• NDR - Devices generating most network traffic

    Karl_Ackerman
    Karl_Ackerman
    • Approved on 28 Jan 2023
    • 0 Comments
    -- NAME: NDR - Devices generating most network traffic -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the top 100 talkers on a network. -- Fields are ip: the private IP address of the machine, total_bytes: the total number of bytes sent...
    • 28 Jan 2023 8:48 PM
  • NDR - Protocol Report

    Karl_Ackerman
    Karl_Ackerman
    • Approved on 28 Jan 2023
    • 0 Comments
    -- NAME: NDR - Protocol Report -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying protocols used and how often -- NOTE: avg_pcr is the Producer Consumer Ratio (PCR) (-1 Pure Push to +1 Pure Pull) -- NOTE: mac_addresses is a list of the top...
    • 28 Jan 2023 8:55 PM
  • NDR - Top 100 most trafficked hostname

    Karl_Ackerman
    Karl_Ackerman
    • Approved on 28 Jan 2023
    • 0 Comments
    -- NAME: NDR - Top 100 most trafficked hostnames -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the top 100 most trafficked hostnames by traffic volume -- SOURCE: Data Lake -- VARIABLE $$Destination IP Address$$ IP ADDRESS -- VARIABLE...
    • 28 Jan 2023 9:06 PM
  • NDR - Top Clusters

    Karl_Ackerman
    Karl_Ackerman
    • Approved on 28 Jan 2023
    • 0 Comments
    -- NAME: NDR - Top Clusters -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the clusters with the most traffic in bytes. -- A cluster is a group of flows defined by their shared values for src_ip, dest_ip, dest_port, protocol, app_protocol...
    • 28 Jan 2023 9:10 PM
  • NDR - Mac IP Hostname Correlation

    Karl_Ackerman
    Karl_Ackerman
    • Approved on 28 Jan 2023
    • 0 Comments
    -- NAME: NDR -Mac IP Hostname Correlation -- CATEGORY: NDR -- DESCRIPTION: Source Mac IP and Hostname Correlation based on MDNS and NetBIOS -- NOTE: This includes hostname information extracted from the flow data where available. -- If no web_hostname...
    • 28 Jan 2023 9:11 PM
  • NDR - Raw record data

    Karl_Ackerman
    Karl_Ackerman
    • Approved on 28 Jan 2023
    • 0 Comments
    -- NAME: NDR - Raw record data -- CATEGORY: NDR -- DESCRIPTION: Display all fields for the NDR Detection or Report record. -- NOTE the interesting bits are in the 'raw' field. It is a JSON structure. -- The 'mapped_raw' is an array structure of...
    • 28 Jan 2023 8:59 PM
<