3.10 Viewing the Advisor Data

The Advisor provides a cross-reference between real-time intrusion detection systems attack signatures and the Advisor's knowledge base of vulnerabilities. The Advisor feed has an alert and attack feed. The alert feed contains information about vulnerabilities and viruses. The attack feed lists the exploits associated with vulnerabilities. The Advisor data is updated on a regular basis if you have opted for the optional Advisor data subscription service.

The supported intrusion detection systems are listed in Section 9.0, Advisor Usage and Maintenance.

To View Advisor Data:

  1. In a Real Time Event Table of the Navigator or Snapshot, right-click an event or a series of selected events, then click Analyze > Advisor Data.

    If the DeviceAttackName field is properly populated, a report similar to the one below displays. This example is for a WEB-MISC amazon 1-click cookie theft.