Unseen Command
Unseen Command search terms have the prefix “Unseen Command - ”, for example, “Unseen Command - Anomaly - Similarity - High”
Field |
Description |
---|---|
Anomaly - Score |
Score (0 to 1.0) indicating how frequently the command line was seen previously, lower score implies that the command is more anomalous |
Anomaly - Similarity - High |
True if the anomaly score is larger than 0.8 and is smaller than 1 |
Anomaly - Similarity - Medium |
True if the anomaly score is larger than 0.6 and is smaller than or equal to 0.8 |
Anomaly - Similarity - Low |
True if the anomaly score is larger than 0 and is smaller than or equal to 0.6 |
Anomaly - Similarity - Seen |
True if the anomaly score is 1, i.e. the same command has been seen before |
Anomaly - Similarity - Unique |
True if the anomaly score is 0, i.e. the command has never been seen before |
Parent Cmdline |
Full command line of the parent process |
Parent Exepath |
Binary path of the parent process |
Parent Uptime |
Time since the parent process was executed |
Parent Username |
Username of the user that executed the parent process |
Sensor Uptime |
Uptime of the sensor |
Anomaly - Latest Similar Commands |
5 latest previously observed command which are similar to the command of the event |