The equipment list : your machines
14 Views •A machine's detail page
14 Views •Alerts : the list of what was noticed
14 Views •Risk analysis : a score, and why
25 Views •Vulnerabilities : the updates that are missing
14 Views •The asset inventory : everything you own
15 Views •Activity : the running thread of what happens
23 Views •Checking a suspicious address, and outside intelligence
14 Views •Opening a support ticket
25 Views •Risk analysis : a score, and why
25 Views •Your everyday tools, properly configured
24 Views •Choosing your subscription
23 Views •Backups : verified, not just launched
23 Views •Activity : the running thread of what happens
23 Views •Exclusions : silencing what is normal at your site
23 Views •My organisation : companies and licences
23 Views •Frameworks : measurement and declaration
23 Views •Declaring a false positive : teaching the tool your habits
23 Views •Who is watching while you work
15 Views •Finding your way around the menu
15 Views •Container platforms
15 Views •Checking a suspicious address, and outside intelligence
14 Views •The asset inventory : everything you own
15 Views •Secrets forgotten in the code
15 Views •Alerts : the list of what was noticed
14 Views •Vulnerabilities : the updates that are missing
14 Views •Creating your workspace and accepting the terms
14 Views •The equipment list : your machines
14 Views •Checking a suspicious address, and outside intelligence
"Observables" and "Threat intelligence" pages
These two screens answer the same family of question, "is this thing known to be dangerous?", but in opposite directions. One asks, the other listens.
Observables: you ask the question
Marie gets a dubious email with a link in it. She copies the link, opens "Observables", picks the type, address, domain, link or file fingerprint, pastes the value, and clicks "Analyse".
Several analysis services answer within seconds. The result appears in a table: the date, the value, the analyser, the state, and the verdict. Four counters track total analyses, successful ones, those in progress, and failures.
This action costs nothing and commits to nothing. Checking a link before clicking it is the single most profitable reflex in all of computer security. Do it without hesitation, even ten times a day. An analysis "failure" is never a verdict of danger: it is a service that did not reply.
Threat intelligence: you are informed
The other screen works the other way round. It gathers lists kept by the worldwide security community, addresses and links known to be malicious, and continuously compares them against what your machines see.
Four counters: the number of active sources, the total of indicators tracked, the malicious addresses and the malicious links. A search box finds a specific value within those lists.
There is nothing for you to do on this page: it works for you in the background. You open it out of curiosity, or to check that a source is indeed active.
Commenting is not enabled on this course.