Skip to main content
Version: 2.2.2

Alerts Table

One of the most important components of the Sycope system is alerting functionality. This functionality allows the user to flexibly build Alerts based on a number of conditions and rules that operate on the data streams collected by the system.

Sycope includes many predefined Alerts created by a team of cybersecurity experts. These rules can be used as a template from which you can create your own rules. You can also create rules on your own using the wizard.

In this menu [Alerts>Alerts Table] there is a table with a list of all the alarms that are included in the system. Within each Alarm is a column of fields which, depending on user preference, can be made visible. These are listed below.

Field NameNQL NameDescription
Alert IdidAlert Identifier
TimetimestampAlert Time
Rule TypealertRuleTypeRule Type
Alert NamealertNameAlert Name
Rule IdalertRuleIdRule Identifier
Alert DescriptionalertDescriptionAlert Description
Alert SeverityalertSeverityAlert Severity
Threshold LevelalertThresholdLevelThreshold Level (Criticial, Major, Minor)
Alert TagsalertTagsTags
Mitre TacticalertMitreTacticMitre ATT&CK Tactic
Mitre TechniquealertMitreTechniqueMitre ATT&CK Technique Id
Mitre Technique IdalertMitreTechniqueIdMitre ATT&CK Technique Id
Mitre SubtechniquealertMitreSubtechniqueMitre ATT&CK Subtechnique
CorrelationsalertCorrelationsRule Correlations
Mitigation SystemalertMitigationSystemMitigation System
Mitigation IPalertMitigationIpFieldMitigation IP
Raw DatarawDataRaw Data
ACKalertAckSetting the Acknowledge flag
ACK UseralertAckUserUser updating the Acknowledge flag
ACK TimealertAckLastUpdateAcknowledge flag update Time
False PositivealertFalsePositiveAlert handling False Positive flag
FP UseralertFalsePositiveUserUser updating the False Positive flag
FP TimealertFalsePositiveLastUpdateFalse Positive flag update time
CommentalertCommentComment
Commented UseralertCommentUserUser updating a comment
Comment TimealertCommentLastUpdateComment update time
Client IPclientIpClient IP
Client PortclientPortClient Port
Client TCP FlagsclientTcpFlagsClient TCP Flags
Client GroupclientGroupsClient Group
Client CountryclientCountryClient Country
Client MacclientMacClient Mac
Client HostnameclientHostnameClient Hostname
Server IPserverIpServer IP
Server PortserverPortServer Port
Server TCP FlagsserverTcpFlagsServer TCP Flags
Server GroupserverGroupsServer Group
Server CountryserverCountryServer Country
Server MacserverMacServer Mac
Server HostnameserverHostnameServer Hostname
UsernameuserUsername
Unique Client IPsuniqueClientIPsUnique Client IPs
Unique Server IPsuniqueServerIPsUnique Server IPs
Unique Server PortsuniqueServerPortsUnique Server Ports
Unique Client ASNsuniqueClientASNsUnique Client ASNs
Unique Server ASNsuniqueServerASNsUnique Server ASNs
Unique Client CountriesuniqueClientCountriesUnique Client Countries
Unique Server CountriesuniqueServerCountriesUnique Server Countries
BPF_bpfBytes Per Flow
BPP_bppBytes Per Packet
Bytes_bytesSum Bytes
Flows_flowsSum Flows
Packets_packetsSum Packets
PPF_ppfPackets Per Flow
PPS_ppsPackets Per Second
SYN_synCount of SYN flags
Unique ASN_uniqueASNsUnique Count of ASNs
Unique ClientIPs_uniqueClientIPsUnique Count of Client IPs
Unique ServerIPs_uniqueServerIPsUnique Count of Server IPs
Unique Server Ports_uniqueServerPortUnique Count of Server Port