Attack Map
The Attack Map is a visual representation of the entire network showing real endpoints, Decoy VMs, and ongoing attacks.
The nodes on the map are color-coded by severity.
Node |
Color |
Description |
---|---|---|
Decoy | Pink | Click to view the Name, MAC address, IP, DNS, and Gateway. |
Victim | Red |
Click to view the attack history including Attacker, Start Time and Incident ID. When a node is both Victim and Attacker, the node will appear as Attacker. |
Attacker | Black | Click to view the attacker's history including Attacker, Start Time and Incident ID. |
To filter the Attack Map by IP:
- Under Filter Current View, click in inside Click to begin filtering. The options menu is displayed.
- Select one of the following options:
- Attacker IP
- Victim IP
- Decoy IP
- Enter the IP address. FortiDeceptor sorts the nodes on the map.
To save the current view of the map:
Under Filter Current View, click the Save View icon .
To filter the map by date:
Drag the red arrows at the bottom of the page to set the start and end dates.
To search for a node by IP:
In the Locate by IP box, enter the IP address.