Viewing detections

The Detections tab of Kaspersky CyberTrace Web displays information about the incoming events that have produced detections in Kaspersky CyberTrace, including source events and detection events. You can use this tab to search events and filter them by criteria. The Detections tab contains the following elements:

Searching in detections

You can use the search bar to perform a full-text search in detections. The text string in a search query is tokenized so that search results contain both exact and fuzzy matches. Wildcards are not supported. Search results are displayed in the table below.

If the Search also in detection events toggle button is switched on, Kaspersky CyberTrace will search for a text string in incoming events and detection events. Otherwise, it will search only in incoming events. By default, the Search also in detection events toggle button is switched on.

The table with information about detections contains the following columns:

Each row of the table contains information about one detection. You can click a detection to view the following detailed information:

Detections in the table are sorted by date and time, in descending order.

If the Auto-update table toggle button is switched on, Kaspersky CyberTrace updates the table with information about detections every 10 seconds.

Filtering detections

You can filter detections in the table by the following criteria:

To filter detections in the table by criteria:

  1. Click the column that you want to use as a filtering criterion.
  2. Specify the filtering condition, and then click Apply.

The content of the table is updated so that it contains only detections that meet the specified conditions.

You can specify several filtering criteria.

By default, filtering conditions are not applied.

Page top