The table shows, for each executed event: execution status, exploitation status, event number and name, date & time of execution, severity, availability of an IOC / Sigma rule / comments / evidence, event type, MITRE ATT&CK tactic, execution source, targets, detection status, detection, reaction, Time to Detect (TTD) and Time to React (TTR). Use the button at the top right to choose which columns to display.
The first column reports the outcome of the execution itself: whether the Attack Vector actually carried the adversary action out on the scope. It conditions how the rest of the row reads, since an event that did not execute carries neither a detection result nor an exploitation result. The detailed execution information for a given event — source and target, start and end times, duration, and the commands run with their results — is available on the Event details page. The second column reports each event's exploitation status — Exploited, Contained or N/A — which records the outcome of the action from the attacker's standpoint, independently of whether it was detected (see Scores & statuses ). This is what makes the events list directly usable to identify exploitable security weaknesses: the Exploited events are the actions that actually succeeded on your systems, and therefore the exposures to address first. Read them together with the scope and the privileges granted for the campaign, as explained in Security validation . The bar at the bottom shows the total number of events and lets you set how many to display per page.
Order events by date or event ID, search, and filter by event start time, severity, type, comments, proofs, Sigma rule, IOC, MITRE ATT&CK tactic, detection status, detection source, and reaction.
Next to the search field, an execution control panel shows the simulation's progress. From it, you can stop the execution of an event at any time, then resume it or skip to the next event.
This sketch cannot currently be displayed in exports
Export everything for the campaign: a with all technical event information, and a with all evidence added to the events.
This sketch cannot currently be displayed in exports
Set each event's detection status directly from the list. The default is Unqualified; the three others are Undetected, Logged and Alerted (see Scores & statuses ). The number of unqualified events is shown under the simulation name. Qualifying every event gives complete results and a better measure of your defenses — status is the criterion with the most impact on the score.
Change detection status in live