Software Secure Workload
Activity Configure

Unseen Command

Unseen Command search terms have the prefix “Unseen Command - ”, for example, “Unseen Command - Anomaly - Similarity - High”

Field

Description

Anomaly - Score

Score (0 to 1.0) indicating how frequently the command line was seen previously, lower score implies that the command is more anomalous

Anomaly - Similarity - High

True if the anomaly score is larger than 0.8 and is smaller than 1

Anomaly - Similarity - Medium

True if the anomaly score is larger than 0.6 and is smaller than or equal to 0.8

Anomaly - Similarity - Low

True if the anomaly score is larger than 0 and is smaller than or equal to 0.6

Anomaly - Similarity - Seen

True if the anomaly score is 1, i.e. the same command has been seen before

Anomaly - Similarity - Unique

True if the anomaly score is 0, i.e. the command has never been seen before

Parent Cmdline

Full command line of the parent process

Parent Exepath

Binary path of the parent process

Parent Uptime

Time since the parent process was executed

Parent Username

Username of the user that executed the parent process

Sensor Uptime

Uptime of the sensor

Anomaly - Latest Similar Commands

5 latest previously observed command which are similar to the command of the event