Event details

Event details

Each event has its own page describing execution, recommendations, IOC, logs and more. It is also where you enrich the event's detection information.


Use the up and down arrows next to the event name to move between events without returning to the list.


Adversary action details



Left panel

Detection status history

A banner at the top shows the history of this event's detection status across the campaign's simulations.
Below it are three distinct, complementary blocks: the execution details, the detection qualification, and the reaction qualification.

Execution details

Technical details of the event's execution:
  • Source IP address
  • Target IP address and/or name
  • Start and end date & time
  • Duration
  • Exploitation status: the outcome of the adversary action from the attacker's standpoint, complementary to its execution status and independent of detection. It can be Exploited, Contained or N/A. See  Scores & statuses .

Qualify detection and reaction

Add detection information with the Add detection status button. The default status is Unqualified; the three others are Undetected, Logged and Alerted (see  Scores & statuses ).
Depending on the status, you can add the source(s) that detected the event, the detection date & time, and evidence (a screenshot of an interface, an email, or a log file).
For Alerted events, record the response with the Add reaction button: the action taken or final status, the date & time, and reaction evidence.
TTD (Time To Detect) and TTR (Time To React) are computed automatically from the dates & times you provide. This detection and reaction data feeds the campaign KPIs on the Threat brief page (cyber score, detection rate, most active sources, etc.). Qualifying every event gives complete results; status is the criterion with the most impact on the score. Use the Edit button in each section to change the information.
When a connector is active, the technical information it returns — for example from an EDR — is shown directly in BlackNoise to help you qualify the detection.


Right panel

Detection score

The event's detection score, computed in real time from the information you provide.

Event description

The technical description of the event, to help you understand it and investigate: the description of the executed action, the MITRE ATT&CK correlations (tactic and technique), the event type, and its severity.


Enhance detection (recommendations)

Most events executed at OS level come with a Sigma rule, provided by the BlackNoise CERT, to complement your existing tools (EDR, SIEM, etc.) when the event was not detected. The solution also provides Suricata rules for most network-related events. You can copy or download the rule to integrate it into your defenses. Rules may need adapting to your specific tool, and you should check the rule's requirements before using it.


Comments


The Comments tab lets you exchange messages about handling the event. Each user can post comments, and edit or delete their own.
You can directly mention other users within the company so that they are notified directly of the ongoing discussion


IOC

The IOC tab lists, in a table, the technical markers (indicators of compromise) associated with the executed event. It helps analysts by pointing to the key markers to look for in their detection tools. These IOCs are provided either in MISP format or in a BlackNoise-specific format, and can include, for example, executed system commands or dropped files.


Logs

The Logs tab provides detailed execution logs, with full visibility into each event step, including the executed system commands and results obtained.