Analysis
Incident > Analysis lists the Incidents detected by FortiDeceptor. You can download the detailed analysis report by clicking Export to PDF.
To use the Analysis page:
- Go to Incident > Analysis.
- The Analysis page displays the list of events:
Severity
Severity of the event.
Last Activity
Date and time of the last activity.
Type
Type of event.
Attacker IP
Attacker IP mask.
Attacker User
Attacker username.
Victim IP
Start
Date and time when the attack started.
Attacker Port
Port where the attack originated.
Attacker Type
The attacker type is shown as Unknown, Connection, Interaction, or Reconnaissance.
Victim Port
Port of the victim.
Password used by the attacker.
Download File
If the Decoy VM captured network traffic or files, download the PCAP files or dumped files.
Timeline
Click Timeline to see the entire timeline of all the Incidents from start to finish.
Table
Click Table to see all the Incidents in table view.
- To refresh the data, click Refresh.
- To download the detailed analysis report in PDF format, click Export to PDF.
- To mark items as read, expand the incident details or click Mark all as read.
Newly-detected incidents are in bold to indicate they are unread.
- To display specific types of events, click Show All, IPS Events Only, or Web Filter Events Only.