Digital Impression
tab.
2.
From the list, select an item that you want to explore.
By default, the digital impression report is listed in tabular format, which is
organized by identifier type. All identifiers that interacted with the centering
identifier are displayed. The interacting identifiers are organized by identifier
type and are sorted by frequency of interaction.
3.
If you see an identifier of interest, select it.
Identifiers are hyperlinks and you can use them as the centering identifier of
another report. Another tab is created and the new centering identifier is
displayed. You can see who a given suspected attacker interacts with and then
who the suspect's interactions interact with. You can expand the radius of an
investigation to more suspected attackers and entities with whom they interact.
4.
To look at another host, select the IP address from the Select Remote Host list.
In distributed installations, you can choose the QRadar Incident Forensics host
and then view the digital impression. The default view is the primary host, but
you can select any secondary host that is associated with the QRadar Incident
Forensics host.
5.
To see a visualization of the associations and relationships of the interactions of
the centering identifier to other identifiers, click the Visualize Data tab.
Visualize tool
You can explore associations and relationships visually across multiple attributes
and data categories.
Use the Visualize window to look at a metadata relational map of one, two, or a
large selection of documents. When large selections of documents are used, the
investigator gets a comprehensive view of metadata relationships and relative
frequency. Investigators can then follow these paths to further their investigation of
a security incident.
The visualization of the selected documents can easily be rebuilt with a different
relation by changing one or both relations.
The visualization shows every relation that is contained within the selected
documents and shows the frequency of relation. Each node represents a distinct
piece of metadata that is being related from the selected documents. The size
conveys the relative frequency when compared to other nodes. Links show the
connections that are found between the distinct pieces of metadata and convey
frequency through size. Investigators can use the nodes to identify possible
avenues for further investigation.
Chapter 4. Investigation tools
Do'stlaringiz bilan baham: |