The equipment list : your machines
129 Views •A machine's detail page
117 Views •Alerts : the list of what was noticed
126 Views •Risk analysis : a score, and why
143 Views •Vulnerabilities : the updates that are missing
132 Views •The asset inventory : everything you own
90 Views •Activity : the running thread of what happens
118 Views •Checking a suspicious address, and outside intelligence
124 Views •The cybersecurity dictionary
157 Views •Defence : the blocked addresses
153 Views •Who is watching while you work
147 Views •Risk analysis : a score, and why
143 Views •The crisis room: the button never to press
139 Views •The help centre and the explanation bubbles
139 Views •Opening a support ticket
136 Views •Your three habits, and what comes next
135 Views •Exclusions : silencing what is normal at your site
134 Views •The dashboard : ten seconds to know
134 Views •My organisation : companies and licences
133 Views •Companies : the administrative record
132 Views •Who it is for
132 Views •Creating your workspace and accepting the terms
132 Views •Vulnerabilities : the updates that are missing
132 Views •Signing in : and what if I lost my password
132 Views •The equipment list : your machines
129 Views •Playbooks : ready-made responses
126 Views •Finding your way around the menu
126 Views •Alerts : the list of what was noticed
126 Views •Checking a suspicious address, and outside intelligence
"Observables" and "Threat intelligence" pages
These two screens answer the same family of question, "is this thing known to be dangerous?", but in opposite directions. One asks, the other listens.
Observables: you ask the question
Farida gets a dubious email with a link in it. She copies the link, opens "Observables", picks the type, address, domain, link or file fingerprint, pastes the value, and clicks "Analyse".
Several analysis services answer within seconds. The result appears in a table: the date, the value, the analyser, the state, and the verdict. Four counters track total analyses, successful ones, those in progress, and failures.
This action costs nothing and commits to nothing. Checking a link before clicking it is the single most profitable reflex in all of computer security. Do it without hesitation, even ten times a day. An analysis "failure" is never a verdict of danger: it is a service that did not reply.
Threat intelligence: you are informed
The other screen works the other way round. It gathers lists kept by the worldwide security community, addresses and links known to be malicious, and continuously compares them against what your machines see.
Four counters: the number of active sources, the total of indicators tracked, the malicious addresses and the malicious links. A search box finds a specific value within those lists.
There is nothing for you to do on this page: it works for you in the background. You open it out of curiosity, or to check that a source is indeed active.
In closing
Two screens, two directions: you ask, or you are told. Get into the habit of checking a doubtful link before clicking; it costs fifteen seconds and prevents most bad days.
Commenting is not enabled on this course.