Mandiant, Inc.
Infection vector and malware tracking with an interactive user display
Last updated:
Abstract:
According to one embodiment, a computerized method comprises detecting a malicious attack on an enterprise network, where the enterprise network comprises a plurality of network devices. Upon detection of a malicious attack, information (metadata) associated with the malicious attack is gathered. Examples of the information may include at least a geographic location associated with each of the plurality of network devices. Thereafter, an interactive display of a propagation of malware associated the malicious attack is generated. The interactive display includes a plurality of display items representative of the plurality of network devices, each of the plurality of display items is selectable to provide information as to at least one of (i) an origin of the malware, (ii) an entry point of the malware into an enterprise network, or (iii) a targeted destination of the malware.
Utility
26 Jun 2014
13 Oct 2020