This
widget displays all C&C callback event information including the target of the attack
and the
source callback address.
You can choose to view C&C callback information from a specific C&C server
list. To select the list source (Global Intelligence, Virtual Analyzer), click the
edit icon (
) and select the list from the C&C list source
drop-down.Use the View by drop-down to select the type of C&C
callback data that displays:
-
Compromised host: Displays the most recent C&C information per targeted endpoint
Compromised Host Information
ColumnDescriptionCompromised HostThe name of the endpoint targeted by the C&C attackCallback AddressesThe number of callback addresses that the endpoint attempted to contactLatest Callback AddressThe last callback address that the endpoint attempted to contactCallback AttemptsThe number of times the targeted endpoint attempted to contact the callback addressNote
Click the hyperlink to open the C&C Callback Logs screen and view more detailed information. -
Callback address: Displays the most recent C&C information per C&C callback address
C&C Address Information
ColumnDescriptionCallback AddressThe address of C&C callbacks originating from the networkC&C Risk LevelThe risk level of the callback address determined by either the Global Intelligence or Virtual Analyzer listCompromised HostsThe number of endpoints that the callback address targetedLatest Compromised HostThe name of the endpoint that last attempted to contact the C&C callback addressCallbacks AttemptsThe number of attempted callbacks made to the address from the networkNote
Click the hyperlink to open the C&C Callback Logs screen and view more detailed information.