Entity Lookup
An Entity Lookup (or search) is the starting point for an investigation if you have very little information to work with, because the entity record may contain important contextual information.
You can start an Entity Search by entering an IP address or domain in the Search field in the navigation menu at the top of the portal. |
To perform an entity lookup:
-
Go to Investigations > Entity Lookup.
-
Enter an IP address or a domain name in the search field. Separate Multiple IP addresses and domain names by spaces.
-
Click the date picker to select the time range. The default is Last Seven Days. The maximum is 90 days.
- Click Search. The following results are returned.
Network Intelligence Network traffic by service, by device, and source addresses interacting with the entity
Entity Intelligence WHOIS, IP History, Registrar History, Passive DNS Security Intelligence Associated VirusTotal Detections and VirusTotal Detections Over Time You can view the Entity Panel by clicking the IP address at the top-left of the page next to Entity information for <IP address>.
- (Optional) If multiple IP addresses or domain names are looked up, right-click on a result and select Entity Lookup to view the intelligence panes.
- (Optional) Click Investigate to launch the new investigation.
To perform a bulk entity export:
-
In the search field, enter IP addresses or a domain names separated by spaces.
-
Click Search.
- Click the CSV button. A CSV file with the timestamp, action, param, user_uuid, account_uuid, and account are downloaded to your device.
Source Device List
View the internal devices communicating with the specific IP or domain. Right-click the IP address of any source device and click Investigate.
Passive DNS
Passive DNS links on the entity panel function like normal links. Clicking the link replaces the entity panel with the panel for the clicked on element.
Right-clicking opens a context menu.
Option | Description |
---|---|
Entity Lookup | Open the entity lookup page for the item. |
Copy to Clipboard | Copy the item to the clipboard. |
Guided Queries | Launch Guided Queries. This options is not available for ad-hoc search result items |
Investigate | Show appropriate pivots for the item type. This options is not available for ad-hoc search result items. |
Search Events |
Show the event searches appropriate for the type. The text in the search box is replaced, but the search will not run automatically. This options is only available for ad-hoc search result items. Types include:
|