Graph View for Signals

In any environment, during the process of collecting, processing and analyzing data, outliers can come from many sources and hide in many dimensions. Detecting outliers is of major importance for the success and survival of organizations. The rule based correlation, on-demand outlier detection and anomaly models along with automated analysis through graph analytics and threat intelligence ensures to lighten the load on Analysts by adding contexts to everything that demands attention. You can have a detailed understanding of every signal raised and at the same place, visualize and diagnose all the connected anomalies and compromises that happened, a summary of all the observations are generated.

How to View Connected Graph?
  • On the left navigation bar of the home screen, click the Signals icon. The following screen will be displayed.


  • Click View Graph at the top right corner of the Signals list page. The graph provides a visual overview of suspected, compromised, and targeted entities, along with the signals associated with them. Users can use the date-time picker to focus on a specific time frame and better identify anomalies within the network.


  • Click a signal to view its connected graphs and to view the list of signals associated with it for the selected duration.


  • The graph displays signals, artifacts, and campaigns involved, indicating that multiple systems may have targeted the system. 
  • Click the dropdown to select Signal, Artifacts, and Campaigns.




  • Click Signal to view the list of all signals associated with the connected graph for the selected duration.


  • Click Artifacts to view the list of suspected, targeted, and compromised entities.


  • Click Campaigns to view threat campaigns (as per the MITRE framework) attributed based on common indicators or behavior patterns observed across the signals associated with the selected connected graph


The connected graph displays the following:

IconsDescription
The green and white with solid line indicates the target in the current case.
The red and white with solid line indicates the suspect in the current case
The red with dotted line indicates the suspect in connected signals
The blue and white with solid line indicates that the particular signal or entity is a part of the current case
The blue with dotted line indicates that the particular signal or entity is a part of the connected signal
The yellow and white with solid line indicates the compromised entity in the current case
The yellow with a dotted line indicates the compromised entity in the connected signal.
image 7-Dec-07-2023-11-24-29-4551-AM
Click to automatically assign a Case to this signal. Note: By default, the Case name will be same as that of Signal name.
image 8-Dec-07-2023-11-25-12-4760-AM
Click to view and edit the automatically created Case.