Events
17 min
events represent malicious activity surfaced for the assets you monitor across the clear and dark web and other illicit data sources each event is where investigation of a potential threat begins, giving you a structured starting point to detect, investigate, and respond all events collected by flare make up the events feed, which is organized into two views tenant feed this shows the events that match your identifiers, such as a domain, ip address, or keyword for more information, see the tenant feed docid\ dtls7nx5g qwodcs3ydpd global search this covers every collected event and lets you search across all of them, including those that do not match your identifiers for more information, see global search docid\ duvcx vwniajeylllrni0 each event brings together the context you need to assess and prioritize it, so you can fully understand a potential threat an event provides the following information what was found the nature of the exposure, along with supporting details such as the indicator, file, url, domain, or port involved, and a preview of the raw content where it was found the source or location the event was collected from who is involved who is affected, such as your organization, a third party, or an employee, and the actor or author responsible for the activity when it was collected the date the data was ingested and matched to your tenant why it matters its severity and the potential impact on your organization the events feed walkthrough the new events feed has been re architected to give you the full context behind every threat event in one place, so you can investigate faster and protect your organization with confidence click through the following demo to learn how to use the new events feed click the try the new events toggle to switch to the new layout, and use the give feedback button to share your thoughts toggle back to the old layout anytime until november 23rd , when the new feed becomes permanent the tenant feed events are matched to your tenant feed through the identifiers configured in your tenants as data sources are scanned continuously, an event is matched whenever collected data matches an identifier's parameters common triggers include leaked data, such as credentials or internal documents vulnerability detections on exposed infrastructure brand impersonation, such as lookalike domains, or mentions on illicit forums exposed identities, including credentials, active sessions, and personally identifiable information (pii) each row in the tenant feed is one event and shows the name, the identifier the event is matched to, the source the event was collected from, and the date the event was matched to your tenant feed viewing event details there are two ways to view the details of an event, expand it inline, or open the details panel expand an event inline click the expand icon for an event to reveal a summary of its context directly in the feed, organized into the following sections what was found? describes what the event contains, with a content preview of the full event content beneath it where was this found? shows where the event was collected, such as the room or source, as a link who did this? shows the responsible entity, such as the actor or author, as a link tip click the expand all icon to expand all events in the feed all together open the details panel click an event to open the details panel on the right and view complete event data the tabs available for an event depend on its type summary, content, secrets, ai assist, and advanced are available for most events other tabs appear only when they apply for example, leaked files appear for ransomware events, and takedown for events eligible for a takedown request threat cards entities within an event, such as the actor or author and other surfaced objects, are shown as links that lead to further context where available, hovering over an entity displays a threat card showing quick information about that entity event actions you can act on an event from the actions column in the feed and from the actions menu in the details panel the actions column in the tenant feed provides access to quick actions on each row the actions menu in the details panel provides a full set of actions for the event sharing an event the share option copies a shareable link to the event to your clipboard you can then share this link with a stakeholder when they open it, they are routed to the correct tenant context and the event opens directly, without needing to search for it or navigate the feed manually this is useful when you need to flag an event for review, escalate findings, or collaborate on a response marking events as remediated when you have taken action to address an event, mark it as remediated so that it is hidden from the feed to restore visibility of remediated events, choose the remediated option in the status filter ignoring events ignoring an event excludes it from your feeds to view all ignored events, choose the ignored option in the status filter changes to the events feed an event that was previously remediated or ignored will not reappear in the feed in most cases, unless a difference in its content is detected some event types have particular behaviors, as described below infected devices (stealer logs) a previously matched stealer log can reappear when a new source reposts the original stealer log, or when a change is detected in the content of the stealer log, which is treated as a new event open web github events can reappear when the github repository being queried changes because the entire page is queried again, the section that includes your identifier can appear again alongside the parts that changed for github, you can use ignore term policies to ignore specific github authors and projects see policies leaked credentials when you remediate a leaked credential event in the feed, or a credential item in the credentials browser, future instances of the same credential pair appear as remediated in both places and are filtered out of the default view the severity of a remediated leaked credential event is lowered if it reappears when you ignore a leaked credential event in the feed, or a credential item in the credentials browser, future credentials related to the same email or username are ignored as well, in both the tenant feed and the credentials browser adjusting severity, tags, and notes you can manually adjust change an event's severity and add any relevant tags and notes from the details panel open the event, then edit its severity , tags , and notes in the summary tab searching and filtering events the search bar at the top of the events page searches within flare's existing data use the tenant selector to the left of the search field to choose which tenant to search, then enter a query in the search in existing data field refine results using the filters below the search bar status controls whether new, remediated, and ignored events are shown creation date sets the date range of the events shown severity sets which severity levels are shown categories sets which event categories are shown tags filters by the tags applied to events attributes filters by event attributes the active filter count and the clear button appear below the filters click clear to remove all active filters above the results, you can set sort by to change the order of the feed, set display to change how many events appear per page, and click export events to export the current results exporting events to export your events, click export events from the tenant feed the basic export includes all metadata and a content preview exporting the full content of events increases the size of the export and should be utilized as needed