• For an alert item, the Alert Details page displays, if available.


• For alert searches, the search will run again and the search results display

Search for Items


Enter a search term in the text box and click Search to find specific items in an Investigation. A
string search is performed on item names and comments.

Edit Item Comments


Mousing over the comment section of an item displays a tool tip for the item that contains
information from the first part of the comment such as short comments created when the item was
added. Comment content can differ depending on whether the item is an alert, metadata, alert
search, or metadata search item.
Note: Editing search criteria in comments for an alert or metadata search does not
change the search itself. To change the search, you need to change search criteria at
the Alert or Metadata>Explore page and create a new entry in the Investigation.

Click to view the comments in their entirety or to edit comments.


Click in the Comment text box to add, delete, or edit text. You can also select text and click on a
formatting button to underline text, change font color, or change the background color of the
selected text. Any formatting or editing changes display in the PDF file. You can also copy
comments to include them in an email or a text document.

Fidelis XPS User Guide 128


Chapter 7 Metadata
Metadata provides five pages that enable you to perform the tasks listed below.
Metadata provides five pages that enable you to perform the tasks listed below.
Explore enables you to search and view metadata stored by a Fidelis XPS Collector.
Analytics provides the tools for you to create analytic rules to run on a selected Collector. Analytic
rules enable cross-session analysis and correlation of events. Each analytic rule can be
programmed to generate alerts or save the analytic results for temporary storage during rule tuning.
Automation allows for scheduling of analytic rules to run periodically and analyze metadata in near
real-time. It also allows for the option to run once and analyze historic data. This page also lets you
review the run time of analytic rules run on Collector to allow you to optimize the scheduling of
automations.
Analytic Results displays the results of analytic rules when they were run on Collector with Save
Results as the selected action. You can view results without the need to create alerts. This can be
useful while you create new analytic rules, or are in the process of tuning them, and do not want to
run the risk of creating large amount of false positive alerts.
Performance Monitor displays performance for your Collector. The metrics include write throughput
of metadata from Sensors, run time duration of analytic rules, and the run time duration of user
queries at the Explore page.
Note: Metadata is available to users with View or Full access to Metadata. To export
metadata, users need Full access to Metadata. To save filters, users need Full access
to reports in addition to View access to Metadata. Refer to Define User Roles.
Users can only see Fidelis XPS Collectors to which they have been assigned.

Fidelis XPS User Guide 129


Explore
Metadata stored by a Fidelis XPS Collector is available for review at CommandPost under
Metadata>Explore. You can select four different layouts for the Metadata Explore page which can
display up to four different views of the data. The data can be filtered by simple or advanced search
criteria, by clicking specific information with the data, and by altering the amount of data to display.
The controls on the page enable you to find information quickly and perform investigations and
analysis on the data.

Metadata Controls
The top of the Metadata>Explore page contains three rows.

Top Row
The top row provides information about the applied filters, including the current filters, a button to
save the filters, a control of your layout options, and the ability to Export data.
Enables you to select a previously saved filter at the drop-down list or
return to the default filter. Selecting another filter without saving existing search criteria and layout
information as a filter will delete your criteria. Click and enter a name to save search
criteria and layout information under that name.

Enables you to select a previously saved filter at the drop-down list or return to the
default filter. Selecting another filter without saving existing search criteria and layout information as
a filter will delete your criteria. An asterisk indicates that changes were made. Click
and enter a name to save search criteria and layout information under that name.

Select a filter permission:

• Private – The author has full access to the filter. Other users have no access to private filters.
The author can copy Private filters to other users and those users will become the authors of
the copies.
• Public (Read Only) – These filters can be viewed and run by all users. The author of a Public
(Read Only) filter is the only user permitted to edit, schedule, or delete the filter.
• Public (Read-Write) – These filters can be viewed and modified by all users. Any user with
the same permissions as the original author can edit, copy, run, delete, or schedule the filter.
The last user to change the filter is listed as the author.
Filters you create and save are available for your use later. The saved filter will also be available as
a Metadata report at Reports>Saved reports. The report will be available to you to export or delete.
Refer to Saved Reports.
The Dashboard checkbox makes the filter available as a report at the Custom Metadata Widget on
the Dashboard.
To change the filter, refer to Metadata Search. If you change an existing filter, an asterisk (*)
displays next to the filter name. Click . You can choose to Update the existing filter or
to save your changes as a new filter.
Note: You can only save changes to the default filter under a new name.

Click to select a new layout. Refer to Layouts and Views.

Click to export metadata. Refer to Export to Excel.

Fidelis XPS User Guide 130


Middle Row
The middle row provides the ability to change the filters, based on time or search criteria. Refer to
Metadata Search. It also provides an interface to Investigator to save your filters.

To change the time filter, click the current time selection to display a drop down list. The
default for time is Today (from 12:00 am to the current time). You can select from time presets to
filter data from the last hour to the last 7 days. You can also select All Data. Your choice of time
period will impact the performance of the metadata search.

You can enter a specific time and date in the text boxes or click to select a date and time from
the calendar.

Use the sliding bars to select the hour, minute, or second. Click Done when finished.
To enter a range: enter a later time and date at the To text box. Click Apply when done.

Add Filter to Investigation: Click and select Add Filter to Investigation. Refer to Investigator.

Bottom Row
The bottom row includes information about the data including the last time new data was retrieved
from Collector, the number of rows to display per page, and the ability to move through the pages
of data.
Last Search: Indicates how long it has been since data was retrieved from the Collector. Click Last
Search to retrieve new results and refresh the Metadata page. By default, the last results are
cached and retrieved, even if you reload the page or navigate to another page then return to the
Metadata page. Clicking on last search or changing the search parameters initiates a new search.
Click Cancel Search to stop a running search, if desired. This cancels the search in all views. You
can click Refresh to resume the search.
Transactions per Page: You can select how many transactions display on each page. The options
range from 25 to 1000.
Previous, Next: Click Previous or Next to move to the next page in either direction. Clicking a page
number takes you to another page of transactions.
The Collector name This name will be on the top right of the Metadata page. If available and if
you have the proper user permissions, you can select another Collector.

Fidelis XPS User Guide 131


Layouts and Views
The Metadata>Explore page enables you to use four different layouts with each containing
between one to four panes.

Click and select from the drop down list.

You can resize each pane in a layout if needed and specify a view for each.
To change a view, access the drop down list at the top of each pane.

The data displayed in each pane reflects the applied filters and page size, except for the Group
Chart. As you manipulate the data within one view, it may impact the other views.
The Group Chart reflects all data available within Collector that matches the filter, but is not
influenced by the page size.
The view selection for each layout is saved. So if you choose Tabular and Details view for layout 2
and switch to layout 3 then switch back to layout 2, the Tabular and Details view will display. These
settings are kept even if you log out and log in again.
The sections below provide a description of each view.

Fidelis XPS User Guide 132


Tabular View
The Tabular view provides a list of the network transactions stored on the selected Collector. This
view shows metadata transactions grouped into sessions. Sessions are differentiated with deeper
and paler shades on the left side of the Tabular View. To display partial results quickly, the
database scan is split up into small timespans. The search will continue until all transactions
display for the selected rows per page -- up to 1000 transactions or until the entire selected
duration has been scanned.

Figure 48. Metadata: Tabular view

In Layout 1, Tabular View contains a icon. Click to view Metadata Details for that transaction.
Click to return to the Tabular View. The only displays for Tabular View in
Layout 1

Click and select Add Transaction to Investigation. Refer to Investigator.

Click to select or deselect columns. Refer to Columns for a description of available


columns. You can also resize columns at the column heading or change column order by using
your mouse to drag columns to another location. Click the Timestamp heading to change the sort
order. Sorting is only possible by Timestamp.
You can click an item name to add it to a search, exclude it from a search, or create a new search.
Refer to Search by Item.
When you click a transaction in the tabular view, the selected transaction becomes highlighted in
green. If you are using multiple views in your layout, the Metadata Details view will show all
transactions of the selected session and the graphical view will highlight the chosen transaction.

Fidelis XPS User Guide 133


Metadata Details
The Metadata Details view presents the decoding tree associated with all transactions in the
session. The tree provides a collection of decoding paths – one for each content-bearing object, or
leaf node on the decoding tree. Alerts are associated with a single transaction or leaf node. While
the Tabular View is a collection of transactions found on the network, Metadata Details will present
all transactions of a single session. Therefore, several transactions may share the same details
page.

Figure 49. Metadata Details

Click to see basic information about the session at the top of Metadata Details or click to
close this information. The basic information includes client and server IP address, port, and
country information and sensor name. The session ID is also displayed -- a unique identifier for
each session.
• Arrows indicate the direction of each transaction. The arrow indicates that the direction
is from the client to the server. The arrow indicates that the direction is from the server
to the client.
• The icon indicates that this node contains subnodes.
• The icon indicates that this node does not contain subnodes
If more information is available, you can click to expand. Click to close.
You can click an item name to add it to a search, exclude it from a search, or add it to an
investigation. Refer to Search by Item.
The Metadata Detail view displays 50 items by default. If there are more transactions in a session a
node with: load more … is displayed at the end. By clicking on this node 50 more transactions will
be loaded.

Fidelis XPS User Guide 134


If there are related Alerts to this session, displays with a count at the upper right
corner. Click to go to the Alerts page to view the alerts.

Graphical View
The Graphical View displays metadata that matches selected filters. This view contains a main
display with a y axis that displays IP addresses and an x axis that indicates time or sequence of
transactions. The x axis shows the time or sequence between the first and last transaction and is
relative to selected filters.
Vertical lines show individual transactions. Their colors correspond to the color of the individual
item type selected at Color Type in the right pane, such as protocol or file type. Each vertical line
provides high level details of the transaction within the view. Mousing over the vertical line will
display all metadata associated with the transaction. It will also highlight the client and server IP
addresses in the Connection View.

Click a vertical line to highlight the transaction in all views. This action will also reveal the and

icons. Click to add the transaction to an investigation. Click the to pin the transaction,
which will remove the popup while remaining on the highlighted transaction across all views.
After you have pinned a popup for a vertical line, you can click an item in the pop up and then
either select to add it to a search, exclude it from a search, or create a new search based on the
selected item.
Curved lines illustrate sessions.
You can zoom into a specific area to focus on specific transactions. As you zoom in, each
transaction line lists protocol and other information.

Figure 50. Metadata: Graphical View

Navigating the Graphical View


The bottom pane shows a summary of the main display and provides the ability to navigate. Place
your cursor in this pane to focus on a portion of the main display or to move to a different part of
that display.

Navigation controls help you move around the display or zoom into or out of a specific
area. Clicking anywhere in the bottom view or in the upper view (not on items) will reset
the zoom.

Fidelis XPS User Guide 135


Changing the Graphical View
The right pane enables you to select different items for display in the graphical view.
X-Axis enables you to select Sequence/Time: Select Time to show when transactions occurred.
Select Sequence to display transaction in the order that they occurred.
User Labels: Select one or more labels for transactions to show in addition to the labels that are
automatically displayed by the system.. User Labels also display vertically next to each transaction
and may require a zoom to view them.
Color By: Select either Action, File Type, Protocol, Server Port, Tag, or Tunnel. The types of
transactions and the colors that they display in are determined by your selection.

Connection View
The Connection View displays flow information between hosts found in the metadata based on
current filters. A circle represents the IP address of a host or server. Lines between the circles
represent the transactions between the IP addresses.
Mousing over a circle displays a popup that lists the IP address represented by the circle. It will
also highlight the IP address in the Graphical View. If multiple connections emanate from an IP
address this is indicated by a cluster of dots.
Mousing over the line displays a tool tip that indicates the type of transaction and how many
transactions are on the current Metadata page. The transaction type is shown if you selected a
partition type.

Figure 51. Metadata: Connection View

Fidelis XPS User Guide 136


You can click on an IP address or line to access search options. Refer to Search by Item.

You can view different information in the Connection View by selecting a


different item to display for each connection. You can select from: No
Partition, Filetype, Protocol, Server Port, or Tunnel. Once selected, items
display in different colors in the legend and in the main display. For example,
selecting Filetype displays all available file types, each in a different color. If
you select No Partition, then all lines will display in the same color. Mousing
over these lines will indicate the number of transactions, but not the type.
Click an item such as the HTTP protocol or a line in the connection view to
access search options. Refer to Search by Item. If you selected No Partition,
you will not be able to click on these lines to access search options.

Group Chart
Group Chart enables you to group data by selecting one or more columns to apply a grouping. The
data in the chart represents all transactions that match the filter criteria and is not limited by the
selection of the number of transactions per page.
If a search is running you can click Cancel to stop the search at a Group Chart. The search will
continue at other views.
Transactions are grouped by the selected columns.

Click to select or deselect columns. You must select at least


one. Click Apply to save your selections or Cancel to return to Group
without making changes. Refer to Columns for a description of available
columns. You can also resize columns at the column heading or change
column order by using your mouse to drag columns to another location.
Click the Transactions heading to change the sort order.

The top pane of the Group Chart displays grouped data in rows. Click Limit to select between 10
and 1000 rows. The bottom pane displays data in a bar chant. The x axis displays the transaction
count. The y axis shows how transactions are grouped according to column selections.

Fidelis XPS User Guide 137


Clicking a bar highlights the corresponding row.

Figure 52. Metadata: Group Chart


You can click an item name to add it to a search, create a new search, or exclude it from a search.
Refer to Search by Item.

Column Items
Column items listed below can be selected for Tabular View and Group Chart with the exception of
Transactions and Timestamp. Transactions applies to Group Chart and Timestamp applies to
Tabular View.

T a bl e 1 3. C ol u m n It e ms

Column Item Description

Action Any action taken by a sensor in reaction to a policy violation


detected for this transaction. Action might be none.

Client Initiator host of the session

Client Country The country information derived from IP address of the client.

Client IP The IP address of the client

Client Port The TCP port used by the client


Client port information is not available for metadata from Mail
sensors.

Decoding Path The decoding path of the transaction

Dir The data flow direction of the transaction: either client to server
or server to client.

Duration The length of the transaction in seconds

Filename Name of the file in the transaction

File size Size of the file

Fidelis XPS User Guide 138


Column Item Description

File type Type of file

From The From field extracted from email (if any) or other protocols.

Host Host name

Malware Name The name of the malware

Malware Type The type of malware

Malware Severity The severity of the malware

MD5 MD5 associated with the file in the transaction

Referer The referer field from the HTTP header

Rel Session ID Session identifier used to identify a session in network


communications

Protocol The application protocol in the transaction

Sensor The sensor that recorded the session

Sensor UUID A sensor's unique UUID (Universally Unique Identifier)

Server County The country information derived from the IP address of the
server

Server IP The IP address of the server


Server IP information may not be available for metadata from
Mail sensors.

Server Port The TCP port used by the server


Server port information is not available for metadata from Mail
sensors.

Session Start The start time of the session

Spool The Fidelis XPS sensor module that generated the event

Subject The Subject field extracted from email (if any) or other protocols

Tag The tag field inserted by the sensor when a transaction triggers
on a rule that has an action of Alert or Tag Metadata. A
transaction could have multiple tags associated with it.
Refer to chapter 7 in the Guide to Creating Policies.
Note that in such cases, the advanced search operators such
as: Equals, Isn't Equal, Contains, Doesn't Contain apply to any
of the tags associated with a transaction.

Timestamp The time when the session data was stored by the Fidelis XPS
Collector. Format is YYYY-MM-DD HH:MM:SS. Example: 2014-
07-02 :27:11

To The To field extracted from email (if any)

Transaction A unique identifier of the transaction.

Fidelis XPS User Guide 139


Column Item Description

Transactions Number of transactions grouped together in the Group Chart

Transport The transport protocol

Tunnel The tunneling protocol (if any)

URL The specific URL involved in the transaction (if any)

User The User field extracted by any protocol that carries a user field

UserAgent Application using the HTTP as transport

X-Forwarded-For HTTP header field used for identifying the originating IP address
of client using an HTTP proxy

Metadata Search
Metadata includes multiple ways of searching: Simple Search, Search by Item, and Advanced
Search.

Simple Search

You can enter criteria into the Search text box and click Enter or . When you enter data,
CommandPost will parse the information, determine the information type, and apply the appropriate
filter value to the search. If you enter a new search value, the previous value will be overwritten.
Note that the search entry field is limited to 100 characters.
If no time range is specified Today’s data will be used. To change this, specify a time.
To provide multiple search criteria, use the Advanced Search feature.

Search by Item
You can add search criteria using individual items that display in the views. Nearly all items in rows
are available for search options. If a displays next to an item when you mouse over it, you can
click to open search options. A list of search options displays that enables you to add the item to a
search, create a new search based on this item, or exclude it from an existing search.

Note: Creating a new search eliminates any previously selected search items.
At the Graphical View, Group Chart, or Connection View, you can also select transactions, IP
addresses, or sessions for search options.
Individual display items to the right of the Graphical View or Connection View such as file types or
protocols are available for search options.
Your selection displays at the top of the Metadata page. Note how adding an item changes the data
in other views. For example, selecting a Server IP address at the Tabular View changes what is
displayed in the Graphical View and in the Connection View.

Fidelis XPS User Guide 140


If no time range is specified Today’s data will be used. To change this, specify a time.

Advanced Search
The Advanced Search enables you to select multiple fields and values to narrow your search and
return transactions that meet all of the criteria.
Any search criteria previously entered in a simple search or time filters will display in the Advanced
Search. Click Clear to clear all search criteria.
To access the Advanced Search, click Advanced at the top of the Metadata page.

Figure 53. Metadata: Advanced Search


To enter values for Advanced Search:
1. Select a time filter data from the last hour to the last 7 days. You can also select All Data.
Select Custom Time range to enter more specific criteria. Enter a specific time and date in the
text boxes or click to select a date and time from the calendar. You may enter only a start
date to find all data from start until present. You may also enter only an end data to display all
data up to the specified date.
2. Select the logical operator, AND or OR. AND requires that all conditions are met when
searching for matching transactions. OR requires that only one criteria is met when searching,
3. Select search criteria at the drop down selection. When you click the selection, a list displays.
You can type in the text box or select from the list. As you type, the list of available search
criteria will change to match your typing. Search criteria are described at Advanced Search
Criteria and Column Items. Many of the search criteria are also decoder attributes and are
described in Decoder Attributes.
4. Select an operator for the value. Operators are available depending on the search criteria
entered. Choose from the following:
Contains =~ Contains the listed values (for non-numerical values).
Does Not Contain !~ Does not contain the listed values (for non-numerical values).
Equals = Equals the numerical value entered.
Does Not Equal != Does not equal the numerical value entered.
Greater than > Greater than the numerical value entered.
Less than < Less than the numerical value entered.
Regular Expression ~ Provides the ability to do a pattern search on one regular expression at a time.
Is in List [IN] Searches for a series of values.
Is Empty [ ] Searches on empty fields.
Is Not Empty [ ] Searches on fields that are not empty.
5. Enter a value. You can enter comma-separated values in the text box, but not with the
operators: Greater or Less than, or equals or does not equal. With the IN operator, you must
press Enter after entering a value to separate it from the next entry. You can copy a string of
values and paste it into another value text box.

6. Click to add new line of search criteria. Click to delete a line. Clicking moves a
line of search criteria to a subsection of the previous line. Click returns search criteria to

Fidelis XPS User Guide 141


the main or parent level.
The first line of search criteria is connected to Time Range with AND (all conditions are met).
If desired, you can change this to OR (any condition is met). Subsections of a main entry of
search criteria depend on the parent and will be opposite of the parent.
In the example below, you can change the first AND that connects Time Range to other
search criteria to OR. This will automatically change connections for all subsections.

7. Click Apply. You can also click Cancel to remove all values.
Metadata Search results display in a list at the top of the page.

Click to delete the search criteria. Click Refine or click in the advanced search results to
return to the advanced search. Advanced Search displays with the previously selected search
criteria.
Click Simple to start a simple search. This deletes the advanced search criteria previously
entered.

Fidelis XPS User Guide 142


T a bl e 1 4. A d v an c e d S e ar c h C ri t er i a
Advanced search can be based on any column or decoder attributes. Refer to Column Items or in
Decoder Attributes. In addition, the following search criteria is available for advanced search.

Search Criteria Description

Any Country Country information

Any Email Email address

Any IP IP addresses

Any Port TCP port information


Port information is not available for metadata from
Mail sensors.

Any String Any string to search on

Sensor UUID A sensor's unique UUID (Universally Unique


Identifier)

Export to Excel
Export Metadata to Excel or other application that can accept a tab-separated file.

1. Click . at the top right of the Explore page.


2. Select criteria for the export file: You can specify a number of Metadata transactions, or all
the transactions in the list.
CommandPost limits number of rows that are included to 100,000. Users should also
understand limitations of their version of Excel (or other spread sheet applications) that may
require the reports to be limited using the options provided.
3. File Options: Click to compress the exported file, if desired.
Note: Large numbers of transactions can result in a large file. Using
compression will reduce download time.
4. Column Options: includes multiple options:
Export columns in Tabular view exports only the columns currently selected in the Tabular
View.
Export all columns export all database columns.
Customize export columns lets you select which columns to export
5. Include additional attributes buffer: If you click Customize export columns, the option to
include additional attributes buffer will appear. Clicking this will include the entire attribute
buffer, which is used to render the metadata details and often contains more attributes than
the available columns in the Metadata list page. The maximum field size for each attribute
can also be larger in the attribute buffer compared to the corresponding column in the list
page.
6. Click Export to Excel. You can choose to open or save the file.

Fidelis XPS User Guide 143


Analytics
At Metadata>Analytics, you can specify analytic rules that run against metadata stored within one
or more Collector. Analytics provides a method to analyze behavior that spans multiple network
sessions. When analytic rule violations are detected, you can choose to generate alerts or to store
the results for details analysis. Generated alerts will fall into the normal workflow provided for all
alerts..
The Analytics page does not come with any predefined analytic rules.. All analytic rules must be
created by users.
The Analytics page has three main sections:
Filters appear on the left. If you have created many analytic rules, you may use filters to quickly
find analytic rules of a specific type or action. If you have included labels in your rules, you may
also identify analytic rules based on their labels. Click to hide the filters section or click to
open filters.
Analytic Rules appear in the center of the screen. This section provides a list of all analytic rules
that have been defined. Each analytic rule provides the name, type, action, author, last modified
date, and any labels applied to the rule. Clicking on the analytic rule provides the details on the
right of the screen.
Analytic Rule Details appear on the right side of the screen. Use this page to define your rule,
provide the action, and review results of automated run.

Analytic Rule Types


Two types of analytic rules can be defined: Event Rate and Sequence Rules. To add a new analytic

rule, click and choose the analytic rule type.

Event Rate
The event rate analytic rule can detect multiple occurrences of a specific event within a time frame.
For example, consider an analytic rule that identifies users who use FTP more than ten times in an
hour.

Fidelis XPS User Guide 144


Figure 54. Metadata Analytics: Event Rate rule type
The event can be defined as any combination of metadata using all available matching criteria
available in the advanced search of the Explore page. Refer to Advanced Search at the Explore
page.
The Group By value can be any column available within the metadata. If multiple values are
grouped, then the count has to be met over the combined group. For example, if Group By were
User and Client IP, the count would apply to each unique combination of User and Client IP values.
The result of this example is one alert (or result) of each user that uses FTP more than ten times
per hour. If a specific user were to violate this analytic rule many times, you may get one alert (or
result) for each hour during which they used FTP more than ten times. The result can be limited
(100 results is the limit in the example).

Sequence
A sequence analytic rule is used to find events that occur in sequence. Each event in the sequence
may or may not generate an alert using the Policy engine, but the combination of multiple events
would lead to the creation of an alert by identification of a sequence.
Sequence analytic rules can be used for a variety of purposes including, but not limited to
identification of a kill chain, insider threat, and data leakage. The example below creates a
sequence looking for the word “password” followed by a password-encrypted file within ten
minutes. Event 1 relies on a tag, refer to Combining Policies with Metadata to insert content
analysis results into the metadata. Event 2 would identify the password-encrypted file based on
metadata. The two events are correlated by the Client IP, so that an alert would be generated when
both events are detected on the same Client IP within 10 minutes.

Fidelis XPS User Guide 145


Figure 55. Metadata Analytics: Sequence rule type
Similar to the Event Rate analytic rule, the results can be limited (to 100 alerts in this example).

Combini ng Poli cies with Metadata


Fidelis policies use analytic rules that are a logical combination of the analysis of content, channels,
and locations. Refer to chapter 8 in the Guide to Creating Policies. Each rule is applied to one
network transaction and when a violation is detected, an action is taken. The action will create a tag
within the metadata whenever a rule generates an alert or when the rule action is set to “tag
metadata”. The value of the tag is the name of the violated rule.
To fully use the capabilities of metadata analytics, the tag value can be used. Metadata includes all
of the data available to channel and location fingerprints, but no content. Analytic rules can be
created to provide the results of content analysis into the tag value, and subsequently into analytic
rules.
Refer to chapters 3 and 4 in the Guide to Creating Policies.
For example refer to Metadata Analytics screen shot above. In this example, the event requires
content analysis to identify the keyword “password” in content. This word may appear many times
on the network and would create many alerts if the analytic rule were set to generate an alert.
However, the analytic rule could be used to simply tag metadata so that it can generate an alert if
subsequent network activity warrants.
When creating analytic rules, consider the impact of tags and create content-based analytic rules
appropriately.

Analytic Rules
The Analytic Rules pane displays a list of analytic rules sorted by selected filters. You can also find
analytic rules by entering an analytic rule name at the Search text box. Any that are found display
at the top of the list.

Click to copy an analytic rule. You can make changes to the copy and save it under a new
name. A copied analytic rule is a new analytic rule and this enables you to change the rule type.

Fidelis XPS User Guide 146


Click to delete an analytic rule. Select Yes at the confirmation dialog box to continue with the
deletion.

You can create a new analytic rule by clicking and select either Event Rate
or Sequence Rule. An example of your selection displays at the top of the rule pane.
A Sequence rule enables you to define an analytic rule by the occurrence of an event that you
specify.
An Event Rate rule enables you to define an analytic rule by a count of repeated events.
To edit an analytic rule, select it from the list.
Note: You cannot change the rule type for an existing analytic rule.
1. Enter a name for the rule.
2. Define an event. Each analytic rule needs at least one event. The event can be defined as
any combination of metadata using all available matching criteria available in the advanced
search of the Explore page. Refer to Advanced Search at the Explore page.
3. Specify the context in which one or more events violate the rule
For Event Rate rules:
• Specify a value to group the event by. For example, grouping by Client IP would look at all
events on each unique Client IP and apply the count to each value.
• Select the time period over which the time is applied. You can select a rate (using the
greater than option) or a range (using the between option)
• Specify a count for the rule.
For Sequence rules:
• Select a time for an event to occur after the preceding event.
• Provide the Event Correlation context. You may choose any metadata item over which all
events must occur within the provided times. For example, if you define three events and
correlate the events by Client IP, then the analytic rule will identify those three events all
occurring over the same client IP.
4. Add General rule parameters (optional):
Enter comments if desired and select a label for the analytic rule or enter a new label. Rule
labels can help you to organize and find them later.
The General tab also shows the rule type and whether or not it was automated.
5. Define the rule Action:
Select an Action Type either Alert or Save Results.
Alert: Select to generate alerts. Alerts display at Alerts>List page. You will also need to select
the Alert Severity from Low to Critical and assign an Alert Management Group.
You can choose to limit alerts by entering a number or keep the default of 100 alerts.
Save Results: Select to save the results in a list on the Metadata>Analytic Results page. You
can also choose to limit results by entering a number or keep the default of 100.
Click Send email notification and enter an email address, to receive email notices of results
when the analytic rule is run.
6. For a new analytic rule, click Save New Rule. The analytic rule will appear in the list of
analytics rules and the Automation tab will appear. The Run and Save buttons will also
appear.
7. Click Run to run the rule. A window will appear to define the run.

Fidelis XPS User Guide 147


Figure 56. Metadata Analytics: Save and Run rule
• Collectors: define one or more Collectors to run the rule
• Date Range: provide the time range of data over which the analytic rule will run. Fidelis
recommends that you run new over a short time frame to identify the performance impact of
your new rule. Once you are comfortable with the performance, run the analytic rule over
longer time frames. Then automate the analytic rule so that it will continually be applied to
new metadata as it arrives at the Collector. Automation can be scheduled at the Automation
page.
• First Run: Define when to run the rule. Leave this blank to run immediately, or schedule the
run for a later time.
• Click Save and Run to save this run.
The Automation tab will present a summary of each run of the rule.

Fidelis XPS User Guide 148


Filters
Enables you to filter by Type, Action, or Label. Each filter item under Type, Action, or Label has a
count of the total number of that match this filter.

Figure 57. Metadata Analytics filters


Type: the analytic rule type: either Event Rate or Sequence rule
Action: the analytic rule action: either Alert or Save Results.
Label: Rule labels created by users to help organize and retrieve them later. For example, you can
label all for the IT department with the label IT.
Click to create a new label. Enter the label in the text box and press Enter.

Click to delete a label and click Yes at the confirmation.

Click to edit a label and enter changes at the text box.


Select one or more labels. You can only select one filter type (Type, Action, or Label) at a time.
Click to clear all filters.

Fidelis XPS User Guide 149


Automation
At Metadata>Automation, you can schedule analytic rules to run automatically at specified time
intervals and review the results of all automations. The screen offers four panes:
History: The history pane on the top left provides a summary of all automated runs.
Automation: On the bottom left, the automation pane provides a summary of each automated rule
that has been run. Clicking on a row in the table will modify the Automation Details and Run History
panes on the right side of the page.
Automation Details: in the top right provide details of the selected automation.
Run History: in the bottom right displays the run history of the selected automation.

Initially, the automation page will be empty. Click to add an


automation.

History
History provides you with a historical view of automated analytic rules. It should be used as a guide
to identify optimal time slots for scheduling automations.

Figure 58. Metadata Automation History


1. Select a time period of either the last 24 hours, last 3 or last 7 days.
2. Select a Collector from the drop-down list if CommandPost has more than one Collector
available.
3. Click Name to display or hide all analytic rule names and their associated processes in the
History bar chart. You can also select or deselect individual analytic rules to narrow your
results.

4. Expand or contract the slider bar as needed to focus on specific


days or times. You can also select and move the slider bar to view another portion of the
bar chart.
Each vertical line represents a run of the analytic rule. The legend on the right provides a color
code associated with each automated analytic rule. The red highlighted rule is associated with the
selected rule in the Automation pane. Mouse over a line in the History view to display information
about the process: rule name, the Collector the rule is assigned to, start time, duration, status, and
the number of results.

Fidelis XPS User Guide 150


Automation
The Automation pane lists all automations and provides information about each. You can sort the
list in ascending or descending order by clicking on a column name.
Automation statuses are listed below. You can cancel an automation at Run History if status is
Standby or Running. Clicking Cancel can take a minute or two to occur.
• Standby-- The automation is waiting to run
• Running -- The automation is running
• Completed-- The automation has run.
• Disabled-- The automation is disabled
• Canceled-- The automation was canceled
• Error-- An error occurred while the process was running.
Select an automation at the list. The details of the selected automation and the Run History panes
are changed to reflect the selection. The Last Run column provides a snapshot of the Run History
pane.

Click to edit the rule automation.

Click to delete an automation and confirm the deletion at the confirmation dialog box.

Automation Details
Automation Details displays specific information about an automation selected at the Automation
pane.
To create a new automation:

1. Click ..
2. Select a type: either rule or feed.
Rule refers to analytic rules. To define a rule, refer to Analytic Rules.
Feed refers to Collector feeds.
Refer to chapter 10 in the Guide to Creating Policies.
If any Collector Feed is enabled, you can select Fidelis Insight Threat Feed to schedule the
time of day to run the feed analysis. This automation will be run daily. If no Collector Feed
is enabled, you cannot automate feed analytics.
3. Select a specific rule or feed.

Fidelis XPS User Guide 151


Figure 59. Metadata Automation create or edit automation for a rule
4. Select a schedule for the rule automation either one time, automatic, every 1, 6, or 12
hours, daily, or weekly. Feed automation can only be run daily.
One Time: If you choose to run the analytic once, you will specify First Run and a Date
Range. You may leave the First Run blank to run the rule immediately or to specify a future
date when the rule should be run.
Date Range: Refers to the Collector data over which the rule will be run. This will appear if
One Time is chosen as the Schedule. For new rules, you should enter a small time frame
to gauge the duration. Once you understand any performance impact, you can consider
running the rule over more (or all) data in your Collector. After the rule has been run over
all data, you will want to choose a different schedule frequency to run the rule periodically
against new metadata.
Automatic: If automatic is scheduled, Fidelis XPS will determine a run frequency that is
sufficient for your rule. Hover over the to view the run frequency that was chosen.
When the rule is run it will apply to only new metadata that arrived since the prior run.
Defined time frames: Include hourly, six hours, twelve hours, daily, and weekly. If you
choose a define time frame, the rule will run at the given frequency. When the rule is run it
will apply to only new metadata that arrived since the prior run.
5. Select one or more Collectors for the automation.
6. Click Enabled to activate the automation.
7. Click Save.
The new automation displays in the Automation pane.
To Edit an existing automation:
1. Select the automation from the Automation pane by clicking the row in the table or by
clicking .
2. The Type and Rule are already defined and cannot be changed.
3. Modify the schedule to change the run frequency of the rule. Refer to the definition of the
schedule in the New Automation description. Note: feed automations will run daily and
cannot be modified.
4. Add or remove Collectors from the automation.
5. Click the Enable box to enable or disable the automation.

Fidelis XPS User Guide 152


Run History
Run History enables you to view the run history for an automation. Each time the automation is run,
a row is added to the table to display the run time, duration, and action as number of results or
alerts.
The line graph provides a run time history charting the run duration or results in the vertical axis
and date of the run in the horizontal axis.
To use the Run History:
1. Select an automation at the Automation pane.
2. Choose the vertical axis for the line graph either Duration or Results. Duration shows how
long each automation ran. Results indicates the number of results as alerts or analytic
results. Both selections enable you to see trends over time.

3. Expand or contract the slider bar as needed to focus on specific


days or times. You can also select and move the slider bar to view another portion of the
bar chart.
The Run History table shows results by Collector, Run Time and Duration and Action. You can sort
each column in ascending or descending order by clicking on a column name.

The Action column displays the number and type of results with a icon next to the result.

If the automation has results, clicking takes you to the Analytics Results page. This page
provides additional information about each of the results. Refer to Analytics Results.

If the analytic rule action was alert, clicking or the number of alerts, takes you to the Alerts List
page. Alerts will be grouped by the rule, Collector, and by the run start time. Refer to Alert List. If
the alerts were deleted or purged, the Alert List will state, No data available.
Note The alert count is updated when the Collector generates the alerts and it may
take some time before the alerts are inserted in the CommandPost database and are
ready for viewing.

If there are no results, the Results column states None and the icon does not display.

Fidelis XPS User Guide 153


Analytic Results
Metadata>Analytic Results displays the results of all analytic rules with an action of Save Results. It
should be used as an alternative to alerts when new analytic rules are being developed and there’s
uncertainty about the rule’s precision. The page is presented in four panes: Time Range, Group by
Rules, Results, and Result Details.

Time Range
Time Range enables you to modify the view of your results. The time range is displayed at the top
of the page with the time selector on the left and a bar chart of results on the right. At the bar chart,
results are graphically displayed. You can mouse over the bar chart to see the total number of
results and the date and time that the results occurred. You can expand or contract the slider bar
as needed to focus on specific days or times. You can also select and
move the slider bar to view another portion of the bar chart. Note how the listed results change in
the table.
The time selector offers selections of 24 hours, 3, 7, or 30 days, and all data. The scale of the
horizontal axis of the bar chart will change as you modify the time selection..
Each bar in the chart may be clicked to view the results from that specific time frame. Depending
on the scale of the chart, the bar may represent one run or many.
If you select a bar, a refinement to the time range will appear below the selector. Click the to
remove the refinement from the chart. You will notice the refinement if you enter the Analytic
Results page by clicking on the results link or icon at the Automation or Analytics pages.

Group by Rules
Below the time range pane, to the left is the Group by Rules pane. If the results of the selected time
range include results from multiple rules, each will be listed. You may use the search interface to
find results from a specific rule. Clicking the rule name will change the data available in the Results
pane and will change the highlight on the left to associate the results with the rule that generated
them.

Click to expand the rule and show details of the past ten runs. You can click on any specific
run to limit the results to that single run..

Click to hide the Group by Rules pane. Click to show the pane.

Results
The Results table shows each analytic result in a separate row. Each row represents a violation to
an analytic rule. Information about each result includes event time (the date of the metadata that
violated the analytic rule) , the number of transactions in the result, the run time (the time that the
rule was run) and the unique context or group by item that violated the rule..

At each row, you can click to go the Metadata>Explore page to see detailed information about
the result.
The data in the table depends on the selections made at the time range, Group by Rules, and bar
chart.

Fidelis XPS User Guide 154


Result Details
Result Details provide the complete metadata associated with every transaction that violated an

analytic rule. Click to navigate through the first eleven transactions. Click
to go to the Metadata>Explore page to view all transactions in the rule violation.
The data provided here is the same available at the Alert Details page for analytic rules that specify
an action of Alert. Alerts are provided in the analyst workflow as alert tickets and can be exported to
third party SIEM systems. Results are not placed into the analyst workflow and provide a method to
develop and test analytic rules without overwhelming the analyst.

Fidelis XPS User Guide 155


Performance Monitor
Performance Monitor enables you to monitor Collector performance. This enables you to more
effectively schedule automations so that they do not impede performance.
To monitor performance:
1. Select a time period, either the last 24 hours, 3, or 7 days.
2. Select a Collector.
Information displays graphically for Write Throughput, Automations, and User Queries.
You can expand or contract the slider bar as needed to focus on specific
days or times. You can also select and move the slider bar to view another portion of the bar chart.
For the Automations and User Queries you can select a portion of the bar chart and zoom in to see
more detail.

Write Throughput
This chart displays a trend line that indicates the number of metadata rows written per hour. The
bar chart in this section enables you to view performance trends over time. The performance will
normally fluctuate over time as the volume of data available on your network fluctuates.
Automations scheduled during peak network activity may run longer than automations scheduled
when network activity is less.

Automations
This chart graphically displays rule and feed automations for the selected time.
Click Name to display or hide all rule names and their results in the bar chart. You can also select
or deselect individual rule or feed names to narrow your results.
Mouse over a line in the bar chart to display information about the automation: name, status, start
time, duration, status, and the number of results. For details about rule statuses, refer to
Automation.

User Queries
User Queries graphically displays search run times associated with use of the Metadata>Explorer
page. The y-axis shows the number of parallel query executions while the x-axis is the same
timeframe as the other charts on the page. Mouse over a line in the bar chart to display more
detailed information for a user query: start time, duration, query parameters such as rule type,
sensor name or times, and whether or not the query is running (true) or not (false). You may want
to schedule automations for periods of low user activity.

Fidelis XPS User Guide 156


Chapter 8 Saved Reports
Saved Reports enables you to access and manage all your reports from one location. You can use
29
criteria entered at the Alert List or Summary Report pages and save these reports which are
then available at the Report List.
To access the list of your saved reports, click Reports>Saved Reports. When you first access the
list, it displays default system reports. You need full access to Saved Reports/Summary Reports to
view these reports. Refer to Define User Roles.

• System Reports – These reports ship with Fidelis XPS and include: Default, Alert
Management, Malware, Malware by Host, Malware by Type, Label, and My Alerts. You can
run these reports or use them as the basis for a new custom report. If saved as a custom
report, the original system report is not affected. System reports are also available at the Alert
List page. Refer to System Reports for Alerts.
System Reports have the Public (Read Only) permission. You run these reports or copy and
save them under different names.
• Custom Reports – Customized reports allow you to control the contents and the display of
your report. From the Saved Reports page you can run, modify, and schedule these reports.
Refer to Create Reports.
• Saved Summary Reports – These are Summary Reports that were created and scheduled
at the Summary Reports page. From the Saved Reports page you can run, modify, and
change the execution schedule. Refer to Create Summary Reports.
• Metadata – These are reports created and saved at the Metadata page. You can export these
reports or delete them.

29
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 157
Figure 60. Saved Reports page

Report Permissions
Reports have one of the following permission levels described below. The report author refers to
the user that created the report.

• Private – The report author has full access to the report. Other users have no access to
private reports. The author can copy Private reports to other users and those users will
become the authors of the copies.
• Public (Read Only) – These reports can be viewed and executed by all users. The author of
a Public (Read Only) report is the only user permitted to edit, schedule, or delete the report.
All System Reports are Public (Read Only) and cannot be deleted by any user.
• Public (Read-Write) – These reports can be viewed and modified by all users. Any user with
the same permissions as the original author can edit, copy, run, delete, or schedule the
report. The last user to change the report is listed as the author of the report.
Public reports can be copied in a process known as Report Cloning. The new report is exactly the
same as the original, with the same report contents, and permissions. The author of the cloned
report will be the user that made the copy.
The permission of any report can be changed when the report is saved.
All reports execute under the permissions of the report author. Only those alerts available to the
author by sensor and alert management group assignment will be available in the report. In the
case of Public (Read-Write) reports, the author is the last user to modify the report.

Fidelis XPS User Guide 158


Hierarchical Management of Reports
If you are logged into a CommandPost that has been configured with Subordinate CommandPosts,
an extra column of checkboxes will appear in the report list to the far right. The Push button will
also be available at the top of the page.
To push reports to Subordinate CommandPosts:
• Use the checkboxes to select reports to be pushed to Subordinate CommandPosts.
• Selected reports will be pushed when the Push button is clicked.
• If there are multiple configured Subordinate CommandPosts, only those set up to receive
reports will receive the reports. Refer to Set Up a Subordinate Relationship.
• After clicking Push, reload the page and click the row of any selected report to view the
status of the Push for each Subordinate CommandPost. Once the process is completed,
the status will remain unchanged until the next report Push. Status values include:
• In progress: the push process has begun.
• Synced: the push is complete. Subordinate is synchronized with the Master for the
selected reports.
• Failed: the process failed. If one Subordinate is not available or if a maximum limit of
reports has been reached, the push will fail.
• You need to reload the page to see the updated status values.
• When reports are received by a Subordinate CommandPost, any existing reports that share
the same name will be overwritten.
• On the Subordinate CommandPost, received reports will show the Author as the person
that performed the push. Report permissions will be maintained.
Note: the person performing the Push operation must have an account on the
Subordinate CommandPost with a role that includes Full access to Saved
Reports/Summary reports.
System reports are included with all CommandPosts and cannot be altered or
pushed.
Reports are executed under the privileges of the report author. When pushing a
report, note your role, sensor assignments, and alert management group
assignments on the Subordinate CommandPost. Those assignments will dictate the
results of the report when executed.
To delete reports from a Master CommandPost:
Click Delete and you will be provided with an option to delete locally (only on the Master
CommandPost) or to delete globally (Master CommandPost and all Subordinates).. Note: The
person performing the delete must have an account on the Subordinate CommandPost with
a role that includes Full access to Reports. You must also be the report author for private
and public read-only reports.

Fidelis XPS User Guide 159


Report Details and Buttons
Click a report to see report details. The author of the report is listed with its permissions. Create
and modify times are also listed. These times and the author information are assigned by
CommandPost cannot be changed directly.
Push Status will display if the report was selected for push to a Subordinate CommandPost. Refer
to Hierarchical Management of Reports. The Push status provides the current state of the Push
either: requested, started, synced, or failed. If the Push failed, an error message is also provided.
Status lists the CommandPost and user requesting the Push and when the Push started and
finished. If one slave Subordinate is not available, the push will fail.
The following buttons display depending on the report selected and the permissions associated
with it.

• Run enables you to execute the report. This is active for all reports. Refer to Run Reports.
• Edit takes you to the Custom Report page to edit criteria and save the report. Refer to Create
Reports.
• Modify is available for saved Summary Reports and takes you to the Summary Reports page.
Refer to Create Summary Reports.
• Delete is available for Custom and Summary Reports. Refer to Delete Reports.
• Schedule enables you to enter scheduling information. This button is active for Custom
Reports.
• Modify Schedule also enables you to enter scheduling information and is active for Summary
Reports. Refer to Save and Schedule Reports.
• Export enables you to save the report definitions in a file on your client workstation. Exported
reports can be imported. Refer to Import.
• Export All enables you to save all report definitions to your client workstation.

Create Reports
Depending on the permissions of each report, reports can be modified, scheduled for automatic
execution, and copied to other users.
There are several ways to begin creating a report:


30
Click Customize Report at the Alerts>List page. All alert search, filter, time selection, and
group criteria is selected in the Custom Report page. You can change any parameter and
save it.
• Click the appropriate report at the Saved Reports page and click Edit. The Custom Report
page displays with any criteria selected for the saved report. This enables you to create a new
Custom Report based on a system report or an existing report.
• Click Create New Report at the Saved Reports page.
The Custom Report page contains the following sections that you can expand or collapse as
needed:

• Search provides an interface to identify alerts by a search rather than an exact match. Search
terms are typed into the available input fields.
• Filters provide an interface to identify alerts by an exact match of one or more alert fields.
Values are selected by choosing one or more values from the available lists.
• Time Range provides an interface to identify alerts by time.

30
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 160
• Columns provides a control for the information available in your alert report.
• Group By provides a control to summarize and chart the results of your report. The fields
available for grouping are those chosen as your primary columns for the report.

Search
To search, enter criteria into one or more of the text boxes within Search.

Figure 61. Custom Search: Search

Fidelis XPS User Guide 161


T a bl e 1 5. S e ar c h Fi el ds

Search fields Description

Alert ID Enter a single alert ID, a comma-separated list of alert IDs or a range.
Ranges are entered by a hyphen between the start and end of the range

File Name Searches the name of the file that caused the violation.

Forensic Data The search is applied over the forensic data field of the alert, as shown in
31
the Alert Details page. Note that some alerts will not contain forensic
data per policy definition.

From Searches on the From field.

IP:Any Searches on any IP address, either source or destination.


Note: Selecting Any IP overrides Source and Destination.

IP:Destination Enter an IPv4 or IPv6 IP address, a comma-separated list of IP addresses,


or a range. Ranges are entered by a hyphen between the start and end of
the range. Custom Search cannot accept resolved IP addresses, however,
other information is valid inSearch IP Addresses.

IP:Host Enter an IPv4 or IPv6 IP address, a comma-separated list of IP addresses,


or a range. Ranges are entered by a hyphen between the start and end of
the range. Custom Search cannot accept resolved IP addresses, however,
other information is valid in Search IP Addresses.

IP: Pair Specify the IP addresses on which to filter alerts. Each IP address can be
source or destination. IP Pair is used to find alerts where the source AND
destination match the pair. It is used to find communication between
specified IP addresses.
Any IP is used to match alerts where the source OR destination is within
the defined range. Any IP is used to find communication that involves a
specified IP address.
Note: Selecting IP Pair overrides Any IP and Source and Destination
IP.

IP Source Enter an IPv4 or IPv6 IP address, a comma-separated list of IP addresses,


or a range. Ranges are entered by a hyphen between the start and end of
the range. Custom Search cannot accept resolved IP addresses, however,
other information is valid in Search IP Addresses.

Malware Name Searches on the Malware Name.

MD5 Searches the MD5 hash value associated with the file.

Port: Any Searches on any port: source or destination.

Port: Destination Enter a TCP port number, a comma-separated list of port numbers, or a
range. Ranges are entered by a hyphen between the start and end of the
range.

Port: Source Enter a TCP port number, a comma-separated list of port numbers, or a
range. Ranges are entered by a hyphen between the start and end of the
range.

31
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 162
Search fields Description

Resolved IP:Any Searches on any IP address: source or destination that matches the
resolved DNS name.

Resolved IP: Enter an IPv4 or IPv6 IP address, a comma-separated list of IP addresses,


Destination or a range. Ranges are entered by a hyphen between the start and end of
the range. Custom Search cannot accept resolved IP addresses, however,
other information is valid inSearch IP Addresses.

Resolved IP: Searches on any IP source address that matches the resolved DNS name.
Source

Session Attributes This search is performed over the Channel Attributes of the alerts. The
value will match the name of a protocol or file format for which attributes are
available, the attribute name, or the attribute value. Refer to chapter 4 in the
Guide to Creating Policies for details about protocol or file formats and their
attributes.
Refer to Protocol and Format Decoders.
Refer to Enter Search Terms.

Subject Searches the value of the extracted Subject field.


Summary The search is applied over the summary field of the alert.

Target Target refers to the destination of the information. The value is protocol
specific. Examples include the destination URL, share name, or host name.
Target is based on extracted protocol information and not based on the IP
address of the data. In many network configurations, the IP address may be
an internal address corresponding to a local NAT server or proxy, whereas
the target represents the intended destination of the data.

Threat Score Searches for alerts that match the specified threat score. Enter search
values between 0 -100. If the alert does not include execution forensics, the
value is empty.
To search for alerts with a specific score enter the value. For example,
enter 4 to find alerts with a threat score of 4.
To search for alerts with a list of specific scores, enter a comma-separated
list of values. For example, enter 4,37,82,100 to find alerts with a threat
score of either 4, 37, 82, or 100. Do not enter spaces between the commas.
To search for alerts within a range of scores enter the range separated by a
hyphen. Be sure to not include spaces in your search text. For example, to
find all alerts with a score greater than 50, enter 51-100 into the search text.
To find all alerts with a threat score, enter 0-100 into the search text.

Ticket Content Searches the content of the alert ticket Subject and Comment fields. This in
the Alert Workflow Log section of the Alert Details page.

To The value of the extracted To field.

User Searches on information from the extracted User field.

UUID Enter a specific alert UUID number. This is an exact search.

Note: In searching IP addresses, the priority is IP Pair first, then Any IP, and finally
Source IP and Destination IP.
Note: Search terms entered for Summary, Forensic Data, and Session Attributes
follow the same syntax as described in Search for Alerts.

Fidelis XPS User Guide 163


Filters
Filters use an exact match to find alerts. You can use filters to limit the report to only those alerts
that match your filter criteria. If you select multiple fields, all are applied to the filter. The more filters
that you select, the more narrow your results.
When you click Customize Report from the Alert Report, you will notice that many search terms will
be shown as filters on the Custom Report Edit page.
This translation occurs because exact match filters perform faster than inexact searches. It also
allows you to save your report with the specific data matched by your search.

Figure 62. Custom Search: Filters

Fidelis XPS User Guide 164


T a bl e 1 6. Fi l t ers

Filter Description

Alert Actions Select an alert action.

Alert Management Select one or more alert management groups to which the alerts belong. All
Groups groups available in CommandPost are listed.

Components Select one or more sensors or Collectors.

Country: Any Select one or more countries for source or destination.

Country: Select one or more destination countries.


Destination

Country: Source Select one or more source countries.

Execution Searches on alerts based on their execution forensics status You can select
Forensics Status from: Failed, Not Submitted, Pending, Received, Rejected.

Format Type Select one or more file format types for the alerts.
Host Activity Select either detected or not detected on Carbon Black.

Labels Select one or more alert labels. Refer to Select Alert Actions to understand
how to apply labels to alerts.

Malware Type Select one or more malware types.

Policies Select one or more policies. This list displays all policies on CommandPost.

Protocols Protocol refers to the network protocol over which the violation was
detected.

Rules Select one or more rules. This list displays all rules on CommandPost.

Severity Select one or more severity levels. Severity could be low, medium, high, or
critical.

Ticket Owner An alert can belong to only one owner. However, if you enter a search with
multiple terms, the search will match an alert containing any one of the
terms (most other search fields require a match of all terms). For example,
a search for: Owner1Owner2 yields all alerts belonging to either Owner1 or
Owner2.
Also, a search for the term unassigned (with or without quotes) will display
all alerts that have not been assigned.

Ticket Resolution Select one or more resolutions for the alerts.


Ticket Status Select one or more statuses for the alerts.

With Malware Select to include or exclude malware.

Fidelis XPS User Guide 165


Time Range
Time Range enables you to specify a time period for your Custom Report and include trending
information.

Figure 63. Custom Search: Time Range


Time Range selections include:

• Last Login: reduces alerts to those that have occurred since the last time you logged into
CommandPost.

• Last 24 Hours, 7 Days, or 30 Days: provide shortcuts to reduce alerts to the prior day, week,
and month.

• Specific Hours: will display a text box to which you can enter a two digit number, N. Only
alerts occurring in the past N hours will be displayed. You can use this feature to reduce
alerts by partial days with granularity of one hour increments.
• Specific Days: will display a text box to which you can enter a two digit number, N. Only alerts
occurring in the past N days will be displayed. You can use this feature to reduce alerts to
those that occurred during a specific number of days.
• Specific Date: when you click the text box a calendar will appear. This reduces your alerts to
those that occurred on the specified date.
• Date Time Range: you can enter a range by entering start and end dates and times. When
you click a text box a calendar will appear. Select the desired date and use the sliders to
select a time. Click Done to enter the chosen date and [Link] reduces your alerts to those
that occurred during the specified range, including the specified dates and times.
Click Trending to graphically display the trend for all alerts within your current settings
Select time mode.
• Insert Time is the time when the alert was inserted into CommandPost.
• Alert Time is the time when the alert was created in the sensor.
Under normal operating conditions, these times should be relatively equal. Insert Time can differ
from Alert Time if alerts are imported from an archive file into CommandPost or if alerts are spooled
during database maintenance or CommandPost upgrade.
Selecting Insert Time will result in faster response from CommandPost.

Fidelis XPS User Guide 166


Columns
Columns determine what information is displayed in the custom report. You must select at least
one primary and one secondary row to run or save a report.

• Column Choices lists all columns that you can include in a report. Refer to the table below
that describes report columns.

• The Primary Row contains the columns that will display as the main columns for the custom
report. These columns can be sorted or used to group alerts.
• The Secondary Row contains additional columns that can be used to provide extended
information on the Alert Report. When the report is run within CommandPost, each primary
column is shown per alert. You can click the alert to open the Quick Summary to access your
secondary information. Secondary row columns can be used to filter alerts and to navigate to
other pages by following clickable information fields. When the report is scheduled for
automatic delivery, secondary rows are not shown as part of the report.
• Sort By displays columns selected for the primary row or those selected for grouping. The
selection will determine the order of your report.

Figure 64. Custom Search: Columns


To set up columns:

• To add a new column: Select one or more choices from Column Choices and click or
.

• To edit column order: Select one or more columns and click or until all columns are
in the desired order.

• To delete columns: Select one or more rows and click .

Fidelis XPS User Guide 167


T a bl e 1 7. R e p o rt c ol u m ns

Available Description
columns

Action The action taken by the sensor in response to the violation.

Alert Details
Icon Displays the icon at the location of your choice in the Alert List .

Alert Id Displays the alert ID. The alert ID is unique to a single CommandPost.
Refer to UUID for the alert ID unique across all components.

Alert Displays the alert management group to which the alert belongs.
Management
Group

CommandPost Displays information about CommandPosts.

Component Select one or more sensors or Collectors.

Compression Indicates the number of additional events represented by an alert. Refer to Alert
Compression.

Country: The country to which the destination IP address is registered.


Destination

Country: Source The country to which the source IP address is registered.

Filename Displays the name of the file that caused the violation. Will be empty if no file was
involved in the violation.
Format Type Displays the data format type that caused the violation.

From Displays the value of the extracted From field. The value is protocol specific and
most applicable to email or webmail. The value will be empty if the violation
occurred over a protocol that does not provide From.

Host Activity Displays host activity information as a red flag when the host reports activity
related to the malware detected on the network.. The column will be empty if there
was no activity on the host.

Insert Time Time when the alert was inserted into the CommandPost database.

IP:Destination The IP address of the recipient of the data. When available, both IP and resolved
host name are provided.

IP:Host The IP address of the host. The host usually identifies a workstation infected by
malware.
IP: Source The IP address of the sender of the data. When available, both IP and resolved
host name are provided.
Label Displays the label assigned to the alert.
Refer to Select Alert Actions to understand how to apply labels to alerts.

Malware Name Displays the name of the identified malware.

Fidelis XPS User Guide 168


Available Description
columns

Malware Type Displays the type of the identified malware.

MD5 Displays the MD5 of the file with the malware. Information displays in this column
if a malware event occurred.
Owner The name of the CommandPost user to whom the alert has been assigned.

Policy The name of the policy that was violated

Port: Destination The destination TCP port number


Port: Source The source TCP port number

Protocol The application protocol on which the violating transfer occurred.

Resolution Displays the resolution to an alert ticket that was closed. Resolution can take the
following values: Allowed, Action taken, No action taken, and False positive. Refer
to The Alert Workflow Log.

Rule Displays the name of the rule that was violated.

Severity Displays a level of severity. Severity could be low, medium, high, or critical.

Status Provides the status of an alert ticket, which can be new, open, or closed. Refer to
The Alert Workflow Log.
Subject Displays the value of the email subject line. The value is protocol specific and only
applicable to email or webmail. The value will be empty if the violation occurred
over a protocol that does not include email.

Summary Displays summary text associated with the rule.

Target Target refers to the destination of the information. The value is protocol specific.
Examples include the destination URL, share name, or host name.
Target is based on extracted protocol information and not based on the IP
address of the data. In many network configurations, the IP address may be an
internal address corresponding to a local NAT server or proxy, whereas the target
represents the intended destination of the data.

Threat Score Displays the threat scores.

Time Displays the time when the alert was detected on the sensor.

To Displays the value of email recipients. The value is protocol specific and most
applicable to email or webmail. The value will be empty if the violation occurred
over a protocol that does not include email.

User Displays the value of the extracted User field. The value is protocol specific and
most applicable to protocols that require a login or user name. The value will be
empty if the violation occurred over a protocol that does not provide User.

UUID The Universal Unique ID (UUID) is an alert ID that will be unique over all Fidelis
XPS components. If an alert is archived and imported at a later date, the UUID will
not clash with the current set of CommandPost alert IDs, however the Alert Id
may.

With Malware A Yes/No value to indicate if the alert contains malware.

Fidelis XPS User Guide 169


CommandPosts
Enables you to select multiple CommandPosts from which t
o search for alerts. This option is only available if you have set up at least one Subordinate
CommandPost. Refer to Set Up CommandPost Relationships. The CommandPosts that display are
your local CommandPost and one or more Subordinate CommandPosts.

Sort By
Sort By enables you to sort your report results by selecting an available column in either ascending
or descending order. Available columns can either be from the Primary Column entries if here is no
group by, or from the Group By list (with the Count and Last Seen columns). You can only select
one column at a time. Report results are sorted by your column and sort order selections and can
be saved..
If there is no group by in the report, Alert Time in descending order is used by default (most recent
to least recent alert time). You can change the sorting order to ascending, or you can select one of
the other Primary Columns.
If there is group by in the report, group results are sorted by Count in descending order (from
largest to smallest count) by default. You can change the sort order to ascending (smallest to
largest), or select one of the other group by columns (including Last Seen or Count).

Group By
Group by enables you to summarize your report by grouping selected values. The list of available
columns matches your selection of primary columns. Use CTRL-Click to select one or more
columns to group report results. You may also select a view for your report, either tabular, pie
chart, bar chart, or stacked bar chart. Refer to Group.

Figure 65. Custom Search: Group By

Report Controls
After entering criteria, you have the following options:

• Reset–resets the report to the last saved state.


• Run–runs the report. If the report was not saved before running, the report will be
named: Unnamed Report.
• Save–enables you to save the report with any new criteria.
• Save As–enables you to save the report with a new name and new permissions. Refer to
Save Reports.
• Save & Schedule–enables you to save and schedule the report. Refer to Save and Schedule
Reports.

Fidelis XPS User Guide 170


Run Reports
Select the appropriate report and click Run. CommandPost displays any data that matches your
32
criteria in the Alert List page. The criteria chosen will be displayed at the top of the report. All
normal operations of the Alert List page are available. Refer to Understand and Manage Alerts.
Click Customize Report to return to the Custom Report page.

Figure 66. Report Results

Edit Reports
To edit a report:
1. Click Reports>Saved Reports.
2. Select the appropriate report.
Note: You can edit private reports that you created or public (read-write) reports.
3. Click Edit. The Custom Report page displays with any previously selected criteria. Refer to
Create a Custom Report to make any needed changes.
4. Save your changes. Click Save to save your changes to this report. Enter a new report name
to save this report with a new name.

32
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 171
Save and Schedule Reports
You can save or schedule a custom report.
To schedule a system report, you must edit it and save it as a custom report. To schedule a
Summary report, refer to Schedule Summary Reports.

Save
To save a custom report:
1. After entering your report criteria, click Save at the Custom Report page.
2. Enter a unique report name with a maximum length of 40 characters.
3. Enter a description for this report, if desired.
4. If needed, ensure that the checkbox next to Alerts is selected. This option is selected by
default to make this report available at the Alerts List page.
5. If needed, ensure that the checkbox next to Dashboard is checked to make this report
available at the Custom Alerts widget on the Dashboard.
6. Select a new report permission, if needed or keep the current permission. Select from either:
33 34
private ,public (read only) , or public (read-write).
7. Click Save.
Your saved report displays in the Saved Reports page.

Save and Schedule


To save and schedule a custom report:
1. Click Save & Schedule at the Custom Report page.
If you select a Custom Report and click Schedule you can select scheduling information
without entering a report name or saving as an alerts report. Proceed to step 4.
2. Enter a unique report name with a maximum length of 40 characters.
3. If needed, ensure that the checkbox next to Alerts is selected. This option is selected by
default to make this report available at the Alerts List page.
4. If needed, ensure that the checkbox next to Dashboard is checked to make this report
available at the Custom Alerts widget on the Dashboard
5. Select a new report permission if needed or keep the current permission. Select from either:
35 36
private , public (read-only), or public (read-write) .
Note: If a previous user has scheduled a public (read-write) report to send an email
periodically and a second user modifies the same report without changing the
scheduling, the report will run with the second user's changes and be emailed to the
first user.

33
The private report permission gives users full access to the reports they created. Other
CommandPost users have no access to private reports. Private reports can be copied to other
CommandPost users.
34
Public (Read Only) reports can be viewed by all users. You can run a report with this permission
level or copy and save it with a new name. The author of a Public (Read Only) report is the only
user permitted to edit, schedule, or delete the report. All System Reports are Public (Read Only)
and they cannot be deleted.
35
The private report permission gives users full access to the reports they created. Other
CommandPost users have no access to private reports. Private reports can be copied to other
CommandPost users.
36
Public (Read-Write) reports can be viewed by all users. Any user with the same permissions as
the original author can edit, copy, run, delete, or schedule the report. The last user to change the
report is listed as the author of the report.
Fidelis XPS User Guide 172
6. Select a report delivery time.
7. Specify report frequency. This ranges from every day to specific days of the week or the
month. Report Frequency only determines the delivery schedule for the report and does not
change any times entered when creating the report.
Note: If you selected Date Range for the report, this date range will not change when
the report is executed. However, if you choose Last 24 hours, 7 days, or 30 days, the
time frame of the report will change with each execution.
8. Enter an email address for report delivery.
9. Choose to send the report as a pdf attachment to the email. You can also send the report as
HTML, text, or zipped alert details PDF. Click Save.
Note: If your report includes group by, trending, or pie or bar chart criteria, the Send
As option is not available. The report is sent as a pdf attachment.
To send as HTML: Click, HTML and select columns. Any columns that display in the column
list will send that information from your report in the email.
For more information about columns, refer to Columns.
To send as Text: Click Text. Select keywords and click Add Keyword. Keywords display in
the text box. If a user-defined format is chosen, type your format into the text box. Use
keywords to select the specific alert information to include in the report. If you desire a
comma-separated list, for example, enter each keyword from the drop-down list and type a
comma between each valid entry.
For more information about keywords, refer to Email user-defined.
To send as a zipped Alert Details PDF: Click Zipped Alert Details PDF. This creates a zip
file that contains a PDF of alert details for each alert in the report up to 50 alerts. You can
customize the PDF file. Refer to Customize the PDF for Alert Details.
10. Click Save.
Your saved report displays at the Saved Reports page. The Scheduled column at the Report List
indicates that your report is scheduled.
Note: the report will run under the permissions of the author, using their sensor and
alert management groups. For a Public (Read-Write) report the author is the user that
made the last change. This may change the alerts that are available in the report
output.

Delete Reports
To delete a report:
1. Click Reports>Saved Reports.
2. Click Delete next to the appropriate report.
Note: You can delete all reports that you created, whether public or private. You can
also delete any public (read-write) reports.
3. Click OK at the confirmation dialog box. The report is removed from the Saved Reports page.
If applicable, it is also removed from the Alerts Report List and from the Dashboard Custom
Report List.

Fidelis XPS User Guide 173


Chapter 9 Summary Reports
37
The Summary reports page provides access to commonly used reports of alert data. Reports can
be generated immediately or scheduled for periodic creation and delivery.
Click Reports>Summary then select a report by clicking on the corresponding link. Refer to Define
Summary reports.

Figure 67. The Summary reports page

Define Summary Reports


Summary reports enable you to answer key questions about violations detected on your network
and associated alert management activities. These reports are organized under some of the more
common concerns that administrators often need to address.
The Executive Summary provides multiple reports in one view to give you a snapshot of your
alerts.

• Select a date range.


• Select one or more sensors.
• Include the number of results to be considered.
Traffic Summary reports provide a view of violating network traffic compared to the total traffic
analyzed by Fidelis XPS sensors.

• Choose from available data filters.


• Select a date range.
• Select one or more sensors.
Tickets provide an analysis of your alert management activities. Tickets reports can provide a
summary of ticket activity as well as a breakdown by current status and the resolution of closed
alert tickets.

• Choose from available data filters.


• Select a date range.
• Select one or more sensors.
• Select the chart type (for status and resolution reports only).

37
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 174
Alerts Breakdown reports provide an analysis of your alerts.

• Choose from available data filters.


• Select a date range.
• Select one or more sensors.
• Include the number of results to be considered, up to 99. The graphics will display the top
nine results individually and sum the remaining results into a tenth result. The chosen number
will influence the size of the associated data table, if selected.
• Select the chart type: pie or bar chart.
Malware Breakdown reports provide an analysis of malware events.

• Choose from available data filters.


• Select a date range.
• Include the number of results to be considered, up to 99. The graphics will display the top
nine results individually and sum the remaining results into a tenth result. The chosen number
will influence the size of the associated data table, if selected. This option is not available for
the Malware by Time of Day report.
• Select the chart type: pie or bar chart.
Data Discovery provides a view into the source and destination of sensitive data crossing your
network. The report enables you to track the location of this information so that you may take the
necessary actions to secure it.

• Choose from available data filters. Choose to view results based on the sender (source IP
address), receiver (destination IP address) or the transmission path (IP Pair).
• Choose to view results based on the sender (source IP address), receiver (destination IP
address) or the transmission path (any IP address).
• Select a date range. Select 24 hours, or 7 or 30 days or enter a date range.
• Select one or more sensors.
• Include the number of results to be considered, up to 99. The graphics will display the top
nine results individually and sum the remaining results into a tenth result. The chosen number
will influence the size of the associated data table, if selected. This option is not available for
the Malware by Time of Day report.
• Select the chart type: pie or a stacked bar chart.

T a bl e 1 8. S um m ar y r e p ort s

Report Report Description


Organization

Executive Executive The Executive Summary displays the number of malware by


Summary Summary host ip, by malware by name, malware by source country,
alerts by policy, and alerts by rule. Each display is a line
chart accompanied by a trending chart showing the data
over the previous week.
Traffic By Protocol The Traffic Summary by Protocol report compares TCP
Summary sessions analyzed by the selected sensors to those that
were in violation. The report breaks down the analysis by
application protocol.
For each protocol, you will see a comparison between
compliant and non-compliant sessions as well as a trend

Fidelis XPS User Guide 175


Report Report Description
Organization
analysis of the non-compliant sessions.

By Session The Traffic Summary by Session report compares TCP


sessions analyzed by the selected sensors to those that
were in violation.
The report includes a trend analysis of all violations.

Tickets By Status The Tickets by Status report displays the total for tickets
grouped by the current ticket status: New, Closed, or Open.
Time selections and trend graphs refer to the alert creation
time.

By Resolution The Tickets by Resolution report displays the total for


closed tickets grouped by resolution: Allowed, Action taken,
No action taken, and False positive.
Time selections and trend graphs refer to the alert creation
time.
Workflow Workflow Summary displays alert management statistics
Summary including the average time to progress ticket status and the
total number of alerts processed. You can run this report by
owner or group.

Alerts By Policy The Alerts by Policy report displays the total for alerts
Breakdown generated during a selected time period grouped by policy.

By Rule The Alerts by Rule report displays alerts generated during a


selected time period grouped by rule.

By Severity The Alerts by Severity report displays the total for alerts
generated during the selected time period grouped by
severity. Severity includes Low, Medium, High, and Critical.

By IP Address The Alerts by IP Address displays the total for alerts


generated during a selected time range and grouped by
source, destination, or any IP addresses. The choice of IP
Pair results in a report showing communications paths.

By Destination This report displays the number of alerts grouped by


Country destination country. This enables you to determine which
country the transmission was going to when the alert was
generated.

By Protocol The Alerts by Protocol report displays the total for alerts
generated during the selected time range summarized by
application protocol.

Malware By Host Malware by Host displays malware events and trends


Breakdown grouped by Host IP addresses.

By Malware Malware by Name displays malware events and trends by


Name name.

By Country Malware by Country displays malware events and trends by

Fidelis XPS User Guide 176


Report Report Description
Organization

the country associated with the source of the malware.

By Protocol Malware by Protocol displays malware events and trends by


network application protocol.

By Format Type Malware by Format type displays malware events and


trends by format type.

By Time of Day Malware by Time of Day displays malware events grouped


by the hour of during which the malware was detected. The
report contains two graphs, which present the malware by
severity and by malware type.
Data Discovery Data Discovery Data Discovery report groups alerts by the combination of
the violated rule and the IP address (source, destination, or
any). If you select only a single rule, you can use the report
to discover the flow of that type of information in your
network.

Note: The Traffic by Session and Traffic by Protocol reports are the only ways to view
the effects of policies that use the prevent option. This option prevents violating
sessions without generating an alert. The alert and alert and prevent options generate
alerts that display in all custom and alert reports.

PDF Controls
When you place your mouse over the Report button a window appears with PDF controls. From
this menu you may:
• Generate PDF, which is equivalent to clicking the Report button.
• Customize PDF.
• Email PDF.

Customize PDF
Customize PDF enables you to customize a PDF report for your needs. You can enter a title,
description, a footer, and add a logo.
1. Enter a title for the PDF report that will display on the top left.

Figure 68. Customize the PDF

2. If needed, enter a description to display under the title.

Fidelis XPS User Guide 177


3. To include a footer in the report, type the desired footer text into the box and click Save.
To change the existing footer:

Select the checkbox next to the previously saved footer to use in your report. Click and
enter the desired text. Click Save. This footer is available for other PDFs and for all other
users until changed.
To disable the footer without changing it, uncheck the box.
To disable the footer without changing it, uncheck the box.
5. To include a corporate logo or image: choose a .jpg, .gif, or .png file from your workstation
and click Save to upload the image to CommandPost. This image will be inserted into the
PDF at the top left of the report. The size of the logo file should be less than 500 kB.

Select the checkbox next to the previously saved footer to use in your report . Click
and choose the image file from your workstation. Click Save to upload the image. The logo
is available for other PDFs and for all other users until changed.
To disable the image without changing it, uncheck the box.
6. Select the page orientation: portrait or landscape.
7. Click Export PDF. The resulting PDF file contains the report information. Export PDF does
not save changes, but these changes will be available for other PDF reports until you log
out or until these settings are changed.

Email PDF
This option enables you to send a PDF report via email.

Figure 69. Send Report PDF via Email


1. Click the Email checkbox. The email portion displays.
2. Enter an email address.
3. Enter a subject or keep the default.
4. Enter information for the email body, or keep the default text.
5. Click Export PDF. The PDF report is sent as an attachment to the specified email address.

Fidelis XPS User Guide 178


Schedule Summary Reports
You can schedule any of the Summary Reports to distribute automatically via email at specified
times and intervals. You can use the default criteria when creating a report or select your own
criteria.
To schedule a Summary Report:
1. Select one of the Summary Reports.
2. Keep the default report criteria or edit as needed. Refer to Create Summary Reports.
3. Click Schedule. The Schedule Report dialog box displays.
4. Enter a unique report name.
5. Select a report delivery time.
6. Specify report frequency. This ranges from every day to specific days of the week or the
month. Report Frequency only determines the delivery schedule for the report and does not
change any times entered when creating the report.
7. Enter an email address for report delivery.
8. Click Submit.
The report can be managed at Reports>Saved Reports with all other saved reports.

Fidelis XPS User Guide 179


Chapter 10 Network Reports
The Network Reports page displays statistical information about the data flow observed by Fidelis
XPS sensors.
To display network statistics:
1. Click Reports>Network.
2. Select the time period from 10 minutes to 14 days.
3. Select the type of report.
4. Click on the text box with the current sensor name. The sensor selection dialog box displays.
You can select one or more sensors (using CTRL-Click) or click All. Click OK when you finish
selecting sensors. Note for the Interface Statistics report, the All selection is not available.
Note: Selecting <all> provides consolidated network statistics for all sensors. The
report is most useful when CommandPost is connected to a Fidelis XPS BladeArray
that distributes high volume traffic over several sensors.
5. Click Go.
The following reports are available: depending on the type of Fidelis XPS sensor connected to
CommandPost. If a component you select is not present for the selected sensor, a message
appears stating that the it is disabled.
Network Statistics
Application Protocols
TCP Processor
IP Defragmenter
Average Alerts Insertion Rate
TCP Resets
DNS Processor
Inline Module
Web
Mail
Interface Statistics
Many of the Network reports include interface wire statistics that provide the following
information.
The hardware interfaces refers to the set of Active interfaces on the sensor.
• Errors: number of packet errors reported by the hardware interfaces
• Dropped: number of packet dropped by the hardware interfaces
• Invalid: number of invalid packets(with format errors) received by the hardware interfaces.
Many of the Network reports, except for Interface Statistics provide the following information at the
top of each report page:
• Current time: current CommandPost time
• First sample time:Start of the actual period from which data are retrieved
• Last sample time:End of the actual period from which data
• Last restart time: The last time Fidelis XPS was restarted.
• Total processed packets: The total number of packets processed

Fidelis XPS User Guide 180


Many network reports provide an interactive performance graph that you can use to closely
examine what is occurring on your network. You can click items listed in the legend next to many of
the graphs to select or deselect specific items to filter information. With the performance graph, you
can look at time periods from 10 minutes to 14 days.
To do this:
• Highlight an area of activity to expand that portion of the report.

Note how the time changes in the button below the slider bar. Time
measurements also change on the graph.
• Mouse over a line to see what occurred at that point and how frequently.

Figure 70. Network reports: interactive performance reports


• To return to a larger view, double click in the graph. Each time you double click, the time
displayed in the graph doubles.

• Clicking displays the information available for the maximum 14 day period,
even if you initially selected a shorter time period.
• Use the slider bar to see another portion of the graph.

Move the to expand or contract the time period being examined. You can also move to another
part of the performance graph. The time changes in the button and time
measurements on the graph also change.
Click any line in the legend to hide the associated line from the chart. As you hide lines, the scale of
the graph will change so that each line can be more visible,

Click to switch the graph to linear or to logarithmic scale.


\

Fidelis XPS User Guide 181


Network Statistics
CommandPost displays the following statistical information about your network data flow by sensor,
including:
• Packets by protocol: a graphical display and a numerical breakdown
• Bytes by protocol: a graphical display and a numerical breakdown, bits/sec
• Packets per second by transport protocol, graphically
• Kbytes per second by transport protocol, graphically
• Packets per second by service, graphically. If the service is unknown, the TCP port number
displays.
• Bytes per second by service, graphically. If the service is unknown, the TCP port number
displays.
• Volume of packets by size, graphically
• Wire statistics (NIC errors, dropped and invalid packets)

Figure 71. Network statistics


The legend contains controls to remove or restore the associated information from the graph.

Fidelis XPS User Guide 182


Application Protocols
CommandPost shows the following information about the Application Protocols observed by the
sensor:

• Sessions per minute by protocol with a graphical display


• Observed protocols: a graphical display and a numerical breakdown

Figure 72. Application Protocol statistics


The legend contains controls to remove or restore the associated information from the graph

Fidelis XPS User Guide 183


TCP Processor
CommandPost displays the following Configuration information and runtime statistics about the
TCP Processor module:
The TCP processor report also includes a Runtime graph of TCP sessions per minute up to the
past 14 days
Configuration information includes:

• hash
• max payload

• payload limit

• descriptors

• payload handlers
• Shared memory

T a bl e 1 9. TC P R u n ti m e St a ti sti c s
The following table lists and defines TCP runtime statistics.

TCP Runtime items Description

Processed Packets The total number of packets processed by a sensor. This value
provides a percentage of processed packets versus all received
packets. If the sensor is processing less than 100% of packets,
the sensor may be under too much traffic load.

Payload Faults The total number of payload faults for all sessions since the last
sensor software restart.
A payload fault occurs when a session was not allocated a
payload buffer. A payload buffer is used to save TCP and UDP
payloads in memory.
This fault is an indicator of low memory resources because of
sensor stress. One common cause of a payload fault are large
numbers of sessions with large amounts of traffic on each
session such as a large file transfer or a system backup.

Payloads Total number of sensor internal payloads processed. Inside the


sensor, TCP/UDP payloads are reassembled and saved into
larger sensor internal payloads.

Total Sessions Total number of sessions processed by the sensor.

Session Label Faults The total number of session label faults over all sessions since
the last sensor software restart. A session label fault is a session
for which a label descriptor was not allocated.
This fault is an indicator of low memory resources because of
sensor stress. A common reason for this fault may be large
numbers of simultaneous TCP or UDP sessions. This fault
should not happen often for sensors with greater than 32G of
memory installed.

Session Labels The total number of session descriptors over all sessions since
the last sensor software restart.
Session labels also known as session descriptors are
parameters that describe the parts of a session. Each parameter
will contain a value such as the session types: SSH, TELNET,

Fidelis XPS User Guide 184


TCP Runtime items Description

SSL, SMTP. These parameters are fed to the decoders that use
them to identify whether this is a session it should or should not
decode.

IPv6 Sessions The total number of IPv6 sessions processed by the sensor.

Midstream Sessions The total number of midstream sessions since the last sensor
software restart. The percentage represents the number of
midstream sessions as compared to all sessions.
A midstream session is a session where the sniffer process did
not detect both the SYN or SYN-ACK TCP handshake packets
for a session. This means that the beginning of the session was
not seen for the client or the server.
These faults will increment for a short period of time immediately
after the sensor boots because it will miss the first part of the
session while offline.
Persistent large numbers of midstream sessions are indicators
of a permanent or transient problem with the network traffic. The
sensor or upstream device, such as a TAP or SPAN port could
be dropping packets due to FCS errors or an overloaded device.
Midstream sessions are also typically seen in deployments
where there is asynchronous traffic routing and the sensor is
only provided one direction of the traffic..
Some midstream sessions can be detected and decoded,
however, any data attributes contained in the handshake will be
missed. This will result in loss of data for alerts and metadata.
A properly functioning sensor will report a high percentage of
midstream sessions when it starts. Over time, the percentage
should steadily decrease.

Midstream The total number of midstream established sessions over all


Established Sessions sessions for a given period of time.
Midstream established sessions are sessions where the sniffer
process did not detect both the SYN or SYN-ACK TCP
handshake packets for a session, however the sensor
subsequently detected both the incoming and the outgoing
packets in that session.

Holes Added When the sensor receives packets out of order, holes are
created in the session and filled when the out-of-order packet is
received. If the packet never arrives, the hold is marked as an
Unfilled Fault.
Holes Added represents the total number of hole descriptors
added over all sessions since the last sensor software restart

Holes Unfilled Faults Unfilled faults is a count of all lost packets. The percentage
provided is the number of unfilled holes over all holes added.
A small number of hole add faults and unfilled faults are
common because network traffic is not perfect and packets will
be lost.. A large number of these unfilled faults indicates a
problem with network traffic.

Sesring Faults The total number of session ring faults over all sessions since
the last sensor software restart.
A sesring fault is where a session was not assigned to the

Fidelis XPS User Guide 185


TCP Runtime items Description

session ring buffer. A session ring buffer is a memory buffer


used by the sensor to temporarily store sessions as they are
analyzed by Fidelis XPS decoders.
This fault is an indicator of low CPU resources.
Two of the most typical causes for this fault indicator is a sensor
that may possibly have a large number of policies assigned to it
or a large number of rules that use the regular expression or
YARA fingerprints. The more time that the policy engine spends
on any one given session, the fewer session ring buffers are
available for incoming sessions.

Figure 73. TCP Processor statistics


The legend contains controls to remove or restore the associated information from the graph.

Fidelis XPS User Guide 186


IP Defragmenter
CommandPost shows the following information about the IP Defragmenter module:

• Configuration information (shows current configuration and capacity of IP defragmenter


module including the hash, max datagram, shared memory, descriptors, timeout, and
conversion memory

• Runtime (information about the IP defragmentation alerts per minute over the selected time
period). Faults, frags, and rebuilt info for IPv4 and IPv6.

Figure 74. IP Defragmenter statistics


The legend contains controls to remove or restore the associated information from the graph.

Fidelis XPS User Guide 187


Average Alert Insertion Rate
This report displays the average alert insertion rate per minute for the selected sensor or for all
sensors.

Figure 75. Average Alert Insertion Rate

Fidelis XPS User Guide 188


TCP Resets
CommandPost shows the following information about inline and throttle modes.

• Requests: number of requests


• Resets: number of resets
• Recent Resets; the number of resets with server, service, client, and session data
• Runtime: TCP resets per minute graphically display

Figure 76. Active Mode statistics


The legend contains controls to remove or restore the associated information from the graph

Fidelis XPS User Guide 189


DNS Processor
CommandPost shows the following information about the DNS Processor observed by the sensor:

• Runtime information including the number of packets, queries, responses, success, total
38
errors, Name Not Found (NNF) errors, alerts , and events.
• DNS performance statistics per minute, graphically displayed

Figure 77. DNS Processor statistics


The legend contains controls to remove or restore the associated information from the graph

38
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 190
Inline Module
CommandPost shows the following information about inline and throttle modes.
Throttle provides the following information by packets and bytes

• TCP; total number of packets and bytes


• Throttle drop: how many packets (or bytes) dropped in response to the throttle action

• Throttle TCP window cut: the number of packets (or bytes) on which the TCP window size
was reduced
• Packets per second and bytes per second displayed graphically

Figure 78. Inline statistics


The legend contains controls to remove or restore the associated information from the graph.

Fidelis XPS User Guide 191


Web
39
CommandPost shows the following information about a Web sensor using the ICAP interface to
an external proxy server:

• Total transactions since last restart

• Total protocol errors

• Connection information: current, postponed, total, and rejected connections

• Traffic information in bytes: input and output traffic and buffers

• Web Traffic: a graphical display and a numerical breakdown, Web traffic per minute

Figure 79. Web server statistics


The legend contains controls to remove or restore the associated information from the graph.

39
Internet Content Adaptation Protocol (ICAP) is a lightweight and extensible point-to-point protocol
used for requesting services for content inspection.
Fidelis XPS User Guide 192
Mail
CommandPost shows the following information about the Mail sensor:

• Number of total email messages processed since the last restart


• Performance:
• Number of connections

• Events generated

• Messages prevented

• Messages rerouted

• Messages that were appended to


• Messages with custom header added

• Number of messages

• Messages quarantined

• Messages rejected by IP white list

• Sender notification messages sent out

• Messages that did not violate policy


• Messages with attachments removed
• History displays mail performance per minute graphically

Figure 80. Mail statistics


Hard drive utilization displays a breakdown of usage on the Mail sensor. Postfix queue size
indicates space currently used by all emails (including quarantined emails) handled by Postfix
(equivalent to disk usage of the /var/spool/postfix directory and subdirectories.
The Postfix Queue graphic displays a breakdown of the postfix queue size. Refer to the Postfix web
site for more information.

Fidelis XPS User Guide 193


Interface Statistics
This report displays the number of received and transmitted packets for each interface on the
selected sensor. Note that you can only select one sensor at a time for Interface Statistics.
The first table in the report, Current Interface Statistics displays statistic counts since last restart
until the current time. The time stamp in the title bar indicates when you generated Interface
statistics. You can click to hide this table or to expand.
The second table in the report, Interface Statistics Changes, displays changes in statistics. The first
time this table displays, it shows statistics from a 3-second delay. Click to update the statistics
for this table. The statistics change and the time stamp in the title bar changes to indicate the time
difference between the Current Interface Statistics and Interface Statistic Changes.

Figure 81. Interface Statistics


The Interfaces column lists all interfaces on the selected sensor. Other columns display the number
of received and transmitted packets, errors, packets dropped, and overruns. The average packet
size is listed for received packets.

Fidelis XPS User Guide 194


Chapter 11 Import
You can import report files created by a report export from the same or different CommandPost.
This enables you to back up your reports and to use the same report definitions on multiple
CommandPosts.
To use this feature, you need to have full permissions for reports. Refer to
Note that importing reports into CommandPost can affect the Created and Last Modified
information included in the imported report. If the original author exists in CommandPost, then the
Created and Last Modified dates and user information are not affected. If the author does not exist,
then the Created and Last Modified dates and user information will be the date of the import and
the user performing the import.
To import:
1. Locate the report xml file on your workstation.
2. Upload the file. The Import dialog box displays with the name of the selected file.

Figure 82. Report Import


3. Select an option for conflict handling. A conflict occurs when any report has the same name
as an existing report on the CommandPost. Your selection tells Import what to do if it detects
a conflict.

• Ignore Import File–will ignore the conflicting report in the import file. This is the default
option. All non-conflicting reports in the file will be imported.
• Import File Overwrites Database Entry–If there is a conflict with a Public read-only report
that is not owned by the user performing the import, the report will be rejected and will
not overwrite the database.
The import can take several minutes depending on the size of your import file. When complete, the
Import Result displays.

Fidelis XPS User Guide 195


Chapter 12 Manage Users, Roles, and Groups
CommandPost includes Local, and non-local users such as LDAP or RADIUS/TACACS+
administrative users.

• Local users are defined within CommandPost. Using the System>Users page, you can
create a user profile, which includes the local password and all permission settings. Local
users obtain a CommandPost user name and password and are the easiest to configure and
manage. CommandPost includes one default local user (admin) which must be used to
configure all other settings. Fidelis recommends that you create local user accounts for all
persons responsible for the maintenance and support of the Fidelis products.
• LDAP users are created and managed by an external LDAP or Active Directory server.
RADIUS/TACACS+ users are created and managed at a RADIUS/TACACS+ server.
Directory attributes can be used to map users or user groups to CommandPost permission
settings. LDAP and RADIUS/TACACS+ users can access CommandPost using their directory
user names and passwords. LDAP and other non-local users are not provided a
CommandPost user name or a password. Some capability will be limited due to the lack of
these credentials. Management is performed by creating a user profile that maps directory
attributes, such as group names, to CommandPost access permissions.
Note: LDAP and other non-local users display in the Users>Profiles list after the first
login. This is used for user account management purposes only.
To create and manage LDAP users , refer to LDAP Configuration . To create and manage
RADIUS/TACACS+ users , refer toRADIUS/TACACS+ Configuration.
To understand CommandPost permissions, refer to Define User Roles.
To manage users , click System>Users. The Users page displays with the current list of
CommandPost user profiles and basic information about each user.
Note: The Users option is only available if you have access to user features. Refer to
Define User Roles.

Figure 83. Users information


When first installed, CommandPost has one default user, admin, with full System Administrator
privileges.
Refer to chapter 2 in the Enterprise Setup and Configuration Guide for the the default password
for the admin user. Change this password immediately after you first log in.
Fidelis XPS enables you to manage local user access by assigning each user to:

• A role; required

Fidelis XPS User Guide 196



40 41
Zero or more groups; needed for alerts and Quarantine management features.
• Zero or more sensors; needed to manage sensors and to view alerts from sensors.
LDAP users are managed in a similar fashion. Create a profile to map user attributes to role, group,
and sensor assignments. Each profile may manage a single user or many users, depending on
your configuration.
The user page provides two icons to note user status:

Denotes a valid user. The user has a role and has at least one group and sensor
assignment.

Denotes a user with limited access to the system. This user may have a role, but lacks either
a group or sensor assignment
They may log into the system, but will not be able to execute their role.
This icon can also indicate a user who has been locked out of accessing CommandPost for
one of several reasons such as an expired password. Refer to Reset a Local User Account .
User Authentication contains more information about account lock and password age
settings.

Users Page
The Users page can be sorted by any column on a page in either ascending or
descending order.
To do this:
Click the column header to sort by that column.

The or icons display when a column has been sorted. You can only sort by one column at
a time.

Reset a Local User Account


If a user is locked out of an account because of inactivity, multiple failed login attempts, or an
expired password, you must reset the user's password.
To reset an account:
1. Select the user and click Edit to access the Profiles page for that user.
2. Change the password for the user.
3. Provide the user with the new password.

Access Control in CommandPost


CommandPost provides multiple layers of access control to the secure information stored in
CommandPost and to the information collected from network sensors. The design is scalable from
small to large enterprises, so that access can be easily assigned to security teams that range in
size from a single person to a large, multi-tiered team.
Access control is managed by three entities: a role, alert management groups, and sensor access
control.

• Roles provide access to CommandPost functions.

• Sensor access restricts the CommandPost functions to specified sensors.

40
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
41
In Fidelis XPS, refers to e-mails that were quarantined by a Fidelis XPS Mail Sensor and are
currently held in the quarantine queue.
Fidelis XPS User Guide 197
• Alert Management Groups can be used to divide the work of violation review and to segregate
violations by type.
The role is the first part of the access control system. Each CommandPost user is assigned one
role. This determines which parts of the system the user can access. Refer to User Roles.
Sensor access control is the second part of the access control system. Each user’s role provides
that user with access to certain CommandPost features. However, these features may only be
applied to the sensors to which the user is assigned. This control applies to all CommandPost
functions.
For example:

• A network operator may only configure and manage sensors to which that operator is
assigned.

• A Policy author may write policies, but may only install these policies on assigned sensors.

• An alert or quarantine manager may only view violations from sensors to which the manager
is assigned. The sensor access control serves to segregate data depending on where it was
found in the network.
The alert management group is the final component of the access control system. This is a group
of one or more users with a similar function, who should review similar network violations.
Examples might include a network administration group, Human Resources, or a network security
office.
Rules are associated with an alert management group. When a rule is violated, an alert or a
quarantined email may only be managed by persons in the assigned group. Once viewed, an alert
manager may move the alert or quarantined email to a different group as needed.
Alert management groups allow you to segregate data based on the rule that was violated. For
example, PII (personally identifiable information) violations may be sent to one group of users,
while violations involving inappropriate use of network resources are sent to a different group. It
also helps to split the workflow involved with alert management across one or more teams of
individuals.

Small Security Teams


Many enterprises may be too small to need access control. This is especially true of enterprises
with a single network security officer. To simplify access control, General Dynamics Fidelis
Cybersecurity Solutions has set up default configurations:

• The System Administrator role provides full access to the system. The admin user has access
to all groups, all sensors, and all system functions.

• All rules and all new users are initially assigned to the default group.

• When a sensor is registered to a CommandPost, no user will have access, except the admin
user and the user who created the sensor.

Hierarchical Management of Users


On the System>Users>Profiles page, there is an extra column of checkboxes in the users list to the
far right that are only available on a CommandPost that is configured as a Master.
Hierarchical User Management is only for local users and does not support user syncing to
Subordinate CommandPosts for non-local users such as RADIUS, TACACS+, or LDAP users.
If you are logged into a CommandPost that has been configured with Subordinate CommandPosts,
an extra column of checkboxes will appear in the users list to the far right.
To push users to Subordinated CommandPosts:
• Selected users will be pushed when the Push button is clicked.

Fidelis XPS User Guide 198


• If there are multiple configured Subordinate CommandPosts, only those set up to receive
users will receive the users. Refer to Set up a Subordinate Relationship.
• After clicking Push, reload the page and click the row of any selected user to view the
status of the Push for each Subordinate CommandPost. Once the process is completed,
the status will remain unchanged until the next user Push.
Status values include:
• Req: the push request has been initiated.
• Started: the push process has begun.
• Sync: the push is complete. Subordinate is synchronized with the Master for the
selected users.
• Failure: the process failed. If one Subordinate is not available, the push will fail.
• You need to reload the page to see updated status values.
• When users are received by a Subordinate CommandPost, any existing users that share
the same username will be overwritten.
• User passwords and user sensor assignments can be overwritten or left unchanged based
on the settings of the CommandPost. Refer to Set up a Master Relationship.
• When Users are pushed, the information includes selected user profiles and all role and
alert management groups defined on the Master. If the roles and alert management groups
already exist on the Subordinate, their definitions will be overwritten by the information
received from the Master
Note: the person performing the Push operation must have an account on the
Subordinate CommandPost with a role that includes Full access to Users.
When you perform the User Push, users currently logged into the Subordinate may
be logged out as a result. Refer to Set Up a Master Relationship.
To delete users from a Master CommandPost:
Click Delete and you will be provided with an option to delete locally (only on the Master
CommandPost) or to delete globally (Master CommandPost and all Subordinates). Note: the
person performing the delete must have an account on the Subordinate CommandPost with
a role that includes Full access to Users. Refer to Delete a User for other conditions.

Define User Profiles


At Profiles, you can view all users. Each user will be denoted as Local or non-local users such as
RADIUS/TACACS+ within the profile list.

• Local users can be added, deleted, and managed from this page.
• LDAP users can be deleted at the Users>Profiles page. Management of these users is
performed by mapping your external LDAP or Active Directory server information to
CommandPost user access profiles. Refer to LDAP Configuration.
LDAP users are added to the table at their first login. The user name is extracted from their
entry at the login page. They will remain on the page as long as they remain active users or
until an administrator removes the account.
• RADIUS /TACACS+ users can be deleted at the Users>Profiles page. Management of these
users is performed at the RADIUS/TACACS page.
LDAP and other non-local users are added to the table at their first login. The user name is
extracted from their entry at the login page. They will remain on the Users page as long as they
remain active users or until an administrator removes the account.
To access user profiles:
Click System>Users>Profiles.

Fidelis XPS User Guide 199


The Profiles page appears with a list of users . Clicking a column name reorders the list in
ascending or descending order. If a is next to a user name, that indicates a problem with the
profile such as a disabled account. Mouse over the icon to see the reason for the alert.

Expand User Information


Click on any user name at the Profiles page to see expanded information, and the Edit or Delete
buttons as appropriate.
The roles, groups, and component assignments are links that you can click to access the Roles,
Groups, or components pages.
Push Status provides the current state of the Push either: requested, started, synced, or failed. If
the Push failed, an error message is also provided. Status lists the CommandPost and user
requesting the Push and when the Push started and finished. If one Subordinate is not available,
the push will fail.

Figure 84. users

Fidelis XPS User Guide 200


Add or Edit a Local User
You can add, edit, or delete local users if your role contains full access to Users. Refer to Roles.
Adding a user involves the following:

• Provide identifying information for the user to CommandPost. This information includes user
name, password, and email address. This information is stored and managed within
CommandPost.

• Determine access to CommandPost features by assigning the appropriate role.

• Assign the user to the appropriate groups and components to implement assigned roles. Alert
Management Groups can be used to divide the work of violation review and to segregate
violations by type
The following restrictions apply when creating or modifying users:

• Create users with permissions equal to or less than their own permissions.
• Assign users to groups to which they belong. For example, a user that belongs to group A and
group B can only assign new users to those groups. Use CTRL+click to choose multiple
groups. Select No Groups to unassign a user from every group.
• Assign users to components to which they belong. For example, a User Manager assigned to
component A and component B can only assign new users to those components. Use
CTRL+click to choose multiple components. Select No Components to unassign a user from
every component.
The following table provides an overview of how to make role, group, and component
assignments so that a user has access to the more frequently used features.

T a bl e 2 0. D e t er mi n e us e r a c c ess

To access: The assigned role Group assignment Component assignment


must provide:

Alerts Full or view access Users must be assigned to Users must be assigned to
to Alerts the same group as the alert the component that
and its associated rule to generated the alert.
access the alert.
Details Full or view access Users must be assigned to Users must be assigned to
to Details the same group as the alert the component that
and its associated rule to generated the alert.
access the alert.

Quarantine Full or view access Users must be assigned to Users must be assigned to
to Quarantine the same group as the alert component that generated
and its associated rule to the quarantined email.
access the quarantined
message. No impact If a
message violates multiple
rules, any user with access
to one of the associated
alert management groups
can access the quarantined
emails.

Tickets Full or view access Users must be assigned to Users must be assigned to
the same group as the alert the component that

Fidelis XPS User Guide 201


To access: The assigned role Group assignment Component assignment
must provide:

to Tickets generated the alert.

Reports Full or View No impact No impact


access to Reports

Policies Full or view access No impact Users can only assign


to Policies policies to components to
which they are assigned.

Users Full or view access A new user may be added to A new user may be added to
to Users any group to which the user any component to which the
manager belongs. user manager belongs.

component Full or view access No impact Users can only configure


admin to component components to which they
Admin are assigned.
CommandPost Full or view access No impact No impact
admin to CommandPost
Admin

Audit Full access to No impact No impact


Audit

Metadata Full or View No impact Users can only view and


access to access the Collector to
Metadata which they are assigned.

To add or edit a local user:


1. Click Add User and the New CommandPost User page displays. To edit an existing user,
select the user and click Edit.

Figure 85. New CommandPost User page


2. Enter user name, password, and email address.

Fidelis XPS User Guide 202


• User name is required for new local users and must conform to valid name restrictions.
Valid names start with a letter and may contain letters, numbers, underscores (_), or
periods ( . ).
• If needed, you can enter a full name to identify this user.
• Email is optional. If entered, a correctly formatted Internet email address is required. If
omitted, this user will not receive notification messages when alerts are assigned.
• Passwords are required for new local users. Passwords must conform to the
CommandPost password settings defined in CommandPost Configuration. For an
existing user, click the Change Password button to change the password.
Note: Local users can change their account information after they log into
CommandPost. LDAP and other non-local users have limited ability to change their
account settings.
3. Select a role from the drop-down list.
4. Select the appropriate alert management groups for this user. Multiple groups may be
selected by dragging the mouse or using CTRL+click. Assignments may be reset by choosing
the “No Group” option.
5. Select the appropriate components for this user. Multiple components may be selected by
dragging the mouse or using CTRL+click. Assignments may be reset by choosing No
Component.
6. Click Save.
The new or modified user is included in the list on the users page.

Delete a User
42
Before you can delete a user, you must first reassign all alerts assigned to the user. Deleting a
user will delete all items authored by the user. These include:
• Exports
• Reports (public or private)
• Retention plans
• Investigations (public or private)
Note – Ensure that any Exports, Reports, or Retention plans are not part of any
established workflow or critical business processes. To reassign an Export, Report,
or Retention plan simply have the user that will manage the object make a minor edit
and then save the object. This will change authorship to that user.
To delete a user:
1. Click Profiles.
2. Click the appropriate user. Click the appropriate user. The Delete button becomes available.
The Delete button will not be available if open alert tickets are assigned to the selected user
or if you do not have permission to delete this user. Permission to delete requires that the
user has a role that is a subset of your own role.
3. Click Delete.
4. Click OK at the confirmation dialog box.
The user is deleted from the list on the Users>Profiles page.
To prevent future login from an LDAP user, you will need to change or remove this user from your
directory server or alter or remove the profile to which this user belongs.
To prevent future login from a RADIUS/TACACS+ users, you will need to change or remove this
user. Refer to User Authentication.
42
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 203
Define Alert Management Groups
You can create alert management groups to which you can assign users and alerts.
43
Each rule is assigned to an alert management group. Alerts generated when a rule is violated are
assigned to this group and visible only to the users in the group associated with the rule.
The alert manager may later move an alert to a different alert management group so that it may be
managed by members of other Alert Management Groups.
To access alert management groups:
Click System>Users>Groups. The Alert Management Groups page appears with a list of existing
groups. You can click on any group name to see expanded information, and the Edit and Delete
buttons.
The user and rule names and Assigned to Alerts are links that you can click to access Users,
44
Rules, and Alert List pages.

Figure 86. Alert Management Groups page

Add or Edit an Alert Management Group


You can use groups to control user access to alerts. For example, a legal group could include
users with access to alerts generated when a personally identifiable information (PII) rule is
violated, while a different group could manage alerts for inappropriate use of the network.
To add or edit an alert management group:

43
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
44
An Alert List is created from all alerts available within your assigned groups and sensors. The List
can be greatly customized by choosing the columns to display, selecting specified criteria, and by
choosing to display the results in a chart or as a table.
Fidelis XPS User Guide 204
1. Click Add Group. The New Alert Management Group page appears with empty text boxes. or
select an existing group and click Edit.
2. Enter a name and a description for a new group.
3. Enter an email address for the group. When an alert changes from one group to another, a
notice is sent to this email. Similarly, notifications of quarantined emails are sent to this
address if a Mail sensor has been configured for quarantine notification. The email address
must be a single address, which can be a group distribution list, and must conform to email
syntax requirements.
4. Click Save.
A new group displays in the list with other alert management groups. You can now assign users to
the new group, assign alerts to the group, and modify rules to place alerts into the group.

Delete an Alert Management Group


Any group associated with a rule cannot be deleted. Similarly, any group that contains alerts cannot
be deleted. To delete such a group, first remove it from all rules and move all alerts to another
group.
To delete a group:
1. Click the appropriate group. The Edit and Delete buttons become available.
2. Click Delete.
3. Click OK at the confirmation dialog box.
The group is deleted from the list at the Alert Management Groups page.

Define User Roles


Roles determine access rights for users. Fidelis XPS ships with predefined roles that determine
user access to each of the major CommandPost features.

Figure 87. User Roles page


Predefined roles cannot be edited or deleted. These are indicated with a Fidelis logo next to a role
name. Multiple users can share a role, but each user can only have one assigned role. You can
customize user access by creating a custom role.
Custom roles may be edited or deleted and are identified by the pencil icon.
Predefined roles are generally one of the following:

Fidelis XPS User Guide 205


T a bl e 2 1. Pr e d e fi n e d R ol e s

Role Description

No Role No assigned roles;


Prevents access to all Fidelis XPS.

System Provides full access to all Fidelis XPS features. This role can be applied to any
Administrat user.
or

Network Adjusts sensor network settings and communications between CommandPost and
Admin the sensor, monitors network statistics to verify connectivity, and installs software
upgrades to Fidelis XPS.
Full Control: for Details, Reports, Sensor Admin, CommandPost Admin, and
Metadata
45
View Only: for Alerts , Quarantine, Tickets, Policies, and Users.
None No access for Audit

Network Includes all the roles of the Network Admin plus full access to Users to add and
Admin manage local users.
Supervisor

Policy Creates and manages policies and rules to one or more sensors.
Author Full Control: for Details, Reports, Policies, and Metadata
View Only: for Alerts, Quarantine, and Tickets
None No access to Users, Sensor Admin, CommandPost Admin, and Audit

Policy Includes all the roles of the Policy Author plus full access to Users to add and
Author manage local users
Supervisor

Alert Reviews alerts (or quarantined emails) and manages any action required within the
Manager enterprise.
Full Control: for Alerts, Details, Quarantine, Tickets, Reports, and Metadata
View Only: access for Policies
None:No access for Users, Sensor Admin, CommandPost Admin, and Audit

Alert Includes all the roles of the Alert Manager plus full access to Users to add and
Manager manage local users.
Supervisor
A role’s (and a user’s) access to each feature is determined by the access levels specified for that
feature: Full, View, or None. The following table describes each access level.

45
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 206
T a bl e 2 2. Us e r a c c ess l ev el s

Access Level Description

Full Provides read and modify access to the feature. Depicted by a full
green circle.

View Provides read-only access to the feature. Depicted by a green half-


circle.

None Provides no access to the feature. Depicted by an empty circle.

Access Roles
To access roles:
Click System>Users>Roles.
On the Roles page, the permission levels and user information are hidden by default. Click on a
row, or click expand all to reveal the access levels and any user information associated with a role.
The user names display in links that you can click to access the Users page and see expanded
information for that user.

Figure 88. Viewing role permissions


The available permissions are described in the table below:

T a bl e 2 3. A c c es s R ol e s

Access Permissions
Roles

Alerts Provides access to Alerts>List. View permission allows you to read and
manipulate the report. Full permission allows you to purge and export alert data.

Details Provides access to the detailed forensic data for alerts and quarantined email
messages. Without access to details, you cannot view the forensic data or
retrieve the data that caused an alert. Details access is only available as either
Full or None.

Quarantine Provides access to Alerts>Quarantine . View permission allows you to read the
list of messages. Full permission allows you to discard and deliver quarantined
email messages. Quarantine permissions also depend on the alert management
group. In addition to quarantine permissions, you must also belong to the same
alert management group of at least one of the alerts generated by the

Fidelis XPS User Guide 207


Access Permissions
Roles

quarantined email.

Tickets Provides access to the alert workflow. With Full privilege you can assign alerts,
change the alert management group and close alerts. With View privileges you
can read the workflow log of any alert, but may not change it.

Reports Provides access to reports and to report customization and management. You
may view, create, save, and schedule reports for automatic delivery. Access is
only available as either Full or None.

Policies Provides access to policies. Full access is required to edit or create policies,
rules, or fingerprints. View access allows you to view, but not change, existing
policies.

Users Allows access to System>Users. With Full access you can add, remove, and
modify user profiles (including passwords), alert management groups, and roles.
View access allows you to view, but not modify, user profiles, alert management
groups, and roles.

Sensor Admin Provides access to the sensor configuration pages at System>Components. Full
access is required to modify the configuration of sensors. With View access, you
may view the configuration, but not modify it. Access to Reports>Network is also
granted based on the Sensor Admin setting.

CmdPost Provides access to the CommandPost configuration page at


Admin System>Components. Full access is required to modify the configuration of
CommandPost. With View access, you may view the configuration, but not
modify it.
Note: Access to System>Version Control requires Full access to
both Sensor Admin and CmdPost Admin.

Audit Provides access to System>Audit . Audit access is only available as either Full or
None.
Note: Fidelis recommends that you restrict audit log access to
system administrators and network security personnel. A user with
Audit access can see all auditable actions.

Metadata Provides access to Metadata. Select either View or Full. View access provides
access to the Metadata page and with full access to Reports enables users to
save filters. Full access to Metadata is required for export.

Add or Edit a Custom Role


If the predefined roles do not meet your requirements for user access, you can create custom roles.
To add or edit a custom role:
1. Click Add Role and the New Role page appears. To edit an existing role, select the custom
role and click Edit.
2. Enter a name and a description for the new role.

Fidelis XPS User Guide 208


3. Specify an access level for each permission. None is the default value; you can select Full or
View access.
Note: You can also base your role on an existing role. Select from the list next to Base
Role On. You can customize access levels.
4. Click Save.
The new custom role displays in the Roles page with a pencil icon next to its name.
Not all combinations of features are available in the definition of a custom role. Specifically:

• Saved Reports/Summary is available as either no access or full access. View-only is not


available.

• Details are available as either no access or full access. View-only is not available.
• Access to Audit is either no access or full access. View-only is not available.

• Access to Quarantine, Saved Reports/Summary reports, and Ticket functions requires View
or Full access to Alerts. If you choose access to one of these three functions, CommandPost
will raise the level of Alerts to an acceptable level.
Note: Not all options are available to all users. You may only create a role with less
than or equal privileges than your own role.

Delete a Custom Role


After you delete a custom role, any users assigned to it are reassigned to the No Role role. This
means that these users will not have access to any features until they are assigned to a new role.
Note: Predefined roles cannot be removed from the system.
To delete a custom role:
1. Select the appropriate role.
2. Click Delete.
3. Click OK at the confirmation dialog box.
The role is deleted from the Roles list.
Note: Deleting a role that is currently assigned to a Profile will remove all system
permissions for that user and they will not be able to view any data on the
CommandPost.

Fidelis XPS User Guide 209


Chapter 13 Configure Fidelis XPS Components
The Components page allows you to view, manage, and configure Fidelis XPS components
including CommandPost, sensors, and Collectors.
For definitions of these terms, refer to Component Roles.

The Components Page


To access this page: click System>Components.
Note: The Components page is only visible to users with the correct privileges. Refer
to User Roles.

Figure 89 . The Components page


The Components page provides a quick view of all Fidelis components in your enterprise. The view
is relative to the Console, which is the CommandPost to which you are logged in. From the
Console, you can view the Master CommandPost (if any), all sensors and Collectors registered to
the Console, all Subordinate CommandPosts (if any), and all components registered to the
Subordinate CommandPost. The configuration page for all components registered to the Console
or to any Subordinate CommandPost may be accessed and modified without needing to log into
the Subordinate CommandPost.
Add Component – Clicking Add Component enables you to add a new sensor or secondary
sensor, a master or subordinate CommandPost, or a Collector. Refer to Add a Component.
Note: When adding a component, remember that all components must have either
IPv4 or IPv6 IP addresses. Mixing IP address types is not supported.

Fidelis XPS User Guide 210


CommandPost Management Console and Sensor
Information
The components are listed in four groups:
• The Master CommandPost will be displayed at the top of the [Link] Master cannot be
configured from the Subordinate, but the relationship between the two CommandPosts can
be modified or removed. If your Console is not set up with a Master CommandPost, this
group will not be displayed.
• The Console and all sensors. The list will include all sensors that have been added to this
CommandPost, including those that have not yet been registered.
• All Collectors, Collector Controllers, and Collector XAs added to this CommandPost If you
do not have a Collector or a Collector Controller added to the Console, this group will not
display.
• All Subordinate CommandPosts with each associated sensor and Collector. If you do not
have Subordinate CommandPosts, this group will not display
To add new components or to register and unregister components to a Subordinate
CommandPost, you must log in to the Subordinate and Add a Component. Once added and
registered to a Subordinate CommandPost, component configuration can be performed while
logged in to the Master CommandPost.
To register, unregister, configure, or see more details about a specific component, click the row for
that component. Component details provide a summary of the current status and relevant
configuration details.
Full configuration details can be accessed at each component configuration page.
Note: If your product is a CommandPost with an embedded sensor, such as the
Scout, the initial list will show the embedded sensor. For embedded products, you
cannot add or remove sensors, but can configure the embedded sensors.

Status Lights
Shown as a green, red, yellow or grey diamond at the top of the GUI, the status light indicates
whether a component is operational. Green indicates that the component is fully operational.
Yellow indicates a warning message, which may indicate operational problems or the detection of a
condition that warrants attention. Red indicates that the component is not communicating. This can
mean that the component is unreachable, offline, or being updated with a new version of Fidelis
XPS.
Grey indicates that there is no information available for the component.
By mousing over the status light, you can see a short description of any detected problem or
warning. The same description is available in the details of the component status.

Details
Click a row to view details about a component. CommandPost information includes the Name,
Version, OS Version, CommandPost Time, Relationship, Setup, and any yellow or red
Notifications. The absence of notifications indicates that the component is fully operational.
Collector and Sensor information includes:

• Name– the name of the component which was given when it was added to CommandPost.
• Description – an optional field supplied when the component was added to CommandPost.
You can edit the description at any time.
• Version– provides the Fidelis XPS software version installed on the component.
• Patch Version – provides the patch version installed on the sensor. If no patch has been
applied, this field will be empty.
Fidelis XPS User Guide 211
• OS Version– provides the operating system version installed on the component.

• IP Address – provided when the component is added to CommandPost. If the component is


unregistered, you can change the IP address by editing the component information.

• Alerts – is a current count of alerts generated by this sensor. Clicking the count will take you
to an Alerts List showing alerts from this sensor. This field does not appear within the
information for a Collector.

• State – the state of the component; either registered or unregistered.


• Last Seen – tells you how long ago CommandPost last received communication from this
component. Each component posts statistical information to CommandPost every five
minutes, or with each alert from a sensor. The lack of information within a ten minute window
indicates a communication problem.
The green arrow indicates that communication is working properly.
A broken yellow arrow indicates that communication has been lost between CommandPost
and the component.
A broken red arrow indicates that the component has never communicated with
CommandPost.
A grey arrow indicates that the component is unknown.
• Setup – describes how the master or subordinate CommandPost is set up. Setup will only be
displayed for CommandPosts.
• Relationship – a relationship will be displayed for CommandPosts and secondary policy
managers.
• Notifications – displays messages from the component with a status light to indicate the
importance of each message, either medium (yellow diamond) or high (red diamond).
• User Assignments – provides a list of users assigned to the component. Clicking a user
displays the Profiles page for that user.
Note: If communication is lost, many of the details listed above cannot be obtained.

License Messages
The following license messages can display in the Notifications section for the Console or a sensor:

• Demo Mode – You need a valid license key. Refer to License.


• License Refresh Required – It is recommended that you get a new license for each sensor,
Collector, and CommandPost from Fidelis Technical Support.
• License will expire in – The license will expire in the stated number of days. Contact
Technical Support to request a new license. for each sensor, Collector, and CommandPost.

Component Buttons for the Sensor


When you click a component row for a component that has been added to the Console, several
buttons will appear. When you click a component row for a component at a subordinate
CommandPost, only the Config button may appear. Button availability depends on user access
privileges and communication status between CommandPost and sensor.

• Register (Unregister) Sensor or Collector – click to register (or to unregister) a component.


Upon registration, CommandPost attempts to initiate an encrypted session to the component.
The session must be authenticated by a sensor or Collector with the given name and IP
address as entered into CommandPost. If successful, the component will come online. After
registration, the component will not communicate to any external device other than the
CommandPost to which it is registered.
Click Unregister to take a component out of service. You can then register this component to
a different CommandPost or change the IP address.
Note: If your product is a CommandPost with an embedded sensor, such as the Scout,

Fidelis XPS User Guide 212


you will not see the Register or Unregister buttons. These products communicate
internally and do not require registration.
Primary Collector Controllers cannot be unregistered until the Failover Controller is
unregistered. Refer to Collector Configure

• Edit Sensor (Collector) – click to change basic information about a component, including
name, IP address, and description. If the component is currently registered, name and IP
address cannot be changed. This button is not available for embedded sensors.

• Delete Sensor (Collector) – click to remove a component from CommandPost. This button is
available only if there are no alerts in the database generated by this sensor and if the sensor
(or Collector) is currently unregistered. If you wish to delete a sensor with alerts in the
database, you must first go to the Alert Reports page and purge all alerts generated by this
sensor from CommandPost. Refer to Purge Alerts for more information. When you return to
the Components Config page, you will be able to remove the sensor. This button is not
available for embedded sensors.

• Config – click to configure the component.

Secondary Policy Manager and Sensor Management


If your enterprise has designated CommandPosts as Secondary Policy Managers, you can
download policies to a sensor from two or more CommandPosts. Alerts that result from policy
violations will be sent to the CommandPost that originated the policies. Refer to Secondary Policy
Manager.
CommandPosts designated as Secondary Policy Managers will not have any other rights on the
sensor, such as system configuration. Also, these CommandPosts will not get any network stats
from the sensor.
Note: If you unregister a sensor that has a CommandPost configured as a Secondary
Policy Manager, that sensor will no longer function on the Secondary Policy Manager.

Set Up Secondary Policy Managers

Figure 90. Secondary Policy Managers and Sensors


To set up Secondary Policy Managers and Secondary Sensors:

Fidelis XPS User Guide 213


From CommandPost, access the sensor configuration page at System>Components>Sensor
Config page and click Secondary Managers. At this page, enter the IP address of the
CommandPost that will be the Secondary Policy Manager. This process authorizes communication
and policy downloads from the Secondary Policy Manager (CP 2 in the illustration) to the sensor.
Refer to Secondary Managers. Note that the Secondary Mangers page is not available for
embedded sensors, such as those in a Scout.
At the Secondary Policy Manager (CP 2 in our example), add a sensor (Sensor 2) at
System>Components>Add Sensor page. Click the Secondary checkbox to define the relationship
between the Secondary Policy Manager and a sensor. Refer to Add a Secondary Sensor.

Component Buttons for the Secondary Sensor


Secondary sensors are registered to another CommandPost, so the Config button does not display
and you cannot make any configuration changes to them.
• Edit Sensor – enables you to change the description for this sensor.
• Test – click to test the connection between the sensor and your CommandPost.
• Delete Sensor – click to remove a secondary sensor from the CommandPost. This button
is available only if there are no alerts in the database generated by this sensor for the
policies pushed to it. The sensor is only deleted from this CommandPost.

Fidelis XPS Collector Management


The Fidelis XPS Collector enables you to collect and store information about every session
analyzed by Fidelis XPS Direct, Internal, or Mail sensors on your network. Refer to Fidelis XPS
Collector.
Click Add Component to add a Fidelis XPS Collector to CommandPost. If Collectors are added to
CommandPost, a list will display in the Collector section of the Components page. Refer to
Configure a Collector and to Link a Collector.
If you established a Failover Controller, that component displays when the Collector row is
expanded. Refer to Configure a Collector to assign a Failover Controller. For more information
about a Collector Controller, the Collector XAs connected to the Controller, or a Failover Controller,
refer to Component Page Definitions.

Fidelis XPS Collector Controller Health Monitoring


If your Collector is a Fidelis XPS Collector Controller, status for each Collector XA connected to the
Controller can be obtained by clicking the row. For each Collector XA, the XA name, status, and IP
address are provided. The Buddy Projection column lists the IP address of the failover for each XA.
The status can be either up or down.

Figure 91. Collector Controller Health Monitoring

Fidelis XPS User Guide 214


Fidelis XPS Collector SA (Demo)
The Demo Collector Is a limited Collector SA that resides on the CommandPost. This Collector is
available to users with a CommandPost or a virtual CommandPost that do not have a Collector SA
or Collector Controller. The Demo Collector is not available from CommandPost+. Depending on
the traffic, the Demo Collector can collect limited amounts of metadata sent from one Direct,
Internal, or Mail sensor at a time.

Figure 92. Demo Collector


This Collector:
• Is automatically added and registered to the CommandPost.
• Has a very limited capacity (for metadata input rate, total database size, etc.).
• Disables itself if its limited capacity is exceeded.
• Can only accept metadata from one sensor at a time (either a Direct, Internal, or Mail
sensor).
• Is not licensed individually. The License page for the Demo Collector will indicate this.
By default, the Demo Collector is not enabled, you need to enable it at the Collector>Config page.
Refer to Configure a Collector.
On the Direct, Internal, or Mail sensor>config page , you will see the IP address of the Demo
Collector. Ensure that the Demo Collector's IP address is selected and that you enter the IP
addresses that you want the sensor to monitor.
Note: The Demo Collector uses a lot of CommandPost resources and enabling it can
degrade CommandPost performance. If this occurs, uncheck Enable Collector at the
Collector>Config page.

Fidelis XPS User Guide 215


Hierarchical Management of CommandPosts
A CommandPost can typically support approximately ten alerts per second. This leads to an
estimate of ten sensors per CommandPost, however the number of sensors to CommandPost
depends on the policies that you deploy in your environment. In an environment where multiple
CommandPosts are required, they can be configured in a hierarchical manner allowing you to
perform most functions from a Master CommandPost. When planning your configuration, there are
two models to consider:
• The Master is the only interface to your environment. In this model, the Subordinate
CommandPost is used to add and register sensors and store alerts from the registered
sensors. Once components are registered to the Subordinate CommandPost, nearly all
functions can be performed by logging into the Master CommandPost, including alert
management, reporting, data extraction, policy creation and assignment, and applying
software updates. The hierarchy of CommandPosts serves as a distributed storage of
alerts.
• The environment requires the creation and assignment of global and local policies. The
Master CommandPost would administer all global policies, while the Subordinate
CommandPost would administer local policies. Individuals with accounts on the Master
would require accounts on the Subordinate to administer the global policies. Individuals
responsible for local policies would have accounts on the Subordinate but not the Master.
Your enterprise may fit one of these models or require some combination of tasks. The system can
conform to your needs. Refer to Master CommandPosts and to Subordinate CommandPosts.
The relationship between two CommandPosts is defined during the setup and registration process.
The GUI will describe the relationship relative to the Console (the CommandPost which you are
accessing).

Figure 93. Subordinate CommandPost and its components


Each CommandPost row provides the name of the CommandPost, a description, and its
relationship to the Console. Each Subordinate's sensors or Collectors display under it.

CommandPosts: Master and Subordinates


For a CommandPost that is Master to the Console, setup refers to how user information is handled
when received by the Console:
• Password – signifies that passwords will be received from the Master and will overwrite
the passwords of users on the Console.
• Sensor Assignment – signifies that any new users pushed from the Master will be
assigned to all sensors attached to the Subordinate CommandPost.
• Master as Proxy - This enables the Subordinate CommandPost to use the Master
CommandPost as a proxy to access Fidelis Cloud Services such as policy and Fidelis
feeds.
For a CommandPost that is Subordinate to the Console, setup refers to which information can be
pushed from the Console to the Subordinate:
• Push User – signifies that User information can be pushed. This refers to local users, not
LDAP users. Refer to Users.
• Push Report – signifies that Reports can be pushed.
Information flow from Master to Subordinate is a manual process. Refer to Set Up for details about
how the CommandPost relationship can be set up and modified.

Fidelis XPS User Guide 216


CommandPost Component Buttons for Master and
Subordinates
When you click a Component row for a CommandPost, several buttons appear. Button availability
depends on user access privileges and the relationship to the Console.
• Register – click to register a Subordinate CommandPost to the Console . Upon registration,
the Console attempts to initiate an encrypted session to the Subordinate. Registration
always occurs from the Master CommandPost.
The CommandPost user performing the registration must have an account on both
CommandPosts and must possess a role that includes CommandPost Administration Full
access.
• Unregister – click to unregister a Subordinate to the Console.
• Edit – click to change basic information about a CommandPost, including name, IP
address, and description. Once a CommandPost is added, the relationship to the Console
cannot be changed.
• Delete – click to remove a CommandPost.
• Setup – click to set up the CommandPost.

Add a Fidelis XPS Component


A Fidelis XPS component can be a sensor, Collector, or a CommandPost.
To add a component:
1. Click System>Components.
2. Click Add Component.
3. Select the component type at the drop down list. You can select from sensor, Secondary
sensor, Collector, Master CommandPost, or Subordinate CommandPost.
If you have a Master CommandPost, you will not be able to add another Master. This type will
not be available until the current Master is deleted.
4. Provide the component's name, IP address, and an optional description. The IP address is
used to identify the component to other components.
The Component Name text box is not available if Secondary sensor is the component type.
5. Click Save.
6. Click Register.
After the component begins to communicate, the status indicator turns green and the Last
Seen value indicates the time of the last communication.
You can now configure the component by selecting it and clicking Config.
7. If needed, add the sensor (or Collector) to user profiles.
For local users:
After you add a sensor, your user profile is automatically updated to include an assignment to
the new sensor. The system default user (admin) will also be assigned to the new sensor.
Note: No other user will have access to the sensor until the User Profile is updated.
Refer to Define User Profiles.
For LDAP and Radius/TACACS+ users:
If a sensor is added by an LDAP user, the new sensor will not be accessible to the LDAP
user after logout. To avoid this situation, LDAP users should update the appropriate profile to
set security settings to the new sensor. LDAP users may need to add profiles to establish
access. If profiles are not updated before logout, only the system admin will have access to
the new sensor. Refer to User Authentication.

Fidelis XPS User Guide 217


Edit a Sensor
You can change the sensor name or IP address (if unregistered). You can also change the
description as needed.
To edit a sensor:
1. Click System>Components.
2. Select theappropriate sensor.
3. Click Edit Sensor.
4. At the Edit Sensor page, enter needed changes.
Note: For secondary sensors, you can only edit the description.
5. Click Save.
Note: After a sensor is renamed, all alerts associated with that sensor are
automatically associated with the new name.

Edit a Collector
You can change the name or IP address (if unregistered). You can also change the description as
needed.
To edit a Collector:
1. Click System>Components.
2. Select the appropriate Collector.
3. Click Edit Collector.
4. At the Edit Collector page, enter needed changes.
5. Click Save.

Edit a CommandPost
To edit a CommandPost:
1. Click System>Components.
2. Select an existing CommandPost and click Edit. Edit is not available for the Console. (This is
the CommandPost to which you are logged in.)
3. Change the CommandPost name, IP address, or description as needed. The IP address is
used to identify the CommandPost to other Fidelis XPS Components.
4. Select either Master or Subordinate if you need to establish hierarchical relationships.
5. Click Save.
6. Click Register.
After the CommandPost begins to communicate the status indicator turns green and the Last Seen
value indicates the time of the last communication.
You can now configure the CommandPost by selecting it and clicking Config.

Fidelis XPS User Guide 218


Set up CommandPost Relationships
CommandPosts can be set up in a hierarchy, allowing you to manage all components within your
environment from a single interface. The Master CommandPost can control Subordinate
CommandPosts and all registered components.
Refer to Assignments. chapter 9 in the Guide to Creating Policies.

Add and Register CommandPosts


The process of creating communication between CommandPosts, requires proper security
precautions to ensure that any CommandPost within your enterprise can only be controlled by a
properly configured Master CommandPost.
1. Define your hierarchy and identify the relationship between all CommandPosts.
2. Log in to a CommandPost that will be Subordinate to another CommandPost. Click
System>Components.
3. Click Add Component and choose Master CommandPost.
4. Provide information about the CommandPost that will serve as the Master. The information
includes a CommandPost name, IP address, and an optional description. The IP address is
used to identify the Master to this CommandPost.
5. Click Save.
6. Repeat steps 2 through 5 for each Subordinate that will use the same Master CommandPost.
7. Login to the CommandPost that will serve as the Master for the CommandPosts set up in
steps 2 - 6. Click System>Components.
8. Click Add Component and choose Subordinate CommandPost.
9. Provide information about the CommandPost that will serve as a Subordinate. The
information includes a CommandPost name (a name unique within this Console), IP address,
and an optional description. The IP address is used to identify the Subordinate to this
CommandPost.
10. Click Save.
11. Click Register. This operation must be performed by a user that has an account on both the
Master and Subordinate CommandPosts. The user must maintain a role that includes Full
CommandPost Administration privileges on both systems. Registration must also be
performed to a Subordinate that has already been configured to accept registration from this
CommandPost. (See steps 2-5 above.)
Note: The registration process will fail if the steps above have not been followed.
If successful, a communication channel is established between the two CommandPosts.
12. Repeat steps 8-11 for each CommandPost that will be Subordinate to the Master.
After the CommandPost begins to communicate, the status indicator turns green and the Last Seen
value indicates the time of the last communication.
You can now set up the CommandPost by selecting it and clicking Setup.

Fidelis XPS User Guide 219


Set up a Subordinate Relationship
The relationship between the Master and a Subordinate defines what types of information can be
pushed.
Setup of a Subordinate on the Master:
1. Select Push User or Push Report.
2. Click Save when done.
The setup process defines what can be pushed to a specific CommandPost. Your choice may be
different based on the location of the Subordinate CommandPost and the information that may be
pushed to it, based on the needs of your enterprise.
Information is pushed from the Reports, and Users pages where individual reports and users can
be chosen individually.
Note: Reports or user profiles that are deleted on the Master can be deleted on
Subordinates by choosing the global delete option.

Set up a Master Relationship


The relationship between the Subordinate and a Master defines how user information is handled
when received from a Master.
• If the Password option is selected, then Passwords on the Subordinate will be overwritten
when user information is pushed from the Master. This only applies to local user accounts
and has no bearing when the Subordinate uses LDAP or Active Directory for user
authorization.
If a user is received from the Master that does not currently exist on the Subordinate, the
password setting is ignored. In this case, the user is added as a new user and the account
will have the same password as the Master.
Note: When a push is received from a Master and the Password Overwrite option is
selected, affected users currently logged into the Subordinate will be logged out.
These users will need to log in with their new passwords.
• If the Sensor Assignment option is selected, then any new users pushed from the Master
will be assigned to all sensors attached to the Subordinate CommandPost.
If the Sensor Assignment option is not selected, any new users pushed from the Master
will not have sensor assignments. An administrator will need to log in to the Subordinate
and modify the sensor assignments.
Sensor assignments for any users on the Subordinate that were present before
establishing the Master are not affected by this checkbox.
• Select Master as Proxy: This enables the Subordinate CommandPost to use the Master
CommandPost as a proxy to access Fidelis Cloud Services such as policy and Fidelis
feeds. The Master CommandPost acts as a feed server to Subordinate CommandPosts.
Click Save when done.

Fidelis XPS User Guide 220


Configure CommandPost
The CommandPost configuration page enables you to specify settings for CommandPost
operations. Your role requires full access to CommandPost administrative functions to access this
page. Some Configuration settings may require additional access permissions, as noted in the
specific CommandPost sections. Refer to User Roles.
46
To access CommandPost configuration, click the CommandPost row at System>Components
and click Config.
License
Alert Retention
Alert Storage
Archive
Audit
Backup and Restore
Custom GeoIP
Diagnostics
Email Config
Exchange Config
Language Config
LDAP Config
Logs
Network Forensics
Proxy Config
RADIUS/TACACS+ Config
Session Timeout
System Monitor
User Authentication
User Notification

License
License shows the Host ID information, the current license key, and an expiration date. Each
component requires a separate license.
To access the License page:
Click System>Components>CommandPost>Config and click the License tab.
When you initially install Fidelis XPS on CommandPost, CommandPost will run in demo mode. A
sensor or CommandPost remains in demo mode until a license key is entered.

46
Components enables you to set up licensing and configure Fidelis XPS components. This
includes adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail,
and setting up user notification and LDAP among other features.
Fidelis XPS User Guide 221
Figure 94. The License
Clicking Request License or the component's Host ID creates an email to
license@[Link], with the subject line automatically completed with the component’s
Host ID. Include in the body of the email your name, the location name and address, phone
number, and reseller name (if pertinent), and Fidelis Technical Support will respond within one
business day with a license key.
When you receive the license key, paste or type it exactly into the License Key box, and click Save.
If the information was entered correctly and matches the Host ID provided, the key will be
accepted. If there is a problem with the license, you will receive an error and the License Key field
will display <Invalid>.
You must enable Execution Forensics at Malware Detection before entering the Execution
Forensics Key.
Enter the Execution Forensics Key.

Expirati on
Fidelis XPS begins displaying notices that your license will expire starting 60 days before the
expiration date. If you receive this notice, contact Technical Support to obtain a new license.

Modify a Li cense Key


To make changes to your license key in case of an entry error for example, just enter a new license
number in the License Key text box and click Save. Please remember that making changes to
license keys should be done with great care.

Demo Mode
If no license key is detected, the sensor and the CommandPost will operate in demo mode. The
sensor does not function in demo mode. A CommandPost in demo mode will not accept alerts from
any sensor and will only accept statistics.

Fidelis XPS User Guide 222


Alert Retention
CommandPost performs daily maintenance which includes three distinct processes:
• Optimization of the stored statistics that feed [Link] operation is performed hourly.

47
Alert purge is the removal of all alerts and recorded objects that are no longer required.
You can setup numerous plans to define when alerts are purged and whether or not to
archive the alert data before the purge operation. Alert purge will briefly lock the database
so that new alerts cannot be inserted during this time. This operation should last only a few
minutes or less and runs once a day at the defined time.
• Disk optimization is required after alerts are purged. This function is very important to the
long term integrity of CommandPost and must be run at least once a week. Optimization will
lock the database so that new alerts cannot be inserted during this time. This operation may
require several hours to complete, depending on the size of alerts and recorded sessions
stored by CommandPost.
Note: If CommandPost storage becomes full, new alerts will overwrite old alerts, even
if the retention period has not been exceeded.
To access this page:
Click System>Components>CommandPost>Config and click the Alert Retention tab.
The Alert Retention page is divided into two sections: Alert Retention Plans and Alert Maintenance
Configuration.

Figure 95. CommandPost: Alert Retention

Alert Retention Plans


Database Maintenance must be performed at least once per week to optimize the CommandPost
database. This process includes the removal of old alerts, per the default plan setting. Alert
Retention plans can be created to remove certain alerts sooner or to retain certain alerts for a
longer time period. Plans are created based on alert characteristics.

47
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 223
Database Maintenance will also remove data associated with the alerts selected with a plan. This
data includes recorded objects, PCAP files, and quarantined email.
Note: this data will be removed only after all alerts associated with the data are
purged.
For alerts that have been imported to the system from an archive file, the age of the alert is based
on the import date and not the timestamp associated with the alert. The system defines a single
plan named Default that purges all alerts older than 45 days as well as any remaining recorded
objects, PCAP files, and quarantined email. The number of days (45) can be changed.
If any plans have been defined, they will be listed above the Default plan on the page. The list
provides a descriptive name, the retention period for the plan (in days), the archive setting (Yes or
No), and the Author, which provides the user name of the person who last saved the plan. An Edit
button and a Delete button is available for each plan in the list.
To change the Default plan:
1. Click Alert Retention.
2. Change the number of days to a value between 1 and 999.
3. Click the Archive checkbox if you wish to archive alerts before purging. Refer to Retention
Archive.
4. Click Save Default.
Any number of retention plans can be added to change the behavior of the alert purge operation. A
plan can define alerts by one or more attributes and can be set to retain the matching alerts for a
period shorter or longer than the default setting. If two or more plans identify the same alert, the
longer retention period will apply and archiving will be done if any matching plan had the archive
checkbox set. You can access the Edit page by clicking Edit next to an existing plan or by clicking
New Plan.
To create a new plan or edit an existing plan:
1. Click Alert Retention.
2. Click Edit next to a plan in the list or click New Plan.
3. The Edit Alert Retention Plan page displays.

Fidelis XPS User Guide 224


Figure 96. CommandPost: Alert Retention edit plan

Fidelis XPS User Guide 225


4. For an existing plan, information about the plan is provided. This includes the name of the
plan, the name of the user that last saved the plan, and the date and time of the last save.
The username is important in this context because alerts are chosen based on the role,
assigned alert management groups, and assigned sensors for this user. Refer to Users,
Roles, and Groups.
5. Enter the retention period as 1 to 999 days.
6. Select the archive option, if desired.
7. Choose one or more of the available alert parameters to apply alerts to this plan. The
available options include:
• Sensors, which refers to the name of the sensor that generated the alert.
• Severity of the alert
• The name of the Rule that was violated
• The name of the Policy that was violated
• The name of a Label applied to the alert
• The name of the group to which the alert belongs
• The alert action
• Ticket Status refers to the CommandPost workflow status.
• The Resolution of closed tickets
You must choose at least one filter criterion to distinguish this plan from the Default plan.
8. Enter a name for the plan in the Save As text box. This name will be the unique identifier of
the plan and should be descriptive.
9. Click Save Plan. Click Reset to revert to the last saved state for the plan. Click Cancel to
return to the Alert Retention page without saving.
When saved, the alert access will be determined by your role, assigned alert management groups,
and assigned sensors.
If you are saving a plan that was last saved by a different user, a warning message will appear
informing you of the potential change in alert access.

Alert Maintenance Confi guration


The Alert Maintenance Configuration enables you to control the master settings of alert
maintenance operations. These controls include the following:

• Execution time can be configured by Daily Execution Time and Maintenance Days. The Alert
Purge and database Optimization processes will be executed at the chosen time on the
chosen days. Based on this configuration, Purge and Optimization will run at most once per
day or at least once per week. The settings do not change the normal hourly optimization of
statistics.
• Archive options include the External Archive Directory, the Maximum Archive Attempts, and
the setting for Archival of Recorded Objects. Refer to Retention Archive.
Click Update to save any changes made to the Alert Maintenance Configuration.

Retenti on Archive
CommandPost appliances contain a local hard drive for storage of alert data. The local storage
may not be adequate for your long term storage requirements, therefore alert archival may be an
important feature in your environment.
There are three methods available for archival:

• Automated archiving at routine intervals; refer to Export.

Fidelis XPS User Guide 226


• Manual archiving of alerts; refer to Export.
• Archiving alerts before the alert purge operation associated with Alert Retention.
Archiving alerts before a Purge has the following considerations and controls associated with
retention plans:

• Archive creates a Fidelis-formatted archive file and sends it to an external system. The name
of the external system and login credentials are defined at the Archive page. Refer to Archive.
• When a plan includes the Archive option, the maintenance process creates an archive file and
attempts to send it to an external system. If archive fails, no alerts associated with this plan
will be purged. If a failure occurs, CommandPost status will indicate the problem. In this case,
you should correct the problem and visit the Archive page to test the correction. A successful
test will clear the CommandPost status error.
• If there are repeated failures of archive, CommandPost will increase the severity of the status
message. The setting for Maximum Archive Attempts defines the number of days for which
purge will be skipped upon archive failure. If archive fails for this number of days, alerts will be
purged without archive. The Maximum number of attempts can be set between 1 and 7 days.
• A successful archive transfers the archive file to the external system located in the directory
path provided by External Archive Directory. This must be a fully qualified path to the desired
location on the external system. Once the file is stored on the external system, you can move
it to any location required for long term storage. Refer to Archive for information about
importing archive files to CommandPost.
• The Alert Maintenance Configuration for Archive Recorded Object applies to all plans where
Archive is chosen. When this option is selected, the archive file will contain the recorded
objects associated with the alerts. You can select to Archive sessions when alerts are
archived or to Archive PCAPs when alerts are archived. Whether this option is selected or
not, the alert purge operation removes any recorded object associated with an alert subject to
removal.

Alert Storage
Alert storage provides a control to encrypt alert information within the CommandPost database. By
default, alert forensic data and the associated recorded objects are stored in plain text. The
information is only accessible through the CommandPost GUI or API. Access requires an
authenticated user with the proper privileges. Refer to Define User Profiles. Database encryption
can provide another level of protection.
When you change the encryption setting, forensic data and recorded objects already stored by
CommandPost will no longer be available. An encryption change will provide a warning regarding
the availability of current information.
If encryption is important to your organization, Fidelis recommends that you enable this feature
immediately upon receipt of your CommandPost. Fidelis uses AES 128-bit key encryption. For
existing installations, you should archive your alerts before changing encryption status.
To enable encryption:
1. Click System>Components>CommandPost>Config and click the Alert Storage tab.
2. Enter an encryption key in the text box. Retain this key for future use. You will need the
original encryption key to disable encryption or to enter a new key.

Figure 97. CommandPost: DbEncryption

3. Click Encrypt. A dialog box warns that you will lose access to forensic data and recorded
objects.
4. Click OK to proceed.

Fidelis XPS User Guide 227


When enabled, the Database Encrypted icon displays at the top right of the
CommandPost GUI.
To disable encryption:
1. Enter the original encryption key.
2. Click Unencrypt. A dialog box warns that you will lose access to forensic data and recorded
objects.
3. Click OK to proceed.

Archive
Archive enables you to configure a name and login for a remote FTP server. CommandPost will
use the information to export archive files to the remote system. Refer to Export. Fidelis-formatted
archive files are encrypted. These files are decrypted upon import. Archive also enables you to
import files. Refer to Import from a Remote FTP Server.
Note: To see the CommandPost Config>Archive page, users need View privileges for
48 49
CmdPost Admin, Alerts , and Alert Details . With View privileges, the Archive page
header will display View Only and buttons will not be active.
To save configuration changes and access buttons, users need Full access to
CmdPost Admin, Alerts, and Alert Details.
Access to System>Export requires Alerts and CommandPost administration
privileges. This access allows you to export alert archives using the process set up
by the CommandPost administrator, as noted above.

Set Up a Remote FTP Server


To set up information for a remote server:
1. Click System>Components>CommandPost>Config and click the Archive tab.

48
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
49
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 228
Figure 98. CommandPost: Archive
2. Enter a name for the remote server.
3. Enter a login name and password for the remote server.
Note: Remote login name and password do not support the use of non-ASCII
characters.
4. To use an encrypted transmission channel, click Use Secure FTP. The remote server must
have an ssh service.
5. If needed, enter your encryption key to encrypt Fidelis archived alerts or leave this text box
blank to use the default encryption key. You will need the same encryption key to decrypt
Fidelis archived alerts.
6. Click Update Configuration.
After clicking Update Configuration, you may test communication between CommandPost and the
remote server. To test:
1. Click Test Archive Configuration.
Note: No alerts are transmitted during the test process, only test data.
2. Enter a directory name on the remote server where the archive file will be stored. The entry
must be a fully specified path. For example, on a Unix or Linux server: /home/Fidelis/archive.
If the remote directory does not exist, it will be created.
Be sure that the user name provided at the Archive page has permission to write to this
directory.
3. Click Execute Test.
The test process creates a small text file including a timestamp representing the exact time of
creation. This file is sent to the remote server, retrieved from the remote server, and compared to
the original. If the transfers complete and the file comparison passes, then the test succeeds. Any
failure represents problems with configuration of either CommandPost, your remote server, or
network problems that may prevent communication between the systems.
Following a test, the simple test file will reside on your remote server. You may remove it at your
convenience.

Fidelis XPS User Guide 229


Import from a R emote FTP Server
The Archive page is also used to import alert and session data that was previously exported to your
remote server.
To import archive data:
1. Click Import Archive Data.
2. Enter the directory on your remote server that holds the archive files. All files in this directory
will be transferred to CommandPost and imported. If you do not want to import all files, you
will need to manage your remote server storage accordingly.
3. Choose how you would like to handle conflicts between imported alert and object information
and the information currently stored by CommandPost. Your options are:

• Reject duplicate alerts in your import data. The alert UUID is used to determine duplicate
alert information and the Object ID is used to determine duplicate objects. This choice
will ignore the imported data and CommandPost information will remain unchanged.
• Overwrite CommandPost data with information from the import file. Note that
CommandPost maintains an alert ID and a UUID for every alert. The alert ID is
sequential, but not universal across all CommandPosts. The UUID is a uniqueID per
alert. If you choose to overwrite CommandPost data, the local alert ID will most likely be
changed after import. The UUID will be maintained from the import file.
• Restore Alerts as Original preserves the original insert time and alert ID.
4. Click Execute Import.
This operation can be time consuming, based on the network speed between CommandPost and
the remote server, the number of alerts in the imported file, and the number of duplicates detected.
Upon completion, results will be displayed.

Configure Audit
The CommandPost audit log tracks all user activity. Access is available to any user whose role
includes the audit privilege. A user that has both Audit and CommandPost privileges may configure
CommandPost to log only the activity of interest.
50
Note: To see the CommandPost Config>Audit page, users need View privileges for
CmdPost Admin and Audit. With View privileges, the Audit page header will display
View Only and buttons will not be active.
To save configuration changes and access buttons, users need Full access to
CmdPost Admin and Audit. Refer to Define User Roles.
The CommandPost Audit configuration page enables you to select audit levels for actions on the
CommandPost and any sensors registered to it.
To configure audit:
1. Click System>Components>CommandPost>Config and click the Audit tab.

50
Audit enables you to search for audit information.
Fidelis XPS User Guide 230
Figure 99. CommandPost: Audit

2. Enter the amount of time to retain audit records. The default is 190 days. Any audit record
older that this number of days will be removed.
Note: The audit log is stored on the CommandPost hard drive. When the allotted
audit space is full, old audits will be removed to make room for new entries to the
log. This event will also generate user notifications and turn the CommandPost
status to red. Adjusting the storage time can help avoid this situation.
3. Audit records can be exported to an external syslog server. To enable audit export, select
Enable and enter the IP address or host name for the syslog server. Audits will be written to
the external syslog as they are written locally to the CommandPost audit log.
4. Select Audit events as needed.
The audit system is broken into ten facilities with six events. By using the available
checkboxes, you can select the events of interest for your log. Checkboxes are available to
select or deselect all events within a facility as well as a checkbox to select or deselect all
events.

T a bl e 2 4. Ev e nt s t o A u di t

Event Description

Access Events Logs login and logout events, API access and access violations. Access
violations can be caused when a user attempts to access data forbidden by
their role, sensor assignments, or alert management assignments. Access
violation events are also logged when users attempt to load invalid licenses,
upload invalid files, or attempt other actions to circumvent CommandPost or
sensor security.

Addition Logs an addition to the system such as a new user, report, or policy.
For alerts and quarantined an addition is logged when there is an import.

Deletion Logs a deletion of system data, such as removal of a user,report, or policy.


For Alerts or Quarantined items, a purge is logged as a deletion as well as
alerts and audits removed for disk management and database maintenance
operations.

Fidelis XPS User Guide 231


Event Description

Modification Logs a change modification of system data, such as a change of user


information or a report change.

Data Extraction Logs when data is exported from CommandPost. This may be the result of a
user action on the CommandPost GUI or the result of scheduled reports and
exports that occur in the absence of a GUI.

Page Access Logs when system information is viewed using the CommandPost GUI. This
applies to all pages of the CommandPost GUI.

Note: Not all events are available for each facility.

T a bl e 2 5. F a ci l i ty R o ws

Facility Description
51
Alerts Items on the Alerts>List page including Alert Details
52
Quarantine Items on the Reports>Quarantine page including the details of any
quarantined emails

Automated Data Items exported, purged, or modified by scheduled events, such as Alert
Access Retention, exports, and feed updates
53
Reports and Includes Saved Reports, Summary, and Network Reports
Exports

Policies Items on the Policies page as well as policy modification on the sensor as a
result of sensor updates
54
Users Items on the System>Users page

Device Config Any component configuration changes including the CommandPost and all
sensors

Dashboard Items on the Dashboard


55
Audit Items on the System>Audit page

Login, Logout, Includes: all login attempts, both valid and invalid, logout, and any attempt to
Access Denied access data not permitted by the user's role

Metadata Items on the Metadata page

API Audits API calls from external sources. These sources are any API not
accessed by Fidelis XPS Web or regular reporting processes.

5. Click Update to save your selections.

51
Alert Details is the most granular level for examining alert data.
52
In Fidelis XPS, refers to e-mails that were quarantined by a Fidelis XPS Mail Sensor and are
currently held in the quarantine queue.
53
Network Reports display statistical information about the data flow observed by Fidelis XPS
sensors.
54
Users enables you to create and manage users, their roles, and user access.
55
Audit enables you to search for audit information.
Fidelis XPS User Guide 232
Backup and Restore
Backup enables you to back up configuration information for a CommandPost and any components
registered to it. The backup includes configuration information such as policies, reports, user
information but does not include data such as alerts. You can also include a system backup with an
automatic export, provided that you select the Fidelis Archive export method. Refer to Export
Methods.
Restore enables you to restore configuration information for a CommandPost and any components
registered to it.

Backup
To run backup:
1. Click System>Components>CommandPost>Config and click the Backup and Restore tab.
The System Configuration Backup and Restore page displays.

Figure 100. System Configuration: Backup


2. Click Run Backup. The backup stores configuration and policy information in a file. The
name of the backup file and the MD5 hash for it display.
Note: Do not access other items on the page or attempt to navigate away from it while
backup is in progress.
1. Click Download. You can open the file or save it to your workstation.
To back up during an automatic export:
1. Click System>Export. A list of available exports displays.
2. Select Fidelis Archive export method at the System>Export page.
3. Click Include Configuration Backup.
4. Select Alerts to export: either All, By Criteria, or None. If None is selected, the checkbox:
Include Configuration Backup is automatically selected. In this case, the export will only
include the configuration backup file. The backup file is created and is exported to the same
location as the export. Refer to Define Exports for more information.

Restore
You can restore a CommandPost's configuration directly from the backup file or replicate the same
configuration to multiple CommandPosts. You can also select and restore configuration information
to components registered to the CommandPost.
To restore a CommandPost:
1. Select a backup file and click Upload restore file. The name of the Restore File displays.
2. If the Restore File name is correct, click Verify. The host ID , the version number, backup
time, and user information display. If the host IDs match, the license is automatically
restored.

Fidelis XPS User Guide 233


Figure 101. System Configuration: CommandPost Restore
3. Choose the restore mode.
Note: Restoring or Replicating from file overwrites any existing configuration
information. Use options 2 or 3 to replicate configuration information to another
CommandPost.
To restore and overwrite all existing CommandPost configuration information, select option 1.
To restore and overwrite configuration information except for sensor definitions, select option
2.
To restore and overwrite configuration information except for sensor definitions and User
information, select option 3.
4. Click Restore CommandPost.
5. Click OK at the dialog box to proceed.
Note: Do not access other items on the page or attempt to navigate away from it while
the restore is in progress.

Fidelis XPS User Guide 234


To restore a component:
1. Select the backup for the component.
2. Select the target component. You can only restore backup files for a component to the
same component. The component must also have the same name.
Note: For a Collector, only configuration information can be backed up and restored,
not metadata.

Figure 102. System Configuration: Component Restore


3. Click Restore Component.
4. Click OK at the dialog box to proceed.
Note: Do not access other items on the page or attempt to navigate away from it while
the restore is in progress.

Custom GeoIP
Custom GeoIP provides the ability to customize Location information for IP addresses. Location
information appears in Dashboard widgets, Alert List, and in Alert Details and may be used to
create a Location fingerprint. Refer to chapter 3 in the Guide to Creating Policies.
Public IP addresses show the location provided by Maxmind. The names of countries are
maintained by ISO 3166 and augmented by special codes provided by MaxMind. Refer to
[Link]
Private IP addresses will show the location as Unknown. You can use Custom GeoIP to change the
location information of both public and private IP addresses.
When you define locations, you may associate each with a flag using the ISO 3166 country codes
or one of the seven custom flags provided by Fidelis. Location information displayed on the World
Map and Globe dashboard widgets is based on the ISO 3166 flag. You may enter coordinates to
define a location for Unknown locations or any that use a custom Fidelis flag as the location
identifier.

Create the G eoI P Definition File f or Custom GeoI P


Ranges
To define GeoIP information for IP addresses, create a file that contains information about the IP
addresses that you need to specify. This file needs to be in text format and must contain tab-
delimited fields. The file may contain any IP addresses, private or public. If public IP address
ranges are defined, the definition in your file will override the locations that are provided by
Maxmind.
• Enter the low end of the IP range.
• Enter the high end of the IP range.
Note: IP address ranges must not overlap. IPv6 addresses are not supported.
• Enter a 3 to 8-letter code for matching against. This code can be used on multiple entries
but must always correlate to the same country name. This code is used for Location
fingerprints. This code does not display in the GUI.

Fidelis XPS User Guide 235


• Enter a location name for a full display name that will appear as a country name in Alert
Reports and in the Alert Details. This information is also used for search and filter for
source/destination country.
This name must correlate with the country code and can contain up to 32 characters. The
country name, however, cannot be the name of an existing country.
• Secondary Location Name (Optional) You can also specify an optional secondary location
name to further narrow location information in Alert Details. The Secondary Location Name
displays as a city name in Alert Details. Similar to the actual country lookup, there can be
multiple entries that match a given country code.
• Flag (Optional) You can specify a country flag for the IP range at the Alert Details page.
You can use a two letter country code that complies with ISO 3166-1, alpha-2 such as US
or CA. Custom flags are also available as shown below. The Globe and World Map
Dashboard widgets will use the ISO 3166-1 country codes to display alerts on the map. If
you use a custom flag, you may specify a map location. Refer to Specify Map Coordinates
for Unknown and Custom Flags.
Custom flags are:
C1
C2
C3
C4
C5
C6
C7
Below is a sample file:

Specify Map C oordinates f or Unknown and C ustom Flags


If you have not uploaded a Custom GeoIP file, all private IP addresses will appear as Unknown in
Alerts and Alert Details.
On the Globe and World Map Dashboard widgets, these Unknown alerts will appear in the Atlantic
Ocean. The location of Unknown locations on the Globe and World Map can be changed by
entering a latitude and longitude to map the location. If you have provided a Custom GeoIP file that
uses one of the seven Fidelis flags (C1 through C7), you may use latitude and longitude to define a
map location for each of these locations.
Refer to Dashboard for information about the Globe and World Map widgets.

Fidelis XPS User Guide 236


1. Click System>Components>CommandPost>Config and click the Custom GeoIP tab.

Figure 103. CommandPost: Custom GeoIP: Address Ranges


2. Ensure that Enable is checked.
3. Specify a latitude and longitude location for Unknown locations. You can also keep the
default values to map the location in the United States.
4. Specify a latitude and longitude location for each custom flag used in your Custom GeoIP
file. You can also keep the default values to map the location in the United States.
5. Click Save.

Configure Custom GeoIP R anges


Upload the configuration file to CommandPost. You need CommandPost administrator privileges.
Refer to Define User Roles

1. Click System>Components>CommandPost>Config and click the Custom GeoIP tab.


2. Ensure that Enable is checked.
3. Click Upload New. The Upload Custom GeoIP Ranges displays.

Figure 104. CommandPost: Custom GeoIP


4. Click Browse and navigate to the file on your workstation.
5. Click Upload. This will overwrite earlier configuration files.
6. Click Save.
The Custom GeoIP address ranges you added are available for you to include in Location
fingerprints. These display in the Countries list for a Location fingerprint and are also included in
the Filters section of the Custom Reports page.
Refer to chapter 3 in the Guide to Creating Policies.

After uploading the GeoIP file, you can click to download and view the file.
Click OK at the confirmation dialog box.

Fidelis XPS User Guide 237


Diagnostics
CommandPost problems may be caused by corrupt tables within the embedded database.
Diagnostics enables you to check database tables and to repair them if needed.
To check for and fix database corruption::
1. Click System>Components>CommandPost>Config and click the Diagnostics tab.
2. Select the extent of checking you want Diagnostics to perform.
Quick – Checks the integrity of indices on the table and usually executes quickly.
Medium – Performs a Quick check and verifies the checksum value on each row of each
table. A medium check may require several minutes to complete.
Extended – Performs a Medium check and a look up of each row and table index on the table
to verify 100 percent consistency. An extended check may require a long period of time.
Because checks and repairs can be time-consuming, it is recommended that you perform a
Quick Check and Repair first. If the problem is not corrected, attempt the Medium and
Extended Checks.
3. Click Check. A notice displays telling you that this process might take longer than expected.
4. Click OK to proceed. Check indicates the progress of the check and which tables it is
checking within a running dialog box. When complete, Check displays a message indicating
that the Check is complete. A list of files that need repair also displays.
Click + to view the dialog.
Click – to collapse the dialog.
5. Select a Repair option.
The Repair method should correspond to the Check method used. For example, if you
selected a Quick Check, then you should proceed with a Quick Repair.
Quick – Only attempt to fix the index tree.
Medium – Provides the same repairs as Quick.
Extended – Rebuild the index tree by row.
Repair is only available if one or more tables were determined to be corrupt in the preceding
Check operation.
6. Click Repair. A notice displays telling you that this process might take longer than expected.
Click OK to proceed. Repair indicates the progress of the repair within a running dialog box.
Click + to view the dialog.
Click – to collapse the dialog

Fidelis XPS User Guide 238


Email Configuration
Email Config enables you to set email parameters to identify messages sent from CommandPost.
1. Click System>Components>CommandPost>Config and click the Email Config tab.

Figure 105. CommandPost:Email Configuration


2. Enter a name and an email address for CommandPost. The sender’s name is the full name
that will be associated with the sender’s address. If left blank, this will be set automatically to
Fidelis CommandPost.
The sender’s address is the email address from which the reports will be sent. If either field is
left blank, email will not include a From name or address.
Note: If the email address is not a reachable address, some email servers might not
accept the message.
3. Configure Smart Relay by entering an IP address or a host name to specify an email server
on your enterprise's network. Any outgoing email will be forwarded to the specified server.
If the Smart Relay is set to a host name, a DNS lookup will be required and your
CommandPost will require DNS access. If the Smart Relay is set to an IP address, DNS
access is not required.
4. If Smart Relay requires authentication, select Yes at Smart Relay Authentication and enter the
user name and password.
If Smart Relay does not require authentication, select No at Smart Relay Authentication and
leave the user and password fields blank.
5. Click Update.
CommandPost will use these settings for messages from the ticketing system and for reports
delivered by email. Reports include user-generated and scheduled Alerts, Custom, and Summary
reports.

Fidelis XPS User Guide 239


Configure Exchange
Fidelis XPS sensors can inspect encrypted Exchange messages only when presented with the
encryption keys for your domain. Configure Exchange enables you to configure CommandPost to
access and retrieve the necessary authentication information. The retrieved information is
encrypted when stored on CommandPost and sensor as well as the network connections between
CommandPost, Active Directory, and sensor.
Obtain the following information before you configure CommandPost:

• Domain Controller name (For example: DomainController_server)


• Domain Name ([Link])
• Domain Controller IP Address
• User name (Must belong to the Enterprise Admin group.)
• Password
Also ensure that the kerberos.[[Link]] must be inserted into the DNS server with a
valid IP address of the Kerberos server. This must be done for Kerberos authentication to work.
Samba needs to find the kerberos server IP address which will be used for Kerberos
authentication.
To configure Exchange-server Communication:
1. Click System>Components>CommandPost>Config and click the Exchange Config tab.

Figure 106. CommandPost: Exchange


2. Enter the Domain Name, Domain Controller Name, and the Domain Controller IP Address.
3. Enter a user name. The user must belong to the Enterprise Admin group.
4. Click Password to change password and enter a password for authentication by your directory
server in the text box. The name and password will be used by your directory server to allow
CommandPost to retrieve information.
5. Click Update to save your settings.
6. Click Test to verify communication with the [Link] Exchange Configuration Test Output
displays the results.

Fidelis XPS User Guide 240


CommandPost Language Configuration
CommandPost Language Configuration is necessary for Content fingerprint testing and generation
which allows these processes to correctly interpret the contents of your files.
Settings made on the CommandPost will not affect settings for the sensors. Sensors must be
configured separately.
Note: Fingerprint test results may not match sensor results on network traffic if
language configuration differs.
To specify language settings on the CommandPost page:
1. Click System>Components>CommandPost>Config and click the Language Config tab.

Figure 107. CommandPost: Language Configuration


2. Choose the appropriate mode:

• ASCII mode will recognize ASCII characters in any file. When applied to a sensor, ASCII
mode provides the optimal performance. If your sensors are running ASCII mode, you
should perform fingerprint testing and generation in ASCII mode.
• International mode will recognize Unicode (UTF-8, UTF-16, and UTF-32) characters as
well as all supported extended ASCII character sets. When International mode is
selected, a list of summarized character sets will appear. The list of supported character
sets is available within each summary.
Many file formats will indicate the character set used within the file, although this
information may not be visible within the file processing or editing application. For these
files, CommandPost will correctly interpret the contents in International Mode.
If the character set is not specified in the file, CommandPost will utilize the character
sets that you specify on this page. For fingerprint generation, including Keyword and
Keyword Sequence generation, Identity Profile training, Exact and Partial Content,
CommandPost will use the first character set in the list. For fingerprint testing,
CommandPost will translate your file using each character set in your list and test it
against your fingerprint.
3. In International Mode, click a character set summary, such as Latin or Cyrillic. Each opens to
display a list of specific character sets. Select one or more and click Add. Your selection
displays in the text box on the right. Use the arrow keys to change the order of the selected

Fidelis XPS User Guide 241


character sets or to remove a selected set. Character set order matters for fingerprint
generation processes.
4. Click Save.

LDAP Configuration
You can configure CommandPost to interface with an LDAP or Active Directory server. After
configuration, CommandPost will be able to authenticate logins via directory authentication, to use
directory information in policy definitions, and to associate user information detected within alerts to
directory information.
To correctly configure the CommandPost interface with LDAP, you must have thorough
understanding of your local directory server data structure and login access to all user records
stored on your server. You may use your favorite LDAP/AD browser software to gain the required
information for configuration.
Obtain the following information before you configure CommandPost to work with an LDAP server:

• Server name (For example: ldap_server.[Link])


• Server port (usually is 389)
• Authentication method used (usually is simple). Simple means that the password entered is
sent in plain text to the LDAP server. Digest-MD5 sends a hash of the password.
Note: User name and password can be left blank for anonymous access if your LDAP
server supports this.
• LDAP User name (For example:
cn=Administrator,cn=Users,dc=yourcompanyname,dc=com)
• Password
• LDAP Base (example: dc=example,dc=com or cn=Users,dc=example,dc=com)
• Check the LDAP server before configuring LDAP at the CommandPost.
Fidelis XPS systems that use LDAP request all records for a given base/filter combination
and cache the records locally on the CommandPost with a periodic refresh functionality built
in. By default, LDAP directories limit the number of objects that can be returned from a single
search filter. Please make sure this limit is disabled or at least large enough to return all the
records for the base/filter combination configured at the CommandPost.
To configure LDAP Server Communication:
1. Click System>Components>CommandPost>Config and click the LDAP Config tab.

Fidelis XPS User Guide 242


Figure 108. CommandPost: LDAP/AD
2. Enter the Server Name or IP address of your LDAP or Active Directory server.
3. Enter the port number for the server or choose the default of port 389. Make sure that there
are no firewall settings between CommandPost and your directory server that will block this
port.
4. Select the authentication method that your directory server requires. CommandPost supports
simple or Digest-MD5 authentication.
5. If your directory server supports TLS, click Use TLS to encrypt communications between
CommandPost and your directory server. If your directory server's host certificate was signed
by a private CA:
a. Copy the CA certificate in PEM format to /etc/openldap/cacerts on CommandPost.
This CA certificate is from the CA that signed your directory server's host certificate.
b. On CommandPost, run the command: /usr/sbin/cacertdir_rehash
/etc/openldap/cacerts
6. Enter a user name and password for authentication by your directory server. The name and
password will be used by your directory server to allow CommandPost to retrieve information.
Either field may be left empty if your server allows anonymous access.
Note: Fidelis XPS user names are case-insensitive. LDAP or Active Directory
entries that are case sensitive will not be supported.
7. Enter the server timeout in seconds. CommandPost will stop communication attempts if the
server does not respond within this time. CommandPost will resume communication attempts
at the next refresh interval or login attempt.
8. Specify the refresh interval in hours. The refresh rate refers to the frequency of
CommandPost requests to download directory information. This applies to information used in
policies and alert attributes, but not to user authentication. For user authentication, the
directory is accessed with each user login attempt.
9. Click Test to test communications between CommandPost and the LDAP server. Make sure
that the returned records are what you expected.
All records that match the base/filter combination that are returned from the server display in
Fidelis XPS User Guide 243
the test results, but only records with email or user attributes are cached and used for
matching. Test results display a record count that gives the count of such validated records.
10. Click Update to save your settings.
After you establish communication to a directory server, CommandPost can use the link for
three distinct activities.

• User Authentication. To configure user authentication by your directory server refer to


LDAP Authentication.
• Policy Creation. You can direct CommandPost to retrieve user or group attributes from
your directory which can then be used by policy creation. For example, you can set
policies based on the activities from Human Resources, where Human Resources refers
to a group established in your directory. To create policies based on your directory
attributes refer to chapter 3 in the Guide to Creating Policies.
• User Information Retrieval. When an alert is generated, information about the end user
who caused the violation can be extracted from your directory. This information will be
included with any applicable alert. The match information is based on email addresses or
IP-to-ID user mapping information from the A10 Networks server, if configured. To
specify which user attributes you would like to include with your alerts, complete the Alert
Attribute Insertion section on the LDAP Config page:
Note: You can use LDAP browser software on your PC to connect to the LDAP
server to get the correct base, filter, and attribute information.
To use LDAP to retrieve user information, you must first enter LDAP Lookup Parameters to locate
the appropriate user information in your LDAP or AD structure. You can also enter IP2ID User
Match information for an A10 Network Identity Management System or enter extra LDAP attributes
to include in alerts.
To enter LDAP Lookup Parameters:
1. Click Add Parameters to enter Base and Filter information.
Enter a Base to specify the LDAP starting point within your directory server hierarchy. User
information found under this base will be used to extract user information for alerts. For
example: "ou=abcdepartment, dc=mydomain, dc=com"
Enter one or more Filters in the text box, as needed. This enables you to filter search
results from those directory entries found at the Base.
For example, if you enter "cn=Joe*" in the Filter and "ou=abcdepartment, dc=mydomain,
dc=com" for Base, the server will return records for users whose names begin with Joe in
the abc department. Note: The email attribute is configured by default and generated
alerts will match on this attribute.
2. Click Add, then click Update.
In a large enterprise, the LDAP or AD server may not be able to return records for all users
with a single base and filter. If this is the case, you will need to identify multiple base and
filter pairs to extract all user information. There is no limit placed on the number or
parameters that can be added to CommandPost. At the configured refresh interval,
CommandPost will execute all LDAP queries and accumulate the results into its internal
cache of user information.
To edit or remove LDAP Lookup Parameters:

• To edit LDAP Lookup Parameters, click next to the Base and Filter entry you want to
change. Text boxes display that enable you to edit the base or filter entries. Enter your
changes and click Update.

• To remove LDAP Lookup Parameters: click next to the Base and Filter entry you wish to
remove. Click OK at the dialog box to continue with the deletion.
Enter IP2ID User Match information if you have an A10 Network Identity Management system.
When an alert is generated, the user ID will be matched against the provided LDAP attribute for a
match. If a match is found, user information from LDAP can be added to the alert information.

Fidelis XPS User Guide 244


Extra LDAP Attributes can be defined to extract these fields from LDAP to include in alerts. Note:
If you do not have an A10 Network Management System, LDAP information will be used for all
email-based alerts, when the FROM address of the alerted email matches the email attribute in the
LDAP directory.
Specify Extra LDAP Attributes to extract and display from your directory. You may enter RFC-
defined or user-defined attributes directory into the text box. Your list of attributes will be displayed
as user information within Alerts. Refer to Alert Details.

• Enter attributes into the text box and click . Use attributes defined in RFC 4519 or any
user-defined attributes.
The attributes name, email address, organization, organization unit, title, and user id are part
of the query to the server and are present by default.

• To remove attributes from the list, select an attribute and click .

Logs
Logs enables you to view log files from a sensor or from CommandPost that reside in different
directories, including/FSS/log and /var/log among others. Log files can help in troubleshooting
problems and are a valuable resource when interacting with Fidelis Technical Support. After
retrieving a log file, you can send it via email. Fidelis support is the default email recipient of all log
files.
To retrieve logs:
1. Click System>Components>[sensor or Collector name]>Config and click the Logs tab. You
can view logs for another component by selecting it at the Component list.
2. Select a file from the Log Files list.
3. Click Invert Log to reverse the order of log entries, if needed.
4. Click View Log. The selected log entry displays and the Email Log button is available.

Fidelis XPS User Guide 245


Figure 109. Logs

Create D ebug Log


In some circumstances you may need to send a large collection of logs to Fidelis Support for
problem diagnosis. The Debug Log button makes it easy to generate a single archive of many logs
and transfer it to your local workstation.
To do this:
Click Create Debug Log.
A popup message states that creating a system debug log file may requite several minutes. Click
OK to continue to generate the debug log.
When the debug log is successfully generated, you can click Download and either open the file or
save it.

Fidelis XPS User Guide 246


Send Logs
You can view the log and send it via email.
To do this:
1. After retrieving a log file, click Email Log. The Send Log dialog box displays.

Figure 110. Email Logs


2. Enter the desired email addresses. The default recipient address is
support@[Link] and the default sender email address is defined at the
CommandPost>Email Config page.
3. Enter a subject, if needed.
4. Click Send.
The log file displays in the body of the email message.
The log file is sent as an email attachment.

Fidelis XPS User Guide 247


Network Forensics
Network Forensics is used to enable and configure integration with the Solera full packet capture
system.
Ensure that you have properly set up a Solera server accessible to CommandPost. Once enabled
and configured, you will be able to see Solera information in the Packet Capture section of Alert
56
Details .
To configure the Solera interface:
1. Click System>Components>CommandPost>Config and click the Network Forensics tab.

Figure 111. CommandPost: Network Forensics Single Solera Server

2. Select the configuration that fits your network environment: either a single Solera system that
captures all traffic analyzed by each Fidelis XPS sensor in your environment or a different
Solera system where each captures traffic analyzed by one or more Fidelis XPS sensors.
If a single Solera server collects all network traffic:
1. Enable Solera integration.
2. Enter the URL for the Solera server.
3. If desired, enter a login and password set up on the Solera server. This enables automatic
login for Solera versions 5 and below
If Solera servers are different per sensor:
1. Click Solera Servers are different per sensor.

Figure 112. CommandPost: Network Forensics Single Solera Server


2. Enable Solera integration for each sensor as needed
3. Enter the URL for the Solera server for each enabled sensor.

56
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 248
In this environment, each alert will point to the Solera server associated with the sensor where the
alert was detected. If you do not enable Solera for a sensor, then alerts generated by that sensor
will lack the Solera interface on the alert details page.

Proxy Config
If external access from CommandPost goes through a proxy, you need to configure CommandPost
for proxy connectivity.
To configure the proxy server:
1. Click System>Components>CommandPost>Config and click the Proxy Config tab.
2. Ensure that Use Proxy is checked.
3. Enter the host name or the IP address for the proxy server
4. Enter the port number. Communication between CommandPost and the server usually
occurs on port 80.
5. If the proxy server requires authentication, enter a user name and a password.
6. Click Save Proxy Config.
When the proxy server is configured, you can enable its use by clicking Use Proxy for each
configured feed.

RADIUS/TACACS+
RADIUS/TACACS+ configuration enables you to configure CommandPost for RADIUS and
TACACS+ authentication support for login access to Fidelis XPS. RADIUS is Remote
Authentication Dial -In User Service and TACACS+ is Terminal Access Controller Access Control
System+ .
1. Click System>Components>CommandPost>Config and click RADIUS/TACACS+ .
2. Enter the name of the RADIUS or TACACS+ server.
3. Enter the shared secret, a key parameter that needs to be in sync with the RADIUS or
TACACS+ server.
4. Enter a timeout value in seconds.
5. Enter a test user name and password that is already stored on the RADIUS or TACACS+
server. This user name and password are used for testing and are not saved with the rest of
your configuration.
6. Click Test to verify the server name and the shared secret.
7. Click Update to save your changes.
8. Click System>Components>CommandPost>Config>User Authentication to enable
RADIUS or TACACS+ authentication. Refer to User Authentication.

Session Timeout
Session Timeout refers to the amount of time an inactive user account can remain logged into
CommandPost. User inactivity will cause the session to be timed out and the browser will return to
the login page. Inactivity is determined by contact with the server. For many sections of
CommandPost the action of opening and closing rows in the display will not cause interaction to the
server and may require accessing new pages to avoid session time out.
CommandPost Session Timeout can be configured in one of three modes of operation:

• Enable Timeout for All sessions. This is the default mode of operation with a timeout value of
15 minutes. You can change the timeout value to any number of minutes greater than zero.

• Disable Timeout for All sessions. In this mode, session timeout is completely disabled. This
setting is not recommended unless all users are well trained security professionals, diligent
about logging out from CommandPost if they leave their workstation.

Fidelis XPS User Guide 249


• Disable Timeout by IP Address. This mode may be used to disable timeout for a large screen
display or for only those workstations used by properly trained professions. Enter the IP
addresses for client workstations from which you will disable timeout. Session Timeout
remains enabled for other IP addresses. Enter the number of minutes that these connections
can remain idle before being terminated.
To configure session timeout:
1. Click System>Components>CommandPost>Config and click the Session Timeout tab.

Figure 113. CommandPost: Session Timeout


2. Select either Enable Timeout for All sessions, Disable Timeout for All sessions, or Disable
Timeout by IP Address.
3. Click Update. The new configuration becomes effective with the next login to CommandPost.

System Monitor – CommandPost


System Monitor is used to monitor the activity and health of a CommandPost. It monitors
CommandPost status including disk space, process restarts, and statistics counts. It attempts to
make sure that the system is running smoothly. If not, it can send warnings in a number of different
ways.
By default, System Monitor writes all of its messages to the standard system log file. In addition, it
can be configured to write to a remote system log file, to send an email, and to send an SNMP
message.
From System Monitor, you can also shut down the system.
To access System Monitor:
Click System>Components>CommandPost>Config and click the System Monitor tab.

Notificati ons
The Notifications page allows the configuration of Fidelis messages or notifications to be sent to
external entities. These notifications are produced by system monitor as it pertains to Fidelis
Software and system resources required for Fidelis software.

Fidelis XPS User Guide 250


Figure 114. System Monitor: Notifications settings
You can send messages to a system log, an email address, or to SNMP. You can configure the
types of messages sent to each.
Message types:

• Critical—system functioning is severely impacted


• High—a system function is at risk of a severe impact
The System Log section allows for the entry of a remote system name. This system should be
configured to allow remote hosts to send syslog messages to be recorded in its standard syslog
file. Make sure to allow a remote sysmon message through any firewall in your network.
The Email Address section allows for the configuration of an email address and message types to
be sent to that email address. If one or more email relay hosts are configured, outgoing emails are
sent through email relayhosts.
The SNMP section allows for the configuration of a remote SNMP monitor and the message types
to be sent. SNMP traps may be sent to an external system which may be specified by a host name
or IP address.
Choose the alert information to include in these traps. To enable Fidelis SNMP traps, a MIB is
available with sample use instructions at. [Link]/support.
Select SNMP version 1 or 3.
• If you select SNMP 1: You can change the entry for the SNMP Community String. The
default value is public.
• If you select SNMP 3: Engine ID, user names, and authentication and privacy tokens for
users should be configured on the remote SNMP server that runs the SNMP trap.
SNMP Engine ID: Enter the ID for the remote SNMP server.
SNMP User Name: Enter a user name associated with the Engine ID.
SNMP Authentication Protocol: Select Authenticated Only or Authentication and
Encrypted.
For Authentication Only:

Fidelis XPS User Guide 251


Select MD5 or SHA1 Protocol. Enter the Authentication Token for the user in the text box.
For Authentication and Encrypted:
Select an Authentication Protocol and enter the Authentication Token.
Select either DES or AES Privacy (Encryption) Protocol. Enter the Privacy (Encryption)
token for the user in the text box.

Notification Messages
Listed below are examples of notification messages that can be sent by System Monitor.

Critical:
spool writes stopped when partition < 1GB
if a process is dying repeatedly
invalid license
spool writers dying too fast netspool can't start spool writers
export writers dying too fast exportd can't start exporters
one or more registered sensors lost connection
Unable to make space for alerts, alerts & sessions not being inserted
Unable to make space for sessions, alerts & sessions not being inserted
Insufficient disk space, alerts & sessions not being inserted
Archive failed - alerts deleted anyway, check FTP connection
feed handlers are dying fast
repdcp cannot start feed handler<s> <feed names>

High
demo mode or license expired or expiring in < 14 days
no sensors registered.
if alerts/sessions/pcaps deleted to make space for new
alerts
<number> alerts, <number> sessions & <number> pcaps deleted to create space
if alerts are being spooled due to db maintenance running
Database maintenance running, alerts are being spooled
if archiving fails and it will be retried
Archive failed - alerts not deleted, check FTP connection
Archive failed - alerts deleted after next failure, check FTP
connection
problem running db_maint: see /var/log/messages
feed update error
feed "<feed name?" update error

System Logging ( OS)


System Logging of operating system notifications is available on your CommandPost. The
information produced is with regard to the underlying operating system on the appliance. The
information will be written to the system log on CommandPost and can be configured to write the
log to a remote [Link] software notifications are not monitored at this tab.
System logging is performed by syslog-ng. Prior versions of Fidelis XPS used rsyslog, however,
rsyslog is being phased out.

Fidelis XPS User Guide 252


If you previously enabled rsyslog, it will still be used as your operating system logger. However, it is
recommended that you switch to syslog-ng as rsyslog will be removed in a future release. Uncheck
rsyslog and click Save to enable syslog-ng. You will not be able to switch back to rsyslog.

Figure 115. System Monitor: System Logging


1. Enter a remote server to send logs. You can leave this value empty. System logging still
occurs if you do not make an entry for the remote server, but there is no remote logging. If
you do make an entry, ensure that you use a valid host name or IP address. If the host name
or IP address is not correct, syslog-ng stops running and this will be indicated in the status.
A sample entry is:
udp:host<:port> [Use UDP, default port 514]
udp:IPaddress<:port>
2. Click Save.

Shutdown
This page enables you to restart all Fidelis Services.

Figure 116. System Monitor: Shutdown


You can also shut down the CommandPost or reboot.
Items to consider:

• Clicking Restart, Shutdown, or Reboot on the Console Config logs you out of CommandPost.
• Order does not matter when shutting down or rebooting CommandPost with sensors and
Collectors.
• For Shutdown, you need physical access to the CommandPost to start it again.

Fidelis XPS User Guide 253


User Authentication
CommandPost supports user authentication locally or via LDAP (Active Directory) or
RADIUS/TACACS+. The User Authentication page contains a section for each authentication
method that can be hidden (or expanded) by clicking the title bar of the section.
Using CommandPost configuration, you may choose the authentication method for your
environment and modify configuration options. When a user accesses CommandPost,
authentication is performed as follows:

• First, CommandPost checks the user name to see if matches against the database of current
users. If it matches a user, then the configured authentication method (local, *LDAP,
**RADIUS, or **TACACS+) is used. Refer to Define User Profiles.
To use LDAP or Active Directory authentication, you must also configure communication
between CommandPost and your directory server. Refer to LDAP Config.

To use RADIUS/TACACS authentication, you must also configure communication between


CommandPost and your directory server. Refer to RADIUS/TACACS+.
• Second, if the user name does not match a current user in the database, CommandPost will
use any other authentication methods that are enabled (LDAP, RADIUS, or TACACS+) with a
configured User Profile. Upon success, user information is downloaded from the
authentication server to CommandPost and a user account is created.
Note: Only one authentication method per unique user name is supported. For
example, if a user has a local account with the name Joe and attempts to log in using
Joe with LDAP, the LDAP log in will fail. To change the authentication method for a
user, the currently configured user must be deleted. Refer to Define User Profiles.
If none of the above steps are successful, the user login is rejected.
Note: You must maintain at least one local CommandPost user that can be used to
create other local users and configure external communications. CommandPost ships
with one default user (admin) for this purpose. You should create another account for
this purpose, and not rely on the default account. The default user cannot be removed,
but should not be used after initial system configuration.
LDAP and other non-local authentication provides access to the CommandPost GUI,
but no permission to directly access CommandPost using protocols such as sftp or
ssh. Therefore, users without local accounts will not be able to transfer files to or from
CommandPost. Fingerprint creation and test processes may require such access and
only local users will be permitted to perform these transfers.
To access this page:
Click System>Components>CommandPost>Config and click the User Authentication tab.

Configure Password Requirements for Local users


Before configuring password requirements for local users , refer to your enterprise's security
practices for password requirements. After you configure CommandPost password strength
requirements, all new passwords must conform to the new settings.
Note: Existing passwords will not be impacted by changes to password strength
requirements until this password is changed. Password age and account lock
settings take effect immediately for all users.
To configure password requirements:
1. Set Password Strength as needed.
Enter values for the minimum length, upper case, lower case, digits, and special characters. A
value of zero is equivalent to disabling the requirement. The default setting has all password
strength values set to zero, or disabled.

Fidelis XPS User Guide 254


Note: The password length must be large enough to accommodate all other
requirements.

Figure 117. CommandPost: password Requirements


2. Specify age requirements.
Expiration: Click Expiration and enter a number of days for passwords to expire. Users must
reset passwords before passwords expire or they will be locked out of the system.
Warning: If you change the password age requirements and your own password does
not comply, your account will be locked immediately upon saving the password
configuration.
Warn user: If you specify expiration, you may also specify when user warnings start about
the impending expiration. Enter the number of days before the expiration time that you want
warnings to start. If you set the value to the default state of 0, there will be no warnings. The
warning continues on each login until the password is changed or the account is locked
because of the expiration.
Minimum Age: Click and specify a minimum number of days passwords must be in use
before user can change them. Users receive an error message and are prevented from
changing their passwords until the minimum age is met.
3. Specify Account Lock settings.
Inactivity: Select and specify a maximum number of days that an account can remain
inactive. If an account remains inactive beyond this time, the account will be locked.
Failed Login Attempts: Click and specify the maximum number of failed login attempts
allowed.
4. Click Update.
Local passwords are enforced by the Linux Pluggable Authentication Modules (PAM). These
modules can be used to enable many password controls that are not exposed to the
CommandPost User Authentication User Interface. Administrators with direct access to
57
CommandPost and knowledge of PAM can apply settings to include password history
changes, dictionary lookup, and several other attributes. Application of these changes must
be performed with caution because a misconfiguration could lock out all users. Contact for
more information.
Note: If an account is locked, attempts to log in will be denied. To activate the account,
an administrator must reset the password at the Users>Profiles page.

57
Linux Pluggable Authentication Modules (PAM) provide dynamic authorization for applications
and services in a Linux system.
Fidelis XPS User Guide 255
Enabl e LDAP Authentication
If you would like to authenticate users via LDAP or Active Directory, you must enable LDAP
authentication and create a profile. To correctly setup authentication, you must have a thorough
understanding of your local directory server data structure. This can be obtained by using your
favorite LDAP/AD browser software.
Note: You also need to configure CommandPost to LDAP communication. Refer to
LDAP Configuration.
To enable LDAP Authentication:
1. Click Enable LDAP authentication and click Update.

Figure 118. CommandPost: Enable LDAP authentication


2. Enter the Login Prepend. This login prepend specifies name of an attribute whose value
uniquely identifies the user across all profiles’ base/filter settings.
For example:
If the login prepend is: sAMAccountName=
Profile1 – Sales group
Base: CN=Users,DC=fidelissecurity,DC=com
Filter: memberof=CN=sales,DC=fidelissecurity,DC=com

Profile2 – Engineering group


Base: CN=Users,DC=fidelissecurity,DC=com
Filter: memberof=CN=engineering,DC=fidelissecurity,DC=com
In this example, users from the sales and engineering groups are allowed to log in. If a
user enters joeUser at login, the authentication process goes through all the LDAP profiles
and for each LDAP profile looks for the attribute sAMAccountName=joeUser on the LDAP
server.

The Login prepend setting can therefore be thought of as another filter which is internally
applied by the authentication process for each LDAP profile. In our example, joeUser must
be a unique value for LDAP attribute sAMAccountName for both sales and engineering
groups.

a. Enter the LDAP Base.


Members of a group can be represented using LDAP base/filter settings. In Active
Directory, users may have an attribute: memberof in their Active Directory record to
signify membership of a group. So the following example can retrieve all members of
the sales group.
Base: cn=Users,dc=fidelissecurity,dc=com

Fidelis XPS User Guide 256


Filter: memberof=cn=sales,dc=fidelissecurity,dc=com
In this example, base points to root of all user records, and filter is applied to these
records returned from the base and therefore returns records of members of only the
sales group.
b. Enter the LDAP Filter to further define user attributes. The combination of Base and
Filter are used to define the set of users that fit this profile. You may use these
settings to identify a group of users, such as sales or engineering, or to define a
specific user for this profile. The values entered for Base and Filter depend on the
structure of your directory server.
Filter examples could be:
(|(mail=joe*) ( mail=fred*)) This entry would return users with email beginning with joe
or fred.
(&(mail=joe*) (sn=b*)) This entry would return users with an email beginning with joe
and a last name starting with b.
Note: Please see rfc4515 ([Link] for more
examples of LDAP filter expressions.
3. Select an appropriate role for users identified by the Base and Filter. This determines access
to CommandPost functionality. Refer to User Roles.
4. Select appropriate alert management groups. Users identified by the Base and Filter will be
able to access alerts in the selected groups. Refer to Alert Management Groups.
5. Select appropriate components. Users identified by the Base and Filter will be able to
configure and manage the selected components and access alerts from the selected
components. Refer to Define User Profiles.
6. Click Save.
7. Add other profiles as needed and click Save.
After a profile is defined, it will appear in the list of profiles. You can click a profile to expand it to
view all settings for this role and to access the Edit and Delete buttons which allow you to change
or remove the profile.
Important: Use caution in deleting a profile. Multiple users might use a single profile to
access CommandPost.
Note: The profile is applied when a user logs into CommandPost. Any changes to the
system will not change the profile. Therefore, if new groups or components are added
by an LDAP user, the user will retain access to the new group or components for the
duration of the current session. Unless the user profile is updated, upon the next login,
the user will no longer have access to the new group or component.

Fidelis XPS User Guide 257


RADIUS/TACACS+ User Profiles
After configuring RADIUS or TACACS+ authentication, you need to configure CommandPost to
RADIUS/TACACS+ communication. Refer to RADIUS/TACACS+ Configuration.
1. Click Enable for RADIUS or for TACACS+ authentication and click Update.
2. Click Edit to select a Role, Group Assignments, and Component Assignments.

Figure 119. CommandPost: Enable RADIUS/TACACS+ authentication


3. Select an appropriate role for users. This determines access to CommandPost functionality.
Refer to User Roles.
4. Select one or more alert management groups. Refer to Alert Management Groups.
5. Select one or more components. Refer to Define User Profiles.
6. Click Save. Refer to RADIUS/TACACS+.

LDAP and RADIUS/TACACS+ User Expirati on


Management
By default, user accounts that are not local (such as LDAP or RADIUS) are removed after 45 or
more days of inactivity. All data associated with the user account is also removed. To change this:
Click Delete inactive user and specify a number of days after which the inactive user is deleted.
Uncheck Delete inactive user to prevent inactive users from being deleted.
Click Update.
Fidelis recommends that system configuration for notifications, including reports, should be
maintained from Local accounts and not those that are subject to removal after inactivity.

Fidelis XPS User Guide 258


User Notification
CommandPost can be configured to generate a notification message to a user whose email
triggered an alert. The terms "user” and “end user” in this section refer to someone transmitting
data over the network on which your sensor is installed. In this section, “user” does not refer to an
authorized CommandPost user.
The CommandPost user notification feature is limited to alerts generated over email or webmail
protocols. CommandPost can respond to each alert, however, when compression is active or when
58
the violated rule does not include an alert action, CommandPost may not respond to every event .
The Mail sensor has an email notification feature that is more reliable than CommandPost, in that it
can respond to every event, not only those that generate an alert. However, the Mail sensor only
operates on SMTP email traffic, not webmail. CommandPost user notification can be an important
component in your overall security policy for data extrusions, whether or not your solution includes
a Mail sensor.
When this feature is enabled, the user will receive an email notifying them that their action violated
a policy. By default, email notification is not enabled.
For end users receiving a notification message, the body of the message contains two sections: a
message that can be configured by a CommandPost administrator and details of the violating
email. The configurable message can be customized to include information appropriate for the
environment. The details section cannot be customized; it will include the From, To, Subject, and
time of the violating email.
To set up email notification:
1. Click System>Components>CommandPost>Config and click User Notification.

Figure 120. CommandPost: User Notification


2. Select the notification email for No, Alerts, Prevented or All.

• No: Disables this feature. No is the default setting.


• Prevented: Alerts with the action of alert and prevent generate email notification.
• Alert: Alerts with the action of alert generate email notification.
• All: All alerts generate email notification.
3. Enter a domain name to control who receives the email notification. You can provide an
unlimited number of domains by clicking Add domain. Only users in the specified domain

58
An event refers to a network violation detected by the sensor.
Fidelis XPS User Guide 259
receive the notification.
If you do not enter a domain email is sent for every email alert. This may cause notification
messages to leave the local network.
4. Select one or more email protocols from the list. CommandPost will send user notification
email for all alerts generated by the selected protocols. User notification would be generated
for the SMTP protocol if no email protocols are selected from the list.
5. Enter a subject for the notification email. The default value is “You have violated company
protocol....”
6. Enter the body of the email by either entering text into the text box or by uploading a file.
7. Click Update.
Note: Some email systems will not deliver email when the sender cannot be
identified. If you have not properly configured CommandPost email, users may not
receive the notifications.

Fidelis XPS User Guide 260


Configure Sensors
59
To configure a sensor, click System>Components and click Config for the selected sensor. You
can select a configuration option by clicking the appropriate tab at the left sidebar menu on the
Config page.
Note: The Config button only displays if the user permissions are adequate and if
there are no communication problems.

Runtime Information
The table at the top of a sensor configuration page shows runtime information for the sensor, the
time since last restart, name, and how much activity has occurred. The type of activity depends on
the sensor type. Time since last restart is the time since the last restart of Fidelis XPS software.
The information will automatically refresh every few seconds.

Figure 121. Runtime information


You can switch components from the Config page by choosing a different name in the drop down
box. When you click Go the component changes.

Config Page
The configuration page provides access to the tabs listed below.
For products that contain an embedded CommandPost and an embedded sensor, the configuration
is located at CommandPost Config. Refer to Components.
License & Time
Sensor configuration. The label indicates the sensor product type.
Refer to the config page of each sensor to set recorded object or session limits.
Alert Failover
Email Relayhost
Language Config
Logs
Secondary Managers
System Monitor

License & Time


License shows the Host ID information, the current license key, and an expiration date. Each
component requires a separate license.
When you initially install and register a Fidelis XPS sensor the License Key field displays <demo
mode>.
To access the License & Time page:
Click System>Components>[sensor or Collector name]>Config and click the License & Time tab.
When you initially install Fidelis XPS on CommandPost, CommandPost will run in demo mode. A
sensor or CommandPost remains in demo mode until a license key is entered.

59
Components enables you to set up licensing and configure Fidelis XPS components. This
includes adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail,
and setting up user notification and LDAP among other features.
Fidelis XPS User Guide 261
Figure 122. The License and Time
Clicking Request License or the component's Host ID creates an email to
license@[Link], with the subject line automatically completed with the component’s
Host ID. Include in the body of the email your name, the location name and address, phone
number, and reseller name (if pertinent), and Fidelis Technical Support will respond within one
business day with a license key.
When you receive the license key, paste or type it exactly into the License Key box, and click Save.
If the information was entered correctly and matches the Host ID provided, the key will be
accepted. If there is a problem with the license, you will receive an error and the License Key field
will display <Invalid>.

Expirati on
Fidelis XPS begins displaying notices that your license will expire starting 60 days before the
expiration date. If you receive this notice, contact Technical Support to obtain a new license.

Modify a Li cense Key


To make changes to your license key in case of an entry error for example, just enter a new license
number in the License Key text box and click Save. Please remember that making changes to
license keys should be done with great care.

Demo Mode
If no license key is detected, the sensor and the CommandPost will operate in demo mode. The
sensor does not function in demo mode. A CommandPost in demo mode will not accept alerts from
any sensor and will only accept statistics.

Sensor Time
Click Sync time to synchronize sensor and CommandPost times. This can be done for each sensor
that has no access to other time synchronization methods such as NTP. If the sensor is
synchronized with CommandPost, a message displays indicating this and the Sync time button will
not be available. If the sensor and CommandPost are not synchronized, a message indicates this
status and the Sync time button becomes available.

Fidelis XPS User Guide 262


Direct and Internal
This page is available if the sensor includes the Direct or Internal module.
The Direct component detects all supported protocols crossing a defined network border. The
Direct, however, will not analyze sessions specific to the Internal module, which include LDAP and
SMB.
The Internal component detects and analyzes all supported protocols within a defined network
border.
To access the Direct or the Internal:
Click System>Components>[sensor or Collector name]>Config
Instructions for the following pages are available:
General
Advanced
Network Border
DNS Decoder
You can make changes separately in each page by clicking Save changes.

General
You can configure your Direct or Internal component to operate in either inline or out-of-band
mode.
Refer to chapter 5 in the Enterprise Setup and Configuration Guide for more information about
these modes and how to set up and connect hardware to the network.

Figure 123. Direct/Internal connectivity: out of band mode

Fidelis XPS User Guide 263


Figure 124. Direct/Internal connectivity: Inline Mode

T a bl e 2 6. D i r e ct a n d I nt e r na l : G e n er al p a r am e t ers

General parameters Description

Enable Direct/Internal Click to enable the module.

Inline Mode/Out-of- Choose the setting that reflects the network configuration of your module.
Band Mode Out-of-Band mode is used for monitoring via a network tap or SPAN port,
while inline is used when the component is directly in the network flow.
When a component is deployed inline, prevention is performed by
dropping packets received on offending sessions.
Note: To activate inline mode, the component must also be
operating in full duplex mode.
Inline mode also enables you to use a Bypass NIC, if supported by your
appliance.
After clicking the checkboxes for the Bypass NIC, select the failure mode:
either Drop Packets or Fail-to-wire.
Refer to chapter 5 in the Enterprise Setup and Configuration Guide.

Throttle Mode When Inline Mode is chosen the Throttle Mode checkbox displays if
available. Throttle is typically used to identify applications (such as peer-
to-peer or instant messenger) that are allowed on the network, but to
control their use by throttling activity to an acceptable level. Throttle
mode enables the Direct/Internal component to react to throttle rule
actions. If throttle mode is disabled, the component will ignore the throttle
action.

Link Failure In Inline mode, if one link is down, the sensor cannot forward traffic.
Propagation When Link propagation is enabled, if one link goes down (link 1) the other

Fidelis XPS User Guide 264


General parameters Description

link (link 2) will be brought down so that the other device will know that
the link is broken. The sensor then starts sending notifications to
CommandPost. If link 1 recovers, it will restore link 2 and the sensor will
stop sending error notifications.

Primary TCP Reset When checked, TCP Resets are enabled to provide prevention, as
indicated by the action setting when a rule is violated.
When used in out-of-band mode TCP resets used for prevention, you
must specify the dedicated Ethernet interface (Prevent /eth1) used for
packet injection. Make this choice at the drop-down menu. When used in
Inline Mode, the Direct/Internal component will inject TCP Reset packets
(in addition to dropping received packets) to implement prevention. In
Inline Mode, the component will choose the correct Active interface for
injection of reset packets based on the information flow.
Secondary TCP
Reset When a second reset is enabled, resets will also be sent to the chosen
Ethernet interface. This setting should only be used when the sensor is
physically connected to a redundant network.

Active Interfaces Active Interfaces determine which Ethernet adapters the component will
monitor. Click the appropriate checkboxes to select interfaces. One
adapter, such as Monitor A/eth2, indicates that the component is listening
in half duplex mode. Two adapters, such as Monitor A/eth2 and Monitor
B/eth3, indicate full duplex mode.
The information within the brackets indicates the interface type and its
operating status.

Packet Capture Packet Capture enables you to capture alert-related network traffic just
before and after an alert. This option displays if you have a Direct,
Internal, or Edge component capable of supporting Packet Capture.
Refer to product tables in chapter 1 in the Enterprise Setup and
Configuration Guide.
Packet Capture can be selected as an action for each rule for which
traffic information is required. Refer to chapter 7 in the Guide to Creating
Policies.

MDE on Sensor Indicates either Available or Not Available. Available means that the
sensor is capable of supporting the Malware Detection Engine.
If MDE is Not Available on this sensor, malware detection will execute on
the CommandPost.
Malware Detection must be enabled to execute on the sensor. Refer to
Malware Detection.

Bypass Card on Indicates either Available or Not Available .If your appliance supports
Sensor this capability, the sensor configuration page on CommandPost will
indicate: Bypass Card on Sensor: Available.

Select Failure Mode Configuration of the Bypass NIC includes the operation in case of a
for the Bypass NIC power or software failure. If needed, you can also immediately set the
NIC into bypass mode.
After clicking the checkboxes for the Bypass NIC monitors on your
appliance, select the failure mode: either Drop Packets or Fail-to-wire.
Refer to chapter 5 in the Enterprise Setup and Configuration Guide.

Fidelis XPS User Guide 265


Advanced
Advanced enables you to control settings for protocol checksums and length of recorded objects for
Direct and Internal modules.

Figure 125. Direct/Internal connectivity: Advanced settings


The following table describes options advanced parameters for Direct/Internal modules.

T a bl e 2 7. D i r e ct a n d I nt e r na l : A dv a n c e d p ar a m et e rs

Advanced Description
parameters

Alert Recorded Object This setting determines the maximum length (in KB) of data recorded
Limit (0-32768): from the network session associated with each alert. It is important to
keep in mind that a larger limit might substantially increase the size of
your database, which will require more available disk space on
CommandPost. The default is set at 4096 KB because most useful
forensic information occurs in the beginning of a recorded session. It may
be useful, however, to have more data recorded.

Checksum setting A check beside the protocol name under Checksum instructs the software
to verify the checksum of each network packet of that protocol type.
Deselecting a protocol means that packets will always be accepted which
increases performance.

Send metadata to Enables this sensor to send metadata to a Collector selected from the
collector drop down list.
If hierarchical management is enabled, you can select to send metadata
from a sensor registered to a Subordinate CommandPost to a Collector
registered to a Master CommandPost.

Fidelis XPS User Guide 266


Advanced Description
parameters

For the Demo Collector:


An IP address of [Link] displays. The Demo Collector can only accept
metadata from one sensor at a time. Ensure that the IP address for the
Demo Collector is selected at only one sensor. Other sensors should
have None selected.

Send compressed Select this checkbox to compress metadata before sending it to a


metadata Collector. This option compresses metadata by approximately 30 to 50
percent. Compressing metadata can result in an approximately 4%
reduction in sensor performance. Use metadata compression only when
there is limited network bandwidth between the sensor and the Collector.

Metadata Inclusion IP The feature enables you to limit metadata sent to the Collector by the
List sensor to a set of IP addresses defined in the Metadata Inclusion IP list.
This feature is useful when you need to reduce the amount of data sent to
your Collector from your sensors.
If you are using the built in Demo Collector on CommandPost you need to
use this feature to prevent data overload on CommandPost.
Enter the list of IP addresses singly or specify a subnet using subnet
masks in the Metadata Inclusion IP List text box. Each entry must be
separated by either a space or on a separate line. For example:
Separated by a space:
[Link]/8 [Link]/12 [Link]/16
On a separate line:
[Link]/8
[Link]/12
[Link]/16

Network B order
The Network Border is used to limit the sensor analysis to specific data flows, depending on your
sensor type. Applying a Network Border to a Direct sensor will effectively eliminate any alerts
generated from data flows initiated outside of the defined IP address [Link] a Network
Border to an Internal sensor will effectively eliminate any alerts generated from data flows that
cross the defined IP address ranges. If the purpose of the sensor is to monitor all network data
flows, do not configure the Network Border. Depending on the type of sensor the behavior of the
Network Border varies.
• A Fidelis XPS Direct sensor will detect and analyze all session data flows that originate
from within the defined network and are destined to a host that resides outside the defined
network. The Direct sensor will ignore all session data flows originating outside of the
defined network and all data flows that remain inside the defined network.
• A Fidelis XPS Internal sensor will detect and analyze all session data flows where both the
source and destination of the data are within the defined network.
Note: The network border is based on the direction of the data flow. It is not based on
the network TCP/IP source and destination IP addresses. Therefore, it handles data
movement regardless of the application protocol and the mode of operation.

Fidelis XPS User Guide 267


Figure 126 . Direct/Internal: Network Border settings

Add a Border Setting


To add a border setting:
Select either Whitelist Mode or Border Mode.
• Border Mode (the default) enables you to set a network border.
• Whitelist Mode enables you to enter a list of IP addresses on which no alerts will be
generated.
1. Enter IP addresses into the text box on the left. Each line represents a new address or range.
The following are supported:

• CIDR IPv4 addresses such as [Link]


• CIDR IPv4 addresses with subnet masks, such as [Link]/24
• Short form IPv4 addresses as interpreted by UNIX INET formats. For example, 10.8 is
equivalent to [Link]. Subnet masks may be added such as 10.8/24, which is
equivalent to [Link]/24.
• IPv6 addresses with or without a subnet mask, such as fe80:0:0:0:0:0:0:1 or
fe80:0:0:0:0:0:0:1/16
• Short form IPv6 addresses such as fe80::1 or fe::1/16, which are equivalent to the
examples shown above.
• An address range by separating two IP addresses by a dash (-). The address on each
side of the dash must be correctly formatted as explained above. In addition, the address
on the right side of the dash must be greater than the address on the left.
Note: This guide assumes familiarity with IP address notation syntax.
2. Click Add to List. Each line in your text box will be validated for proper syntax. Any errors will
be displayed and the associated lines will remain in the entry box. All valid entries will be
copied to the Border text box.
3. Click Save. For an Internal sensor, this operation will verify the size of the defined border. If it
is either empty or too large, an error will result.

Fidelis XPS User Guide 268


Delete a Border Setting
Once valid addresses are available in the Border text box, they may be deleted. Select one or more
IP addresses or ranges (using control click) and click . Your changes will take effect when you
click Save.

DNS Decoder
At this page, you can enable and configure settings for the DNS Decoder for Direct and Internal
modules. The DNS Decoder works at the packet level and can generate DNS alerts. Note that DNS
alerts are different from the alerts generated by rules built using fingerprints. DNS alerts are not
configured in the Policy section of the Fidelis XPS GUI, but at the DNS Decoder page for Direct or
Internal sensors.
To access this page, click System>Components and select the appropriate Direct or Internal
sensor and click Config. At the Config page for the Direct or Internal sensor, click the DNS Decoder
tab.
At the DNS Decoder page, you can define anomalies that represent possible DNS exploits in your
60
network and generate alerts when these packets are detected on the network.
Note: The DNS Decoder must be enabled for Channel fingerprints that use the DNS
Protocol attribute.
Prevention can be enabled for requests to blacklist malicious sites. For this operation to be
possible, the sensor must be configured for prevention. Refer to the Direct General page.

60
An alert is the recorded and displayed incidence of at least one event. Alerts are generated only if
the alert action for an event is enabled in the violated rule. Alerts are transferred to and stored by
CommandPost.
Fidelis XPS User Guide 269
Figure 127. Direct/Internal: DNS Decoder settings

T a bl e 2 8. G e n er al P ar a m et ers

General parameters Description

Enable DNS Decoder Click to enable the decoder on the Direct or Internal module.

Monitor DNS over Select to detect and analyze when DNS requests are coming over TCP.
TCP

Monitor DNS on Ports Specify one or more ports to inspect for DNS packets. You can enter
single numbers separated by commas or ranges. If you do not specify a
port, the DNS Decoder defaults to the standard DNS port (53).
DNS will only be inspected for the ports specified here.

Alert Management Select an alert management group for any DNS alerts that are generated..
Group
Choose to generate an alert based on the selected criteria. Default settings are provided for each
DNS alert configuration. Change the values as required for your environment. Each alert
configuration item and any settings are described in the following table.
Assign an alert severity to each selected item.

Fidelis XPS User Guide 270


DNS alert Description
configuration

Packet Excess Data Detects a packet containing excess data.


Entering a value for Excess Data Threshold instructs the DNS Decoder to
not alert if the threshold is less than the number of bytes specified. For
example, If you enter 33 bytes for the threshold value, only packets of 34
bytes or more excess bytes will result in an alert.

Not port 53 Select to detect when DNS requests are found on a port other than 53.

Q/A Bounds Specify the upper and lower bounds for Question/Answer (Q/A). Q/A
bounds between 100 and 200 percent are standard. A much greater
difference between the Question/Answer ratio can indicate a problem.

DNS/TCP Ratio Specify the ratio of DNS to TCP packets within a 1 minute timeframe. If this
ratio is too high, this can indicate a possible security breach.

Name Length Enter the maximum number in bytes for a name segment.

Unprintable Selecting this option will trigger an alert when the number of non-ASCII or
Characters in Name non-printable ASCII characters exceeds the setting for Maximum
unprintable characters per label. The default setting is 40 characters.

Error/Success ratio Specify the upper bound percentage for the error to success ratio for DNS
responses. A zero indicates no errors.

Packet Length Enter the maximum number of bytes for the packet length of a query
packet. Alerts will be triggered for DNS requests that are longer than the
length specified.

Packet Parsing Select to check for any malformed packet such as one with a badly formed
name or resource record.

RR Not Allowed Select to not allow resource records except those types listed in the RR
Allowed List. Enter the numerical values for the resource types allowed.

RR Length Enter the maximum length in bytes for a resource record. Note: RR length
does not apply to DNSSEC records.

non-DNSSEC Select to detect if answer data is not signed.


Answers

TTL Duration Specify upper and lower bounds in seconds to determine acceptable TTL
values.

Malware Target DNS This option will cause alerts to be raised for DNS requests made by hosts
Requests in your network that were detected to be the destinations of malware
transfers. The number of alerts is configurable. For example, if you enter
11 for (Alert on first 11 DNS requests), alerts will occur on the first 11 DNS
requests by each host after the malware transfer was detected.

Question Records If the number of questions in a single query is greater than the number
specified, an alert is generated. The default is 5. However, if you select
one or more feeds at Blacklist from Feeds, Fidelis recommends that you
enable this alert and set the upper bound on the number of Question
Records to 1. Blacklist feed matching is only performed on the first record.

Blacklist from Feeds Select one or more feeds as needed.


If you select feeds, ensure that Question Records is enabled. Refer to
Question Records.

Fidelis XPS User Guide 271


DNS alert Description
configuration

The list of available feeds includes all Fidelis feeds that include DNS host
names, including Fidelis-provided feeds and custom feeds. Refer to
chapter 10 in the Guide to Creating Policies.
Click the Assigned checkbox to perform blacklisting against the host
names included in the feed.
If assigned, you can select Prevent to drop the DNS request of any
blacklisted host in the feed. For prevention to be effective, the sensor must
be configured properly, refer to Direct General.
If prevention is selected, you have the option to select Silent prevention. In
silent prevention, no alert will be generated for the blacklisted request. It
will be silently dropped.

Manual Blacklist Note: The Blacklist feature became obsolete with version 7.5.
Blacklists must be defined in feeds.
If you previously entered name strings in the Blacklist text box, a notice
displays stating that the feature is obsolete.
To remove this message, delete all entries from the text box and click
Save. The Blacklist section will no longer be available.
To blacklist sites, create a custom feed that contains the Blacklist entries.
Refer to
chapter 10 in the Guide to Creating Policies.

Whitelist Entries added to the Whitelist will be excluded from any DNS alerts

Mail
The Mail page is available if the sensor includes a Mail module.
The Mail component can be deployed in one of two modes:

• Mail Transfer Agent (MTA), SMTP server.


• Sendmail mail filter or milter as a content inspection agent connected to a third-party MTA via
the milter interface.
In either case, Mail performs content inspection and can prevent, quarantine, or reroute offending
email messages. It can also, optionally, notify the original email sender about their infraction and
append information to the message before sending it.
When deployed via the milter interface, Mail instructs the third-party MTA to hold all quarantined
email. Quarantine management must be performed using the third-party MTA interface. When
deployed as a Mail Transfer Agent, all quarantined email is stored on Mail and can be managed
through CommandPost.
Note: The third-party MTA must be configured properly to work with the Mail in milter
mode. Refer to chapter 7 in the Enterprise Setup and Configuration Guide.

Fidelis XPS User Guide 272


Figure 128. Mail Configuration
The Mail page enables you to configure Mail. The following table describes configurable Mail
parameters.

Fidelis XPS User Guide 273


T a bl e 2 9. M ai l pa r a m et er s

Mail parameters Description

Enable Mail Click to enable the Mail module.


Mode Select a mode: mta or milter.
MTA mode enables Mail to analyze email to determine if a rule is
violated, then based on the rule action, allows you to quarantine the
email within the Mail module. Quarantine management is done at the
CommandPost to which the Mail component is registered. Quarantined
email will be available on the Quarantine page.
If not quarantined, Mail can send email to a relayhost for delivery. If one
or more email relayhosts are configured, outgoing emails are sent
through the Email Relayhosts.
In MTA mode, Mail accepts incoming emails for analysis on the standard
SMTP port.
Milter mode provides an interface to a third-party email server. The third-
party MTA sends email to the Mail for analysis. The analysis result is sent
via the milter interface to the third-party email server to take action. Mail
does not verify if the requested actions are performed.
In milter mode, quarantined email will be stored on the third-party email
server. Quarantine management must be performed through the third-
party quarantine management interface. Quarantined email will not be
available through the CommandPost.

Restrict interface If you select milter mode, this checkbox appears. By default, Mail listens
for traffic over all ports including the admin port which is used for
communication to CommandPost. Click Restrict interface to choose a
single interface for milter traffic.

Mailer port If you select milter mode, you need to enter a Mailer port. You may
configure the TCP port number for use in milter mode. Enter any unused
port. The default is 10025. You can use this default value or make
another entry. When run in milter mode, the third-party email server must
be configured to run the milter interface on this port.

Notify quarantine Click to have email sent to the alert management group assigned to the
manager rule that was violated. Refer to Add or Edit an Alert Management Group
for information about entering and managing group email addresses.

Subject to Quarantine Enter Subject information for the email to the alert management group.
Manager

From Address for all Enter the From address for the notification email that is sent to the user
notification messages or the quarantine manager or use the default.

Email Subject to End Enter Subject information for the email to the end-user.
User

Instructions to End This is the text for the notification email to be sent to the user. This text
User should provide all information needed to send an email to the sensor to
release the quarantined email.
You can keep the default text or modify it.
These instructions will be included with any rule-specific sender
notification text entered at the Rules page. Refer to chapter 7 in the
Guide to Creating Policies.

Reroute server Enter a fully qualified host name or an IP address for an email server. If

Fidelis XPS User Guide 274


Mail parameters Description

the rule action on an email is reroute, the email will be marked for
downstream rerouting and sent to the server specified here by the next-
hop mail server. Consult Technical Support for more information on the
mail infrastructure topology requirements needed to use this feature.

Alerts Recorded This setting determines the maximum length (in KB) of data recorded
61
from the email message associated with each alert . It is important to
Object Limit (0-
51200): keep in mind that a larger limit might substantially increase the size of
your database, which will require more available disk space on
CommandPost. The default is set at 4096 KB.

My networks This text box enables you to specify multiple networks in CIDR format:
separated by commas. For example: [Link]/16, [Link]/24
Note: The CIDR notation should only have relevant bits in the
subnet representation. For example, [Link]/16 is valid but
[Link]/16 is not valid.
The Mail sensor will accept messages only from mail clients on these
trusted networks.

Send metadata to Enables this sensor to send metadata to a Collector selected from the
collector drop down list.
If hierarchical management is enabled, you can select to send metadata
from a sensor registered to a Subordinate CommandPost to a Collector
registered to a Master CommandPost.
For the Demo Collector:
An IP address of [Link] displays. The Demo Collector can only accept
metadata from one sensor at a time. Ensure that the IP address for the
Demo Collector is selected at only one sensor. Other sensors should
have None selected.

Send compressed Select this checkbox to compress metadata before sending it to a


metadata Collector. This option compresses metadata by approximately 30 to 50
percent. Compressing metadata can result in an approximately 4%
reduction in sensor performance. Use metadata compression only when
there is limited network bandwidth between the sensor and the Collector.

Metadata Inclusion IP The feature enables you to limit metadata sent to the Collector by the
List sensor to a set of IP addresses defined in the Metadata Inclusion IP list.
This feature is useful when you need to reduce the amount of data sent
to your Collector from your sensors.
If you are using the built in Demo Collector on CommandPost you need
to use this feature to prevent data overload on CommandPost.
Enter the list of IP addresses singly or specify a subnet using subnet
masks in the Metadata Inclusion IP List text box. Each entry must be
separated by either a space or on a separate line. For example:
Separated by a space:
[Link]/8 [Link]/12 [Link]/16
On a separate line:
[Link]/8
[Link]/12

61
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 275
Mail parameters Description

[Link]/16

Web
The Web page is available if the sensor includes a Web module.
When a Web component inspects traffic it can generate alerts, prevent transmission by dropping
traffic, or both. If the Web stops traffic because that traffic violates a rule, by default, it sends an
HTTP status 403 (forbidden) to the client's web browser. If the enterprise has provided a valid,
absolute HTTP URL, then Web sends an HTTP redirect as the response to the prevented traffic.
Note: The third-party proxy must be configured properly to work with ICAP.

Figure 129. Web Configuration


The following table describes configurable Web parameters.

T a bl e 3 0. W e b p ar a m et er s

Web parameters Description

Enable Web Click to enable the module.

Squid Click to enable Squid compatibility mode. This must be enabled if the
client uses the Squid proxy. By default, this is turned off.

Web prevention Enter a valid, absolute HTTP URL for browser redirection.
redirect URL
Note: This URL does not support the use of non-ASCII characters.
You can create several URLs and force redirection if you include
attributes of the alert information in your URL. For example, you may
have a URL for each policy running on the Web module. The keyword
select box can be used to craft a URL for redirection based on alert
attributes.
To use the module's ability to redirect based on alert attributes, select
one or more keywords from the list and click Add Keyword. The keyword
and the percent signs around it will be replaced with a real value at
runtime. For example, if you add the %SENSOR% keyword, the actual

Fidelis XPS User Guide 276


Web parameters Description

sensor name will replace the %SENSOR% keyword in the URL.


62
Restrict interface By default, the Web component listens to all ports for ICAP traffic,
including the admin port used for communication to CommandPost. Click
Restrict interface to choose a single interface for ICAP traffic.
Alert Recorded This setting determines the maximum length (in KB) of data recorded
Object Limit (0- from the session associated with each alert. It is important to keep in
32768): mind that a larger limit might substantially increase the size of your
database, which will require more available disk space on CommandPost.
The default is set at 4096 KB.

Alert Failover
When the sensor cannot reach a CommandPost, its default operation is to store data locally until
the connection is restored. If an Alert Failover is configured, the sensor will begin to send data to a
backup CommandPost.
To set up a backup CommandPost:
1. Identify a primary and a backup CommandPost for each sensor.
2. Add the sensor to both the primary and backup CommandPost systems. Refer to Add a
Component. The sensor name should be the same on the primary and the backup
CommandPosts. If the sensor names differ, spools from the sensor are rejected by the
backup CommandPost.
Note: Do not register the sensor to the backup CommandPost.
3. On the primary CommandPost, register the sensor. Refer to Add a Component. The
registration process identifies the primary CommandPost.
4. On the primary CommandPost: Click System>Components>[sensor or Collector
name]>Config and click the Alert Failover tab.

Figure 130. Alert Failover


5. Enter the IP address of the backup CommandPost.
6. Click Save.
When the configuration is saved the sensor will operate normally and send alert
information to the primary CommandPost. The primary CommandPost is identified by the
registration process.
Clicking Reset will revert to the last saved IP address for the backup CommandPost.
Failover operation proceeds as follows:
a. The sensor attempts to connect to the primary CommandPost to transfer alerts but this
attempt fails.

62
Internet Content Adaptation Protocol (ICAP) is a lightweight and extensible point-to-point protocol
used for requesting services for content inspection.
Fidelis XPS User Guide 277
b. The sensor then attempts to connect to the backup CommandPost. If successful, data will
be sent to the backup CommandPost. All alerts will be sent to the backup until the sensor
reconnects to the primary CommandPost. The sensor will repeatedly attempt to reconnect
to the primary CommandPost.
If neither the primary nor the backup CommandPost can be reached, data will be stored on
the sensor.
During failover operations, the sensor will continue to operate under its most recent configuration
change. Configuration changes, including policy updates, cannot be performed by the backup
CommandPost. Failover data refers to all data sent from a sensor to a CommandPost including
alerts network statistics data.

Email Relayhost
Email Relayhost will direct email from System Monitor for each sensor to the email server you
specify. Email from the Fidelis XPS Mail sensor is also sent to a server specified at Email
Relayhost. Only one entry is allowed for Relayhost.
To access this page:
Click System>Components>[sensor or Collector name]>Config and click the Email Relayhost tab.

Figure 131. Email Relayhost


Enter an IP address or a host name to specify an email server on your enterprise's network. Any
outgoing email will be forwarded to the specified server.
Clicking Reset will revert to the last saved IP address or host name.

Sensor Language Configuration


Sensor language configuration enables the sensor to recognize content using international
character sets. There are two modes of operation:

• In ASCII mode, the sensor will recognize ASCII characters in any file. This mode provides the
optimal performance of your sensor and works well with most files written in English. Files
written in another language may be interpreted as binary files and the content will not be
decoded.

ASCII mode is the default setting for the sensor.


• In International mode, the sensor will recognize Unicode (UTF-8, UTF-16, and UTF-32)
characters as well as all supported character sets. When International mode is selected, a list
of summarized character sets will appear. The list of supported character sets is available
within each summary.

Many files and Internet protocols will indicate the character set used within the content,
although this information may not be visible within user application. For these files and
protocols, the sensor will correctly interpret the content in International Mode, as long as the
character set is supported.

If the character set is not specified in the file or protocol, the sensor will attempt to translate
the content using the character sets that you specify on this page. If you specify many
character sets, the sensor will use each one, first translating, then decoding, and analyzing.
This process may be time consuming and may impact sensor performance.

Fidelis XPS User Guide 278


To operate in International mode, you must select at least one character set to be used when
the character set cannot be determined from the file or protocol.
Language Config settings are done separately for each sensor since each may need to have
different language settings based on their physical location and the expected content at each site.
Language configuration must also be done separately for CommandPost. Refer to CommandPost
Language Configuration.
Note: Fingerprints generated on CommandPost are based on the CommandPost
language configuration. For proper performance of these fingerprints when installed
on a sensor, the sensor should be configured as the CommandPost was for
fingerprint generation.
To set up sensor language configuration:
1. Click System>Components>[sensor or Collector name]>Config and click the Language
Config tab.

Figure 132. Language Configuration for the Sensor


2. Click International Mode to display the summarized list of all supported character sets. Each
summarized list can be clicked to display specific character sets.
3. Select one or more and click Add. Your selection displays in the text box on the right.
Use the arrow keys to change the order of the selected character sets or to remove a
selected set. The order is used when the sensor attempts to decode a file or protocol whose
character encoding cannot be determined.
4. Click Save.
5. Repeat as needed for each sensor.

Fidelis XPS User Guide 279


Logs
Logs enables you to view log files from a sensor or from CommandPost that reside in different
directories, including/FSS/log and /var/log among others. Log files can help in troubleshooting
problems and are a valuable resource when interacting with Fidelis Technical Support. After
retrieving a log file, you can send it via email. Fidelis support is the default email recipient of all log
files.
To retrieve logs:
1. Click System>Components>[sensor or Collector name]>Config and click the Logs tab. You
can view logs for another component by selecting it at the Component list.
2. Select a file from the Log Files list.
3. Click Invert Log to reverse the order of log entries, if needed.
4. Click View Log. The selected log entry displays and the Email Log button is available.

Figure 133. Logs

Create D ebug Log


In some circumstances you may need to send a large collection of logs to Fidelis Support for
problem diagnosis. The Debug Log button makes it easy to generate a single archive of many logs
and transfer it to your local workstation.
To do this:
Click Create Debug Log.
A popup message states that creating a system debug log file may requite several minutes. Click
OK to continue to generate the debug log.
When the debug log is successfully generated, you can click Download and either open the file or
save it.

Fidelis XPS User Guide 280


Send Logs
You can view the log and send it via email.
To do this:
1. After retrieving a log file, click Email Log. The Send Log dialog box displays.

Figure 134. Email Logs


2. Enter the desired email addresses. The default recipient address is
support@[Link] and the default sender email address is defined at the
CommandPost>Email Config page.
3. Enter a subject, if needed.
4. Click Send.
The log file displays in the body of the email message.
The log file is sent as an email attachment.

Secondary Managers
Secondary Managers enables you to set up CommandPosts as Secondary Policy Managers on a
sensor. You can also configure a failover CommandPost for each Secondary Policy Manager.
To do this:
1. Click System>Components>[sensor or Collector name]>Config and click the Secondary
Managers tab.

Figure 135 . Secondary Managers


2. Enter an IP address for the CommandPost that will be the Secondary Policy Manager.
3. Optionally, enter an IP address for the alert failover for the Secondary Policy Manager.
Refer to Alert Failover.
4. Click Save. Another row of text boxes displays that enable you to enter up to five
Secondary Policy Managers.
Proceed to Add a Secondary Sensor. The secondary sensor will accept policies from the
Secondary Policy Manager and from the CommandPost to which it is registered.

Fidelis XPS User Guide 281


System Monitor – Sensor
System Monitor is used to monitor the activity and health of a sensor or Collector. It monitors a
component's status including disk space, process restarts, and statistics counts. It attempts to
make sure that the system is running smoothly. If not, it can send warnings in a number of different
ways.
By default, System Monitor writes all of its messages to the standard system log file. In addition, it
can be configured to write to a remote system log file, to send an email, and to send an SNMP
message.
From System Monitor, you can also shut down the system.
To access System Monitor:
Click System>Components>[sensor or Collector name]>Config and click the System Monitor tab.

System Logging ( OS)


System Logging of operating system notifications is available on your CommandPost. The
information produced is with regard to the underlying operating system on the appliance. The
information will be written to the system log on CommandPost and can be configured to write the
log to a remote [Link] software notifications are not monitored at this tab.
System logging is performed by syslog-ng. Prior versions of Fidelis XPS used rsyslog, however,
rsyslog is being phased out.
If you previously enabled rsyslog, it will still be used as your operating system logger. However, it is
recommended that you switch to syslog-ng as rsyslog will be removed in a future release. Uncheck
rsyslog and click Save to enable syslog-ng. You will not be able to switch back to rsyslog.

Figure 136. System Monitor: System Logging


1. Enter a remote server to send logs. You can leave this value empty. System logging still
occurs if you do not make an entry for the remote server, but there is no remote logging. If
you do make an entry, ensure that you use a valid host name or IP address. If the host name
or IP address is not correct, syslog-ng stops running and this will be indicated in the status.
A sample entry is:
udp:host<:port> [Use UDP, default port 514]
udp:IPaddress<:port>
2. Click Save.

Fidelis XPS User Guide 282


Shutdown
This page enables you to restart all Fidelis Services.

Figure 137. System Monitor: Shutdown


You can also shut down the component or reboot. Items to consider:
• You can shut down or reboot either a sensor or Collector.
• Order does not matter when shutting down or rebooting sensors or Collectors.
• For Shutdown, you need physical access to the component to start it again.

Configure and Link a Collector


The Fidelis XPS Collector enables you to collect and store information about every session
analyzed by Fidelis XPS Direct and Internal sensors on your network. As network data is received
by a sensor, it is decoded and analyzed. If the analysis results in a policy violation and the rule
specifies an alert action, the analysis results are sent to CommandPost as an alert. If the session
does not violate a policy, the analysis results are dropped – unless you place a Fidelis XPS
Collector on your network. When a Fidelis XPS Collector is present, the sensor will send session
metadata to the Collector for storage whether there was a policy violation or not. Metadata includes
information similar to the data stored with an alert, including:
• The decoding path: For an alert, the decoding path represents the path from application
protocol to the content object that was analyzed. Metadata includes the path to every
possible object in the session. Consider an email with five attachments: each attachment,
plus the email body, would be presented in the session metadata.
• The attributes extracted by the Fidelis XPS sensor for each protocol and file detected within
each decoding path of the session.
• A recording of any action taken on the session because of a rule violation.
• Each transaction within the network session, including the source and destination IP
address and port.
Data stored by the Fidelis XPS Collector can be viewed on CommandPost at the Metadata page.
At the Metadata pages you can create highly customizable reports on usage statistics of various
categories. Each network session that occurs on the network is available on Metadata Details,
which provides a thorough recreation of network activity.
To enable metadata features, you need to do the following:
• Add and register a Fidelis XPS Collector to a CommandPost.
Note: The Collector needs to be configured to have the same date, time, and time zone as
the CommandPost to which it is registered.
• Configure a Fidelis XPS Collector.
• Link a Fidelis XPS Collector to one or more Fidelis XPS sensors.

Fidelis XPS User Guide 283


Configure a Collector
After you add a Collector and register it to a CommandPost, you need to configure it and link it to at
least one Fidelis XPS Direct or Internal sensor.
To configure a Collector, click System>Components and click Config for the selected Collector.

Figure 138. Fidelis XPS Collector: General page


The following table describes general parameters.

T a bl e 3 1. C ol l ec t o r: G e n e r al p ar a m et er s

General parameters Description

Enable Metadata Click to enable.


Collector

Delete old data after The number of days to save data. Data older than the specified number of
(1-180) days will be deleted. The default of 30 days is recommended and a
maximum of 180 days can be specified.
Before increasing the number of days, consider the aggregate bandwidth
of the sensor linked to the Collector and the storage requirements of your
enterprise. The rule of thumb is 20 gigabytes of storage required per day
per 1 gigabit per second of sensor throughput. This can vary depending on
the traffic seen by the sensor. To meet your enterprise storage
requirements, you may need to add Fidelis XPS Collector XA appliances
to a Fidelis XPS Collector Controller to appropriately scale to meet your
storage requirements and performance needs.
Note: Adequate Disk space has priority over the number of days
specified. Therefore, if disk space is exceeded, data will be deleted
even if it is not old.
Deletions occur on a day's worth of data.

IP address of Failover To configure a Failover Controller:


Controller
Enter the IP address of a Failover Controller and click Save. If the Primary
Controller fails, the Failover Controller will control the Collector XAs and
communicate with CommandPost and linked sensors.
To remove a Failover Controller:
Click Remove and Save to remove the IP address of the Failover
Controller. This also unregisters the Failover Controller from
CommandPost.

Fidelis XPS User Guide 284


General parameters Description

Note: You will not be able to unregister the Primary Controller until
you remove the IP address of the Failover Controller.

Proceed to link a Fidelis XPS Collector to a sensor.

Link a Collector to Sensors


A sensor needs to be configured to send metadata to the Fidelis XPS Collector.
1. Select the appropriate sensor and click Config.
2. At the Advanced page for the Direct or Internal sensor or at the Mail config page, select a
Collector at the drop down box.
3. Repeat as needed for each sensor that will communicate with the Collector.

Fidelis XPS User Guide 285


Chapter 14 Malware
From this chapter section, you can enable and configure the following:
Malware Detection—enable the Malware Detection Engine (MDE) and Automatic Malware Policy.
You can also enable Execution Forensics.
Execution Forensics—select file type for automatic submission to Execution Forensics.
Reaction—configure malware action for each alert severity.
Host Activity—configure Host Activity to integrate with the Carbon Black server.
File Check—upload files from your workstation and submit to the MDE for analysis.

Malware Detection Engine


The Malware Detection Engine (MDE) is included with CommandPost and Fidelis XPS Direct,
Internal, and Mail sensors. When enabled, the Malware Detection Engine will analyze all
executable objects. If malware is detected, an action will be taken, as defined on the Malware
Reaction page.
When the Malware Detection Engine is enabled, CommandPost will provide usage statistics to the
Fidelis Insight Feed Server on a daily basis. These statistics provide valuable information that is
used to monitor the effectiveness of the Malware Detection Engine and to quickly provide all
customers with the highest quality updates possible when new threats are detected. The gathered
statistics will not include specific customer information.
From the Malware Detection page, you can do the following:
• Enable or disable the Malware Detection Engine. Disabling the engine will disable it on
CommandPost and all registered sensors.
• View when the Malware Database was last updated.
• Enable or disable updates from Automatic Malware Policy. If the malware policy is disabled,
CommandPost and sensors will not automatically detect malware and prevention of
malware is not possible. Only user-created rules with the MDE filtered action will generate
malware alerts.
• Enable or disable Execution Forensics. Once Execution Forensics is enabled, you can
select Use for Determination. If the MDE cannot determine if a suspicious file is malicious,
the file will be sent to Execution Forensics for determination.
• After enabling Execution Forensics, click Modify License next to Execution Forensics Key to
go to the License page and enter an Execution Forensics Key.
Click Save to save your configuration changes. A confirmation dialog box displays stating that
usage statistics are collected. Click OK to continue.

Execution Forensics
Execution Forensics uses an external sandbox technology to execute files and determine if the
behavior is malicious. When Execution Forensics is enabled, confirmed hits from the Malware
Detection Engine (MDE) are sent to Execution Forensics for analysis. In addition, highly suspicious
files are sent to Execution Forensics to determine if the behavior is [Link] can manually
submit any file from the Alert Details page for analysis. You can change the default so that only
specified file types are automatically analyzed. You can select from three options:

• All supported file types (the default) – automatically sends all supported files to Execution
Forensics for analysis. For a list of supported file types, click Selected file types to view.

Fidelis XPS User Guide 286


Note: Java-Class files can be analyzed only if they are contained within a valid JAR
file.

• No files – No files will be automatically sent for analysis. You still have the option of sending
files for analysis at the Alert Details page if execution forensics is enabled and a valid
execution forensics license has been entered.
• Selected file types – Click and select file types from the list. The files you select will be sent
automatically for analysis. You can send other files for analysis at the Alert Details page.
When the Malware Detection Engine on a Fidelis XPS sensor determines that a file is highly
suspicious, but cannot determine if the file is malicious, the file will be sent to Execution Forensics
for determination. The rationale for sending the file and the determination of malicious behavior is
embedded within the MDE. You may disable this function by unchecking the checkbox: Use for
Determination at System>Malware>Malware Detection. This checkbox will only appear if Execution
Forensics is enabled.
Note: Execution Forensics is only performed when a valid Execution Forensics key is
entered. This applies to automatic and manual file submissions.

Reaction
Reaction enables you to select an action and assign an Alert Management Group for malware
alerts detected by the Fidelis XPS sensor. Malware Reaction is configured for each of the four alert
severities. By default, all alerts are assigned to the default alert management group and the
reaction is Alert.
If your sensor is incapable of Malware detection, then detection is performed by CommandPost and
the configuration on this page does not apply. To verify that your sensor is capable of detecting
Malware, check the sensor.
Malware Detection must be enabled. Refer to Malware Detection.

Figure 139. Malware Reaction Configuration

Configure Malware Reaction


1. Select an action: either Alert or Alert and Prevent.
Alert: An alert is generated upon malware detection. All information about the violating
transmission will be sent to CommandPost and can be accessed through the Alert page.
Alert and Prevent: Prevent takes the following actions, based on sensor type and the
sensor configuration. Refer to Direct and Internal

Fidelis XPS User Guide 287


• A Direct or Internal sensor in out-of-band mode with TCP Reset enabled: the sensor
issues TCP reset packets to kill the session. If TCP Reset is disabled: the prevent
action has no effect.
• A Direct or Internal sensor in inline mode: the sensor drops all incoming packets for
the remainder of the TCP session. If TCP Resets are enabled, the sensor will also
issue reset packets to the appropriate endpoint to more efficiently terminate the
session.
• A Web sensor, including the Web sensor within an Edge sensor, cannot perform
prevention on malware.
2. Select an Alert Management group to associate with any resulting alerts. Refer to Define
Alert Management Groups.
3. Continue for each severity level.
4. Click Save.
The selected alert management group and reaction will apply to all registered sensors. If new
sensors are added at a later date, the configured malware reaction will be applied immediately after
registration.

Configure Malware Reaction for Mail


Fidelis XPS Mail sensors are capable of performing several actions based on the detection of
malware within an email.
1. Click show mail configuration. The mail options display. Configuration may be performed for
each severity type.

Figure 140. Malware Mail Reaction Configuration

2. Select an action: Alert, Alert and Prevent, Alert and Reroute, Alert and Quarantine, or Alert
and Remove Attachments.

Fidelis XPS User Guide 288


Alert: An alert is generated upon malware detection. All information about the violating
transmission will be sent to CommandPost and can be accessed through the Alert page.
Alert and Prevent: The email is rejected by the Fidelis XPS Mail sensor. The user will
receive a message stating that the message was not delivered.
Alert and Reroute: The email is rerouted based on the configuration of the reroute server
at the sensor configuration page. Refer to Mail.
Alert and Quarantine: The email is quarantined upon malware detection. When you
select this option, the Quarantine Action: select box displays. Select either discard or
deliver to specify what happens to quarantine emails after 14 days.
CommandPost quarantine managers can access the quarantined email at
Alerts>Quarantine and can decide to deliver or discard the message before expiration.
Alert and Remove Attachments: All attachments are removed from the email when it is
delivered. A text file will be added as an attachment named: [Link],
the contents are:
All attached files are removed due to malware detected.
<list of files>
Append Message: If needed, enter a message in the text box. This message is appended
to the original email when forwarded.
X-header: If desired, add a custom header in the text box.
3. If desired, select an Alert Management group to associate with any resulting alerts. Refer to
Define Alert Management Groups.
4. Continue for each severity level.
5. Click Save.
Note: The selected Alert Management group will apply to malware detected by all
registered sensors, including Mail sensors.
Mail Reaction: It may be possible that a single email contains multiple malware items with different
severities. In these cases, only one action will be taken on the entire email message. The following
priorities apply:

• Prevent takes first priority. Any email that includes malware with a prevent action will be
prevented.
• Quarantine has second priority. Any email that includes malware with the Quarantine action
will be quarantined (unless it also includes malware with the Prevent action).
• Reroute has third priority. If other actions such as Quarantine or Prevent are detected, they
are taken instead. Remove Attachments has fourth priority. If other actions are detected, they
are taken instead.
• Remove attachments has fourth priority. If other actions are detected, they are taken instead.
• Append Message: The message from each violated rule or malware will be added to the email
body. If the email has violated multiple rules or contains malware of multiple severities and
each has an append message, all the append messages are appended in single file.
• X-header: The X-header for each violated rule or malware will be inserted into the email
header. If the email has violated multiple rules or contains malware of multiple severities, and
each has an X-header, all X-headers will be inserted.

Fidelis XPS User Guide 289


Host Activity
The Host Activity page enables you to configure the Carbon Black server and the Bit9 server to
integrate with Fidelis XPS.

Carbon Black
By integrating with the Carbon Black server, Host Activity Monitor Configuration can detect if
malware seen on the network actually reaches the endpoint and if it is written to disk or executed.
The Host Activity report from Carbon Black is only available when actual malware (whose md5
matches the alert md5) is saved to disk or executed. If the malware is contained in a zip, tar, or
other container file; however, then saving the container file will not trigger a Host Activity report.
Even when a report is triggered, a delay can occur in receiving a Host Activity report depending on
the Carbon Black client.
You need to enable and configure access to the Carbon Black server at CommandPost. To do this:
1. Click the checkbox for Carbon Black Integration.
2. Enter the URL for the Carbon Black server.
3. Enter the token for authentication on the server.
4. Click Use Proxy if the server is outside of your network.
5. Click Verify Certificate if the Carbon Black server uses a verifiable certificate.
6. Click Save.

Bit9
By integrating with the Bit9 server, the Alert Details page will show a link to Bit9 server next to the
MD5 in alerts for exe files. The link will take users to the Bit9 console and search for that MD5.
You need to enable and configure access to the Bit9 server integration at CommandPost. To do
this:
1. Click the checkbox for Bit9 integration.
2. Enter the server name. Server names must start with an alphanumeric character.
Alphanumeric characters and special characters such as _ - . and : are allowed.
3. Click Save.

Fidelis XPS User Guide 290


File Check
This feature enables you to upload any file from your workstation and submit it for malware
analysis. Click Browse or Choose File (depending on your browser) to navigate to a file on your
workstation.
To submit a password-protected ZIP file for analysis, click the checkbox next to Password
protected ZIP? and enter the password into the text box. This unzips the password-protected ZIP
file and enables you to submit it for analysis.
Only traditional PKWARE encryption, also known as standard zip 2.0 encryption or ZipCrypto is
supported for this functionality.
Click Upload.
The file is sent to the Malware Detection Engine (MDE). When MDE completes its analysis, a link
displays stating that the results are available in an alert.
Click the link to open the Alert Details page for that alert.
Files scanned by File Check and found to be malicious are added to the list of files to alert or
prevent for all sensors registered to this CommandPost if Malware Reaction is configured. Refer to
Malware Reaction.

Figure 141. File Check results: Alert Summary


The alert generated by File Check is like any created by Fidelis XPS with the following exceptions:

• The sensor name will be set to [CommandPost]. This name will not appear as a sensor
elsewhere in the system.
• The Target column at the Alert List will display File Upload.
• The rule, policy, and summary are set to UPLOAD if no malware is detected. These values
cannot be clicked because they do not refer to a user-created policy. If malware is detected,
rule and policy are set to Malware Detection Engine. The summary states: Detected malware
using UPLOAD.
• The Alert details will not include a Violation Information section.
• The Malware Information section will always be present. If Malware was not detected, the
Malware section will state this.
• Files will not be automatically sent for Execution Forensics, regardless of the configuration at
System>Malware>Execution Forensics. All alerts will include a button to submit the file
manually. The execution will determine if the file can be executed and will return an error for
files than cannot be executed.
• One alert will be created for the uploaded file, which will contain results. If the file is an archive
file, such as a zip, rar, or tar file, one alert for each malicious file will be generated. These
alerts will appear as related alerts on the Alert Details page. Note that benign files within the
archive file will not create new alerts.

Fidelis XPS User Guide 291


Chapter 15 Version Control
With Version Control, you can manage the software version of Fidelis XPS components.
• The Install page enables you to install a new version of Fidelis XPS software. Installations
can be done at the click of a button or scheduled for installation at a future time.
• The Scheduled Installs page provides the ability for you to view and cancel scheduled
software installations.
• The Download Control page enables you to configure and manage automatic notifications
about new versions of Fidelis XPS software.
• The File Management page provides the ability for you to manually upload and manage
installation packages.
The software installation process is performed as follows:
• First an update package is copied to the CommandPost Management Console. This
process can be performed automatically if Download Control is properly configured for
automated download. The package can also be manually uploaded to CommandPost using
File Management.
• Once installation begins, CommandPost will copy the package to the desired component.
This operation is performed as part of the installation process. The time required for this
operation depends upon the network bandwidth available between CommandPost and
registered components.
• If you are installing to a sensor or Collector registered to a Subordinate CommandPost, the
package will be distributed first to the subordinate, then to the component. Network
bandwidth can impact the speed of this process.
• When the package reaches the intended component, the component will then be shut
down, installed, and restored to functionality at the new version. For a sensor, this process
typically requires a few minutes. For a CommandPost or Collector, the process requires
more time and depends on the amount of data stored by the device. Refer to the specific
release notes associated with the software version for detailed information about installation
times.
• Update packages can be quite large. Fidelis XPS components can store, at most, one
update package at a time. Therefore, it is not possible to update some components to one
version while updating other components to a different version.
• When you install on CommandPost, the screen will be redirected to a status page. All users
currently logged onto the CommandPost Management Console and any user that attempts
to log on during the installation process, will be directed to the same screen.

Fidelis Release Naming Conventions


Fidelis provides software updates in the following forms:

• Major releases provide new capabilities for Fidelis XPS. These releases are identified by
two-digit version numbers, for example, versions 7.0, 7.1, and 7.2. Updates must be installed
on systems running the last major release.
Updates should always be applied in sequence from version 7.0 to 7.1 to 7.2 and so on.
Refer to the latest Release Notes for information.
• Minor releases provide minor features and correct known software problems. These releases
are identified by the third number in the version, for example 7.2.1 and 7.2.2. Updates are
usually applied to the last major release, not necessarily the last minor release. For example,
you may install version 7.2.3 on a system running 7.2.1 without installing the 7.2.2 version.

Fidelis XPS User Guide 292


You may also install version 7.2.3 on a system running any version of 7.1. Refer to the
Release Notes for specific instructions as this may not always apply.
• Patch releases provide fixes for known issues, which may be software problems or may be
the result of a change in proprietary network protocols such as webmail, peer-to-peer, instant
messenger, and social networking protocols. Patch releases are given the version number of
the last release followed by a patch date. For example, 7.2.1-20120924. Patch releases must
be installed in a system running the version stated in the version (7.2.1 in the example). Patch
releases do not need to be installed in any order. All patches will become available in a future
release in one of the categories listed above.
Generally, patches are made available on a limited basis to specific customers that
experience a problem that requires an immediate patch. Once the problem is confirmed, the
fixes will be made generally available in the next major or minor release. Generally available
releases will be available for automated download if enabled using Version Control. Patches
will need to be installed using the manual file upload process.

Installing Fidelis XPS Software


Version Control enables you to install software to CommandPost, subordinate CommandPosts, and
any components registered to CommandPost or its subordinate CommandPosts.
Depending on your system load and network bandwidth between Command Post and sensor,
installing a sensor may take a few minutes to an hour to complete. Installing CommandPost can
take between a few minutes to several hours, depending on the number of alerts in the system and
the specific features added in the new software version. These times can increase significantly if
the network bandwidth between CommandPost and registered components is slow. Refer to the
Release Notes of each release for time estimates.
After a sensor update, it will begin to process traffic immediately, using the policies previously
assigned to the sensor. Alerts will not be sent to CommandPost while it is being updated. In this
case, alerts will be stored locally on the sensor. When the CommandPost update is complete, all
alerts stored on sensors will be sent.
Ideally, all system components are running the same software version. Updates do not need to be
performed in parallel, but all registered components must be upgraded before CommandPost. If
you have a Subordinate CommandPost, you must first update all sensors and Collectors registered
to the Subordinate, then the Subordinate CommandPost, then sensors and Collectors registered to
the Master CommandPost, and finally the Master CommandPost. Everything registered to the
Master must be updated before the Master CommandPost.
If you choose all components to Install Now or to schedule an install time, the installation process
will choose the correct order for installation. Each component will be installed in sequential order to
minimize the bandwidth requirements on your network for transfer of install files to each
component.

Prepare to Install
Before proceeding with the installation, refer to the Release Notes associated with the software
version. Release Notes contain information specific to the software version and describe any
procedures you might need to follow before installing.
To prepare for the installation:
If you plan to manually download installation files:
• Download the Fidelis XPS update installation file from: [Link]/support to
a folder on your local workstation. Refer to File Management.
To use automatic downloads:
• Setup credentials and configure automatic downloads at Download Control.

Fidelis XPS User Guide 293


Log into the CommandPost as a system administrator. Your role must provide access to Version
63
Control to proceed. Refer to Define User Roles.
The installation process automatically saves configuration data stored in the database such as
policies, users, and sensors. If the update fails, the automatic rollback procedure restores
configuration data and returns the system to its previous working version.

Install
The Install page enables you to install software that is available. If you have enabled automated
notifications at Download Control, available software will include all applicable software versions
listed on the Download Center. If you have not enabled automated notifications, available versions
are relative to the file uploaded at File Management.
The page will list all components accessible from CommandPost. This includes the CommandPost
Management Console (the CommandPost that you are currently logged into), all registered sensors
and Collectors, all Subordinate CommandPosts, and all sensors and Collectors registered to
Subordinate CommandPosts. Unregistered components will not be listed.
The Release Notes for all available versions are available by clicking the button on the bottom left
of the page. If no new versions are available, there will not be a Release Notes button. Click the
button to view a list of all available versions and release notes. Click Download Release Notes to
download the PDF of the release notes to your workstation. For the version available on the local
disk, the release notes will be extracted from the package and provided to you. For all other
versions, the release notes will be downloaded from the Download Center.
For each component, the following information is displayed:

• A checkbox to select a component for installation. The checkbox is disabled if no new


software versions are available for this component or if the component is down. The checkbox
will also be disabled if there are ongoing installations or scheduled installations on this
component.
• The component name, IP address, and current version installed on the component.
• The software versions available to be installed on the system. If there are no versions
available, the associated checkbox will be disabled and a message of No Updates Available
displays. If you choose the component for installation, select from the available versions for
installation.
• Clicking a row displays Component Details that list applied patches, the OS version, and
when the last installation occurred. Clicking the View Log button enables you to see a log file
that provides the history of installations on the component. The log is provided in reverse
chronological order, displaying the most recent installation at the top. Each installation
includes a header that indicates what time the install started and a footer to indicate when the
install finished. Note: the install header and footer was added in version 7.7 any installation up
to and including the installation to version 7.7 will only indicate the completion time of the
install.
• If you click the View Log file from a Subordinate CommandPost, the log file may indicate that
the install was done from the Master. The log is kept on the Master when the installation is
performed from the Master. When a component is currently being installed, the Last
installation information is replaced by an active status log.
Clicking the Email Log button enables you to send the log file as an email attachment. At the
Email Log popup, the To address is Support, From is the address defined at the
CommandPost>Email Config page, and Subject is the component name and the results of
the last install.

If Available Version displays: Not Operational, this indicates that the component is not
available for software installation. Check the component status by hovering the cursor over
the System Status and then hovering over the component health diamond.

63
Version Control enables you to update the CommandPost and Fidelis XPS sensors.
Fidelis XPS User Guide 294
Figure 142. Install

Install Now
To perform an installation:
1. Select the components you wish to install by using the checkbox next to each component.
Note: To install from a Master to a Subordinate CommandPost, both must be at least
at version 7.3.
2. Select the version to install for each selected component. The same selection must be made
for all components.
Note: It is possible to reinstall the current version if the update package for the
version is currently stored on the local disk.
3. Click Install Now to proceed with the install.
4. Click Install at the confirmation dialog box to proceed or Cancel to stop.
If you are installing to a Subordinate CommandPost, or any component registered to a
Subordinate CommandPost, any install packages that had previously been stored to the
Subordinate at File Management are obsolete. If all components are already running version
7.7 or higher, these files will be removed by the install process. If you are not currently
running version 7.7, you should log into the Subordinate and remove the obsolete files.
For all components, other than the CommandPost Management Console, you can click the
component name to monitor the installation progress. The information that appears will
update approximately once every 10 seconds. For most of the installation time, the
component will not be accessible and status cannot be obtained. Operations on
CommandPost are not impacted by installations being performed on registered components.
For an installation on the CommandPost Management Console, all CommandPost operations
become unavailable. You will be diverted to an installation status screen until the process is
complete.
Upon completion, you can access the login screen. All users attempting to access
CommandPost during installation will see the same status page.
5. After the Install completes, information about the last installation will appear in place of the
status. A pop up message will tell you that the install is complete.
6. Click OK at the popup to reload the Install page. Click View Log to see details.

Schedule an Install
Software installation can be scheduled for a date and time in the future.
To schedule an install:
1. Click System>Version Control>Install.
2. Select the appropriate components.
3. Select an available version for each component.
4. Click Schedule Install.

Fidelis XPS User Guide 295


Figure 143. Schedule Install
5. Enter a date and time into the text box or select from the calendar. The entry must be at least
10 minutes in the future.
Note: You might want to schedule an update during off peak hours, especially for
CommandPost.
6. Click Done when you finish selecting the date and time.
You can view or, if needed, delete scheduled installs at Scheduled Installs. When the scheduled
time arrives, status is available as described in Install Now.

Update Progress
Status screens display for all components and these screens vary for each.

CommandPost Management Console


When an update is in progress for the CommandPost Management Console, a status screen
displays that provides messages about the status of the update. All users attempting to use
CommandPost will see this screen. You cannot access CommandPost until the Install completes.

Fidelis XPS User Guide 296


Figure 144. Update in Progress: CommandPost
When complete, a message indicates if the update was successful.
Click Return to Login to access CommandPost. You will need to either clear the browser cache or
restart your browser for proper operation of the new version of CommandPost.

Sensors, Collectors, and Subordinate


CommandPosts
Update status for sensors, Collectors, and Subordinate CommandPosts display on the Install page
of the CommandPost Management Console. The process begins with the transfer of the install
package from CommandPost to the component. The start and finish time for the file transfer is
indicated in the display. Immediately after the file transfer, the component will be taken out of
service, installed, and restarted. While the component is out of service, secure communication with
CommandPost is not possible. During this time, a dot will be printed during each minute of elapsed
time. When the installation is complete, whether successful or not, the full log will be available.
If you have selected to update multiple components at once, the install process will determine the
correct order of installations. The status will indicate which component update is active and which
are waiting to begin. You may leave the page and return later to view the status.

Fidelis XPS User Guide 297


Figure 145. Update in Progress: Subordinate CommandPost
Users attempting to log in directly to the Subordinate CommandPost will see the CommandPost
status screen and will not be able to access CommandPost until the install completes.

Scheduled Installs
Click to see a list of scheduled installs.

Cancel Scheduled Installs


You must cancel a scheduled install before scheduling another one for the same component.
To cancel a scheduled install:
1. Click Scheduled Installs. A list displays of all scheduled installs.
2. Click Delete next to the appropriate install.
3. Click OK at the confirmation dialog box. Clicking Cancel stops the procedure.
You can now perform an Install or schedule another job.

Download Control
At Download Control, you can enable CommandPost to automatically check for and download the
latest update packages. When configured, CommandPost will periodically access the Download
Center to check for new updates. If a new update is detected, will appear on the top right of
every CommandPost page.
If you do not want to set up automatic downloads, ensure that Never is selected at Check for
Updates. Never is the default setting. You can manually download updates from Technical Support
and save them to your workstation. Refer to File Management.
Before configuring downloads, you must set up credentials.
To configure downloads:
1. Determine when you want to check for updates. You can select daily, weekly, or monthly.
For daily, select a time. For weekly, select a day of the week and a time. For monthly,
specify the day of the month (1 through 31) and a time. Simply checking for updates does

Fidelis XPS User Guide 298


not impact the system in any way. However, if you choose to download new packages, you
should configure the operation for off-peak times.
2. Select an action when a new download is available either: Notify Only or Notify and
Download the Update Package.
If you select Notify Only, an email will be sent when a new software version is detected and
the icon on the top right of CommandPost will change to reflect the new version availability.
When you choose to install this version, the package will first be downloaded to
CommandPost which may extend the installation time depending on network bandwidth
between CommandPost and the Download Center.
If you have a slow network connection to the Download Center, the recommendation is to
download the package automatically when detected at off-peak times.
3. Enter the email address for notifications. This is the email address that will receive a notice
when a new version is available.
4. Enter Download Credentials. This is necessary to download the update package, either at
the time of detection or at the time of installation. These credentials are the same as those
used to log into: [Link] If you do not enter Download
Credentials, you may be notified of new software availability, but you must use the manual
download process. Refer to File Management.
To change download credentials:
Click the box next to Click to change credentials. Two text boxes display.

Figure 146. Download Control: Credentials


To verify that CommandPost can access the Download Center:
Click Check Now. A list of new versions and release notes displays. If it does not, check your proxy
settings at Proxy Config and verify your network and firewall settings.
Select from the list and click Download. Download will only be operational if Download Credentials
are entered.

Fidelis XPS User Guide 299


File Management
File Management enables you to manually upload software installation packages and manage the
packages stored on the local disk. CommandPost can only support one file on disk at a time, which
may be the result of an automated download from the Download Center or a manual upload. If
multiple files are detected, you will need to remove all but one to perform installations.
To manually upload the installation package:
1. Download the Fidelis XPS installation file from the Download Center at:
[Link]/support to your local workstation. Contact Technical Support if you
cannot access this address or are not sure which file to download. Release Notes are
available from the Download Center.
Files available on your workstation can be uploaded at File Management.
2. Click Upload New File and a dialog box will appear.
3. Enter the file from your workstation and click Upload. A progress message will appear.
The time to upload the file will depend on the level of activity on CommandPost and the
network bandwidth between your workstation and CommandPost. Once the file has been
completely transferred to CommandPost, the progress message will be updated.
Your internal network likely has a timeout for HTTP transfers. If the upload time exceeds
the network timeout, your browser will not complete the file transfer. If this occurs, you
have two options: a) increase the gateway timeout setting of your network, b) manually
copy the package to CommandPost. In most cases, the latter is the only viable option.
Refer to Manual Transfer of Installation Packages for information on the manual transfer
process.
4. After the upload and verification process is complete, a log file is available to view any
errors that may have been detected. If the upload was successful, information about the file
is displayed, release notes can be extracted, and the package will appear as an available
version on the Install page for any applicable component.

Figure 147. File Management

Fidelis XPS User Guide 300


Chapter 16 Configure Exports
Export enables you to integrate with a third-party system by transferring alert and recorded object
data from CommandPost to a remote system. You can also export data in a Fidelis Archive format
which can later be imported to CommandPost (either the original CommandPost or another). The
following export methods are available. For more specific information about each, refer to Export
Methods.

• ArcSight
• Email HTML table
• Email user-defined
• Email Excel File (TSV attachment)
• Fidelis Archive
• SNMP traps
• Syslog
• Syslog LEEF
• Syslog Splunk
• McAfee ESM
• Verdasys Digital Guardian
You need to be a CommandPost administrator with alerts and alert details permissions. All saved
exports are available to users with these privileges. Refer to Define User Roles.
Refer to Define Exports for instructions on setting up a new export.

Export Methods
This topic provides specific information for each of the export methods. For general instructions
about creating an export, refer to Define Exports.

Fidelis Archive
For this export method, the remote server name, login, and directory information need to be set up
at the System>Components>CommandPost Config>Archive page. Refer toArchive.
Specify the remote directory for export at Destination.
Select Include Sessions or Include PCAPs to include in the export, if desired.
Select Include Configuration Backup to add a configuration backup. A separate backup file will be
created and exported to the same directory as the archive file. Refer to Backup and Restore for
more information.
When exported, a file named archive.<extension> will be created and sent to your remote system
and placed into the directory specified in the Destination field. Notes about Fidelis Archive exports:

• An <extension> is a number created based on the time of the export.


• If the remote directory does not exist, it will be created.
• Fidelis uses FTP to transmit archive files to the remote system.
If you encounter errors, check your Archive configuration, your network settings, and the
configuration of your remote system.

Fidelis XPS User Guide 301


Email User-Defined, Syslog, and Syslog Splunk
Syslog, Syslog Splunk, and email exports can be freely formatted by selecting keywords and
clicking Add Keyword. You can use the text box to create a comma-separated list of values, a link
to the alert on CommandPost, and any other required format for your external system.
64
To create a link to the alert CommandPost, enter:

[Link]

The destination for email is provided by a single or comma-separated list of email addresses. The
destination for Syslog or Syslog Splunk is the name or IP address of your external Syslog server.
For Syslog and Syslog Splunk, you can also specify a port, for example [Link]:::1800
Syslog Splunk has a preformatted key=value message format that is parsed by Splunk server. You
can also modify this format if needed.

T a bl e 3 2. A l e rt E x p or t k ey w or d s

Keywords Description Type (values)

%ACTION% The action taken by the sensor in String: Can be alert, quarantine,
response to the violation. prevent, or throttle.
Can also include valid
combinations of actions, such as
quarantine and notify.

%ALERTUUID% Displays a unique UUID belonging to Link


an alert. If you selected ArcSight this
will send a link back to the
65
CommandPost Alert Details page.

%COMPR% Indicates the number of additional Numreric


events represented by an alert.

%DSTADDR% The IP address of the recipient of the IP address


data. When available, both IPaddress and
resolved host name are provided.

%DSTPORT% Destination port number Numeric

%FILENAME% File name that caused the alert String

%FROM% email address source String

%GROUP% The alert management group to which the String


alert belongs.

%HOSTIP% The Host IP address String

%MALWARE_NAME Malware name String


%

%MALWARE_TYPE Type of malware String


%

%MD5% MD5 hash of file String

64
An alert is the recorded and displayed incidence of at least one event.
65
Alert Details is the most granular level for examining alert data.
Fidelis XPS User Guide 302
Keywords Description Type (values)

%POLICY% The name of the policy that was violated. String

%PROTO% The application protocol on which the String


violating transfer occurred.

%RULE% The name of the rule that was violated. String

%SENIP% Sensor IP address String

%SENSOR% Sensor name String

%SEVERITY% Severity level String: Can be low, medium,


high, or critical

%SRCADDR% The IP address of the sender of the data. String


When available, both IPaddress and
resolved host name are provided.

%SRCPORT% Source port number Numeric

%SUBJECT% Email subject line String

%SUMMARY% Displays summary text associated String


with the rule.

%TIME% Time when the alert was detected. String in the format: YYYY-MM-
DD hh:mm:ss

%TO% Email address destination String

%USER% Protocol user String

Email HTML Table and Email Excel File (TSV


attachment)
The items in the column list determine which alert information is included for each alert and the
order in which they are sent.
The destination for email is provided by a single or comma-separated list of email addresses.

Figure 148. Export: Email Excel File

Fidelis XPS User Guide 303


You can use the default column list or select columns from the Column Choices box and click
to move them to the column list. At the column list, you can order choices using and .
Remove a column from the Column List by selecting it and clicking .

Syslog LEEF
Similar to Syslog, but in LEEF (Log Event Enhanced Format). When this export method is selected,
you do not need to enter keywords as in Syslog, but need to specify destination, event criteria for
alerts and malware events, and export frequency.
The destination for Syslog LEEF is the name or IP address of your external Syslog LEEF server,
and an optional port number for example: [Link] or [Link]:::1800.

McAfee ESM
McAfee Enterprise Security Manager (ESM) is a predefined Syslog format designed for use with
the McAfee server. For McAfee ESM, you do not need to enter keywords as in Syslog, but need to
specify destination, event criteria for alerts and malware events, and export frequency.
The destination for is the name or IP address of your external McAfee ESM server.
For McAfee ESM, you can also specify a port for example: [Link]:::1800.

SNMP Trap and ArcSight


You may choose the information to export by SNMP or ArcSight. The items in the column list
determine which alert information is included for each alert and the order in which they are sent.
SNMP traps may be sent to an external system specified by a host name or IP address entered at
Destination. To enable Fidelis SNMP traps, an MIB is available with sample use instructions at.
[Link]/support.
Select SNMP version 1 or 3.
• If you select SNMP 1: You can change the entry for the SNMP Community String. The
default value is public.
• If you select SNMP 3: Engine ID, user names, and authentication and privacy tokens for
users should be configured on the remote SNMP server that runs the SNMP trap.
SNMP Engine ID: Enter the ID for the remote SNMP server.
SNMP User Name: Enter a user name associated with the Engine ID.
SNMP Authentication Protocol: Select Authenticated Only or Authentication and
Encrypted.
For Authentication Only:
Select MD5 or SHA1 Protocol. Enter the Authentication Token for the user in the text box.
For Authentication and Encrypted:
Select an Authentication Protocol and enter the Authentication Token.
Select either DES or AES Privacy (Encryption) Protocol. Enter the Privacy (Encryption)
token for the user in the text box.
ArcSight may be selected if you desire to export alert information to an ArcSight event
management system. The ArcSight export uses an (unencrypted) CEF connector over UDP. In
addition, we should emphasize that the three colons ":::" between the IP and port number must be
used. A single ":" in the IP address does not work.
Identify your ArcSight system by entering an IP address or host name at Destination.
Destination also enables you to specify a port number, for example: [Link]:::1800. Use three
colons ::: between the IP and port number as shown in the example. A single colon between the IP
address and port number will not work.

Fidelis XPS User Guide 304


Figure 149. Export: SNMP trap and ArcSight
You can use the default column list or select columns from the Column Choices box and click
to move them to the column list. At the column list, you can order choices using and .
Remove a column from the Column List by selecting it and clicking .

Verdasys Digital Guardian


66
Verdasys Digital Guardian may be selected if you desire to export alert information to the
Verdasys Digital Guardian product.
To configure this output, enter the URL for your Digital Guardian at Destination. All alert information
will be exported to the appropriate fields within Digital Guardian.
For more information, contact Fidelis Technical Support or your Verdasys representative.

Define Exports
This topic provides instructions on setting up an export. Refer to Export Methods for information
specific to each export delivery method.
1. Click System>Export. A list of available exports displays. The first time Exports is accessed,
the list is empty.

Figure 150. Export page

2. Click New to create a new export or click next to the appropriate export. The Export
Editor displays. (Click to delete an existing Export.)

66
An alert is the recorded and displayed incidence of at least one event.
Fidelis XPS User Guide 305
Figure 151. Export Editor
3. Select an export delivery method. The Export Editor changes to reflect your choice. Refer to
Export Methods.
If you select Fidelis Archive, you can select Include Configuration Backup to back up during
an automatic export. Refer to Backup and Restore.
4. Enter a Destination. This can be an email address, directory name, IP address, or port
depending on the export method.
Note: Destination does not support the use of non-ASCII characters.
5. Select to export either All alerts, alerts By Criteria, or None.

• All–enables you to select all available alerts. Exporting all alerts in your database can
take time. With this option, you might want to limit this export by selecting a maximum
number of alerts.
• By Criteria–enables you to select alerts based on multiple search criteria. These criteria
vary depending on the export method.
• None–No alerts will be exported.
6. Select alert criteria as needed to determine the alerts you want to export. You can select
multiple entries.
For sensors, no selection means all sensors are selected. If user permissions or sensor
assignments change, assignments for the export will not change.
For Time Range, you can select a specific time such as 24 hours or 7 days or enter a date or
date range. Refer to Time Range. You can also select Oldest Alerts to include alerts older
than a specified amount of time (1 - 99 days). If you enter 99, you get alerts older than 99
days.
Other export criteria include severity, rules, policies, labels, and actions associated with the
alert. Refer to Filters for specific information about these criteria.
7. Select the Export Frequency.

• Manually–exports only when you run the export by clicking the Run Now button. This
method is useful to test communication with the external system and for Fidelis Archive.
It is less useful for other export methods.
• Every Alert–exports all new alerts that meet selected criteria. Exporting for each new
alert is guaranteed to export each alert exactly once. The Export occurs immediately
Fidelis XPS User Guide 306
when the alert is received from the sensor. This method is recommended for integration
with external systems. It is not available for Fidelis Archive.
• Periodically–enables you to specify a time and day to run the export. This method is
recommended only for Fidelis Archive, email, and Syslog exports. All other types of
exports should be performed on Every Alert to provide synchronization between the
Fidelis system and the external system.
ArcSight and Syslog export methods support using transport protocols for message delivery.
If you select an Export Frequency of Manual or Periodically the UDP protocol is available. If
you select Every Alert, then UDP, TCP, and TLS are available.
To use TLS with Fidelis XPS, you need to upload certificates (in PEM format) into the
appropriate directory: /usr/local/syslog-ng/3.5.6/etc/ca.d/
You also need to run the following command:

/usr/sbin/cacertdir_rehash /usr/local/syslog-ng/3.5.6/etc/ca.d/

8. Select the maximum number of alerts to be sent. This option is very useful when testing
communication to external systems and is not recommended in any other case. When you
choose this option, the selected alerts will be random, based on your criteria. You should not
depend on the exact alerts exported when this option is selected.
9. Enter a name for the export in Save As. You must save the Export before you can run it.
Clicking Reset restores settings to what was last saved.
10. Click Run Now to export.

Available Export Buttons


• Save will save the export as currently configured. You must save before you can Run.
• Run Now is used to test communication. This button is not available until you save any
changes made to the Export. Run Now is also not available if you select Every Alert for Export
Frequency.
• Reset will restore the export to the last saved state. This will enable the Run Now button if you
have made changes that you do not wish to save.
• Cancel will return you to the list of Exports.

Testing Export Communication


The Run Now button is provided as a mechanism to test communication with the external system
provided by the Export Method and Destination. When clicked, alerts are exported immediately
regardless of the chosen Export Frequency.

• If the Export Frequency is set to Every Alert, Run Now will export exactly one alert, if one can
be found to match the criteria of the alert. This alert will be transported to the external system
and handled accordingly.
• If the Export Frequency is set to Manual or Periodic, all alerts that match your criteria will be
exported to the external system. Note that this can be millions of alerts and can take a very
long time to execute. You can use the maximum number of alerts to limit the size of the
export for testing purposes.
Run Now can only be performed after the Export is saved. If you make any changes on the Export
page, the Run Now button will be disabled until you either Reset or Save.

Fidelis XPS User Guide 307


Delete Exports
To delete an export:
1. Click System>Export.
2. Click Delete next to the appropriate export.
3. Click OK at the confirmation dialog box. The Export is removed from the Exports page.

Fidelis XPS User Guide 308


Chapter 17 Audit
The CommandPost audit trail is used to monitor user activities throughout Fidelis XPS. User
actions that modify system configuration or system data or export information result in an audit
entry.
Auditable actions include:

• CommandPost user login (successful or not)

• CommandPost user actions that change system configuration, including sensor and
CommandPost configuration, sensor registration, and policy updates to sensors.

• CommandPost user actions to remove or export data from the system. This includes alert
purge, alert export, and user-generated reports.


67
CommandPost user actions to add, modify, or delete system components such as policies
and policy components, users, groups, roles, etc.
• User actions taken at sensor or CommandPost front panel keypad and LCD display. Actions
performed at the sensor will be recorded to the CommandPost to which the sensor is
registered.
You can access the Audit Log from the CommandPost GUI to find audit entries.
Note: Fidelis recommends that you restrict audit log access to system administrators
and network security personnel. A user with Audit access can see all auditable actions.

67
Components enables you to set up licensing and configure Fidelis XPS components. This
includes adding and registering Fidelis XPS sensors, setting password strength, configuring e-mail,
and setting up user notification and LDAP among other features.
Fidelis XPS User Guide 309
Access Audit
Click System>Audit at the main menu. The Audit Log displays.

Figure 152. Audit Log


Clicking on a column heading sorts all rows by that column. By default, the Audit Log displays
content in descending order of time. To change this sort order, click the header of any column. If
the column header is clicked multiple times, the order alternates between descending and
ascending order.

T a bl e 3 3. A u di t L o g c ol u m ns

Column Description

ID The audit log ID number.

Timestamp The date and time when the action occurred.

User The user who performed the action.

Category The general type of action that occurred. For example, roles, users, and
audit.
Action The specific action that occurred. Most actions relate to the section of the
CommandPost used to trigger the action. For example, Alerts, Policies,
and Reports. The Action column may also include information about what
occurred, such as a login.
Click a row to display more detailed information about an audit log entry. Expand all displays more
details about all rows. Detailed information includes the effect and a description of the action.

Fidelis XPS User Guide 310


Figure 153. Audit Log details

Audit and Hierarchical Management


At the top left of the Audit page, you can select another CommandPost if you have set up
CommandPost relationships. At the Master CommandPost, you can select a Subordinate to view
its audit logs. If you selected a Subordinate CommandPost, you return to the Audit page for the
Master CommandPost by clicking Console.
Only the audit logs for the selected CommandPost display.

Search for Audit Entries


Searching for audit entries can be done by entering criteria at the Search bar. If the searching
options are not visible, click in the upper right corner of the Audit Log to open it.
You can search for specific audit entries by entering terms into the Find: text box. This enables you
to focus the search on specific areas of the audit entry.

Search Terms
Entering an ID number returns one and only row. For example, entering 21 matches only 21 and
not 211. Ranges are not supported for ID searches.
Enter specific terms in the Find: text box. Searching for term will match any audit entry containing
term in the chosen field. This will match audit entries with words such as term, terminate, and
exterminate.
Entering multiple words such as
term1term2
matches any audit entry containing both term1 and term2. The terms can be found in any order and
with any amount of separation between them.
The use of quotes around a phrase will be treated as a single search term. The phrase “term1
term2” will match any audit entry containing the exact phrase within the quotes. Any spaces in the
phrase will match any space characters in the audit entry, including a space, a tab, a new line, etc.
Matching is done on the character boundaries, not word boundaries. Therefore, a phrase of “top
secret” will match an audit entry containing a phrase such as “stop secrets.”
Multiple phrases such as a “literal phrase 1” and a “literal phrase 2” can be included in the Find
field. This will match any audit entries containing all of the phrases listed.
You can combine word-terms and phrase-terms. Any combination is allowed, such as “literal
phrase 1” word word1 word2 “literal phrase 2”
Matching does not consider the order of the terms, only that all are found within the search field.

Notes about Search Options


All searches are case insensitive.
There is a limit of 40 terms (words or literal phrases) in the search bar. If more terms are entered,
the 41st and beyond will be ignored.
Clicking Search without entering a search term, results in the Audit Log list redisplaying.
You can change the time frame by selecting any value at the During Last list and clicking Search,
without making any other entries.

Fidelis XPS User Guide 311


Time Periods
To specify a new time period, select a value from the During Last list, select hours or days, and
click Search. Options range from 1 hour to 96 days and also include the default value of all.

Fidelis XPS User Guide 312


Appendix A: Manual Transfer of Installation
Files
CommandPost offers an interface to upload software installation packages by using the UI
available at Version Control>File Management. However, in many enterprise settings, the use of a
browser-based HTTP interface is not sufficient to transfer large files such as the installation
package. If you are unable to perform this task without a network timeout, you will need to find an
alternate method to transfer the package. Use of the automated download capability from the
Download Center is recommended whenever possible. If neither the automated download nor the
CommandPost interface is acceptable, you can follow these instructions:
1. Create an SSH commandline session to CommandPost and log in using the fidelis account.
Note: You must use the fidelis account and password for the first four steps in
this process.
2. Once logged in, change directory to /FSS/jail/TARUPDATE.
3. Remove all files located in this directory.
Note: The system does not support multiple update packages at one time. If
old packages are not removed, GUI operations and installations will not
function properly.
4. Transfer the installation package to /FSS/jail/TARUPDATE. The name of the file must be
the same as the file found at the Download Center, for example, fidelis_xps_update-
7.3.x86_64.tar.
5. Make sure that the copied file is owned by Fidelis with read and write permissions for owner
and group. Use Linux chown and chmod functions to modify file ownership and permissions
if necessary.
6. Access CommandPost Version Control>File Management. CommandPost access for this
step can use your personal CommandPost account. If steps 3 through 5 were executed
properly, the UI will perform verification of the file found at /FSS/jail/TARUPDATE. If
there are no problems, the file version, MD5, and usage will be updated on the screen
within a few minutes. If there is a problem with the file, the error will be shown at the bottom
of the page.
Contact Fidelis Technical Support if you experience any problems with this process.

Fidelis XPS User Guide 313


Appendix B: Changing IP Addresses
Before changing the IP address of a component, you need to do the following:
1. Disable all links to all other components.
2. Change the IP address.
3. Reestablish links to other components.
For specific instructions for each component, refer to:
Changing a Sensor IP Address
Changing a CommandPost IP Address
Changing a Collector IP Address

Fidelis XPS User Guide 314


Changing a Sensor IP Address
Before changing a sensor's IP address, note which other components are connected to the sensor.

Figure 154. Sensor Relationships


Changing the IP address of a sensor involves several steps:

1. If the sensor is linked to a Collector (at in the diagram), you need to unlink it from the
Collector.
a. Select the sensor at the System>Components page and click Config.
b. At the Advanced tab, select None at Send metadata to collector.
c. Click Save.

2. Unregister the sensor from the primary CommandPost .


Select the sensor at the System>Components page of the primary CommandPost click
Unregister.
3. Change the IP address of the sensor. Refer to chapter 2 in the Enterprise Setup and
Configuration Guide.
4. Enter the new IP address for the sensor at the Primary CommandPost. Refer to Edit a
Sensor.

5. Reregister the sensor to the primary CommandPost .

6. If this sensor links to a CommandPost that is a Secondary Policy Manager , add the
sensor to the Secondary Policy Manager.
Click System>Components>Add Component. Refer to Add Component.

7. If this sensor links to an Alert Failover CommandPost , add the sensor to the Alert
Failover CommandPost.
Click System>Components>Add Component. Refer to Add Component.
8. Link to a Collector . Refer to Link a Collector to Sensors.
9. If needed, assign policies to the sensor. Refer to chapter 8 in the Guide to Creating
Policies.
Fidelis XPS User Guide 315
Mail Sensors
Follow the steps above to change the IP address of a Mail sensor.
In milter mode, the MTA is sending data to the Fidelis XPS Mail sensor. If the MTA is
communicating with the Mail sensor on the admin interface, then the MTA needs the new IP
address for the Mail sensor.

Web Sensors
Follow the steps above to change the IP address of a Web sensor.
If the third-party proxy is communicating with the Fidelis XPS Web sensor on the admin interface,
then the third-party proxy needs the new IP address for the Web sensor.

Fidelis XPS User Guide 316


Changing a CommandPost IP Address
Before changing a CommandPost's IP address, note which other components are connected to it.

Figure 155. CommandPost Relationships


Changing the IP address of a CommandPost involves several steps:
1. If the CommandPost is Subordinate to a Master CommandPost, unregister it at the Master
CommandPost (at in the diagram).
2. Unregister all components linked to your CommandPost, including all Subordinate
CommandPosts , sensors , and Collectors .
3. Change the IP address of the CommandPost. Refer to chapter 2 in the Enterprise Setup
and Configuration Guide.
4. Enter the new IP address for the CommandPost.
5. If this CommandPost is a Secondary Policy Manager to a sensor, enter its new IP address.
a. Click System>Components>[sensor name] and click the Secondary Managers tab.
b. Enter the new IP address for the CommandPost. Refer to Secondary Managers
6. If this CommandPost is an Alert Failover CommandPost for a sensor, enter its new IP
address.
a. Click System>Components>[sensor name] and click the Alert Failover tab.
b. Enter the new IP address for the CommandPost. Refer to Alert Failover.
7. Reregister all components to the CommandPost, including the any sensors, Collectors, and
Master and Subordinate CommandPosts. Refer to Set up CommandPost Relationships.

Fidelis XPS User Guide 317


Changing a Collector IP Addresses
These instructions pertain to a Collector SA or a Collector Controller. Before changing a Collector's
IP address, note which other components are connected to it.

Figure 156. Collector Relationships


Changing the IP address of a Collector SA or Collector Controller on the admin interface involves
several steps:
1. Unlink any sensors linked to this Collector.
a. Select the sensor at the System>Components page and click Config.
b. At the Advanced tab, select None or select another Collector at Send metadata to
collector.
c. Click Save.
2. Unregister the Collector from the CommandPost to which it is registered.
Select the Collector at the System>Components page and click Unregister.
3. Change the IP address of the Collector. Refer to chapter 2 in the Enterprise Setup and
Configuration Guide.
4. Enter the new IP address for the Collector.
5. Reregister the Collector to a CommandPost.
6. Link to a sensor. Refer to Link a Collector to Sensors.

Fidelis XPS User Guide 318

You might also like