The equipment list : your machines
143 Views •A machine's detail page
125 Views •Alerts : the list of what was noticed
126 Views •Risk analysis : a score, and why
147 Views •Vulnerabilities : the updates that are missing
144 Views •The asset inventory : everything you own
106 Views •Activity : the running thread of what happens
132 Views •Checking a suspicious address, and outside intelligence
130 Views •The cybersecurity dictionary
166 Views •Defence : the blocked addresses
159 Views •Exclusions : silencing what is normal at your site
149 Views •The crisis room: the button never to press
148 Views •Companies : the administrative record
147 Views •Who is watching while you work
147 Views •Risk analysis : a score, and why
147 Views •Vulnerabilities : the updates that are missing
144 Views •My organisation : companies and licences
144 Views •The help centre and the explanation bubbles
144 Views •The equipment list : your machines
143 Views •Opening a support ticket
142 Views •Your three habits, and what comes next
142 Views •The dashboard : ten seconds to know
141 Views •Playbooks : ready-made responses
140 Views •The audit log : who did what
139 Views •Backups : verified, not just launched
139 Views •Notifications : being told, without being pestered
139 Views •Who it is for
138 Views •The insurability score : answering insurers
137 Views •Checking a suspicious address, and outside intelligence
"Observables" and "Threat intelligence" pages
These two screens answer the same family of question, "is this thing known to be dangerous?", but in opposite directions. One asks, the other listens.
Observables: you ask the question
Farida gets a dubious email with a link in it. She copies the link, opens "Observables", picks the type, address, domain, link or file fingerprint, pastes the value, and clicks "Analyse".
Several analysis services answer within seconds. The result appears in a table: the date, the value, the analyser, the state, and the verdict. Four counters track total analyses, successful ones, those in progress, and failures.
This action costs nothing and commits to nothing. Checking a link before clicking it is the single most profitable reflex in all of computer security. Do it without hesitation, even ten times a day. An analysis "failure" is never a verdict of danger: it is a service that did not reply.
Threat intelligence: you are informed
The other screen works the other way round. It gathers lists kept by the worldwide security community, addresses and links known to be malicious, and continuously compares them against what your machines see.
Four counters: the number of active sources, the total of indicators tracked, the malicious addresses and the malicious links. A search box finds a specific value within those lists.
There is nothing for you to do on this page: it works for you in the background. You open it out of curiosity, or to check that a source is indeed active.
In closing
Two screens, two directions: you ask, or you are told. Get into the habit of checking a doubtful link before clicking; it costs fifteen seconds and prevents most bad days.
Commenting is not enabled on this course.