Web - Threat Activity
WidgetDescriptionType
Top Blocked DLP Dictionaries Displays a pie chart of a user's top blocked DLP dictionaries.

Hide Query

Show Query

Pie Chart
Top CrowdStrike IOC Hits by Threat Actor Displays a chart of top CrowdStrike IOC hits by threat actor and limits results to the first 10 entries.

Hide Query

Show Query

Time Chart
CrowdStrike IOC Enrichment on Destination Domain Displays a table of CrowdStrike IOC enrichment data regarding the destination domain and associated data (user email, IOC domain, etc) then limits results to the first 1000 entries.

Hide Query

Show Query

Table
Top Vendor Threat Names Displays a chart of the top 10 vendor threat names.

Hide Query

Show Query

Time Chart
Top CrowdStrike IOCs by Confidence Displays a pie chart of top CrowdStrike IOCs by confidence.

Hide Query

Show Query

Pie Chart
Top Blocked DLP Engines Displays a pie chart of top blocked DLP engines.

Hide Query

Show Query

Pie Chart
CrowdStrike IOC Enrichment on Server IP Displays a table of CrowdStrike IOC enrichment instances and server IPs and limits results to the first 1000 entries.

Hide Query

Show Query

Table
Top CrowdStrike IOCs by Country Displays a pie chart of the top CrowdStrike IOCs by country.

Hide Query

Show Query

Pie Chart
Top Threat Name Displays a pie chart of the top threat names via username and user email.

Hide Query

Show Query

Pie Chart
Top Vendor Categories to Threat Names Displays a flow chart of top vendor categories to threat names.

Hide Query

Show Query

Sankey
Web - User Investigation
WidgetDescriptionType
Top Blocked DLP Dictionaries Displays a pie chart of a user's top blocked DLP dictionaries.

Hide Query

Show Query

Pie Chart
Top Users by Volume Displays a chart of top users by volume using user email data, then limits the results to the first 10 entries.

Hide Query

Show Query

Time Chart
Top CrowdStrike IOC Hits by Threat Actor Displays a chart of top CrowdStrike IOC hits by threat actor and limits results to the first 10 entries.

Hide Query

Show Query

Time Chart
Total Distinct Users Displays the number of total distinct users and their email addresses.

Hide Query

Show Query

Single Value
CrowdStrike IOC Enrichment on Destination Domain Displays a table of CrowdStrike IOC enrichment data regarding the destination domain and associated data (user email, IOC domain, etc) then limits results to the first 1000 entries.

Hide Query

Show Query

Table
Top Allowed Domains Displays a user's top allowed domains based on their email address.

Hide Query

Show Query

Table
Top Allowed Super Categories Displays a chart of top allowed super categories by user email, and limits results to the first 10 entries.

Hide Query

Show Query

Time Chart
Top Blocked Domains Displays a list of a users top blocked domains by username and email address.

Hide Query

Show Query

Table
Top Vendor Threat Names Displays a chart of the top 10 vendor threat names.

Hide Query

Show Query

Time Chart
Top Application Names Displays a pie chart of top applications names.

Hide Query

Show Query

Pie Chart
Top Blocked Super Categories Displays a chart of top blocked super categories over time then limits results to the first 10 entries.

Hide Query

Show Query

Time Chart
Top User Agents Displays a list of top user agents by user email address and limits the results to the first 100 entries.

Hide Query

Show Query

Table
Top CrowdStrike IOCs by Confidence Displays a pie chart of top CrowdStrike IOCs by confidence.

Hide Query

Show Query

Pie Chart
Top Blocked DLP Engines Displays a pie chart of top blocked DLP engines.

Hide Query

Show Query

Pie Chart
Top Protocols Displays a pie chart of top network protocols.

Hide Query

Show Query

Pie Chart
CrowdStrike IOC Enrichment on Server IP Displays a table of CrowdStrike IOC enrichment instances and server IPs and limits results to the first 1000 entries.

Hide Query

Show Query

Table
Top Allowed Categories to Domains Displays a flow chart of top allowed URL categories and vendor domains, then limits results to the first 20 entries.

Hide Query

Show Query

Sankey
Top Allowed Categories Displays a table of top allowed URL categories by user email.

Hide Query

Show Query

Table
Top CrowdStrike IOCs by Country Displays a pie chart of the top CrowdStrike IOCs by country.

Hide Query

Show Query

Pie Chart
Top Blocked Categories to Domains Displays a flowchart of top blocked categories by domain name.

Hide Query

Show Query

Sankey
Top Application Classes Displays a pie chart of top application classes using Zscaler data.

Hide Query

Show Query

Pie Chart
Top Threat Name Displays a pie chart of the top threat names via username and user email.

Hide Query

Show Query

Pie Chart
Top Blocked Categories Displays a list top blocked categories based on a user's email address.

Hide Query

Show Query

Table
Request Methods Displays a list of HTTP request methods by username and email.

Hide Query

Show Query

Time Chart
Actions Over Time by Volume Displays a list of user actions over time by volume based on user email.

Hide Query

Show Query

Time Chart
Top Vendor Categories to Threat Names Displays a flow chart of top vendor categories to threat names.

Hide Query

Show Query

Sankey
Total Distinct Locations Displays the number of total distinct locations by username.

Hide Query

Show Query

Single Value
Web - Web Activity
WidgetDescriptionType
Top Users by Volume Displays a chart of top users by volume using user email data, then limits the results to the first 10 entries.

Hide Query

Show Query

Time Chart
Total Distinct Users Displays the number of total distinct users and their email addresses.

Hide Query

Show Query

Single Value
Top Allowed Domains Displays a user's top allowed domains based on their email address.

Hide Query

Show Query

Table
Top Allowed Super Categories Displays a chart of top allowed super categories by user email, and limits results to the first 10 entries.

Hide Query

Show Query

Time Chart
Top Blocked Domains Displays a list of a users top blocked domains by username and email address.

Hide Query

Show Query

Table
Top Application Names Displays a pie chart of top applications names.

Hide Query

Show Query

Pie Chart
Top Blocked Super Categories Displays a chart of top blocked super categories over time then limits results to the first 10 entries.

Hide Query

Show Query

Time Chart
Top User Agents Displays a list of top user agents by user email address and limits the results to the first 100 entries.

Hide Query

Show Query

Table
Top Protocols Displays a pie chart of top network protocols.

Hide Query

Show Query

Pie Chart
Top Allowed Categories to Domains Displays a flow chart of top allowed URL categories and vendor domains, then limits results to the first 20 entries.

Hide Query

Show Query

Sankey
Top Allowed Categories Displays a table of top allowed URL categories by user email.

Hide Query

Show Query

Table
Top Blocked Categories to Domains Displays a flowchart of top blocked categories by domain name.

Hide Query

Show Query

Sankey
Top Application Classes Displays a pie chart of top application classes using Zscaler data.

Hide Query

Show Query

Pie Chart
Top Blocked Categories Displays a list top blocked categories based on a user's email address.

Hide Query

Show Query

Table
Request Methods Displays a list of HTTP request methods by username and email.

Hide Query

Show Query

Time Chart
Actions Over Time by Volume Displays a list of user actions over time by volume based on user email.

Hide Query

Show Query

Time Chart
Total Distinct Locations Displays the number of total distinct locations by username.

Hide Query

Show Query

Single Value